TrustFlare Access · What's broken

The account is approved.
Is the computer?

Your team may approve which computers can access work apps. The question is whether sign-in checks that approval—and what happens when a laptop is lost, replaced or used by a contractor.

One person. Two computers.
Same work account
Work laptopApproved deviceSign-in allowed
Other laptopNot approvedSign-in refused
Example policy for a new protected sign-in.

01

Approval lives outside sign-in

IT has an approved-device list, but application access does not consult it.

How it shows up

  • A new laptop reaches company apps before IT approves it.
  • A laptop removed from the approved list can still start a new sign-in.

02

A network rule stands in for a device rule

A permitted connection is treated as sufficient evidence that the computer is permitted too.

How it shows up

  • An unknown laptop signs in from the office network.
  • A VPN user reaches an app without a separate device decision.

03

Contractor access starts with an exception

A policy designed for company laptops leaves personal and supplier devices without a workable path.

How it shows up

  • A contractor cannot accept company MDM.
  • A short project gets an exemption with no expiry.

04

One lost laptop becomes an account-wide problem

The response process can disable a person but has no clear way to reject one computer.

How it shows up

  • An employee needs to work from a replacement laptop.
  • A contractor’s old device still qualifies for new sign-ins.

05

Approved is mistaken for healthy

Teams use one label for device identity, key protection and endpoint health.

How it shows up

  • An approved laptop misses security updates.
  • Software-stored keys are treated as hardware-backed keys.

Make approval part of sign-in.

TrustFlare Access adds a device decision to your existing SSO. Start with the apps and device policies you need to enforce.

See TrustFlare Access