Without device health and session context, attackers can reuse stolen credentials from an unmanaged device, a risky location, or an abnormal network and still appear legitimate. That creates a blind spot between authentication and real trust. The result is weaker detection of account takeover, poor control over sensitive actions, and a false confidence that login verification alone is enough.
Why This Matters for Security Teams
remote access mfa is often treated as a strong enough gate on its own, but without device health and session context it only proves that a factor was satisfied, not that the session is trustworthy. That gap matters because attackers increasingly work with valid credentials from unmanaged laptops, unusual geographies, or compromised networks. The result is not failed login, but a successful login that should never have been trusted.
For teams managing non-human identities as well as human access, this is the same structural problem seen in poor NHI governance: authentication is mistaken for authorization and continuous trust. NHIMG’s Ultimate Guide to NHIs highlights how broad attack surface and weak visibility compound identity risk, while the OWASP Non-Human Identity Top 10 reinforces that identity controls fail when they do not account for real-world usage conditions. In practice, many security teams discover this only after a valid session has already been used to reach sensitive systems.
How It Works in Practice
Effective remote access decisions should combine MFA with device posture, session signals, and policy that is evaluated at the moment of access. Device health checks typically look for managed status, disk encryption, active endpoint protection, patch level, and signs of compromise. Session context adds information such as network reputation, impossible travel, location anomalies, and whether the login pattern matches normal behaviour. NIST controls in NIST SP 800-53 Rev. 5 Security and Privacy Controls support stronger access enforcement, but current guidance suggests these signals must be used continuously, not just at the initial prompt.
For identity-heavy environments, that means moving from a one-time challenge to conditional access with step-up checks. A practical model is:
- Authenticate the user or workload with MFA and a strong identity proofing method.
- Evaluate device posture before granting access to sensitive applications.
- Re-check context during the session when risk changes, not only at sign-in.
- Limit actions by role, sensitivity, and trust level instead of assuming all authenticated sessions are equal.
NHIMG research on 52 NHI Breaches Analysis and the SonicWall VPN Mass Breach via Stolen Credentials shows the broader pattern: once valid credentials are reused, perimeter-only checks are too late. These controls tend to break down when remote access is allowed from unmanaged endpoints or legacy VPNs because the session can remain trusted long after the initial check.
Common Variations and Edge Cases
Tighter access conditioning often increases friction for legitimate users, requiring organisations to balance security gains against operational latency and support load. That tradeoff is real, especially for contractors, incident responders, and mixed BYOD environments where device posture is hard to standardise.
There is no universal standard for this yet, but current guidance suggests three common exceptions need careful handling. First, emergency access should use separate break-glass procedures rather than weakening baseline controls for everyone. Second, unmanaged or third-party devices may need browser isolation, restricted app scopes, or short-lived access instead of full VPN trust. Third, high-risk sessions should be continuously re-evaluated, because a device that looked healthy at login can drift into a risky state mid-session.
NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks is useful here because the same principle applies across identity classes: trust must be contextual, time-bound, and revocable. The main failure mode appears in environments that still rely on static VPN trust or coarse network allowlists, because those models cannot distinguish a healthy managed device from a compromised session using valid credentials.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 | Covers excessive trust in static identity checks and missing context. |
| OWASP Agentic AI Top 10 | A-03 | Session trust gaps also affect autonomous agents using remote access. |
| CSA MAESTRO | IAM-2 | Maps to identity and access controls for dynamic, session-based risk. |
| NIST AI RMF | Supports ongoing risk evaluation instead of one-time authentication trust. | |
| NIST Zero Trust (SP 800-207) | SC-1 | Zero Trust requires continuous verification of device and session trust. |
Continuously assess access risk and revoke sessions when context degrades.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org