Use Cases

Consider a professional services firm with 150 employees, a small group of administrators, and several external consultants.
Most of the company’s work takes place in cloud applications. Employees connect from the office and remote locations, while consultants use personal computers for limited engagements.
Passwords and MFA help verify the person signing in. They do not necessarily confirm that the computer being used should have access.
With HENNGE Identity, the firm requires device certificates as part of its access policies. Before access is granted, the device must present a valid certificate issued or approved by the organization.
This lets the firm verify both the user and the device behind each request.
The Challenge: Authentication Does Not Confirm Device Trust
The firm needs to protect cloud applications from access through unknown or unauthorized computers.
Without device verification, exposed credentials can be used from a device the organization has never approved. MFA reduces that risk, but it does not establish whether the endpoint itself should be trusted.
This matters most for administrative accounts. An attacker with administrator access can change settings, manage users, and reach sensitive systems.
The IT team needs each access request to answer two separate questions:
Has the user authenticated successfully?
Is the user signing in from an approved device?
The first question verifies identity. The second determines whether the device should be allowed to connect.
Requiring a Certificate Before Granting Access
Using HENNGE Identity, the firm issues trusted device certificates to approved employee and administrator computers.
During login, HENNGE Identity checks whether the device presents a valid certificate. If the certificate is missing, expired, or invalid, access is denied.
The certificate does not replace passwords, MFA, or other Conditional Access requirements. It adds another condition that must be met before the user can reach company applications.
Even if an attacker obtains a valid username, password, and OTP, those credentials cannot be used from an uncertified computer.
Authentication confirms the user. The certificate confirms the device.
Adding Protection for Privileged Accounts
Administrators follow the same device certificate requirement as employees, with additional authentication when connecting from outside trusted networks.
This allows administrators to work efficiently from approved devices while placing a stronger barrier around privileged access.
An exposed administrator credential is less useful because any sign-in attempt still has to come from a certified device.
For accounts with the ability to manage users and security settings, verifying the device adds protection beyond credentials alone.
Approving Selected Personal Devices
The firm also supports consultants who use personal computers.
Instead of allowing access from any device, the IT team issues a personal device certificate to the specific computer approved for the engagement.
Consultants still complete OTP authentication on every login. Access also takes place through HENNGE Secure Browser, which adds controls around the session and limits access to approved applications.
The certificate verifies which computer can connect. Secure Browser helps control how company information is handled after access is granted.
This lets the firm approve a selected personal device without treating it as a fully managed corporate endpoint.
The Outcome: Access from Approved Devices Only
Adding device certificates helps the firm:
Deny access from uncertified computers
Reduce the usefulness of stolen credentials
Strengthen protection for administrator accounts
Verify approved employee and consultant devices
Add device trust to existing Conditional Access policies
Support selected personal devices without fully managing every endpoint
The organization evaluates both user identity and device identity before granting access.
This makes it harder to reuse compromised credentials from an unknown computer while giving the IT team clearer control over which devices can reach cloud applications.
What This Means for MSPs
Many MSP clients need stronger control over the computers accessing Microsoft 365, Google Workspace, and other cloud services.
Their environments may include company laptops, remote employees, privileged administrators, and approved personal devices. At the same time, full MDM may be unnecessary, outside the client’s current budget, or broader than the immediate requirement.
HENNGE Identity gives MSPs a focused way to:
Restrict access to approved computers
Protect privileged accounts from sign-ins on unknown devices
Reduce the risk of stolen credentials being reused elsewhere
Support selected personal devices without extending full trust
Add device verification to a managed identity service
Device certificates do not replace MDM or endpoint security. They address a specific access question that passwords and OTP cannot answer on their own: whether the device requesting access is one the organization recognizes.
Learn More About HENNGE
HENNGE helps IT teams and MSPs manage identity and control access across Microsoft 365, Google Workspace, and hundreds of other cloud services.
With HENNGE Identity, organizations can verify trusted devices, apply Conditional Access policies, and prevent access from unauthorized computers.
To learn how device certificates could support your organization or client environments, contact our team or request a demo.
Interested in offering HENNGE Identity through your managed security services? Learn more about becoming a HENNGE partner.
This article presents an illustrative scenario based on a real HENNGE Identity configuration. The company, industry, workforce details, and use case are provided as examples to demonstrate how the controls may be applied. They do not represent a named customer deployment or verified customer results.



