- Quick Links
- Highlights
- MFA
- SSO
- Adaptive authentication
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- ADSelfService Plus Identity security with adaptive MFA, SSPR, and SSO
- Exchange Reporter Plus Exchange Server Auditing & Reporting
- EventLog Analyzer Real-time Log Analysis & Reporting
- M365 Manager Plus Microsoft 365 Management & Reporting Tool
- DataSecurity Plus File server auditing & data discovery
- RecoveryManager Plus Enterprise backup and recovery tool
- SharePoint Manager Plus SharePoint Reporting and Auditing
- Identity360 A cloud-native identity platform for workforce IAM
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
Why device authentication is a necessity for modern IAM
As workforces grow more distributed, securing access at the device level has become critical. Device authentication ensures that trusted users can only access authorized Windows, macOS, and Linux systems, whether in the office or from a remote location. With ManageEngine Identity Access, organizations can unify and manage device logins through a centralized Universal Directory, streamlining access while maintaining strong, consistent security across all endpoints.
Unified device authentication across platforms
Ensuring the users and devices that log in to IT systems are legitimate typically comes at a cost: an entire reconfiguration to adapt to newer systems or plain lack of support. With Identity Access, you can achieve your ideal IAM solution without worrying about these obstacles.
Whether devices run Windows, macOS, or Linux, and whether they're domain-joined, cloud-native, or enrolled directly, Identity Access secures them equally, all from a single console.
What authenticators are used for device authentication in Identity Access?
Identity Access supports 11 unique and convenient authenticators that you can use to secure access to your devices and your device's access to your resources.
Phishing-resistant authenticators
- FIDO2 security key
- Platform biometrics (Windows Hello, Touch ID, Face ID)
- Smartcard
Software tokens
- Software TOTP
- HMAC-based OTP (HOTP)
Federated authenticators
- SAML 2.0 authentication
- Identity provider-based authenticators (Google, Microsoft 365)
What devices can you secure with device authentication?
Identity Access can secure every major desktop platform used in enterprises—Windows, macOS, and Linux—without requiring separate tools or configurations for each. It extends the same consistent authentication coverage to personal devices and non-standard endpoints like IoT devices, so no part of your device estate operates outside your security perimeter.
Which device join types are supported?
Identity Access works with how your devices are already managed, without any reconfiguration. Whether your endpoints live in Active Directory, Microsoft Entra ID, or are yet to be joined in an IAM, authentication policies apply consistently across the board.
Active Directory-joined devices
Devices registered and managed through on-premises Active Directory can be secured by Identity Access. It layers modern MFA and passwordless methods on top of your existing Active Directory infrastructure without disrupting domain policies.
Hybrid-joined devices
Identity Access can authenticate and resolve devices co-managed across both Active Directory and Microsoft Entra ID. This is ideal for organizations midway through a cloud migration.
Microsoft Entra ID-joined devices
Identity Access offers support for Microsoft Entra ID-joined devices, making them eligible for modern authentication flows, even outside of Microsoft 365.
Identity Access-joined devices
Devices with no Active Directory or Microsoft Entra ID enrollments can still be secured by registering them to Identity Access. Purpose-built for organizations managing workgroup devices, contractor endpoints, or environments outside the Microsoft ecosystem, this helps organizations just starting out on their IAM journey secure identities from day one.
Local device accounts are automatically linked to cloud identities at enrollment, so users authenticate with a single set of credentials across every device they access.
How Identity Access makes device authentication easy
- Hybrid environments: Manage mixed OS environments from one central console with consistent authentication policies.
- Offline capability: Maintain secure access even when devices are disconnected from the internet with Identity Access's offline MFA implementation.
- Device enrollment: Bring new devices into the trust boundary through a guided enrollment flow. Audit, revoke, or update device access as your organization scales.
What actions can be secured across platforms?
Identity Access does not limit authentication to the login screen. Every action that could expose sensitive data or elevate access—remote sessions, admin prompts, file transfers, and privilege commands—can be secured with MFA across Windows, macOS, and Linux devices.
Windows device actions
- Login: Secure user logins with MFA.
- Unlock: Protect workstation unlocks.
- User Account Control: Verify identity before running admin-level tasks.
- Remote Desktop Protocol: Safeguard remote desktop sessions.
- Secure Shell (SSH) for CLI remote access: Ensure a secure command-line remote experience with MFA.
macOS device actions
- Login: Secure user logins with MFA.
- Unlock: Add an authentication layer to device unlocks.
- SSH for CLI remote access: Control command-line remote access with MFA.
- SFTP/SCP: Protect file transfer protocols with identity verification.
- Admin elevation prompts: Secure reauthentication prompts for sensitive actions.
- sudo/su: Verify users before elevating to root or admin privileges.
Linux device actions
- Login: Require strong authentication at login.
- Unlock: Secure device unlocks with MFA.
- SSH for CLI remote access: Protect remote access via CLI with authentication.
- SFTP/SCP: Ensure secure file transfer protocols.
- Admin elevation prompts: Enforce MFA for privileged actions.
- sudo/su: Protect root access commands with authentication.
Device authentication built for Zero Trust
For device authentication to support a genuine Zero Trust architecture, it needs to do more than check a password at login. Identity Access treats every access request as untrusted by default, continuously validating who the user is, what device they're on, and whether that combination meets the bar required for the resource being accessed.
Identity and device binding
In a Zero Trust model, a valid username is not enough. Identity Access binds user identities to specific registered devices in Universal Directory, so authentication requires both a verified identity and a trusted endpoint.
Never trust, always verify
Trust granted at login doesn't carry forward indefinitely. Identity Access continuously evaluates session context and can trigger step-up authentication whenever risk signals deviate from the norm, like a new location, unusual access pattern, or risky action.
Adaptive risk-based access
Not every session carries the same risk, and a fixed authentication policy treats them all the same way. Identity Access's conditional access evaluates real-time signals such as device posture, network context, user behavior, and login history to adjust the authentication requirement dynamically. Low-risk sessions stay convenient while high-risk sessions get challenged.
FAQ
Device authentication verifies the identity of a device attempting to access organizational resources. It ensures only authorized devices running Windows, macOS, or Linux can log in, enhancing security beyond user credentials.
Centralized device authentication consolidates the management of all devices and user identities into a single Universal Directory. This simplifies administration, improves visibility, and allows consistent enforcement of security policies across all endpoints.
Yes. ManageEngine Identity Access supports device authentication for Windows, macOS, and Linux, enabling seamless and unified security across mixed OS environments.
Yes. You can configure passwordless policies based on conditional access rules, allowing granular control over who uses which authentication method.
Other features
MFA
Add a second authentication factor to endpoint, application, VPN, OWA, and CLI logins. with authentication factors ranging from FIDO2 security keys to smartcards.
SSO
Give users one-click entry to every cloud application using a single set of credentials.
Passwordless authentication
Replace passwords with FIDO2 security keys and platform biometrics, removing the credential most often phished and replayed.
Conditional access policy
Evaluate every access request against user, device, IP address, geolocation, time, and operating system, then allow, deny, or challenge it accordingly.
Machine MFA
Verify identity at the Windows, macOS, and Linux login screen on both domain-joined and cloud-joined machines.
MFA for enterprise apps
Set MFA and access rules for each application on its own terms, so that critical applications carry a stronger challenge and routine ones stay quick.