What is a trusted device?¶
A trusted device is a device or application state that a service has previously approved for easier future access.
That can mean fewer password prompts, fewer MFA challenges, or the ability to approve other sign-ins.
For an investigator, it can explain why an account was accessed without the security checks you expected to see.
Trust is something the service remembers¶
A provider may recognise trust through:
- a device registration;
- a cookie;
- an application token;
- a device identifier;
- a cryptographic key; or
- another provider-side record.
A simplified history might look like:
That may explain why the later event did not trigger a new MFA challenge.
Find out when and how trust was granted¶
The useful questions are:
- when was the device first trusted;
- what authentication was required then;
- which account approved it;
- whether the trust record changed;
- whether the device was later removed; and
- whether the disputed event actually used that trusted route.
Historical trust matters more than the device's current status.
“Trusted device” does not mean “trusted person”¶
The label describes the provider's relationship with the device.
It does not tell you who was holding it later.
A phone may be borrowed or stolen. A laptop may be shared. A device may be remotely controlled.
So combine the trusted-device record with:
- session history;
- local account artefacts;
- device possession;
- notifications;
- other active accounts;
- CCTV or access records; and
- surrounding communications.
The practical point is: a trusted-device record explains why access may have been easier. It identifies provider-approved device state, not the person using it.