TrustFlare Access · What's broken
The account is approved.
Is the computer?
Your team may approve which computers can access work apps. The question is whether sign-in checks that approval—and what happens when a laptop is lost, replaced or used by a contractor.
01
Approval lives outside sign-in
IT has an approved-device list, but application access does not consult it.
How it shows up
- A new laptop reaches company apps before IT approves it.
- A laptop removed from the approved list can still start a new sign-in.
02
A network rule stands in for a device rule
A permitted connection is treated as sufficient evidence that the computer is permitted too.
How it shows up
- An unknown laptop signs in from the office network.
- A VPN user reaches an app without a separate device decision.
03
Contractor access starts with an exception
A policy designed for company laptops leaves personal and supplier devices without a workable path.
How it shows up
- A contractor cannot accept company MDM.
- A short project gets an exemption with no expiry.
04
One lost laptop becomes an account-wide problem
The response process can disable a person but has no clear way to reject one computer.
How it shows up
- An employee needs to work from a replacement laptop.
- A contractor’s old device still qualifies for new sign-ins.
05
Approved is mistaken for healthy
Teams use one label for device identity, key protection and endpoint health.
How it shows up
- An approved laptop misses security updates.
- Software-stored keys are treated as hardware-backed keys.
Make approval part of sign-in.
TrustFlare Access adds a device decision to your existing SSO. Start with the apps and device policies you need to enforce.
See TrustFlare Access