What is a trusted device?¶
id: "AI-023" title: "What is a trusted device?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"
What is a trusted device?¶
Script¶
A service asks for a password and a second factor.
Then it offers to remember the device.
If the user agrees, that device may become trusted.
A trusted device is one the service has previously recognised and decided can receive easier access in future.
That may mean fewer password prompts, no repeated multi-factor challenge, or permission to approve logins elsewhere.
The trust may be recorded through a cookie, application token, device identifier or provider-side setting.
This matters because a person using a trusted device may access an account without going through the full authentication process each time.
Finding no new multi-factor code does not therefore prove the account was not accessed.
The device may already have been trusted.
But “trusted” is a technical status, not a conclusion about who was holding the device.
A phone may belong to the account holder but be used by somebody else.
A laptop may be shared within a family or workplace.
A stolen device may remain trusted until the session or device authorisation is revoked.
Ask when the device became trusted.
What authentication was required at that point?
Was the device later renamed, removed or replaced?
Did the provider send a security alert?
Did the relevant activity occur through the trusted device or through a different session?
Device records, account-security pages and provider logs may help.
So may examination of the device itself.
Look for active sessions, authentication applications, saved credentials and account notifications.
Be careful not to overstate the evidence.
A trusted-device record can support the conclusion that the service previously accepted that device for the account.
It may explain why later access did not require a fresh challenge.
It does not identify the person using the device at the relevant time.
A trusted device lowers friction for account access.
For investigators, it is part of the authentication history and an important alternative to a fresh password login.