Manage Users & Devices Inventory

  • Last validated: Jul 15, 2026

Managing your users and devices inventory

This section covers how Cloud Secure Edge (CSE) draws users from your identity providers, enrolls and evaluates the devices those users work from, and manages the lifecycle of both.

Access decisions in CSE depend on knowing who a user is and what device they are using. Rather than maintaining a separate directory, CSE connects to the identity provider and device management tools you already run, so that user identity and device state stay authoritative in their source systems.

How it works

  1. You connect one or more identity providers (for example, Entra ID, Active Directory, Okta, Google Workspace, Duo, or another SAML IdP) so that users authenticate with their existing credentials.
  2. Users register their devices with CSE, typically through the desktop app or an invite code, and CSE distinguishes registered devices from unregistered ones.
  3. CSE evaluates each device’s trust, using device trust verification, certificate-based authentication, and integrations with device managers such as Intune, Jamf Pro, Kandji, JumpCloud, and Workspace ONE UEM.
  4. Administrators manage the ongoing lifecycle of users and devices, including de-registering or banning devices and archiving or deleting users.

Tip: If you are getting started, begin with Set up Directory to connect your first identity provider and add users.

Sections

Entra ID

Manual Configuration

Configure Device Registration

Enable SCIM for Entra ID

Grant Access to 3rd-Party Contractors Using Entra ID B2B

Entra Licensing for CSE security functions

Active Directory

Enable cert-based MFA

Okta

Enable SCIM for Okta

Google Workspace

Grant Access to 3rd-Party Contractors Using Google Workspace

Duo

Other IDPs

OneLogin

JumpCloud

SAML IDPs

Device Managers

Install the Desktop App for Windows (MSI)

Install the Desktop App via Zero Touch Script (EXE)

Distribute Chrome Extension

Intune

Jamf Pro

Kandji

JumpCloud

Workspace ONE UEM - Device Identity & Enhanced Trust Scoring

Device Identity Using Pre-Installed Device Certs

Invite Code and Device Enrollment

Registered & Unregistered Devices

Device Trust Verification

Certificate-based Multi-Factor Authentication

Silent Certificate Authentication for User Sessions

Passwordless Authentication

Enable App Auto Update

Enable Event Geolocation

Allowlist CSE app in AV/EDR Solutions

Customization and Support Messaging

Remote Diagnostics

Service Bundles

De-register and Ban Devices

Archive and Delete Users

Was this page helpful?