Overview
Go to Compliance > Compliance issue settings. Every issue type appears as its own section, with every status it can report.
Two kinds of issue type:
- Global — Enrolment Status and Online Status. They apply to every device, depend on nothing, and are always editable.
- Tied to an MDM control — everything else. They become editable once the matching control is deployed.
Both kinds are listed either way. The ones waiting on a control are collapsed and read-only, with a line telling you which control to set up first — so you can see what compliance is able to watch before deciding whether to deploy it.
How to use
Each status is set to one of three behaviours:
Behaviour |
What happens |
|---|---|
Off |
The status is still reported on the device, but raises nothing |
Create Issue |
Raises a compliance issue, visible in the list, on the device, and in your counts |
Create Issue and Ticket |
Raises the issue and opens a ticket, which auto remediation can then work |
- Find the issue type you want to configure.
- Set each status. On Online Status, for example, many teams set Offline 7+ days to Create Issue and leave Offline on Off, because short check-in gaps are normal.
- Nothing to save. Changes apply automatically, from the next device sync.
An issue type with every status Off is effectively disabled.
Exempt devices that should never raise an issue
An exception removes a whole category of device from compliance, across every issue type at once. Nothing is raised for it: no issue, no ticket, no remediation.
Exception |
Skips |
|---|---|
Unassigned devices |
Devices with no owner |
In stock devices |
Devices held in stock |
Neither is on until you turn it on. And exempting a device does not blind you to it: its true state is still computed and still shown on its own page. What changes is that the queue, the counts and the tickets stop counting it.
Saving one recomputes the whole company: anything that no longer qualifies disappears, and the tickets attached to it close with it.
Give settling statuses time to clear
Not every non-compliant status means something is wrong. Some mean not finished yet: a profile still travelling to the device, an account mid-creation, a demotion waiting on its prerequisites. Left alone, these raise an issue the instant they are computed and withdraw it minutes later — which trains people to ignore the list.
Setting |
Effect |
|---|---|
No grace period |
A settling status raises its issue immediately. This is the default |
1, 3, 7, 14, 21 or 30 days |
The status must persist that long first |
Two caveats. It applies only to the settling kind — an unencrypted disk or a device offline for a week is a real violation and is raised on your terms regardless. And the clock is read at computation time, so expect the issue on the first computation after the window closes rather than to the minute.
Reduce the noise
The three that most often need turning off:
Status |
Why it is noisy |
|---|---|
Online Status — Offline |
Laptops are shut on evenings and weekends. Most teams only care past a week |
Encryption — Missing recovery key |
The key is escrowed up to a day after encryption starts, and needs a restart. Every freshly encrypted machine trips this and then fixes itself |
OS Update — Grace period |
The device is late but still inside the window you granted it. Raising it now asks admins to act before their own deadline |
Issue types waiting on a control
Issue type |
Becomes available when |
|---|---|
ThreatDown / SentinelOne |
You connect your endpoint protection integration |
USB Blocking, App Blocking, Disable AirDrop, Screen Capture, Lock Profiles Pane |
You create the control it belongs to |
Admin Password Rotation |
You set up rotation for local admin passwords |
Entra SSO, Okta SSO |
You add the identity control for that provider |
Permissions
Action |
Permission |
|---|---|
View settings |
MDM_READ |
Change settings |
MDM_WRITE |
Tips and Best Practices
- Keep ticketing narrower than issue-raising. Raise issues widely to keep your posture visible; open tickets only on what somebody will actually work.
- Turn on the stock exception before your first audit, not after. Warehouse devices are meant to be offline and unencrypted, and they will otherwise dominate your queue.
- Use the grace period instead of turning a status off. It keeps the real violations and drops the ones that were only mid-flight.
- Expect a batch the first time you set a status to Create Issue and Ticket. It backfills tickets for devices already affected.
- Revisit after the first full week. The noisy statuses are obvious once you have seen normal traffic and impossible to guess in advance.
Troubleshooting and FAQ
Troubleshooting
- The issues list is empty. No statuses are set to raise anything. An issue type with everything Off records data but never flags.
- An issue type is greyed out. Its MDM control has not been deployed. Set the control up and the issue type becomes editable.
- Newly encrypted devices keep raising issues. That is Missing recovery key. Escrow lags encryption by up to 24 hours and a restart. Set a grace period, or turn the status off during a rollout.
- A device that should be exempt is still listed. The exception is saved but the recompute has not reached that device. It clears on the next computation.
FAQ
-
Do I have to save my changes?
No, they apply automatically.
-
What is the difference between Create Issue and Create Issue and Ticket?
The first flags it for you to see. The second also opens a ticket, which auto remediation can work.
-
Does an exception hide the device's real state?
No. The state is still computed and shown on the device page. Only the list, the counts and the tickets skip it.
-
How quickly do changes take effect?
From each device's next sync.