Published at: 2026-09-17

Manage employee devices


Configure device binding rules and monitor employee sign-in devices on mobile and PC in the Org Structure. Equipment Management covers these bindings.

Overview

💡 Use employee device management to limit the number of endpoint devices that an account can use. This helps prevent remote sign-ins, account sharing, and password disclosure and provides an endpoint security control.

Before you begin

[!IMPORTANT] - Role permissions: You need System Administrator permissions or a management role with Employee Device Management permissions. - Behavior: After binding is enabled, the first device used for a successful sign-in is physically bound to the account. A sign-in from another device is blocked.

Procedure

1. Configure device binding policies

  1. Go to Setup > Company Settings > Company Security Settings > Device Binding.
  2. Configure the binding switches:
    • Mobile Devices: When enabled, the account can sign in only from the first phone or iPad used for a successful sign-in.
    • PC Devices: When enabled, the account can sign in only from the first computer browser or desktop client used for a successful sign-in.
  3. Configure the Device Allowlist:
    • Click New.
    • Add employees who frequently travel or provide operations support.
    • Click Save. Whitelisted employees are exempt from binding rules and can sign in from any computer or phone.

2. Monitor and manage binding records

Go to Setup > Organization Management > Employee Device Management. Review and reset bindings by using these views:
  • Authorization Records:
    • View each binding, including the authorizer nickname, department, device system, Equipment Model, and authorization time.
    • Revoke Authorization: Select a record and click Revoke Authorization. The employee can bind a new device at the next sign-in.
  • Accounts with Multiple Authorized Devices:
    • View employees with two or more bound devices.
    • View account status and the number of bound devices. Select accounts to cancel authorization in batches.
  • Devices Used by Multiple Accounts on One Day:
    • Identify devices that may be shared. The list shows the device model, system, and different account nicknames used on that device that day.
    • Reset Device Owner: Select a device and click Reset. The system clears its current owner and records the first account that signs in from it next.
  • Accounts Using Multiple Devices on One Day:
    • Monitor accounts with unusual device changes and view their different device models used during the day.

Verify the result

  1. Confirm that mobile device binding is enabled and that the test account is not on the whitelist.
  2. Sign in with the test account from an unbound phone.
  3. Sign out and try to sign in from another unbound phone with the same account and password.
  4. Expected result: The system reports that the account is bound to another device and asks you to contact an administrator.
  5. In Authorization Records in Setup, find the test account and click Revoke Authorization.
  6. Try to sign in from the second phone again. Confirm that the sign-in succeeds and the phone is bound automatically.

Related topics

Submit Feedback