Skip to content →
Log in

Device trust

Control how endpoints prove organization membership.

Interactive enrollment#

Interactive device flow is always enabled:

  1. Start pulsectl login on Linux or browser authentication from the macOS app.
  2. Sign in and approve the displayed device.
  3. Confirm it appears under Network → Devices.

There is no pulsectl on Windows or macOS; both authenticate from the PulseHA app.

Other methods#

Settings → Device Trust can configure Microsoft Entra ID device login for eligible joined Windows devices. Enrollment tokens and workload identity are API-managed; the Console does not create or revoke them.

Device trust establishes enrollment identity. Device posture evaluates health, and Device policies configure agent behavior. Treat these as separate controls.

If an interactive device remains Pending, restart the authorization flow. Revoked devices must be enrolled again.