When policy is bound only to a device serial number, shared workstations and multi-user systems can inherit the wrong access state. One user may receive excessive access, while another may be blocked or underprotected. That creates audit gaps, weak isolation, and a poor fit for environments where the same terminal is used by different roles or trust levels.
Why This Matters for Security Teams
Binding access and network policy to a device serial number sounds precise, but it collapses when identity is shared, virtualised, reimaged, or handed between users. The device becomes the anchor instead of the person, workload, or session that is actually making the request. That creates policy drift, false trust, and weak auditability, especially in shared terminals, hot-desking, kiosks, VDI pools, and operational technology.
This is why device-only policy is a poor fit for modern identity governance. The better question is not “which box is this?” but “which identity is acting, under what context, and with what current risk?” That aligns more closely with the NIST Cybersecurity Framework 2.0 and with NHI governance patterns documented in Ultimate Guide to NHIs. In practice, teams discover the problem only after a shared endpoint inherits an old trust state and exposes systems to the wrong user, rather than during design.
How It Works in Practice
Serial-number binding is brittle because it treats a device as a stable proxy for trust. In real environments, the same endpoint may be used by different staff, temporary contractors, service desks, or automated workflows. If network access control, application entitlements, or conditional access are tied only to hardware identity, then the policy cannot distinguish between a trusted session and a risky one on the same machine.
Current guidance suggests separating device posture from user or workload authorisation. A more resilient model combines device signals with identity, session, and context checks, then evaluates policy at request time. That approach is consistent with NIST SP 800-207 Zero Trust Architecture, where the device is one input, not the sole trust anchor. For non-human identities, the same principle applies: the access decision should follow the workload identity, token scope, and task context, not just the endpoint that launched the request.
Operationally, teams reduce failure modes by doing three things:
- Bind access to authenticated identity and session state, not only to device serial numbers.
- Use short-lived credentials or tokens so trust expires quickly if a terminal is reused.
- Re-evaluate network policy when user, role, location, or workload context changes.
NHIMG research shows why this matters at scale: only 5.7% of organisations have full visibility into their service accounts, and 97% of NHIs carry excessive privileges. That makes static device trust especially dangerous when the same terminal is used to reach sensitive services, as described in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs and reinforced by OWASP Non-Human Identity Top 10. These controls tend to break down in shared workstation fleets because the endpoint remains “known” even when the current user, session, or workload is entirely different.
Common Variations and Edge Cases
Tighter device binding often increases operational friction, requiring organisations to balance access precision against user mobility and support overhead. That tradeoff becomes sharper in environments that rely on shared kiosks, industrial terminals, contractor access, or virtual desktops. In those cases, serial-number policy can create either over-permission, where the endpoint inherits a privileged state, or under-permission, where legitimate users are blocked because the device record is stale or mismatched.
Best practice is evolving toward layered trust rather than single-factor device identity. For human access, that means device posture plus user identity plus session assurance. For NHI and agentic workloads, it means workload identity, ephemeral credentials, and request-time authorisation rather than a static asset list. The risk is not only unauthorised entry, but also poor isolation between users who share the same device or between jobs that reuse the same execution environment. Additional perspective is available in Top 10 NHI Issues and NIST SP 800-53 Rev 5 Security and Privacy Controls.
There is no universal standard for serial-number-based policy correctness because the answer depends on whether the device is shared, virtualised, or tied to an autonomous workload. In practice, serial numbers should be treated as one signal among many, never the sole source of access truth.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access permissions must reflect identity and context, not just device trust. |
| NIST Zero Trust (SP 800-207) | Zero Trust rejects static device-only trust as sufficient for authorization. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | Static device binding can hide excessive NHI privilege and stale access state. |
| CSA MAESTRO | Agentic and workload access should be based on runtime context, not fixed endpoints. | |
| NIST AI RMF | AI RMF stresses governance and contextual risk handling for autonomous systems. |
Use short-lived NHI credentials and review trust boundaries around shared endpoints.
Related resources from NHI Mgmt Group
- What breaks when network controls are used instead of request-level policy for machine access?
- What breaks when device health is not part of access policy?
- What breaks when access decisions are tied to network location instead of identity?
- What breaks when mobile access is not tied to device posture?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org