What is Device Posture?
Device posture is the current security state of a device. Signals can include device identity, management state, operating-system version, encryption, screen lock, endpoint protection, and known vulnerabilities. An access policy can use these signals when it evaluates a request. Posture data can become stale, so the system must define how it collects, refreshes, and trusts each signal.
Why it matters
A valid user account can still make a risky request from an unmanaged, compromised, or outdated device. Current device signals give authorization policy facts beyond user identity.
How it works
- A trusted device, management service, or security tool collects defined posture signals and associates them with the device or user.
- The access system checks signal origin, freshness, and required values when it evaluates the request.
- The enforcement point permits, restricts, or denies access and reevaluates the posture when policy or signals change.
Example
A policy allows access to a production console only when the user is in the operations group and the current device record reports management enrollment, disk encryption, and an approved operating-system version.
Pomerium boundary
Pomerium can combine identity claims, device identity, and external data when it evaluates route policy. Pomerium Enterprise can use FleetDM host data, vulnerability data, and policy results for device-posture checks, with a client certificate linking the request to a Fleet host. WebAuthn provides device identity, but it does not provide full operating-system posture.
Limits and non-claims
- A signal can be stale, incomplete, forged, or incorrectly linked to the current device.
- A compliant posture result does not prove that the device is free from compromise.
- Strict posture policy can block legitimate users when collection, enrollment, or the posture provider fails.
Evaluation checklist
- Which device identity and posture signals are authoritative for this decision?
- How fresh must each signal be, and what happens when it is missing or conflicts?
- Can an unmanaged device, direct route, or unsafe enrollment path bypass the check?
