Tracking the policy distribution status for devices

Administrators can view all devices that are in the scope for a policy and track the policy distribution status for those devices.

Supported devices

  • iOS
  • Windows
  • Android
    Note: This feature is not available for Android devices if geo-fencing rules are enabled for your MaaS360 account.

Follow these steps to track the policy distribution status for devices:

  1. From the MaaS360 Portal Home page, select Security > Policies.

    The Policies page is displayed.

  2. Click the More link that is displayed under the policy name and then click Assignment Status.

    The Devices in scope page is displayed if the policy has an active distribution.

    Note: An appropriate message is displayed if the policy does not have an active distribution.
    Devices in scope page
    Section Description
    a - Policy details The policy details include policy status, name, type, version, and last published information.
    b - Primary policy statuses Navigation links to quickly view the devices in each primary policy status. Click the relevant tab to display the corresponding devices in the grid.

    The primary policy statuses are as follows:

    • Success: The policy was successfully delivered to the device.
    • Failed: The policy failed to deliver to the device.
    • In progress: Policy delivery to the device is in progress. This status contains the following sub-statuses:
      • Policy assignment processed
      • Scheduled for delivery
      • Certificate requested
      Note: The primary policy status is displayed as In progress when a device is in one of the sub-statuses.
    c - Accordion Expand the accordion or twistie next to a device name to view the policy distribution status for the device.
    d - Refresh Refreshes the Devices in scope page.
    e - Filter Filters the devices based on the following criteria:
    • Status
    • Status updated

    Select the filter criteria to sort the devices and display the relevant devices in the grid.

    f - Customize columns Customizes the columns based on the device details that you want to view in the grid. You can only display the columns that you want to view in the grid and hide the remaining columns. You can rearrange columns based on the information that you want to display first in the grid or reset the grid to the default column settings.
  3. Expand the accordion or twistie next to a device name to view the policy distribution status for the device.
    Accordion or twistie in Devices in scope page

    The view displays the intermediate stages of the policy distribution. All stages must be completed to successfully deliver a policy to the device.

    policy distribution status
    The administrator can view the following:
    • Track the policy distribution status for devices.
    • Determine the specific stage that policy distribution failed.
    • View the list of payloads that failed to install.
    • Push a policy again if that policy failed to deliver to devices.

    The policy distribution statuses in the accordion or twistie view are as follows:

    Status name Description Additional information
    Policy assignment processed The device is eligible for policy delivery.
    Note: Hover over this status to view the reason why the policy delivery was triggered for this device.
    MaaS360 performs various evaluations to identify the devices that are eligible for policy delivery.

    For information on the order of priority to decide which type of policy is applied on a device, see Using policy precedence on devices.

    Scheduled for delivery The policy delivery is initiated and a policy update command is scheduled for the device. The device must be online and must continuously report to the MaaS360 Portal to receive the policy update command.
    Note: The device might remain in this status for a long time if these conditions are not met.
    Certificate requested The device waits for the Cloud Extender to generate and deploy the certificates that are required for policy delivery.
    Note:
    • This status applies to devices that require certificates for policy delivery.
    • This status does not apply to Android devices.
    The following conditions must be satisfied to successfully complete this stage:
    • The device must be online and must continuously report to the MaaS360 Portal.
    • The Cloud Extender must be up and running.
    • The Cloud Extender must successfully generate and process certificates.
    • The certificate authority must be up and running.
    Note: The device might remain in this status for a long time if these conditions are not met.
    Policy installed The policy is successfully delivered to the device. All payloads were successfully installed.
    Policy delivery failed/Partial policy delivery failed The policy failed to deliver to the device.
    Note: Use the Repush policy action to apply the entire policy configuration to the device again. For more information, see Repushing a policy to devices section.
    A policy fails to deliver to a device if installation of all or some of the scheduled payloads fails.

    To view the list of failed payloads, go to the Device Summary page by clicking the Device Name. The Failed Settings field in the Workplace and Security section displays the list of payloads that failed to install.

Repushing a policy to devices

You can repush a policy if the policy failed to apply to devices or the policy is partially delivered to devices. Policy delivery fails when the installation of a scheduled policy payloads failed, the Cloud Extender is down, requested certificates are unavailable, or the device is unavailable. When you repush a policy, the entire policy configuration is applied to the device again.

Note:
  • This action is not available for administrators with Read-only permissions.
  • Use the Repush policy action with caution since the entire policy (including all policy-related configurations) is applied to the device again. This action might cause payloads to reload on the device and devices might request certificates that were already configured for the device.

Follow these steps to repush a policy to a device:

  1. Navigate to the Devices in scope page.
  2. Select the devices that you want take the Repush policy action on.
    • Follow these steps to take the Repush policy action in bulk:
      1. Click the navigation links for the devices in the Failed status.
        Quick navigation links for devices in failed status

        All the devices in the Failed status are displayed in the grid.

      2. Select the checkboxes next to the Device ID or click Select all to select all the devices in the grid.
        Select devices in failed status
      3. Click Repush policy to push the entire policy configuration to all the selected devices again.
        Repush policy

        A confirmation message is displayed that indicates that the Repush policy action will push all the policy-related configurations to the device again, which might reload some of the configurations.

    • Follow these steps to take the Repush policy action on individual devices:
      1. Click the Repush policy icon next to the device that is in a failed status.
        Repush policy action on a single device

        A confirmation message is displayed that indicates that the Repush policy action will push all the policy-related configurations to the device again, which might reload some of the configurations.

  3. Click Confirm.

    The policy distribution is triggered and all policy-related configurations are applied to the selected devices again.