TrustFlare Access · Patterns without a device decision

The laptop is the hole.
Most stacks still ignore it.

SSO answers who signed in. It does not answer which computer did. Until that question is in the sign-in path, teams invent substitutes: VPN, MDM, spreadsheets, exceptions. Each one fails in a different place.

This is what it looks like from the inside.

If they can VPN, they can work.

The stolen laptop still has a password manager and a live tunnel.

Contractors will just use MDM.

They will not. The exception becomes the real fleet.

We revoked the account.

The application session on the device is still open.

01

VPN as the device check

The tunnel proves the person knew a secret, or still had a certificate from last year. It does not prove the computer is one you would let hold customer data. Once the tunnel is up, every app behind it inherits that guess.

How it shows up

  • A home PC with a saved password joins the same network as the work laptop.
  • Split-tunnel exceptions quietly widen until the VPN is a convenience, not a gate.
  • Incident response starts with “who was on the VPN”, not “which machine”.

02

MDM for everyone, or for no one

MDM is a strong control for company-owned machines. It is a political fight for contractors, personal laptops and short projects. Teams then choose: block the work, or let those people in with nothing but the SSO cookie.

How it shows up

  • BYOD is “temporarily” exempt and still exempt two years later.
  • Agencies refuse an MDM profile, so they get a shared jump host — or a personal Mac.
  • Security writes a policy that only the employed fleet can satisfy.

03

A spreadsheet of approved laptops

Someone keeps a list of serials, asset tags or MAC addresses. It is stale the week a machine is reimaged, sold, or borrowed. The list is not in the sign-in path, so nothing enforces it at 9:14 on a Monday.

How it shows up

  • Finance still has last year’s leavers in the “approved” tab.
  • A contractor’s personal laptop is added by Slack message and never removed.
  • Nobody can say whether the computer in front of GitLab is on the list.

04

Contractors as a permanent exception

The policy was written for employees. Everyone else is a ticket. Tickets accumulate. The real access path for the people who touch production most often is the one with the fewest checks.

How it shows up

  • A vendor gets a “guest” IdP account with the same apps as staff.
  • Short-term help uses a shared admin browser profile.
  • Offboarding the person is a process. Offboarding their computer is not.

05

You disabled the person. The computer still belongs.

A lost laptop is often answered by disabling the user in the directory. That punishes every other machine they still need. The useful lever is to revoke that computer and leave the person able to sign in from an approved one. Access does that for the next protected sign-in. It does not close an application tab that is already open — that session is the app’s.

How it shows up

  • A contractor is blocked in the IdP so they cannot finish the week from the office Mac.
  • VPN is cut. The same account still gets a new SSO session from the stolen laptop.
  • Security wants one device gone. HR only has a user toggle.

06

Conditional access that never sees the machine

The IdP can ask for MFA, a group, a country. It still does not know whether this is the work laptop or a family iPad with the password manager. “Trusted location” and “managed app” are not a computer.

How it shows up

  • MFA is satisfied from a phone while the session runs on an unknown PC.
  • Impossible-travel alerts fire. Nobody can say which computer it was.
  • Admins argue about geo and risk scores instead of a device policy.

07

Any computer with the password is a work computer

SSO asks who is signing in. It does not ask where. A home PC, a partner’s laptop or a hotel machine with a password manager is the same person as far as the IdP is concerned. Access refuses that computer unless policy has approved it.

How it shows up

  • An employee finishes a ticket from the kitchen Mac.
  • A password manager fills work SSO on a friend’s notebook.
  • Finance logs into the ERP from a personal iPad because the battery died.

08

Waiting for perfect hardware

The plan is FIDO keys, new laptops, Secure Enclave everywhere. Procurement slips. Meanwhile the fleet signs in with passwords. Hardware-backed keys matter; they are not a reason to have no device check on the machines you already own.

How it shows up

  • A project stalls until “we refresh the fleet”.
  • Old hardware is declared out of scope and keeps the production VPN.
  • A few executives get keys. Everyone else is “phase two”.

09

One policy for every chip

Either you demand in-chip signing and lock out older machines, or you accept software keys everywhere and give away the stronger path. The useful move is a policy that knows both classes and still names the device.

How it shows up

  • Windows 10 boxes cannot join, so people RDP into a blessed VM and call it compliance.
  • macOS with Enclave is treated the same as a VM with a file on disk.
  • Security cannot explain the difference in an incident without a screenshot of the agent.

Ask the computer, not the spreadsheet.

TrustFlare Access adds a device decision to the SSO you already run. Company-owned and personal machines. No mandatory MDM. Hardware-backed when the chip can.

See TrustFlare Access