A verified user on an unmanaged device can still expose the organisation to malware, session theft, or data loss because identity assurance does not guarantee endpoint integrity. Zero Trust assumes every access request must be evaluated in context, so device posture is a core security signal, not an optional extra.