Back

Configure compliance issue settings

Alert rules define which device statuses trigger alerts. Until rules are set, no alerts appear. This article explains how to configure and manage them.

Overview

Go to Compliance > Compliance issue settings. Every issue type appears as its own section, with every status it can report.

Two kinds of issue type:

  • Global — Enrolment Status and Online Status. They apply to every device, depend on nothing, and are always editable.
  • Tied to an MDM control — everything else. They become editable once the matching control is deployed.

Both kinds are listed either way. The ones waiting on a control are collapsed and read-only, with a line telling you which control to set up first — so you can see what compliance is able to watch before deciding whether to deploy it.


 

How to use

Each status is set to one of three behaviours:

Behaviour

What happens

Off

The status is still reported on the device, but raises nothing

Create Issue

Raises a compliance issue, visible in the list, on the device, and in your counts

Create Issue and Ticket

Raises the issue and opens a ticket, which auto remediation can then work

  1. Find the issue type you want to configure.
  2. Set each status. On Online Status, for example, many teams set Offline 7+ days to Create Issue and leave Offline on Off, because short check-in gaps are normal.
  3. Nothing to save. Changes apply automatically, from the next device sync.

An issue type with every status Off is effectively disabled.


 

Exempt devices that should never raise an issue

An exception removes a whole category of device from compliance, across every issue type at once. Nothing is raised for it: no issue, no ticket, no remediation.

Exception

Skips

Unassigned devices

Devices with no owner

In stock devices

Devices held in stock

Neither is on until you turn it on. And exempting a device does not blind you to it: its true state is still computed and still shown on its own page. What changes is that the queue, the counts and the tickets stop counting it.

Saving one recomputes the whole company: anything that no longer qualifies disappears, and the tickets attached to it close with it.


 

Give settling statuses time to clear

Not every non-compliant status means something is wrong. Some mean not finished yet: a profile still travelling to the device, an account mid-creation, a demotion waiting on its prerequisites. Left alone, these raise an issue the instant they are computed and withdraw it minutes later — which trains people to ignore the list.

Setting

Effect

No grace period

A settling status raises its issue immediately. This is the default

1, 3, 7, 14, 21 or 30 days

The status must persist that long first

Two caveats. It applies only to the settling kind — an unencrypted disk or a device offline for a week is a real violation and is raised on your terms regardless. And the clock is read at computation time, so expect the issue on the first computation after the window closes rather than to the minute.


 

Reduce the noise

The three that most often need turning off:

Status

Why it is noisy

Online Status — Offline

Laptops are shut on evenings and weekends. Most teams only care past a week

Encryption — Missing recovery key

The key is escrowed up to a day after encryption starts, and needs a restart. Every freshly encrypted machine trips this and then fixes itself

OS Update — Grace period

The device is late but still inside the window you granted it. Raising it now asks admins to act before their own deadline


 

Issue types waiting on a control

Issue type

Becomes available when

ThreatDown / SentinelOne

You connect your endpoint protection integration

USB Blocking, App Blocking, Disable AirDrop, Screen Capture, Lock Profiles Pane

You create the control it belongs to

Admin Password Rotation

You set up rotation for local admin passwords

Entra SSO, Okta SSO

You add the identity control for that provider


 

Permissions

Action

Permission

View settings

MDM_READ

Change settings

MDM_WRITE


 

Tips and Best Practices

  • Keep ticketing narrower than issue-raising. Raise issues widely to keep your posture visible; open tickets only on what somebody will actually work.
  • Turn on the stock exception before your first audit, not after. Warehouse devices are meant to be offline and unencrypted, and they will otherwise dominate your queue.
  • Use the grace period instead of turning a status off. It keeps the real violations and drops the ones that were only mid-flight.
  • Expect a batch the first time you set a status to Create Issue and Ticket. It backfills tickets for devices already affected.
  • Revisit after the first full week. The noisy statuses are obvious once you have seen normal traffic and impossible to guess in advance.
 

 

Troubleshooting and FAQ

Troubleshooting

  • The issues list is empty. No statuses are set to raise anything. An issue type with everything Off records data but never flags.
  • An issue type is greyed out. Its MDM control has not been deployed. Set the control up and the issue type becomes editable.
  • Newly encrypted devices keep raising issues. That is Missing recovery key. Escrow lags encryption by up to 24 hours and a restart. Set a grace period, or turn the status off during a rollout.
  • A device that should be exempt is still listed. The exception is saved but the recompute has not reached that device. It clears on the next computation.

FAQ

  1. Do I have to save my changes?
    No, they apply automatically.
     
  2. What is the difference between Create Issue and Create Issue and Ticket?
    The first flags it for you to see. The second also opens a ticket, which auto remediation can work.
     
  3. Does an exception hide the device's real state?
    No. The state is still computed and shown on the device page. Only the list, the counts and the tickets skip it.
     
  4. How quickly do changes take effect?
    From each device's next sync.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice