Skip to main content

Device Posture Check Overview

What is Device Posture Check?

Device Posture Check is a set of conditions that the SSE will check against, before allowing the Connector to connect with the service. A non-complaint device will not be able to access the resources behind the Connector as well. Its important to note that on the SSE platform, Device Posture policies are only created in this menu, but they are applied elsewhere.Device-Posture-란.jpg


Device Posture Menu

This guide will give an overview of the Device Posture menu.

image.png

SearchAllows for filtering of the different profiles based on name, rule or description
CreateOpens the create menu in order to create a new posture check
CheckboxUsed in conjunction with the delete button in order to delete one or multiple selected device postures
EditAllows for the editing of the specified posture check, opening up the “create” menu prefilled with the rules current information

To create a policy, click the Create button on the top right part of the console.


Device Posture Create Menu

This form is used to create new device posture check policies:

image.png

Below is a list and description of each condition for the device posture check:

AttributeAttribute InfoConditionsValue Information
Anti-VirusChecks the status of Anti-Virus softwareisis not
File PathChecks whether the file path provided in the value exists on the machineinnot in
ProcessChecks whether a specified process is currently runninginnot in
OS VersionChecks the version number of the OS on the deviceinnot in
FirewallChecks the status of the OS Firewallisis not
CertificateChecks the installed certificates on the deviceinnot in
AD DomainChecks the AD Domain(Windows only)innot in
Device SerialChecks the exact serial number of the deviceinnot in

Applying Device Posture Check

Simply creating the policy in the posture check menu doesn't activate the policy. It instead creates the policy which can subsequently be applied in other parts of the SSE. This section will show the section where DPC can be applied.

ZTNA Access Control

image.png

The main current location to apply DPC is in ZTNA Access Control. When setting up a policy, selecting Device Posture Check will force all devices to make the check first before seeing if they can access the resource.