Device posture management

Last validated:

Device posture management is a feature for managing security requirements for devices that access your network. You can create rules so that devices have conditional access based on a custom set of security standards, called a posture. You configure a posture to include rules relating to specific device attributes, such as its operating system or the Tailscale version it runs.

You can use device posture management to create basic rules, such as denying all access to devices that don't meet your posture requirements, or you can control access with far more granularity. For example, you can require devices to meet stricter security requirements to connect to production. Or you can disallow access to most of your corporate network for devices that don't meet your posture requirements, but still allow them to reach the IT help desk.

Device attributes you use to create rules can include pre-populated host information such as the operating system version, or you can use custom attributes by integrating endpoint detection and response (EDR) and mobile device management (MDM) tools.

Attribute availability varies by Tailscale plan.

Benefits

  • Enhanced security: Reduce risks from compromised or non-compliant devices by verifying the device security state and configuration before granting tailnet access.
  • Context-aware access controls: Limit access to critical applications and tailnet resources based on the state of a device. You can provide elevated access for high-compliance devices, or completely block access for non-compliant devices.
  • Continuous verification: Make ongoing assessments of device health and compliance and enable adaptive access controls.

Use cases

  • Security audits: Evaluate the configuration and compliance of devices in real-time.
  • Remote work security: Make sure employees' devices meet security standards before accessing company resources.
  • Bring your own device (BYOD): Safely enable BYOD with tiered access to applications and tailnet resources for un-managed and managed devices with device state incorporated.
  • Move toward Zero Trust: Help your organization achieve Zero Trust with micro-segmentation, least-privileged access, continuous verification, and adaptive policy.

Usage by plan

Your Tailscale pricing plan determines which device attributes you can use in your device posture configurations. For more information on the different types of device attributes, refer to Device attributes.

Attribute typesPlan
DefaultAll plans
Third-party integration attributes (MDM and EDR)Standard, Premium, Enterprise
GeolocationStandard, Premium, Enterprise
CustomPremium, Enterprise

For more information, refer to our Pricing page.

Learn more about device posture management

Understand device postures and attributes and how to use them.

Understand how postures work with access rules

Review available integrations for device posture management.

Review API commands for device posture attributes