website/docs/endpoint-devices/authentik-agent/device-authentication/device-access-groups.mdx
Device access groups control access to endpoint devices. You can organize devices into groups and bind users, user groups, and policies to determine which users can access the device.
:::warning Device access groups are required for local device login to work. If a device is not assigned to an access group with the appropriate bindings, all login attempts to that device will be denied. :::
To create a device access group, follow these steps:
After creating a device access group, you need to assign devices to it. There are two ways to do this: