Zero trust for mobile, past the slide
The architecture is well described and rarely implemented on the fleet. Four things have to be true on a handset before the model means anything.
Zero trust has been explained more times than it has been implemented. The principles are not in dispute: verify explicitly, use least privilege, assume breach.
Where it goes wrong is that the implementation gets done for the corporate laptop, the identity layer and the applications — and then stops, leaving the mobile fleet as the one population where access is granted on the strength of having authenticated once, on a device nobody is evaluating.
That is not a zero trust architecture with a gap. It is a perimeter that has moved to a different place.
The four things that have to be true
1. The device is a subject, not a bystander.
In a zero trust model, access decisions consider the device as well as the user. On mobile this means the handset has a managed identity, reports compliance state, and that state is current — not the result of a check-in three days ago.
Most fleets satisfy the first part and fail the third. A compliance signal with a poll interval measured in days is not an input to a real-time access decision, which is why the shift to declarative management matters more than it appears to: the device reports state changes when they happen.
2. The signal changes access, automatically.
A device that falls out of compliance has to lose access without a human reading an alert. If a detection produces a notification that somebody reviews on Monday, you have bought telemetry, not enforcement.
This is a Conditional Access configuration and it is straightforward. What stops it is usually not technology but the reasonable fear of locking people out — which is a deployment problem with a known answer, covered in Conditional Access without locking everyone out.
3. Something is actually evaluating the device.
Compliance state from an MDM answers “is this device configured the way I said”. It does not answer “is this device under attack”. A fully compliant handset on a hostile network, running an application that is exfiltrating data, reports green.
For the device to be a meaningful input to an access decision, something has to be assessing its actual risk — network, device, application and phishing — and feeding that into the same signal. Otherwise the model is verifying a configuration and calling it trust.
4. Access is scoped, not binary.
Least privilege on mobile is usually implemented as a single decision: the device is trusted, so it gets everything the user gets.
The useful version is graduated. Full access from a compliant, managed device on a known posture. Web-only, no-download access from a device that is compliant but unmanaged. Nothing from a device flagged as at risk. That gradient is what makes the model workable in practice, because it gives you an answer between “yes” and “the executive cannot read their mail”.
What people skip
Applications outside the identity provider. Every service that authenticates independently is outside the model. The list is longer than expected and it is where the exceptions accumulate.
Legacy authentication. Protocols that cannot present a second factor cannot participate in any of this. Blocking them is the highest-value single control available and requires an inventory first.
Break-glass and exclusions. Every zero trust implementation has exclusions. The question is whether they are documented, owned, time-bound and reviewed, or whether the exclusion group has quietly become most of the organisation.
The network still matters. “Never trust the network” is often read as “the network no longer matters”. On mobile the network is a live attack surface — rogue access points and interception are among the most common real-world mobile threats — and the fact that you no longer trust it does not mean you should stop watching it.
An order that works
- Get every mobile device into management with a current compliance signal.
- Wire that signal into Conditional Access, in report-only first.
- Inventory and remove legacy authentication.
- Move to phishing-resistant MFA for the populations that warrant it.
- Add real device risk assessment, so compliance means more than configuration.
- Introduce graduated access, so the enforcement decision is not all-or-nothing.
- Review exclusions quarterly and shrink them.
Nothing in that list is exotic. Most organisations have the licences for all of it already, which is usually the surprising part.
More on identity and the modern workplace, and mobile threat defence.