← All controls

29 Device-trust CAA via MDM

Grants access to sensitive apps based on the state of the device it comes from, not just to the account. Endpoint verification collects posture signals — OS version, disk encryption, screen lock, admin-approval state, company-owned flag — into the Context-Aware Access attribute set, and an access level built from those attributes is applied through the three DEFAULT policies (all Google-owned apps, all SAML apps, all OAuth apps). The signals depend on the Endpoint Verification helper or Chrome extension has to be deployed and the user signed into the managed Chrome profile.

Caveats

Setup steps

  1. open ↗

    Devices › Mobile & endpoints › Settings › Universal › Security

    Device approvals = Require admin approval. Applies to user-owned/personal devices; company-owned devices registered by serial number are auto-approved (except Android work-profile devices)

  2. open ↗

    Security › Access and data control › Context-Aware Access › Access levels

    Access level 'trusted-device': Device policy
    admin-approved AND encrypted storage AND screen lock AND OS version ≥ baseline
    company-owned
    true
  3. Security › Access and data control › Context-Aware Access › Access levels

    device.chrome.management_state == ChromeManagementState.CHROME_MANAGEMENT_STATE_BROWSER_MANAGED && device.chrome.versionAtLeast("148.0.0.0")
  4. open ↗

    Security › Context-Aware Access › General settings

    General settings: Policy for all Google-owned apps / all SAML apps / OAuth apps = trusted-device; Action = Monitor first, then Block once the monitor log is clean. Do not use Warn (OAuth policies offer only Monitor and Block)

Ongoing maintenance

How to verify

  1. From an unmanaged browser, sign in as a test user — the CAA log should show the device failing the level (Blocked, or Access Denied (Monitor mode) while ramping).

  2. From a managed device, confirm the log shows device signals present (no "No Device Signals" / "Device ID: UNKNOWN").

v0.0.3 Prevent edition Ent Std+ + MDM policy #25 · #4, #7 ↗