Device Security Status
Overview
GuardMDM collects security-related information from each managed device and displays it in the device detail page. This helps you verify that devices meet your organization's security baseline without relying on a separate compliance engine.
Where to Find Security Information
Open any device detail page and scroll to the Security & Integrity section. This area shows the current state of key security attributes reported by the device.
Passcode Status
The passcode section shows two pieces of information:
| Attribute | Meaning |
|---|---|
| Present | Whether a passcode is currently set on the device |
| Compliant | Whether the passcode meets the requirements defined by the assigned blueprint's passcode policy |
If a device shows Not Present or Not Compliant, the user either has not set a passcode or their existing passcode does not match the policy (for example, it is too short or too simple).
FileVault Status (macOS)
On macOS devices, GuardMDM reports whether FileVault full-disk encryption is enabled:
| State | Meaning |
|---|---|
| Enabled | FileVault is active and the disk is encrypted |
| Disabled | FileVault is not active |
Supervision Status
GuardMDM displays whether the device is under supervision — an Apple concept indicating organization ownership with elevated management capabilities.
- Supervised — The device was enrolled via Apple Business Manager (ADE) or Apple Configurator. Full MDM capabilities are available.
- Unsupervised — The device was enrolled manually. A subset of MDM capabilities is available.
Supervision is a prerequisite for many security-sensitive controls, including silent app installation, activation lock bypass, and certain restrictions.
Activation Lock
GuardMDM reports whether Activation Lock is active on the device. On supervised devices enrolled via ADE, GuardMDM can retrieve an Activation Lock bypass code, allowing IT to unlock the device without the user's Apple ID credentials.
Acting on Security Findings
When a device shows a security issue (for example, no passcode or FileVault disabled), you can take the following actions directly from the device detail page or the device list:
| Action | When to Use |
|---|---|
| Sync Now | Force the device to check in and report the latest status |
| Lock Device | Remotely lock the device to prevent unauthorized access |
| Erase Device | Factory reset the device as a last resort |
For passcode compliance issues, the user must manually update their passcode on the device to match the policy. GuardMDM will reflect the change on the next check-in.
Best Practices
- Review the Security & Integrity section after enrolling a new device to confirm baseline settings
- Use the Sync Now command to refresh status before acting on older data
- Combine passcode policy, restrictions, and FileVault requirements in your blueprints for defense in depth
- Address unsupervised devices that require supervised-only policies by re-enrolling through Apple Business Manager
