Device posture is the security condition of a device, such as a laptop, phone or tablet, at the moment it asks to reach company applications or data. It covers things like whether the operating system is up to date, the disk is encrypted, endpoint protection is running and the device is managed by the company. Access systems check device posture and use the result, alongside who the user is, to decide whether to allow, limit or block access.
At a glance
- Device posture describes how healthy and trustworthy a device is from a security point of view.
- Typical attributes include patch level, encryption, endpoint protection status, screen lock and whether the device is company-managed.
- It is a core input to zero trust access decisions, alongside user identity and context.
- Posture data usually comes from device management or endpoint security tools, or from an agent on the device.
- Failing a check can mean blocked access, limited access or a prompt to fix the problem, depending on policy.
What problem it solves
A correct username, password and second factor prove who someone is, but not what they are using. A legitimate employee on an unpatched, unencrypted home computer infected with malware can still expose company data. With remote work and personal devices, IT often can’t assume that whatever connects is safe.
Checking device posture closes that gap. Access policies can require, for example, that only encrypted, up-to-date, company-managed laptops reach sensitive systems, while other devices get restricted or browser-only access. That reduces the chance that a compromised or poorly maintained device becomes the way in, and it gives auditors evidence that access depends on device health.
How it works
Gathering posture data. Information about the device comes from a mobile device management (MDM) or unified endpoint management platform, from endpoint detection and response software, or from an agent installed by the access product itself. Some checks can be done in the browser, though these tend to be more limited.
Defining policy. Administrators decide which attributes matter for which resources: for example, a minimum operating system version for email, plus disk encryption and running endpoint protection for finance systems.
Evaluating at access time. When a user connects, the access system, such as zero trust network access (ZTNA), an identity provider’s conditional access rules or network access control (NAC) on the office network, checks the device’s posture against policy.
Enforcing the result. The device is allowed, given reduced access or blocked. Some products reassess posture continuously during a session and can cut access if, for instance, endpoint protection is turned off.
Remediation. Users are told what to fix, and the device is checked again once it is compliant.
When it matters for buyers
- When rolling out zero trust, ZTNA or security service edge. Device posture is one of the main signals these products use. Our security service edge overview covers how these platforms apply access policy.
- When allowing bring your own device (BYOD). Posture checks help decide what personal devices may reach.
- When cyber insurers or auditors ask about endpoint controls. Showing that access depends on encryption and endpoint protection is useful evidence.
- When choosing device management and access tools. Check that they share posture data with each other; otherwise the checks may be limited to what one tool can see.
- When contractors and third parties need access. Unmanaged devices usually need a different, more limited access path.
Questions to ask vendors
- Which posture attributes can you check on Windows, macOS, iOS, Android and Linux?
- Do you need your own agent, or can you use data from our device management and endpoint security tools?
- How often is posture re-evaluated, and how quickly is access changed when a device falls out of compliance?
- How do you handle unmanaged and personal devices?
- What does the user see when a check fails, and how do they fix it themselves?
- Can we report on which devices passed or failed, and why, over time?
How it differs from security posture
Security posture describes the overall strength of an organization’s defenses: its controls, processes, people and exposure across the whole environment. Device posture is much narrower: the security state of one device at the moment it requests access. Device posture checks contribute to a stronger overall security posture, but they are a specific access control, typically enforced automatically each time a device connects, rather than an organization-wide assessment.
