I’ve added a few servers for testing to tag:backend using an auth key and --unattended tag for Windows machines. On the Windows servers, when I run a tailscale status I can see all of my untagged personal devices linked to my account.
I only want the machines in tag:backend to be able to see the tagged devices, without any of my devices, this server will be in a shared environment.
You’ll still see the machines listed in the status, but they’re not necessarily connected: that’s the dash in tha last column. For a connected machine you’ll see
active; direct {IP Address}, tx {number} rx {number}
You should find if you attempt to contact the machine from the tagged host (a ping to the tailscale address for example) it won’t work. They know the machines are in your network but cannot contact them.