Device Enrollment and Trust

How devices are registered with CSE and how their trustworthiness is assessed

  • Last validated: Oct 1, 2026

Overview

CSE grants access based on both the user and the device they are working from. These pages cover how a device becomes known to CSE, and how CSE establishes whether it can be trusted.

  • Invite Code and Device Enrollment covers how a device is first registered against an organization.
  • Managed, Registered, and Unregistered Devices defines the states a device can be in, and how access is configured for each.
  • Device Trust Verification covers establishing device trust on mobile devices and in authentication views that cannot use the CSE device certificate.

For the security standard a device must meet before access is granted, see Trust Scoring. To remove a device, see User and Device Lifecycle.

Pages in this section

Invite Code and Device Enrollment

Managed, Registered, and Unregistered Devices

Device Trust Verification

Was this page helpful?