Device trust should match what is actually measured

"Managed device" is a claim about enrolment, not about health.

A device can be enrolled and still be missing updates, running unapproved software or already compromised. Policies that grant access on the basis of enrolment are checking a much weaker thing than they appear to. If device state is going to be part of an access decision, the decision should rest on what is genuinely being measured, not on the fact that the device is on a list.

More on Zero trust