Multi-factor authentication for your corporate online services
Page 5 of 7
Gaining trust in devices

Trusted devices are the critical link in strong authentication. You need trust in your devices to make strong MFA achievable (and easier). For example, the strength of assurance provided by FIDO2 and authenticator app credentials are largely underpinned by the trust of the user’s device.
Your organisation’s IT model should make some statements about the devices that you know about, and how much you trust them with accessing your corporate services. This includes static workstations on-premises and, increasingly, mobile devices that roam with your users. Trustworthy devices can:
- effectively narrow down where a credential is permitted to be used from, strengthening the authentication provided
- allow organisations to separate out user-to-service authentication into two separate functions: user-to-device and device-to-service
User-to-device authentication
The user first has to authenticate themselves to a device. This will need to be robust and rely on more than just a password. For example:
- the initial ‘bootstrap’ authentication to the device requires multiple factors to register and bind the identity of a user to the device. For example, a user password plus existing MFA app, or hardware security key plus its PIN.
- ongoing authentication where the user’s registered device can now become a trusted possession factor of their authentication, so subsequent authentication can be simpler and still multi-factor. For example, using a biometric or PIN bound to that device.
Device-to-service authentication
Once a trusted device can authenticate its user, it can store a credential and use it to authenticate to online services on their behalf. This will include the identity of the device as well as the identity of the user to bring some of the security benefits of zero trust architectures.
The critical link between a user authenticating to the device, and that being passed to online services is that the device has to be trusted enough to store and protect the user’s digital identity. That trust can only be gained if the device has been configured to include appropriate mitigations. Whichever management model you use, you will need to be confident that the device and apps on it have been designed to use secure credential storage. Some examples of common credential storage options on modern devices include:
- Keychain on iOS, iPadOS, and macOS
- Windows Hello for Business
- Identity-as-a-Service authenticator apps (such as Google Prompts, Microsoft Authenticator, Okta Mobile, and PingID)