SecOps

Device Posture

Device posture checks are evaluated at session initiation and can gate access to privileged sessions and high-sensitivity secrets. The posture agent (installed on the client endpoint) reports: OS version and patch level, full-disk encryption status, EDR agent presence and last check-in time, and certificate trust chain validation.

Posture results are cached with a configurable TTL. Policies define minimum requirements per workspace or session target; users on non-compliant devices receive a remediation prompt rather than an access denial.

Device Posture screenshot

Key Configuration

  • Posture agent endpoint
  • Check TTL (minutes)
  • Required OS patch age (days)
  • EDR vendor allowlist
  • Remediation redirect URL
All documentation Question about this? Talk to us