Process pending device approvals

Set New device login to Admin approval required to approve new devices before allowing sign-in. This page explains how to enable approval requests and approve or deny them.


Before you begin

  • Required role: an administrator with permission to manage security settings
  • A regular administrator cannot process a device request from the owner.

Require approval for new devices

  1. On the administrator page, select Security Management > Security Settings.
  2. Expand New device login and select Admin approval required.
  3. Select Save at the bottom of the page, then confirm the change.

The card displays a View pending devices link after you select the policy. See Security Settings for the other options.

Message shown to the user

When a new device needs approval, entering the correct password shows a message asking the user to wait for an administrator to approve the device, then sign in again.

Administrators also receive a security notification. Repeated requests from the same device are grouped into ten-minute notification intervals.

Approve or deny a request

  1. Select Security Management > Pending Devices.
  2. Review the user, device, IP address, request time, and attempt count.
  3. Select Approve or Deny.

Pending devices list

ActionResult
ApproveThe approval message appears. The user can sign in again from that device.
DenyThe request disappears. If the user attempts to sign in again, the device returns to the pending list.

You can also approve or deny the same request under Needs your attention on the administrator home. To see all requests, open Security Management > Pending Devices.

Good to know

  • New approval requests are created only when the policy is Admin approval required. Otherwise, the pending-device page shows a message explaining this.
  • Each user can have up to ten pending requests and thirty approved devices.
  • Review and revoke approved devices from the user details page. Revoking a device also ends its sessions.
  • If a reverse proxy does not pass the actual client IP, even whitelisted IPs cannot skip device approval.