Set Conditional Access for Self-Service Workpod Enrollments

One Workpod. Different Devices. Complete Control. 

In a previous blog, I introduced introducing Cloudpager Workpod Enrollment. We explored how employees can self-enroll into a digital workspace using their existing corporate identity. Whether their device is corporate-managed, a Windows 365 Cloud PC, or a personal BYOD device, employees can quickly gain access to the applications they need without the traditional provisioning process. 

But enrollment is only part of the story. The real power of Cloudpager Workpods lies in what happens after an employee enrolls. 

Rather than treating every enrolled device equally, Cloudpager Policies allow administrators to make intelligent, application-level decisions about what should be delivered based on the characteristics of the device, the desktop environment, and their organization’s own security requirements.

The result is a digital workspace that automatically adapts while remaining centrally managed. 

Moving Beyond Traditional Conditional Access 

Traditional conditional access solutions typically answer a single question: 

Can this user access this application? 

Cloudpager takes that concept several steps further. Instead of making a single yes-or-no decision for an entire workspace, Cloudpager Policies evaluate every application within a Workpod independently. An employee may successfully enroll into a Workpod, but the applications they receive can vary depending on the Trust Policies configured by the administrator. 

Rather than creating multiple versions of the same workspace, administrators create a single Workpod and allow Cloudpager Policies to determine exactly which applications should be delivered to each device. 

This dramatically simplifies administration while providing far greater control over application delivery. 

Delivering Applications Based on Device Trust 

Imagine a Workpod containing ten applications and a set of configurations. Most of those applications are suitable for any enrolled employee, but one business-critical application has only been certified on the latest release of Windows 11. 

An administrator can create a Trust Policy requiring Windows 11 25H2 before that application is delivered. An employee enrolling from a Windows 11 24H2 device still receives the Workpod along with every other permitted application. The unsupported application simply isn’t delivered. 

Later that same employee enrolls from another device running Windows 11 25H2. Nothing changes from the user’s perspective; they enroll using the same identity and access the same Workpod. This time, however, Cloudpager evaluates the Trust Policy, determines that the operating system now satisfies the requirement and automatically delivers the additional application. 

No manual intervention. 

No separate Workpod. 

No additional application assignments. 

Just intelligent application delivery based on policy. 

Tailor Application Experience to Users Across Different Devices

Operating system version is just one example of the level of control available. In the video demonstration, I configured a Workpod containing applications intended for different types of devices. Several of those applications were restricted to a group of Windows 365 Cloud PCs using a Trust Policy. When I accessed my Windows 365 environment, every application in the Workpod was delivered exactly as expected. I then enrolled into the very same Workpod from a personal Windows device. The experience immediately changed. The applications intended only for Windows 365 simply weren’t delivered. Everything else remained available. 

The employee didn’t need a different account. 

The administrator didn’t need to create another Workpod. 

Cloudpager simply evaluated the device, applied the configured policies and delivered only the applications that met the organization’s requirements. 

This approach opens the door to a wide range of scenarios. Perhaps an application relies on specialist hardware peripherals connected only to engineering workstations. Maybe a point-of-sale application should only appear on kiosk devices. Perhaps licensed software should only be available inside Windows 365 Cloud PCs. 

Rather than maintaining multiple application catalogues or separate workspaces, administrators define the requirements once and allow Cloudpager Policies to make the delivery decisions automatically. 

Controlling Offline Application Usage 

Not every employee works with a reliable internet connection. Sales teams travel. Consultants spend time at customer sites. Field engineers often work in locations where connectivity is intermittent or unavailable. In these situations, administrators may want certain applications to remain available offline without losing visibility or control. Cloudpager Software Asset Management and Delivery (SAMD) Policies make this possible. 

Administrators can specify exactly which applications may continue running without a network connection and, just as importantly, define how long that offline access remains valid. For example, an administrator may allow an application to operate offline for seven days. During that period, the employee continues working uninterrupted, even without internet access. 

Once the permitted offline period expires, Cloudpager requires the user to reconnect and re-authenticate before the application can continue to run. This strikes an effective balance between usability and security. 

Employees can remain productive while travelling, yet organizations retain confidence that application access is periodically validated and that devices cannot remain disconnected indefinitely. 

Policy-Driven Workspaces 

Perhaps the most compelling aspect of setting conditional access for self-service Workpod enrollments is that administrators no longer need to think in terms of creating different workspaces for different users or devices. Instead, they select a few Workpods containing the applications employees require and then use Trust Policies to determine how that Workpods adapt to each endpoint. 

A Workpod can deliver different applications depending on: 

  • Windows OS version 
  • Device groups 
  • Offline capability through SAMD Policies 
  • License agreements 

The employee experiences a straightforward enrolment process. 

Behind the scenes, Cloudpager is continuously making intelligent decisions about which applications should be delivered. 

Flexibility Without Compromise 

As organizations embrace hybrid working, BYOD initiatives and virtual desktops, the challenge is no longer simply getting applications onto devices. The challenge is delivering the right applications to the right devices under the right conditions. 

Cloudpager Policies provide that level of precision when setting conditional access for self-service Workpod enrollments. 

Whether an employee enrolls from a personal laptop, a Windows 365 Cloud PC, a shared kiosk or a corporate-managed workstation, administrators retain complete control over what is delivered, what remains unavailable and how long applications can continue to operate offline. 

Workpod Enrollment makes application access simple. Cloudpager Policies ensure it remains secure, flexible and appropriate for every device that connects. 

Modern application delivery isn’t just about getting users connected. It’s about delivering exactly what they need and withholding what they shouldn’t have. 

Stick with Numecent for All Things Applications

Numecent’s application container technologies ensure any application can run on all Windows endpoints in a friction-free manner. To see how containerization enables you to dynamically provision applications and updates across all physical and virtual Windows desktops in a highly automated fashion, request time with our Technical Solutions team below:

About numecent

Numecent is an award-winning cloud technology provider headquartered in Irvine, California. The company’s technology portfolio, built upon 67 patents (and counting), simplifies the mobilization and management of Windows applications across modern desktop and multi-cloud environments. Enterprises around the world – including the largest Fortune 500 companies, cloud service providers, and MSPs – leverage these technologies to package and deploy thousands of applications to millions of end-users in a friction-free manner every day.

See Numecent in Action!

Schedule a demonstration with our Solutions Architects to see how we can simplify the mobilization and management of your entire Windows application estate across modern desktop and multi-cloud environments.