Skip to main content
See All Integrations

Fleet (FleetDM)

Use the Pomerium Enterprise FleetDM plugin to evaluate Fleet device policy and vulnerability data during access decisions.

First-party Pomerium Enterprise FleetDM plugin

Category
Device Management

Overview

Fleet, formerly FleetDM, is a device management and security platform built on osquery. Pomerium Enterprise has a documented FleetDM plugin that can add selected policy and vulnerability data to access decisions.

Selected Fleet data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium Enterprise supplies the documented Fleet data source. Pomerium evaluates its records as request context before it sends approved traffic to the protected service.

How it works

Run the Pomerium Enterprise FleetDM plugin with the Fleet API URL, token, and certificate query. Import the external data source and certificate authority. Require a client certificate on the route and attach the reviewed FleetDM deny criteria.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

A managed host presents a private-CA client certificate to Pomerium. The FleetDM plugin maps its certificate fingerprint to the enrolled host record. Pomerium denies access when the selected Fleet policy or vulnerability criteria match.

Considerations

  • The documented FleetDM criteria support deny actions only.
  • Fleet state syncs on a polling schedule. It is not live per-request telemetry.
  • The documented mkcert setup is for testing. Production needs a managed private certificate authority.
  • Pomerium does not manage or remediate Fleet devices.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A vendor device or asset ID does not prove which device made the current Pomerium request.

Sources and official resources

  • Use selected Jamf Pro device data in Pomerium policy through a custom external data source.

  • Use selected Microsoft Intune device data in Pomerium policy through a custom external data source.

  • Use selected CrowdStrike Falcon data in Pomerium policy through a custom external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo