What Is Device Posture?

Also called: Device health, Endpoint posture

Related problems: Staff signing in from unpatched personal laptops; Can't block access from devices without encryption or endpoint protection; Zero trust project needs to check the device, not just the user; Auditors asking how we know which devices can reach company data

Device posture is the security condition of a device, such as a laptop, phone or tablet, at the moment it asks to reach company applications or data. It covers things like whether the operating system is up to date, the disk is encrypted, endpoint protection is running and the device is managed by the company. Access systems check device posture and use the result, alongside who the user is, to decide whether to allow, limit or block access.

At a glance

  • Device posture describes how healthy and trustworthy a device is from a security point of view.
  • Typical attributes include patch level, encryption, endpoint protection status, screen lock and whether the device is company-managed.
  • It is a core input to zero trust access decisions, alongside user identity and context.
  • Posture data usually comes from device management or endpoint security tools, or from an agent on the device.
  • Failing a check can mean blocked access, limited access or a prompt to fix the problem, depending on policy.

What problem it solves

A correct username, password and second factor prove who someone is, but not what they are using. A legitimate employee on an unpatched, unencrypted home computer infected with malware can still expose company data. With remote work and personal devices, IT often can’t assume that whatever connects is safe.

Checking device posture closes that gap. Access policies can require, for example, that only encrypted, up-to-date, company-managed laptops reach sensitive systems, while other devices get restricted or browser-only access. That reduces the chance that a compromised or poorly maintained device becomes the way in, and it gives auditors evidence that access depends on device health.

How it works

Gathering posture data. Information about the device comes from a mobile device management (MDM) or unified endpoint management platform, from endpoint detection and response software, or from an agent installed by the access product itself. Some checks can be done in the browser, though these tend to be more limited.

Defining policy. Administrators decide which attributes matter for which resources: for example, a minimum operating system version for email, plus disk encryption and running endpoint protection for finance systems.

Evaluating at access time. When a user connects, the access system, such as zero trust network access (ZTNA), an identity provider’s conditional access rules or network access control (NAC) on the office network, checks the device’s posture against policy.

Enforcing the result. The device is allowed, given reduced access or blocked. Some products reassess posture continuously during a session and can cut access if, for instance, endpoint protection is turned off.

Remediation. Users are told what to fix, and the device is checked again once it is compliant.

When it matters for buyers

  • When rolling out zero trust, ZTNA or security service edge. Device posture is one of the main signals these products use. Our security service edge overview covers how these platforms apply access policy.
  • When allowing bring your own device (BYOD). Posture checks help decide what personal devices may reach.
  • When cyber insurers or auditors ask about endpoint controls. Showing that access depends on encryption and endpoint protection is useful evidence.
  • When choosing device management and access tools. Check that they share posture data with each other; otherwise the checks may be limited to what one tool can see.
  • When contractors and third parties need access. Unmanaged devices usually need a different, more limited access path.

Questions to ask vendors

  • Which posture attributes can you check on Windows, macOS, iOS, Android and Linux?
  • Do you need your own agent, or can you use data from our device management and endpoint security tools?
  • How often is posture re-evaluated, and how quickly is access changed when a device falls out of compliance?
  • How do you handle unmanaged and personal devices?
  • What does the user see when a check fails, and how do they fix it themselves?
  • Can we report on which devices passed or failed, and why, over time?

How it differs from security posture

Security posture describes the overall strength of an organization’s defenses: its controls, processes, people and exposure across the whole environment. Device posture is much narrower: the security state of one device at the moment it requests access. Device posture checks contribute to a stronger overall security posture, but they are a specific access control, typically enforced automatically each time a device connects, rather than an organization-wide assessment.

Frequently Asked Questions

What does a device posture check usually look at?
Common checks include operating system version and patch level, disk encryption, screen lock, whether endpoint protection or EDR is installed and running, firewall status, whether the device is managed by the company and whether it has been jailbroken or rooted. Which checks are available depends on the platform and the device's operating system.
Can device posture be checked on personal devices?
Partly. Some checks need a management profile or agent the employee may not want installed. Many organizations give unmanaged or personal devices limited access, such as browser-only access to certain apps, and reserve full access for managed devices that pass posture checks.
Is device posture checked only at sign-in?
It depends on the product. Some tools check only when a user signs in or connects; others reassess continuously or at intervals and can cut access if a device falls out of compliance. Ask how often posture is re-evaluated and how quickly a change takes effect.
What happens when a device fails a posture check?
That is set by policy. Typical options are blocking access, allowing limited access, or prompting the user to fix the problem, for example by installing updates, and then re-checking. Clear messages to users reduce help desk calls.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.