--- title: User Device Enrollment lang: en-US meta: - name: keywords content: >- pomerium, identity access proxy, webauthn, device id, enroll, enrollment, authentication, authorization description: >- This guide covers how to enroll a trusted execution environment device as a Pomerium end-user. --- # Enroll a Device as a User If a Pomerium route is configured to [require device authentication](/docs/topics/ppl.md#device-matcher), then the user must register a [trusted execution environment](/docs/topics/device-identity.md#authenticated-device-types) (**TEE**) device before accessing the route. Registration is easy, but different depending on the device being used to provide ID.