Set up Device Posture
Available on: Enterprise
Connect your device management or endpoint protection provider, confirm that Firezone can match its records to your devices, then add requirements to your Policies.
Before you begin
You need a Firezone administrator account, access to administer your provider, and a test device that reports to that provider and runs the Firezone Client. Check the provider guide below for its permissions and platform requirements.
We strongly recommend completing Device Trust setup and enabling Require attestation on the Policy. This lets Firezone match posture records using an identity the device has proved.
Choose your provider
Each guide covers adding the provider, the evidence it supplies, and how to troubleshoot missing records or failed checks.
| Provider | Posture platforms | Connection |
|---|---|---|
| Microsoft Intune | Windows, macOS, iOS/iPadOS, Android | Microsoft admin consent |
| Iru (Kandji) | macOS, iOS/iPadOS | API token and Prism permissions |
| Microsoft Defender for Endpoint | Windows, macOS, Linux, with a matching Intune record | Microsoft admin consent |
| Santa (Workshop) | macOS | Workshop URL and read-only API key |
| SentinelOne | Windows, macOS, Linux | Management URL and API token |
These are the platforms on which Firezone evaluates each provider's posture fields. Individual checks can have narrower applicability. See the attribute reference.
The Firezone Client up to date check uses Firezone's own device record and does not require an external provider.
Connect and verify a provider
- Open Settings → Device Posture in the Firezone admin portal.
- Select Add posture provider, then choose your provider.
- Follow its guide to enter the connection details and select Verify Now.
- Wait for Verified, then select Create.
- In the provider's actions menu, select Sync Now. Wait for Last Synced to update and check the Devices count.
- Open your test device in Devices and select its Posture tab. Confirm that the expected provider record and security attributes appear.
Verification checks access to the provider. A successful inventory sync and a matched record in the device's Posture tab confirm that Firezone has evidence it can use for that device. Review the match badge as well as the values.
Add checks to a Policy
- Open the Policy that grants your test Group access to a Resource.
- In Device posture, choose Simplified and enable the checks you need. Start with values you have confirmed in the test device's Posture tab.
- Enable Require attestation if you have configured Device Trust, then save.
- Reconnect the test Client and confirm it can access the Resource when its applicable checks pass.
- Test a device that fails an applicable requirement and confirm that access through this Policy is denied. Review other Policies for the same Resource so a broader Policy does not grant access during the test.
Use the JSON tab to require a particular provider, change a threshold, or combine fields. The JSON reference covers the rule format and REST API use.
Several providers can supply evidence for a simplified check. A passing result from any supported provider is enough for that check. Each applicable check selected on the Policy must pass.
Checks for other platforms are skipped. An applicable check fails when the evidence needed to pass it is missing. For example, a macOS-only field does not exclude Windows devices by itself.
Keep provider data current
Firezone schedules provider syncs every two hours. Use Sync Now after setup or a provider change to request an earlier sync. This fetches the provider's inventory; the device still needs to report its latest state to that provider.
Last Synced shows when Firezone fetched the inventory. Recently seen checks when the provider last heard from the device. Use a freshness check alongside security checks when old evidence should stop granting access.
To rotate an API token or key, open the provider's Edit action, enter the replacement, select Verify Now, and Save. A blank secret field on an existing provider keeps its saved credential. For Microsoft providers, use Reset verification to grant admin consent again.
| Status | What to do |
|---|---|
| Active | Check Last Synced and the test device's Posture tab to confirm the expected data is present. |
| Warning | A sync encountered an error. Check credentials, permissions, and provider availability, then request Sync Now. |
| Error | Sync errors disabled the provider. Correct the connection details and use Re-verify to enable, then save. |
| Disabled | Syncing is paused. Use Enable when the provider should supply posture evidence again. |
| Unverified | Open Edit and complete provider verification. |
Disabled providers do not contribute evidence to Policy checks, even if their old records are still visible on a device. Deleting a provider also deletes its synced device records. Review Policies that rely on it before disabling or deleting it.
Upcoming providers
Support is upcoming for CrowdStrike Falcon, Sophos XDR, Jamf Pro, Workspace ONE, and Mosyle. You can register interest from the portal.
- Open Settings → Device Posture → Add posture provider.
- Select the upcoming provider. Firezone registers your interest and opens a confirmation panel.
- Optionally describe the platforms and checks you need in Feedback, then select Send feedback.
Choose Other to request a provider that is not listed. Registering interest does not connect a provider or start syncing devices.
Jamf Pro's existing Device Trust integration can provision device identities while its posture integration is upcoming.
Need help? See all support options.