Trinetri logo
Device Control

Device Access Control

Device Access Control: create an access control policy for a device type, register trusted devices, grant temporary access, and deploy to endpoints.

  • 2 min
  • September 2, 2026

What You'll Learn

  • How to create an Access Control Policy with a rule for a specific device type
  • How to choose an access level for each device type, including allowing only trusted devices
  • How to register a trusted device using its hardware identifiers
  • How to grant time-limited temporary access to a device on a single endpoint
  • How to deploy an Access Control Policy to specific endpoints
  • How to track a deployment through to completion and review its per-endpoint output
CTA background

Experience Trinetri Autonomous Platform in Action.

Frequently Asked Questions

What does an Access Control Policy actually control? A policy holds one or more device type rules, each pairing a Device Type with an Access Level. Device types available in the dropdown include Printers, Bluetooth Adapters, Biometric Devices, Imaging Devices, Modems, Keyboards, Mouses, Smart Card Readers, Tape Drives, Wireless Network Adapters, Floppy Disks, Infrared Devices, and Removable Storage. Each policy also has a Name and an optional Description.
What are the available Access Levels? Four options: Allow, Block, Allow Trusted Devices, and No Change. No Change is the default on a newly added rule, so a rule left at that setting is saved but enforces nothing. Selecting Allow Trusted Devices reveals a Trusted Devices field for choosing which registered devices remain permitted.
Can one policy cover more than one device type? Yes. The Add Rule button adds another Device Type Rule to the same policy, so a single policy can block one device class, allow another, and leave a third unchanged.
How is a trusted device identified? A Trusted Device entry has a Name, Device Type, and optional Description, then an Add Device By setting of IDs and Serial Number, with fields for Vendor ID, Product ID, and Serial Number. Serial Number is optional, so an entry can cover one specific unit or every device sharing that vendor and product pair.
How does Temporary Access differ from a Trusted Device? Temporary Access is a time-limited exception for one endpoint rather than a persistent hardware exemption. It takes a Name, Endpoint, and a Duration Type of either Fixed Duration (a Duration Value and Duration Unit such as Hours) or Time Window (an explicit start and end time), plus one or more Allowed Devices with a Device Type and an Allowed For setting such as All Instances. Entries show a status of Pending or Expired and can be revoked, edited, or deleted from the list.
How do I push an Access Control Policy to specific machines? From Deployments, create a new deployment, set the Scope to Specific Endpoints and choose the target endpoint(s), set the Deployment Type to Apply Policy, then select the Device Access Control Policy, a Deployment Policy, and who to notify before publishing. Save As Draft is available if the scope still needs review.
How do I confirm a deployment succeeded? The Deployments list shows each entry's Type (Apply or Remove), Stage (such as Initiated or Completed), and Progress (such as 1/1). Opening a deployment's Tasks view shows the Status per targeted endpoint, moving from Ready to Deploy to Success, and each task has an Output view with a timestamped execution log confirming the policy was applied.