NetNXT Logo

How to Enforce Twingate Device Posture Checks for Secure Access?

Learn how to enforce Twingate Device Posture Checks to restrict access from unmanaged or insecure devices. This guide explains creating trusted device profiles, applying policies, and blocking non-compliant devices from accessing sensitive resources.

January 19, 2026
2 min read
ByNetNXT
On this page
Share this article

Overview

You can prevent unmanaged or insecure devices from accessing sensitive resources, even if they have the correct username and password. This is Twingate's "Device Posture Check."

Step 1: Define a Trusted Device

  1. Go to Settings > Device Security > Trusted Profiles.

  2. Click Create Trusted Profile.

  3. Name: Corporate Laptop Standard.

  4. Requirements:

    • Disk Encryption: Required.

    • Screen Lock: Required.

    • OS Version: Minimum macOS 14.0 or Windows 11 22H2.

    • Trust Method: "Twingate Certificate" (Recommended for JumpCloud/MDM managed fleets).

Step 2: Apply to a Policy

  1. Go to Policies > Resource Policies.

  2. Select (or create) a policy: Prod-DB-Access.

  3. Under Device Security, select "Only Trusted Devices".

  4. Save.

User Experience

  • Scenario: A developer tries to access the Production DB from their personal iPad (which lacks the corporate certificate).

  • Result: Twingate blocks the connection and displays: "Your device does not meet the security requirements for this resource."

FAQ

1) What is Twingate Device Posture Check?

Twingate Device Posture Check ensures that only compliant and managed devices can access sensitive resources by enforcing security requirements like encryption, OS version, and certificates.

2) How do you create a trusted device profile in Twingate?

Trusted profiles are created in Settings > Device Security > Trusted Profiles where requirements such as disk encryption, OS version, and trust certificates are defined.

3) Can Twingate block personal or unmanaged devices?

Yes, Twingate can block access from personal or unmanaged devices even if correct credentials are used by enforcing trusted device posture policies.

4) What security requirements can be enforced with Twingate posture checks?

Twingate can enforce disk encryption, screen lock, minimum OS versions, and certificate-based trust to ensure only secure corporate devices can connect.

5) What happens when a device fails Twingate posture validation?

Twingate denies access and shows a message that the device does not meet security requirements, preventing the connection to protected resources.

Need help securing your environment?

Talk to a NetNXT security expert
Was this article helpful?

Stay ahead of the next vulnerability

New KB guides, threat advisories and hardening playbooks from NetNXT's security team — straight to your inbox.

NetNXT will handle your data pursuant to its Privacy Policy.

Like this guide? Join our team.

NetNXT builds security for how modern enterprises actually run.

View open roles

Have a question about this guide?

Our security engineers read every message.

Contact us