Device trust should match what is actually measured
"Managed device" is a claim about enrolment, not about health.
A device can be enrolled and still be missing updates, running unapproved software or already compromised. Policies that grant access on the basis of enrolment are checking a much weaker thing than they appear to. If device state is going to be part of an access decision, the decision should rest on what is genuinely being measured, not on the fact that the device is on a list.
More on Zero trust
- Zero trust removes implicit trust in network position, not confidence in colleaguesIt was never about the people
- Continuous evaluation means decisions can changeYes is not for ever
- Policy enforcement depends on reliable identity signalsRight rule, smudged label
- Zero trust does not remove network controlsKeep the fence
- Service-to-service traffic needs identity tooMachines need names too
- Policy engines create critical dependenciesOne box, every door
