Zero Trust Security and Your Device Fleet: What It Means in Practice

Most conversations about Zero Trust security start with networks and identity. Which users can access which systems. Whether a login attempt should be trusted. How traffic should be segmented across the corporate environment. These are important questions, but they leave out one of the largest and most overlooked attack surfaces in modern business operations: the device fleet.

Customer-facing kiosks, point-of-sale terminals, digital signage displays, and employee tablets are not passive endpoints. They are internet-connected devices that interact with customers, process transactions, and in many cases sit in publicly accessible locations without direct IT supervision. Applying Zero Trust principles to these devices is not an advanced security posture. It is a basic operational requirement.

What Zero Trust Actually Means

Zero Trust is a security framework built on a single foundational principle: never trust, always verify. Traditional security models assumed that anything inside the corporate network was safe. Zero Trust rejects that assumption entirely. Every device, every connection, and every request for access must be verified before it is permitted, regardless of where it originates.

For device fleets, this translates into three core practices:

  • Least privilege access: Each device is granted only the minimum access required to perform its function. A self-ordering kiosk should not have access to the corporate file server. A digital signage display should not be able to browse the open internet. A POS terminal should only be able to reach the payment processor and the relevant inventory system.
  • Continuous verification: The device’s compliance status is checked on an ongoing basis, not just at enrollment. If a device goes out of compliance, falls out of its expected configuration, or behaves in an unexpected way, it is flagged or isolated before it can cause harm.
  • Micro-segmentation: Device traffic is segmented at the network level so that a compromised device cannot be used as a launchpad to reach other systems or devices on the same network.

Moki’s MDM platform supports all three of these practices through its device lockdown, kiosk mode, real-time monitoring, and configuration management capabilities.

Why Dedicated Devices Are a Specific Risk

General-purpose enterprise devices like laptops and smartphones carry their own security challenges, but dedicated customer-facing devices introduce a distinct set of risks that most security frameworks are not built to address:

  • They are often located in publicly accessible spaces where anyone can interact with them
  • They may run continuously without being rebooted or monitored by an on-site employee
  • They are frequently managed by operations teams rather than IT security teams
  • They are inconsistently updated if there is no centralized app and OS management process
  • When they are misconfigured, the misconfiguration may go undetected for days or weeks

In 2025, Android malware grew 67 percent year over year, and 85 percent of organizations reported direct attacks on their mobile fleets. Devices that are left open, improperly configured, or running outdated software are the easiest targets in any organization’s environment. Applivery

How MDM Enables Zero Trust for Device Fleets

A modern mobile device management platform is the operational layer that makes Zero Trust principles actionable at the device level. Here is how each Zero Trust principle maps to specific MDM capabilities:

Least privilege access is enforced through kiosk mode and device lockdown. When a device is locked to a specific app or set of URLs, it is physically incapable of accessing anything outside that defined environment. The device cannot be used to browse unauthorized content, access system settings, or interact with corporate resources that are outside its designated function. Moki’s app lock and kiosk mode features make this configuration straightforward to apply and enforce across an entire fleet.

Continuous verification is enabled through real-time device monitoring and alerting. Moki’s dashboard gives IT and operations teams live visibility into every device in the fleet, including battery status, connectivity, app health, and compliance with the applied configuration profile. Custom alerts notify the team immediately if a device goes offline, an app crashes, or a device falls out of its expected state. This is the operational equivalent of continuous verification: the platform is constantly checking that each device is behaving as intended.

Micro-segmentation is a network-level control, but MDM supports it by defining and enforcing which network connections a device can make. Restricting devices to specific Wi-Fi networks, blocking access to unauthorized URLs, and configuring VPN policies through the MDM platform all contribute to keeping device traffic appropriately isolated.

Applying Zero Trust in Specific Environments

The practical application of Zero Trust for device fleets looks different depending on the industry and use case:

In retail, a Zero Trust approach means POS terminals are locked to the payment application, restricted to the payment processor’s network endpoints, and monitored for any deviation from that configuration. A device that suddenly attempts to reach an unauthorized external address triggers an alert.

In healthcare, patient check-in kiosks under a Zero Trust model are locked to the check-in application, cannot access the broader EHR network, and are monitored for uptime and compliance with HIPAA-relevant configuration standards.

In hospitality, guest-facing tablets are locked to the concierge or booking app, cannot be used to access other hotel systems, and are automatically reset to their default state after each guest session ends.

In distribution and warehousing, handheld scanners and inventory tablets are restricted to the warehouse management application and monitored for any unauthorized app installations or configuration changes.

What a Zero Trust Device Audit Looks Like

If you want to assess whether your current device fleet aligns with Zero Trust principles, start with these questions:

  • Are all devices enrolled in an MDM platform with an active, enforced configuration profile?
  • Is kiosk mode or device lockdown enabled on every customer-facing device?
  • Are app permissions reviewed and restricted to only what each device needs?
  • Is there a real-time alerting system that notifies your team when a device goes offline or out of compliance?
  • Are device-to-network connections restricted to only the endpoints each device needs to reach?
  • Is there a documented process for isolating or wiping a compromised device remotely?

If the answer to any of these questions is no, there are concrete gaps in your device security posture that Zero Trust principles, implemented through MDM, can close.

Getting Started

Zero Trust for device fleets does not require a complete infrastructure overhaul. It requires an MDM platform with the right capabilities and a commitment to applying configuration standards consistently across every device. Moki’s platform is purpose-built for dedicated device deployments and supports the lockdown, monitoring, and remote management capabilities that Zero Trust requires.

Schedule a Moki demo to see how device lockdown and real-time monitoring work in practice, or start a free trial to begin applying Zero Trust configuration to your fleet today. The Moki FAQ also covers common questions about device security and configuration.

See Moki in Action

Request a Demo today with by phone, email, or just fill out the form






Skip to content