Device trust
Control how endpoints prove organization membership.
Interactive enrollment#
Interactive device flow is always enabled:
- Start
pulsectl loginon Linux or browser authentication from the macOS app. - Sign in and approve the displayed device.
- Confirm it appears under Network → Devices.
There is no pulsectl on Windows or macOS; both authenticate from the PulseHA app.
Other methods#
Settings → Device Trust can configure Microsoft Entra ID device login for eligible joined Windows devices. Enrollment tokens and workload identity are API-managed; the Console does not create or revoke them.
Device trust establishes enrollment identity. Device posture evaluates health, and Device policies configure agent behavior. Treat these as separate controls.
If an interactive device remains Pending, restart the authorization flow. Revoked devices must be enrolled again.