If they can VPN, they can work.
The stolen laptop still has a password manager and a live tunnel.
TrustFlare Access · Patterns without a device decision
SSO answers who signed in. It does not answer which computer did. Until that question is in the sign-in path, teams invent substitutes: VPN, MDM, spreadsheets, exceptions. Each one fails in a different place.
If they can VPN, they can work.
The stolen laptop still has a password manager and a live tunnel.
Contractors will just use MDM.
They will not. The exception becomes the real fleet.
We revoked the account.
The application session on the device is still open.
01
The tunnel proves the person knew a secret, or still had a certificate from last year. It does not prove the computer is one you would let hold customer data. Once the tunnel is up, every app behind it inherits that guess.
How it shows up
02
MDM is a strong control for company-owned machines. It is a political fight for contractors, personal laptops and short projects. Teams then choose: block the work, or let those people in with nothing but the SSO cookie.
How it shows up
03
Someone keeps a list of serials, asset tags or MAC addresses. It is stale the week a machine is reimaged, sold, or borrowed. The list is not in the sign-in path, so nothing enforces it at 9:14 on a Monday.
How it shows up
04
The policy was written for employees. Everyone else is a ticket. Tickets accumulate. The real access path for the people who touch production most often is the one with the fewest checks.
How it shows up
05
A lost laptop is often answered by disabling the user in the directory. That punishes every other machine they still need. The useful lever is to revoke that computer and leave the person able to sign in from an approved one. Access does that for the next protected sign-in. It does not close an application tab that is already open — that session is the app’s.
How it shows up
06
The IdP can ask for MFA, a group, a country. It still does not know whether this is the work laptop or a family iPad with the password manager. “Trusted location” and “managed app” are not a computer.
How it shows up
07
SSO asks who is signing in. It does not ask where. A home PC, a partner’s laptop or a hotel machine with a password manager is the same person as far as the IdP is concerned. Access refuses that computer unless policy has approved it.
How it shows up
08
The plan is FIDO keys, new laptops, Secure Enclave everywhere. Procurement slips. Meanwhile the fleet signs in with passwords. Hardware-backed keys matter; they are not a reason to have no device check on the machines you already own.
How it shows up
09
Either you demand in-chip signing and lock out older machines, or you accept software keys everywhere and give away the stronger path. The useful move is a policy that knows both classes and still names the device.
How it shows up
TrustFlare Access adds a device decision to the SSO you already run. Company-owned and personal machines. No mandatory MDM. Hardware-backed when the chip can.
See TrustFlare Access