Glossary
Zero trust
Zero trust is a security model that stops treating the corporate network as a trusted zone and instead verifies every request individually, on the strength of the user's identity, the state of the device, and the context of the access. For an IT team it means access decisions move from the firewall to a policy engine that needs real signals, and the device signal is the one most organizations are missing.
How it works
The reference document is NIST SP 800-207, published in August 2020. It's short, free, and worth the hour. It describes three logical components: a policy engine that decides, a policy administrator that issues or revokes the session, and policy enforcement points sitting in front of the resources. No implicit trust is granted because a packet arrived from inside the building.
"Never trust, always verify" is the slogan. In practice a decision combines three inputs:
- Identity. The authenticated account, its groups, the strength of the authentication used, and a risk score if your identity provider computes one.
- Device state. Is this endpoint enrolled and known? Encrypted? Running a supported OS build? Free of jailbreak or root? When did it last report in?
- Context. The resource being requested, the sensitivity of the data behind it, the location, the time, the behavior of the same account ten minutes ago.
Sessions are short and re-evaluated. CISA's Zero Trust Maturity Model version 2, released in April 2023, lays out the five pillars (identity, devices, networks, applications, data) and is a better planning tool than most vendor roadmaps because it grades you on all five instead of the one a product happens to cover.
Why it matters for a fleet
Most teams get the identity pillar right and stop. Single sign-on is in place, MFA is enforced, groups are tidy. Then a contractor signs in correctly from a personal laptop with an out-of-date OS and no disk encryption, and the policy engine says yes, because nothing ever told it what that machine was.
That's the gap. Without an enrollment record and a live compliance state, "verify" reduces to verifying the human and guessing about the hardware. Mobile makes it sharper: phones leave the building by design, they sit on hotel Wi-Fi, and they hold cached mail and documents.
Now the honest part. Zero trust is also a marketing label, and you can't buy it in a box. Every vendor in mobility, networking and identity has relabeled its catalog since 2021, and some of those products enforce exactly one rule at exactly one choke point. Treat it as an architecture you build over several years, ask any supplier which of the five CISA pillars it actually covers, and be suspicious of a single product claiming all five.
How Appaloosa handles it
Appaloosa covers the devices pillar. Enrolled iOS, iPadOS, Android, Windows and macOS devices are evaluated continuously against your policies (OS version, passcode, encryption, required apps, last check-in), and that state is the device signal your identity provider needs before it grants a session. When a device drifts, work apps lose access and the data can be wiped selectively, leaving personal content alone. Read how that signal is produced on the mobile device management page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo