Only when the environment can tolerate an additional trusted device in the authentication path. It is better suited to general office use than to clean rooms or tightly controlled shared stations, where a pinned same-device flow is easier to govern.
When Cross-Device Approval Is a Good Fit
Cross-device approval adds a second trusted endpoint into the sign-in flow, so it is best treated as an access design choice, not a convenience feature. It works when users have a dependable primary device, can complete approval without delay, and the organisation is comfortable with a slightly wider trust boundary around desktop authentication.
It is usually a better fit for office populations with managed laptops or phones than for kiosk-style environments, hot-desking, or other shared-workstation models. In those settings, the approval step can create friction, create ambiguity over which device is truly in control, or weaken the simplicity of a pinned same-device flow.
A OpenID Connect Core 1.0 style sign-in pattern can support this kind of step-up or cross-device authentication flow when the implementation keeps the authentication result tightly bound to the intended session and relying party.
Where the Approval Flow Becomes Fragile
The main weakness is not the approval mechanism itself, but the extra trust assumption it creates. If the secondary device is lost, shared, or poorly governed, approval becomes an alternate path into the desktop session. That matters most when the desktop is the gateway to admin tools, finance systems, or sensitive corporate data.
Cross-device approval also depends on users recognising a legitimate prompt and approving the correct sign-in. The more often approval is requested, the more likely people are to accept prompts reflexively. That is why the control is strongest when it is used selectively, with clear user context and strong session binding.
ISO/IEC 27002:2022 Information Security Controls is useful here because the design choice sits at the boundary between authentication, access control, and secure configuration, where organisations need consistent rules rather than ad hoc exceptions.
NCSC UK Advice and Guidance reinforces the broader operational point: remote and interactive access flows need to stay usable enough for daily work, but simple enough that users can reliably recognise legitimate access paths.
How to Decide Whether to Permit It
The right question is whether the extra device materially improves assurance without making the sign-in path harder to govern. If the secondary device is managed, the user population is stable, and the desktop is not a shared control point, cross-device approval can be a pragmatic compromise between usability and assurance.
If the environment depends on strict workstation control, same-device sign-in is usually easier to supervise because the approval and the desktop session stay on one endpoint. That reduces ambiguity during audits, exception handling, and incident review, especially where operators need to prove which device initiated and confirmed the login.
- What to prioritise: bind approval to a clearly owned device and avoid allowing unmanaged personal devices to become an informal second factor.
- What to verify: the user can see the approval context, including the sign-in location or device information, before confirming.
- Common mistake: treating cross-device approval as automatically stronger than same-device approval, when the real question is whether the extra device is actually better governed.
Practitioner takeaway: Allow cross-device approval when it improves practical assurance and user continuity, but keep same-device sign-in for tightly controlled or shared environments where simpler device accountability matters more than convenience.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Desktop sign-in approval is an organizational user authentication decision. |
| Recommendation — Bind desktop approval to strong user authentication and session assurance. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Cross-device approval changes how access is granted to a desktop session. |
| Recommendation — Define when cross-device approval is permitted and require consistent access rules. | ||
| OWASP ASVS | V6 — Authentication | The question concerns how a login is authenticated and approved across devices. |
| Recommendation — Verify the sign-in flow resists prompt abuse and session confusion. | ||
Related resources from NHI Mgmt Group
- When should organisations require device trust before sign-in?
- What breaks when organisations only secure sign-in but do not verify device health and identity context?
- How should organisations govern AI agents that are allowed to sign in with user approval?
- What breaks when organisations allow BYOD without tight session and device controls?