you should be using a client cert on your devices and a proxy which only allows the device to go through if the client cert matches (lots of products do this already, see duo for example).
Now you can use osquery and other factors to populate a set of additional checks in a backend and either have the proxy have them, or have your backend invalidate the device cert