> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Trusted Devices

> Restrict DingTalk sign-in to approved desktop and mobile devices by managing trusted devices individually or in bulk and enforcing access policies.

**Feature Description:** Manage which devices are allowed or restricted from signing in to DingTalk, and configure the corresponding enforcement policies.

***

## Admin Console Navigation

In the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/476352aa-7bf4-4d6d-a1df-f34100b0497e.png" alt="Trusted Device navigation" />
</Frame>

## Personal Trusted Device Management

Navigation path: in the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device > Personal Device**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/f506498a-0770-45e5-aa78-a4363fbadd3a.png" alt="Personal Device navigation" />
</Frame>

### Adding a Desktop Personal Trusted Device

<Tabs>
  <Tab title="Add a single device">
    Administrators can enter the employee name, select the platform (Windows or Mac), and fill in the device's MAC address (format: xx:xx:xx:xx:xx:xx). Multiple MAC addresses are supported with no limit on the number. **Once the information is entered and saved**, the device becomes trusted (takes effect immediately by default), and the employee can use it to sign in to DingTalk.

    <Frame>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/a67dd20a-ddfc-4139-810a-9d4eb5175b1b.png" alt="Add a single trusted device" />
    </Frame>
  </Tab>

  <Tab title="Batch add devices">
    A template is provided for administrators to **bulk-add desktop personal trusted devices**.

    1. **Export** the batch import template.
    2. Follow the template's instructions and **enter the data** in the required format.
    3. **Upload** the template and **click Confirm** to complete the import (re-uploading is supported). The devices listed in the template will become trusted (takes effect immediately by default) and can be used to sign in to DingTalk.

    <Note>
      Batch import only supports MAC addresses of employees already in the organization's directory. To add new employees, first invite them to join from the Contacts section.
    </Note>

    <div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/329a8d87-06da-463b-aaaa-069f8e3d7fff.png" alt="Export batch import template" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/0c0a2ac8-9c1f-43dd-8960-b53881350962.png" alt="Enter data in the template" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/0091c4c7-ed23-4834-b9b4-056fc7d90ca7.png" alt="Upload the template" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
    </div>
  </Tab>
</Tabs>

### Adding a Mobile Personal Trusted Device

Mobile devices cannot be added from the admin console. When an employee attempts to sign in to DingTalk on an untrusted mobile device, they will be prompted to apply for trusted device status.

**Employee side:** **Click "To apply"** to proceed to Step 2. **Select the device type, agree to the terms, and submit the application.** This completes the personal trusted device application.

<Note>
  The "company device" option here does not refer to "shared trusted devices." It simply indicates that the device is company-owned.
</Note>

<div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/9338aeae-fbfa-4b8f-bb12-7119a9504704.png" alt="Apply on mobile" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/4c592da1-cd9e-4b24-b721-f834d125aeb9.png" alt="Select device type" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/36c1b604-5f40-4103-99ce-8db77fa789f6.png" alt="Submit application" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
</div>

**Admin side:** Administrators can **approve or reject** employees' trusted device applications, from either the approval message or the admin console.

<Tabs>
  <Tab title="Approve via message">
    Administrators can **approve or reject** employees' trusted device applications. Devices that have already been processed in the admin console will be synced here automatically, so no duplicate action is needed.

    The following fields are provided: company, employee name, employee ID, department, device name, application time, and current number of trusted devices. Administrators can **approve or reject** each application.

    * **When approved:** The device becomes trusted, and the employee can use it to sign in to DingTalk.
    * **When rejected:** The device remains untrusted, and the employee cannot use it to sign in to DingTalk.

    <Frame>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/8a3b648d-21a3-436c-89dc-349c964ba926.png" alt="Approve via message" />
    </Frame>
  </Tab>

  <Tab title="Approve in admin console">
    In the admin console, administrators can **approve or reject** employees' trusted device applications.

    * Individual approvals: **Approve** or **Reject**.
    * Batch approvals: **Batch Approve** or **Batch Reject**.
    * **When approved:** The device becomes trusted, and the employee can use it to sign in to DingTalk.
    * **When rejected:** The device entry is removed from the list, and the employee cannot use it to sign in to DingTalk. Administrators may also provide a rejection reason and choose whether to allow the employee to reapply.

