Skip to main content

Endpoint Security

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.

What is Endpoint Security?

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services. Endpoints include laptops, desktops, servers, phones, tablets, and connected devices. Controls can include inventory, secure configuration, patching, local access control, disk encryption, host firewalls, malware protection, telemetry, and response. Endpoint security is broader than antivirus, and a managed endpoint is not permanently trusted.

Why it matters

An endpoint handles credentials, sessions, code, and data at the edge of a service. A compromised or unmanaged endpoint can misuse valid access and become a path to other resources.

How it works

  1. Inventory and enroll endpoints, assign an owner, and apply a secure configuration for each device type and risk level.
  2. Maintain patches and protective controls, collect current security signals, and compare each endpoint with policy.
  3. Restrict, isolate, repair, or retire an endpoint when it becomes vulnerable, noncompliant, lost, or compromised.

Example

A managed laptop reports that disk encryption is active and required patches are installed. Endpoint detection later finds malicious activity, isolates the laptop, and marks it noncompliant so protected access is denied.

Pomerium boundary

Pomerium Enterprise can use FleetDM as an external data source and deny a route request when a matched device has specified vulnerabilities or fails Fleet policy. Pomerium is the access-policy enforcement point in this design. Fleet and other endpoint tools collect state and perform endpoint protection and response.

Limits and non-claims

  • A device signal can be stale, missing, incorrectly mapped, or unavailable during an outage.
  • Some personal, legacy, and connected devices cannot support the same management and detection controls.
  • Endpoint security does not replace user authorization, network controls, or application and server security.

Evaluation checklist

  • Which endpoints are inventoried, managed, measured, and allowed to reach the resource?
  • Can a user or process tamper with posture signals or keep stale compliant state?
  • Which direct path, recovery mode, or sensor failure can bypass endpoint enforcement?

Sources and further reading

Keep learning

Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo