Manage Users & Devices Inventory
- Last validated: Jul 15, 2026
Managing your users and devices inventory
This section covers how Cloud Secure Edge (CSE) draws users from your identity providers, enrolls and evaluates the devices those users work from, and manages the lifecycle of both.
Access decisions in CSE depend on knowing who a user is and what device they are using. Rather than maintaining a separate directory, CSE connects to the identity provider and device management tools you already run, so that user identity and device state stay authoritative in their source systems.
How it works
- You connect one or more identity providers (for example, Entra ID, Active Directory, Okta, Google Workspace, Duo, or another SAML IdP) so that users authenticate with their existing credentials.
- Users register their devices with CSE, typically through the desktop app or an invite code, and CSE distinguishes registered devices from unregistered ones.
- CSE evaluates each device’s trust, using device trust verification, certificate-based authentication, and integrations with device managers such as Intune, Jamf Pro, Kandji, JumpCloud, and Workspace ONE UEM.
- Administrators manage the ongoing lifecycle of users and devices, including de-registering or banning devices and archiving or deleting users.
Tip: If you are getting started, begin with Set up Directory to connect your first identity provider and add users.
Sections
Grant Access to 3rd-Party Contractors Using Entra ID B2B
Entra Licensing for CSE security functions
Grant Access to 3rd-Party Contractors Using Google Workspace
Install the Desktop App for Windows (MSI)
Install the Desktop App via Zero Touch Script (EXE)
Workspace ONE UEM - Device Identity & Enhanced Trust Scoring
Device Identity Using Pre-Installed Device Certs
Invite Code and Device Enrollment
Registered & Unregistered Devices
Certificate-based Multi-Factor Authentication
Silent Certificate Authentication for User Sessions
Allowlist CSE app in AV/EDR Solutions