Identity proves who is asking. Device posture answers a different and equally important question: is the device in a fit state to be trusted with access? An account can be perfectly valid while the device it is used from is out of date, unprotected, or managed by someone who should not reach regulated data. We configure posture checks so that this judgment is made consistently rather than left to chance.

J1 · INPUT

Signals we consider

  • Whether the device is enrolled and managed, and by which authority.
  • Operating system version and whether current security updates are applied.
  • Presence and currency of endpoint protection.
  • Disk encryption state.
  • Jailbreak or tampering indicators where the platform supports the check.
  • Compliance attestations from your existing management platform.

Posture is only useful if it is acted upon. We connect these signals to your access policy so that a healthy device follows a normal path, a questionable device is asked to remediate before continuing, and a device that cannot meet the bar is denied access to sensitive resources while remaining able to reach low-risk services where that makes sense. The goal is proportionate control: strict where it matters, reasonable everywhere else.

J2 · PRINCIPLE

Proportionate enforcement

Rigid posture rules applied to everyone create friction that pushes people to find workarounds. We prefer graduated enforcement aligned to resource sensitivity. An ordinary collaboration resource may accept a broad range of devices; a system holding personal or regulated data requires a managed, fully updated device. Graduation keeps the program livable while still protecting what needs protecting.

Ethernet network switches with status indicator lights and connected patch cables in a rack
Health is checked before connection, the way a switch verifies link state before forwarding traffic.

We also design the remediation path, because a denial without a way forward just generates support tickets. Users should be told, in plain language, what condition they failed and what to do about it: update the system, enroll the device, contact the service desk. Where self-service remediation is possible, we configure and document it. Where it is not, the service desk has a defined procedure that stays inside policy.

J3 · OPERATIONS

Keeping posture current

Posture is a moving target. Vendors change requirements, your management platform evolves, and new device classes appear. As part of ongoing operations we review the posture rule set each quarter, confirm that checks are still producing accurate signals, and adjust thresholds as the environment changes. Reports show how many sessions were allowed, remediated, or denied because of posture, so leadership can see whether the balance still matches the organization’s risk appetite.

Done well, posture control is nearly invisible to compliant users because their devices already satisfy the checks. It only becomes visible when something is genuinely wrong, which is exactly when you want it to be. If your organization manages devices today but does not yet use that signal in access decisions, connecting the two is one of the highest-value changes we make.