    <div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/d64f57c9-4081-4bde-808c-6ed90c1fc80d.png" alt="Individual approval" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/953995ae-7405-4d0d-afa2-60522b41819a.png" alt="Batch approval" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/6c9184a8-1498-4505-9ef0-b9a5fc543088.png" alt="Rejection with reason" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
    </div>
  </Tab>
</Tabs>

### Managing the Personal Trusted Device List

* You can search the trusted device list by multiple dimensions, including employee name, device trust status (all, pending approval, trusted), client type (all, Windows, Mac, Android, iOS), MAC address (xx:xx:xx:xx:xx:xx, desktop only), and registration/application time.
* You can **report as lost, delete, batch delete, or promote to a shared trusted device** (lost or deleted devices will be **forced to sign out of DingTalk**). The device list can also be exported locally.

<div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/e44d7352-3eb4-4e6e-8309-8b22d17fc026.png" alt="Search the device list" style={{width: '48%', minWidth: '280px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/194ce174-cfd8-4981-91f7-fca5edeef49f.png" alt="Manage device list actions" style={{width: '48%', minWidth: '280px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
</div>

## Company Trusted Device Management

Navigation path: in the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device > Company Device**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/49cc43d2-d98f-4fe0-9d4e-e79f914c5c62.png" alt="Company Device navigation" />
</Frame>

### Adding a Desktop Company Device

<Tabs>
  <Tab title="Add a single device">
    Administrators can add a single desktop shared trusted device by entering the device name, selecting the platform (Windows or Mac), and filling in the device's MAC address (format: xx:xx:xx:xx:xx:xx; multiple MAC addresses are supported with no limit). **Once the information is entered and saved**, the device becomes trusted. Employees within the designated scope can use the device to sign in to DingTalk.

    <Frame>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/77829ac2-2ed8-493b-b186-a06f2672d8f0.png" alt="Add a single company device" />
    </Frame>
  </Tab>

  <Tab title="Batch add devices">
    A template is provided for administrators to **batch-add desktop personal trusted devices**.

    1. **Export** the batch import template.
    2. Follow the template's instructions and **enter the data** in the required format.
    3. **Upload** the template and **click Confirm** to complete the import (re-uploading is supported). The devices listed in the template will become trusted, and employees within the designated scope can use them to sign in to DingTalk.

    <Note>
      Batch import only supports MAC addresses of employees already in the organization's directory. To add new employees, first invite them to join from the Contacts section. Imported shared devices are **available to all employees by default**.
    </Note>

    <div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/49a5b9c2-d622-494f-87cf-dc5caf62d6e8.png" alt="Export company device template" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/3c965c46-e240-47b9-a630-9200a0fd131b.png" alt="Enter company device data" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

      <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/73c0018d-6316-473c-957f-91f1c37873ca.png" alt="Upload company device template" style={{width: '32%', minWidth: '180px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
    </div>
  </Tab>
</Tabs>

### Managing the Shared Trusted Device List

* You can search the trusted device list by multiple dimensions, including device name, client type (all, Windows, Mac), MAC address (xx:xx:xx:xx:xx:xx, desktop only), and registration/application time.
* You can configure the **available employee scope (all employees / specific employees)**, as well as **delete or batch delete** trusted devices (deleted devices will be **forced to sign out of DingTalk**). The device list can also be exported locally.

<div style={{display: 'flex', gap: '12px', justifyContent: 'center', flexWrap: 'wrap', margin: '16px 0'}}>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/8cba9f9a-aa54-479c-81af-872a6c0a3b73.png" alt="Search shared device list" style={{width: '48%', minWidth: '280px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />

  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/518c63b3-1ec3-4fbf-9e82-f76b159d9237.png" alt="Manage shared device scope" style={{width: '48%', minWidth: '280px', borderRadius: '8px', boxShadow: '0 2px 12px rgba(0,0,0,0.08)', margin: 0}} />
</div>

## Rule Configuration

Navigation path: in the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device > Rule Configuration**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/03c9d010-a35f-44f7-93b1-657d8181474f.png" alt="Rule Configuration navigation" />
</Frame>

## Kick-off Policy Configuration

Navigation path: in the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device > Kick-off Policy Configuration**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/19e8faa1-22cc-40bb-b371-9578c49a607c.png" alt="Kick-off Policy Configuration navigation" />
</Frame>

## Cold Start Configuration

Navigation path: in the left navigation pane, go to **Security & permission > Security > Access Control > Trusted Device > Cold Start Configuration**.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/90465d68-0612-450e-b0dd-912c18d085f5.png" alt="Cold Start Configuration navigation" />
</Frame>

### Enforcement Settings

* **Auto-approve first mobile device and collect information:** When enabled, an employee's first mobile personal device is auto-approved and becomes a trusted device.
* **Auto-collect mobile device information:** When enabled, if an employee signs in on an untrusted mobile device, the device information is automatically collected. The trust status remains unchanged (still untrusted), and the administrator can approve it from the device list.
* **Auto-approve first desktop device and collect information:** When enabled, an employee's first desktop personal device is auto-approved and becomes a trusted device.
* **Auto-collect desktop device information:** When enabled, if an employee signs in on an untrusted desktop device, the device information is automatically collected. The trust status remains unchanged (still untrusted), and the administrator can approve it from the device list.

