What is device authentication?
Device authentication verifies the identity of the machine making a connection, in addition to the user. Common methods are device certificates, checks that the device is enrolled in mobile device management (MDM), and mutual TLS (mTLS) between services. It supports zero trust access policies.
What the buyer is really asking
Beyond verifying the user, do you verify the device before allowing a connection? Device certificates, MDM compliance checks, or mutual TLS between services all count. If you check the user only, say that.
Other ways buyers ask it
Every one of these wants the same answer:
- “Is equipment identification used to authenticate connections?”
- “Do you restrict access to managed or registered devices?”
- “Do you use device certificates or mutual TLS?”
Evidence to have ready
- Device trust or conditional access policies in your identity provider
- mTLS configuration between services, if used
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.