What are trusted devices in a cloud account?¶
A trusted device is a device identity or remembered device context that a service uses when deciding how to allow access. “Trusted” describes a provider decision or policy state; it does not prove who owns, possesses or operated the physical device.
Keep four device propositions separate¶
Northstar's directory lists device ID DEV-71A as registered, managed and compliant. A sign-in at 08:32 reports that device ID, and a OneDrive event follows. Those records form a useful technical chain, but the display name “Dave-Laptop” is user-supplied and the directory cannot see who sat at the keyboard.
Read the exact status and time¶
| Field or event | Useful meaning | Limit to preserve |
|---|---|---|
| Stable device ID and registration time | Which directory device record existed | Not the same as serial number or physical seizure identity |
| Join/registration type | Nature of the directory relationship | Product labels and privileges differ |
| Managed state | Whether a management system was recorded | Does not itself state current security condition |
| Compliance state and assessment time | Whether configured rules were met then | Can change after the event |
| Owner, user or display name | Directory association or label | May be assigned, shared or user-supplied |
| Sign-in device detail | Device context reported for one access event | Compare with local and management evidence |
Microsoft Entra device records - checked 2 September 2026
Microsoft Entra currently distinguishes registered, joined and hybrid-joined devices. Its device export can include IDs, join type, managed and compliant states, registration and approximate last-sign-in times, operating-system details and owner fields.
The point to remember
Treat “trusted” as a provider state with a source and time. Join the directory device ID to the sign-in and physical device before identifying the operator.