Skip to main content
Guidance

Multi-factor authentication for your corporate online services

Advice on implementing strong methods of MFA for accessing corporate online services.

Page 5 of 7

Gaining trust in devices

iStock.com/Abdul Basit Noohani

Trusted devices are the critical link in strong authentication. You need trust in your devices to make strong MFA achievable (and easier). For example, the strength of assurance provided by FIDO2 and authenticator app credentials are largely underpinned by the trust of the user’s device.

Your organisation’s IT model should make some statements about the devices that you know about, and how much you trust them with accessing your corporate services. This includes static workstations on-premises and, increasingly, mobile devices that roam with your users. Trustworthy devices can:

  • effectively narrow down where a credential is permitted to be used from, strengthening the authentication provided
  • allow organisations to separate out user-to-service authentication into two separate functions: user-to-device and device-to-service


Reviewed

Version

2.0