Device and platform restrictions
Last updated
Last updated
The Device OS access control allows organizations to:
Restrict access to specific device platforms
Allow access only from approved operating systems
Block insecure or unsupported device types
Enforce security policies based on device compliance
This helps improve overall security by ensuring users only access systems from trusted platforms.
Before configuring device-based access control, make sure:
You have Admin or Security Management permissions
An Access Security policy can be created or edited
You know which device OS platforms should be allowed or denied (for example: Windows, macOS, iOS, Android)
Choose how the selected device OS should be treated:
Whitelist / Allow
Example:
Blacklist / Deny
Example:
Sign in as an administrator : Oten Admin | Security Policy & User management
Profile Account → Admin
Welcome page Admin
Click on menu Security Policy → Access Security
Click button Create access security
In the Access Security Rules section, select Add rule
A new rule (for example, Rule 1) will be created
Under the rule, select Add condition
Choose Device OS
Users with the selected device OS will have access
Recommended when you want to explicitly allow only trusted platforms
Allow access only from Windows and macOS
Users with the selected device OS will not have access
Recommended when you want to block specific platforms
Deny access from Android devices
In the Device OS field, select one or more platforms
Multiple OS types can be added depending on policy requirements
Select Add condition to combine Device OS with other controls such as:
IP address or IP range
Location
Device compliance
Conditions within the same rule are evaluated together
Review all configured rules and conditions
Select Create access security to save and activate the policy
User access is evaluated based on their device operating system
Access is granted or denied according to the configured policy mode
Policies are enforced during sign-in and access attempts
If Whitelist / Allow is used and no OS is matched, access will be denied by default
If Blacklist / Deny is used, only the selected OS platforms are blocked
Device OS detection depends on client and browser capabilities
For higher security, combine Device OS rules with MFA or IP-based controls
Device OS access control helps secure systems by platform
Supports both allowlist and denylist models
Can be combined with other access security rules
Suitable for both enterprise and high-security environments