Back

Configure compliance alert rules

Alert rules define which device statuses trigger alerts. Until rules are set, no alerts appear. This article explains how to configure and manage them.

Overview

There are two kinds of rule, and the difference decides what you can configure today:

  • Global rules — Enrolment Status and Online Status. They apply to every managed device and depend on nothing. Always configurable.
  • MDM control rules — everything else: encryption, OS update, password policy, firewall, Wi-Fi, antivirus, admin user management. These only become configurable once the matching MDM control exists.

If a rule's control is not set up, it appears in a banner at the top of the page reading "X compliance alerts can't be set up yet", with a chip per affected rule and a Manage MDM controls button. Configure the control there and the rule joins the main list.


 

How to use

  1. Go to MDM > Compliance Alerts.
  2. Click Manage rules, top right. Every rule type appears as its own section, with one toggle per possible status.
  3. Find the rule type you want — Enrolment Status, Online Status, Recovery OS, Encryption, and so on.
  4. Toggle on the statuses that should raise an alert, and leave the rest off. For example, on Online Status many teams turn on Offline 7+ days but leave Offline off, because short check-in gaps are normal.
  5. Nothing to save. Changes apply automatically. From the next device sync, any device reporting a flagged status appears on the Compliance Alerts page.

A rule with no statuses toggled on is effectively off — the status is still recorded, but no alert is raised.

 

 

Reduce the noise

If the alerts list is too busy, go back to Manage rules and switch off the statuses that are transient or expected. The three that most often need turning off:

Status

Why it is noisy

Online Status — Offline

Short check-in gaps are normal. Most teams alert only on Offline 7+ days

Encryption — Missing recovery key

Escrow takes up to 24 hours and a restart after encryption is enabled, so newly encrypted devices trigger it and then resolve themselves

OS Update — Grace period

A Windows device that is late but still inside its grace window. Leave it off unless you want admins acting before the grace period ends

After you change a toggle, the next device sync recomputes the list and affected devices drop off on their own.

 

 

Rules waiting on an MDM control

Rule

You unlock it by

ThreatDown / SentinelOne

Connecting your endpoint protection integration

USB Blocking, App Blocking, Disable AirDrop, Screen Capture, Lock Profiles Pane

Creating the control it belongs to

Admin Password Rotation

Setting up rotation for local admin passwords

Entra SSO, Okta SSO

Adding the identity control for that provider


 

Permissions

Action

Permission

View rules

MDM_READ

Edit rules

MDM_WRITE


 

Tips and Best Practices

  • Start with Enrolment Status and Online Status. They are global, so they work before any MDM control exists and give you a meaningful list immediately.
  • Alert on Offline 7+ days, not Offline. A device that misses one check-in is not a problem, and flagging it trains people to ignore the list.
  • Leave Missing recovery key off during a rollout. Escrow lags encryption by up to 24 hours and a restart, so it fires on every newly encrypted machine and then clears itself.
  • Flag only what you would act on today. Every status you turn on is a promise that somebody triages it.
  • Revisit the rules after the first full week. The noisy ones are obvious once you have seen normal traffic, and they are much harder to guess in advance.
 

 

Troubleshooting and FAQ

Troubleshooting

  • The alerts list is empty. No statuses are toggled on. A rule with nothing enabled records status but never alerts.
  • A rule I need is not in the list. It is tied to an MDM control that does not exist yet. Look for the banner at the top of the rules page and use Manage MDM controls to set the control up first.
  • Newly encrypted devices keep alerting. That is Missing recovery key. Escrow takes up to 24 hours and a restart, so the alert resolves itself. Turn the status off if it is noisy during a rollout.
  • I changed a toggle and the list did not update. It recomputes on the next device sync, not instantly.

FAQ

  1. Do I have to save my changes?
    No. Toggles apply automatically.
     
  2. What happens if I turn every status off for a rule?
    The rule is effectively off. The status is still recorded but no alert is raised.
     
  3. Why can I see a rule but not configure it?
    Its underlying MDM control has not been set up. Configure the control and the rule becomes editable.
     
  4. How quickly do changes take effect?
    From each device's next sync.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice