Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Unmanaged devices and contractor access: what IAM teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Enterprises with mixed managed and unmanaged devices need policy-based controls that adapt access by posture, because blanket assumptions break down when contractors and BYOD users enter sensitive workflows, according to Island's customer story. The real governance issue is not remote access itself, but how identity, device state, and application access are evaluated together.

NHIMG editorial — based on content published by Island: WWLW Ep. 17, the case of securing unmanaged devices

By the numbers:

Questions worth separating out

Q: How should security teams handle unmanaged devices in access policy?

A: They should not treat unmanaged devices as equivalent to managed endpoints.

Q: Why do unmanaged devices complicate zero trust access decisions?

A: Because zero trust depends on continuous verification, and unmanaged devices weaken the confidence you can place in the session context.

Q: What breaks when contractors use the same access path as employees?

A: Access policy becomes too coarse.

Practitioner guidance

  • Define separate policies for managed and unmanaged devices Create explicit access rules that treat unmanaged devices differently from enrolled endpoints, especially for collaboration tools, internal applications, and sensitive data paths.
  • Scope remote access to specific applications Replace broad network-level access with application-scoped controls so internal systems are reachable only through the minimum required path.
  • Tie access decisions to device posture signals Use posture checks in conditional access so the session outcome changes based on device management state, browser context, and application sensitivity.

What's in the full article

Island's full post covers the operational detail this post intentionally leaves for the source:

  • The exact policy flow used to redirect unmanaged-device users into the Enterprise Browser
  • The private access configuration steps for reaching internal applications without a traditional VPN client
  • The practical example showing how managed and unmanaged device experiences were separated
  • The customer workflow details around deploying controls for a mixed employee and contractor environment

👉 Read Island's customer story on securing unmanaged devices and private access →

Unmanaged devices and contractor access: what IAM teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Device trust is now an identity problem, not only an endpoint problem. Once unmanaged devices can reach sensitive applications, access policy has to treat device state as part of the trust decision. That means IAM, conditional access, and session control need to work together rather than sit in separate silos. Practitioners should treat posture-aware access as a governance requirement, not a convenience feature.

A question worth separating out:

Q: How do organisations decide when browser-based access is appropriate?

A: Browser-based access is most useful when the organisation needs to reach web applications from devices it cannot fully manage but still wants to control the session. It is a good fit for contractor workflows, BYOD scenarios, and internal application access where the main goal is to reduce endpoint dependence without opening the network broadly.

👉 Read our full editorial: Unmanaged device controls reduce risk in BYOD and contractor access



   
ReplyQuote
Share: