Configuring enforcement actions for compliance rules

You can automate device compliance by automatically acting when devices break rules. This helps protect company data, reduce security risks, and manage devices consistently across platforms without manual effort.

You can configure various enforcement actions to automatically apply to devices at specified time intervals when the device goes out of compliance (OOC) or does not meet the defined compliance criteria. You can add multiple enforcement actions and configure the required schedule and sequence for these actions.

For example, you might want to ensure that your managed devices are up to date with the required OS versions. You can configure the OS Versions rule and specify the allowed OS versions for different platforms such as iOS, Android, macOS. You can configure multiple enforcement actions to automatically apply when devices do not comply with the configured allowed OS versions as follows.

  • Send an alert immediately after the device enters the OOC state to inform the user.
  • If the device remains OOC one day after applying the first action, apply Selective Wipe action to revoke the device’s access to corporate content such as email, Wi-Fi, and VPN.
  • If the device remains OOC one day after applying the second action, apply the Remove Control action to stop managing the device.

The enforcement actions include Alert, Selective Wipe, Change Policy, Wipe, Remove Control, Hide Device, and so on. The list of enforcement actions varies for different rules. For more information on these actions, see Device details view.

You can also choose to notify the user by email or device notification and notify the admins with customized messages whenever an enforcement action is applied to the device.

Note: When a device enters the OOC state, modifying existing enforcement actions such as changing their sequence, adding new ones, or resetting interval doesn't prompt immediate compliance with the new configuration. Instead, the device continues to follow the previous enforcement actions that were in effect when it entered the OOC state, considering the duration since then. The new configuration is only considered once the time interval for the previously set actions has elapsed. After this interval, the device starts to implement the newly configured actions.