# ICCE: The foundation of device identity

You can’t enforce Zero Trust without proving device identity. Smallstep uses certificates to authenticate every connection, including services, workloads, AI agents, and MCP-based tools.

Secure Wi-Fi with hardware-backed EAP-TLS

Device-bound credentials for Okta Workforce Identity

ZTNA without passwords or agents

Hardware-backed SSH for engineers

SaaS access gated by verified device identity

mTLS for internal services and workloads

## Critical components of device identity

## Combined inventory

Without a comprehensive and trusted device inventory, you can't confidently rely on device identity for secure authentication. Smallstep Inventory is purpose-built for cybersecurity—it complements, but doesn't replace, your existing IT asset management (ITAM) tools.

- A complete inventory of devices that syncs with your MDMs
- Apple, Windows, & Linux devices
- Secure Enclave & TPM 2.0 EKPub key support

## Managed credentials

Once you have confidence in your trusted device inventory, Smallstep securely issues credentials to your trusted endpoints. Smallstep supports high-assurance enrollment via ACME Device Attestation on all major platforms (Windows, Mac, Linux), leveraging hardware-backed, non-exportable credentials.

- Deploy certificates using your existing MDMs
- Uses ACME Device Attestation, even on platforms without native support
- Continuous credential management

## Resource configuration

Configuration management across platforms can be challenging. After issuing credentials, Smallstep automatically configures your endpoints to authenticate securely to resources such as Wi-Fi, VPN, and SaaS apps. Our cross-platform agent seamlessly handles credential and configuration management for all of your endpoints - with or without your existing MDM solutions.

- Manage Wi-Fi, VPN, & browser certificates
- Device identity requirements for SaaS & non-HTTP resources
- Change to Certificate-based access on Linux devices – No MDM required

## Policy enforcement

Effective security requires verifying device identity at the moment resources are accessed. Authentication can occur directly at the resource level (such as an application or server verifying credentials) or via a centralized enforcement point (such as a proxy or gateway) that controls and authorizes access. Smallstep flexibly supports both enforcement approaches, ensuring your security policies are consistently applied across your infrastructure.

- Ensure only trusted devices can access VPN / ZTNA
- Use VPN or ZTNA to protect SaaS & internal Web Apps
- Quickly revoke access to protected resources
- Integrate with SSO providers to protect SaaS apps
- Ensure access to Github or Git from only trusted devices
- Ensure engineers & DevOps can only SSH from trusted devices

## Trusted at Enterprise Scale

Used by global banks, healthcare networks, fintechs, and public-sector organizations. Built on step and step-ca, trusted by 3,000+ organizations, including finance and defense. Powers Wi-Fi, ZTNA, SSH, and internal access modernization at scale. Learn how high-assurance device identity completes your Zero Trust architecture — without friction.

## FAQs critical components

### What are the “critical components” in Smallstep’s device and workload identity architecture?

### How does Smallstep ensure cryptographic trust across distributed components?

### How do Critical Components map to the four steps of establishing device identity?

### What is the role of the Smallstep Attestation CA, and how is it different from other CAs?

### How does Smallstep ensure revoked devices cannot obtain new credentials?

### How do CAs and agents communicate securely with attestation services?

### Can these components be deployed in distributed or hybrid architectures?

### How does Smallstep validate manufacturer attestation chains at scale?

### How does Smallstep integrate with external identity systems (MDM, IdP, IAM, SIEM)?

### How are the critical components hardened against CA compromise or misuse?

### How do critical components support workload identity (not just devices)?

### How do all critical components together enforce a Zero Trust model?
