Device Trust is a security system designed to verify a device's identity and health status before granting it access to an organization's applications and resources. It functions by performing real-time device posture assessments against a set of security policies. These policies can include checks for disk encryption, firewall status, and up-to-date software, with the ability to define custom checks. The system supports a range of operating systems, including Windows, macOS, Linux, iOS, and Android, and is applicable to managed, personal (BYOD), and third-party contractor devices. Access is blocked for any device that fails to meet the established compliance requirements.
The system secures access to both SSO-federated and non-SSO web applications by leveraging a device agent and a browser extension. It integrates with identity providers (IdPs) such as Okta, Microsoft Entra ID, and Google Workspace to enforce device posture checks at the point of authentication. For non-compliant devices, the system provides end-users with guided, step-by-step instructions to self-remediate the identified issues and regain access. This process operates independently of, but can be used in conjunction with, Mobile Device Management (MDM) solutions to enforce security policies without requiring full device enrollment.