Skip to content
Identity and access

The device is part of the access decision.

Device Access brings the endpoint into the authentication decision, so a login can require a known, compliant device rather than only a known person. Our work is policy design and the exception paths that decide whether it survives contact with contractors.

Device Access extends identity to the endpoint, so who is asking and what they are asking from are one decision rather than two.

What it is

Device Access brings the endpoint into the authentication decision, so a login can require a known, compliant device rather than only a known person.

What it does

Device as a factor

Access conditioned on a known endpoint rather than on the credential alone.

Where it fits

L1, identity and access. It narrows the gap between a credential and a person. Where an estate has strong authentication but no device signal, a stolen credential still works from anywhere.

Where it earns its place

An organization with contractors on unmanaged devices

The policy is easy for employees and hard for everyone else, which is where it needs design.

An estate hardening privileged paths

Requiring a managed device for administrative access is a high-value, narrow first step.

Questions we get

What about people without a managed device?
That is the design question. A policy with no workable exception path gets disabled within a month.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.