Device Trust
Device Trust is a security concept in which not only the identity of the user but also the state and trustworthiness of the device used are verified. The aim is that only compliant and secure devices gain access to corporate resources.
Signals such as operating system and patch level, activated encryption, existing endpoint protection, device certificates and the management status via MDM or UEM systems are evaluated for this purpose. On this basis, graduated policies can be defined: a managed, compliant device receives full access, an unknown or conspicuous device only restricted access or additional checks.
Device trust is particularly relevant for remote work and BYOD (bring your own device), because corporate data is processed there on devices outside the classic network perimeter. As a context signal alongside identity, the device state is a central element of Zero Trust: access is not granted by default but decided per request on the basis of user, device and risk – a foundation of effective Identity Security.