Device Security Posture Checks

Device Security allows you to define trusted devices and incorporate those definitions into Security Policies for your Network or for individual Resources. As part of this, the Twingate desktop and client applications perform device posture checks to enforce basic trust definitions.

The settings that are supported by Device Security are specific to each platform.

Windows

Posture checkWhat it reports
Hard drive encryptionIf the system disk and other disks are encrypted by BitLocker
Screen lockIf a password is required when returning from screen saver via WinAPI function LogonUser
FirewallIf the firewall (Windows or third party) is enabled, as confirmed by the Windows Security Center
AntivirusIf antivirus (Windows or third party) is installed, as confirmed by the Windows Security Center

macOS

Posture checkWhat it reports
Screen lockIf a password is required after sleep or screen saver begins
Biometric configurationIf either Touch ID or Face ID is configured
Note: If the device lid is closed (clamshell mode), the device will always report that biometric configuration is disabled regardless of true configuration status
FirewallIf the firewall (native only) is enabled
Note: Currently, if the device has “Block all incoming connections” enabled, the device reports that firewall is disabled. A fix for this will be available in the next standalone client release.
HD EncryptionIf FileVault is on
(Available only in the macOS standalone Client)

Linux

Posture checkWhat it reports
FirewallIf UFW, firewalld, or iptables firewalls are enabled (valid on Debian / Ubuntu, Centos / Fedora, and Arch Linux)
Hard drive encryptionIf all partitions except /boot are encrypted (LUKS encryption) via the libcryptsetup library

iOS

Posture checkWhat it reports
Screen lockIf a password is required on the device
Biometric configurationIf either Touch ID or Face ID is configured

Android

Posture checkWhat it reports
Screen lockIf a screen lock is configured, regardless of type
Biometric configurationIf a biometric login has been configured (either fingerprint or facial recognition)
Hard drive encryptionIf the hard drive is encrypted using File-Based Encryption
AntivirusIf Play Protect is enabled as determined by the App Settings Activity

Last updated 2 months ago