<Frame>
  <img src="https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/v9kqDejXV8oMMOVx/img/193b4d8b-f466-484d-ad51-f1d3f1d9143b.png" alt="Enforcement settings" />
</Frame>

## Q\&A

| Item                   | Description                                                                                                                                                                                                                                                        |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Prerequisites**      | Collecting employee device information requires first signing the *Trusted Device Information Collection* agreement.                                                                                                                                               |
| **Supported Versions** | Desktop (version 8.3.15 and above); Mobile (version 8.3.15 and above)                                                                                                                                                                                              |
| **Enforcement Method** | After approval, the policy takes effect immediately by default. Desktop: Configurable in Admin Console > Policy Settings > Enforcement Settings > Effective Time. Mobile: Configurable in Admin Console > Policy Settings > Enforcement Settings > Effective Time. |

<AccordionGroup>
  <Accordion id="q1" title="Q1: What does 'Remove users on untrusted devices' do in the policy settings? Can't untrusted devices already not sign in to DingTalk?">
    *How do I cold-start the trusted device feature if my organization has already been using DingTalk and then purchases trusted devices?*

    **A1:**

    An employee signed in to DingTalk on Device A on January 1, 2022, before the organization had purchased the trusted device feature.

    The organization purchased trusted devices on January 1, 2023. However, the employee had already signed in on an untrusted device back on January 1, 2022, so Device A is outside of device management.

    Using the "Remove users on untrusted devices" feature, you can force DingTalk to sign out from Device A. After the forced sign-out, you can start the trusted device onboarding process from scratch.

    <Note>
      The current trusted device policy settings require importing some data before they can be used. This will be optimized in the future.
    </Note>
  </Accordion>

  <Accordion id="q2" title="Q2: How do I set multiple MAC addresses for the same desktop device in the batch import template?">
    **A2:** This feature is under development. Stay tuned.
  </Accordion>

  <Accordion id="q3" title="Q3: What is the validation logic for multiple MAC addresses on a desktop device?">
    **A3:** As long as the MAC address used at sign-in matches any one of the MAC addresses registered in the admin console, the device can sign in normally.
  </Accordion>

  <Accordion id="q4" title="Q4: How are personal trusted devices associated with specific employees?">
    **A4:** Personal trusted devices are tied to specific individuals within the organization. For example, if Company A enables the trusted device module, and Employee A of Company A applies for a personal trusted device (Device X), then no other employee in Company A can use Device X to sign in.
  </Accordion>

  <Accordion id="q5" title="Q5: What happens if an employee submits an application after 'Auto-collect mobile device information' is enabled?">
    **A5:** When "Auto-collect mobile device information" is enabled, if an employee signs in to DingTalk on an untrusted mobile device, the request does not go through the approval flow — the administrator will not receive an application. However, the device information will appear in the admin console device list, where the administrator can choose to approve or reject it. If the employee submits a formal application before the administrator processes it from the console, the administrator will receive the application, and the console list will overwrite the previously auto-collected device information.
  </Accordion>

  <Accordion id="q6" title="Q6: After enabling 'Auto-collect mobile device information,' will devices that were already signed in to DingTalk before the organization purchased trusted devices have their information collected?">
    **A6:** No.
  </Accordion>

  <Accordion id="q7" title="Q7: Does batch importing trusted devices overwrite previously imported data? What is the import logic?">
    **A7:** Importing follows an additive logic, not an overwrite logic.

    **Case 1:** If the admin console already contains trusted device information for Employees 1–5, and the administrator adds 10 entries for Employees 6–15 in the template, uploading the template will add entries for Employees 6–15, resulting in a total of 15 entries.

    **Case 2:** If Employee 1 already has one Windows trusted device, and the administrator adds another Windows trusted device for Employee 1 in the template, after uploading, Employee 1 will have two Windows trusted devices.
  </Accordion>

  <Accordion id="q8" title="Q8: Can the device name field be used to obtain the device's unique identifier?">
    **A8:** Due to compliance and system limitations, the unique identifier cannot be obtained.
  </Accordion>
</AccordionGroup>
