Trust is a property of the device, not the person
REF ACC-EPT-500OWNER Endpoint DeskINPUTS Posture signals
A person with valid credentials on an unmanaged laptop is a different risk from the same person on a managed,
patched, encrypted device. Endpoint trust is how an access model tells the difference. We define what a trusted
device looks like in your organization, how that condition is measured, and what reach each trust level earns.
The goal is not to block people. It is to give the managed device a smooth path and to make the unmanaged one a
deliberate, visible exception with a shorter leash and a reason on file.
What we define
REF ACC-EPT-520LEVELS Three tiersCHECK At every session
- Trusted. Organization-managed devices meeting the baseline: current operating system, full-disk
encryption, screen lock, supported browser, and a healthy management agent. Full reach subject to identity
rules.
- Conditional. Devices that meet most of the baseline or belong to a vetted contractor. Reach is
narrowed to specific systems, sessions are recorded, and re-check happens at every connection.
- Untrusted. Unknown or personal devices. Only the minimum collaboration paths open, usually through a
controlled brokering point that keeps the session inside the governed environment rather than on the device.
Enforcement sits with the access broker: posture is checked when a session starts and rechecked during it.
When a device drifts out of policy, the response is defined in advance — step down, warn, or end the
session — rather than improvised in the moment.
Rolling it out to a real workforce
REF ACC-EPT-540WAVES By functionSUPPORT Service desk
Endpoint policy fails when it surprises people. We sequence the rollout by function, beginning with groups whose
work is already close to the baseline, and we publish a short guide for everyone else covering what to check and
who to ask. Exceptions are logged with an owner and an expiry date, and reviewed monthly, so the exception list
cannot quietly become the new normal.
The service desk is prepared before the first wave: scripts for the common questions, a clear path for
genuine exceptions, and a weekly report of who stepped down and why. That feedback loop is how the policy stays
realistic instead of drifting into a rule everybody quietly routes around.
Signals we watch
REF ACC-EPT-560SIGNALS Five coreCADENCE Continuous
Device baseline compliance percentage, count of conditional sessions, step-downs per week, exception list age,
and time-to-remediate after a device leaves policy. Each maps to a threshold and an owner, and each appears in
the monthly report alongside the decisions taken.
Deliverables · endpoint trust policy, posture baseline definition, enforcement configuration,
rollout waves, exception register and the monthly signal report.
Contractor devices deserve a particular mention. They rarely meet the same baseline as staff equipment, and
pretending otherwise leads to blanket exceptions. We instead define a conditional tier that names exactly which
systems a vetted contractor may reach, records every session, and expires the arrangement on a fixed date so that
a completed engagement does not leave a permanent way in.