The device is part of the access decision.
Device Access brings the endpoint into the authentication decision, so a login can require a known, compliant device rather than only a known person. Our work is policy design and the exception paths that decide whether it survives contact with contractors.
Device Access extends identity to the endpoint, so who is asking and what they are asking from are one decision rather than two.
What it is
Device Access brings the endpoint into the authentication decision, so a login can require a known, compliant device rather than only a known person.
What it does
Device as a factor
Access conditioned on a known endpoint rather than on the credential alone.
Where it fits
L1, identity and access. It narrows the gap between a credential and a person. Where an estate has strong authentication but no device signal, a stolen credential still works from anywhere.
Where it earns its place
An organization with contractors on unmanaged devices
The policy is easy for employees and hard for everyone else, which is where it needs design.
An estate hardening privileged paths
Requiring a managed device for administrative access is a high-value, narrow first step.