Security Status
The Security Status view provides a per-device overview of critical security controls. From this single screen you can assess whether a device meets your organization's security baseline and take remediation action without switching contexts.
Per-Device Security Overview
Each device in the list shows a summary card with:
- Device name and model
- OS version and build number
- Compliance badge — green (pass), yellow (warning), red (failing)
- Last check-in time
Click any device to expand its full security detail panel.
FileVault Encryption (macOS)
FileVault provides full-disk encryption on macOS. The status column reports one of:
| Status | Meaning |
|---|---|
| Encrypted | Volume is fully encrypted |
| Pending | Encryption in progress |
| Not Encrypted | FileVault is off |
| Unknown | Device has not reported |
When a device shows Not Encrypted, you can issue a remote FileVault command from the action menu to enable encryption. The user will be prompted on their next login to complete the process.
System Integrity Protection (macOS)
SIP protects critical system files from modification. The status column reports:
- Enabled — SIP is active (recommended)
- Disabled — SIP has been turned off
- Unknown — No report received
A disabled SIP is a significant security finding. Devices with SIP disabled are flagged with a red badge and should be investigated.
Passcode Presence and Compliance
The passcode section shows:
- Passcode set — Yes / No
- Passcode type — Numeric, Alphanumeric, or Complex
- Passcode length
- Compliance — whether the passcode meets your organization's minimum length and complexity policy
Devices without a passcode, or with a passcode that fails policy, are marked non-compliant. You can trigger a passcode compliance re-check from the action menu.
Activation Lock Status
Activation Lock prevents a lost or stolen device from being reactivated without the owner's Apple ID credentials. The status column reports:
- Enabled — Activation Lock is on
- Disabled — Activation Lock is off
- Unknown — No report received
For supervised devices, you can bypass Activation Lock during re-enrollment by clearing the lock from the device detail panel. This requires that the device has been returned to your organization.
Find My Device Status
Find My helps locate lost devices. The status column reports:
- Enabled — Find My is active
- Disabled — Find My is off
- Unknown — No report received
A disabled Find My status on a corporate device may indicate a user attempting to evade tracking. These devices are flagged for review.
Supervision Status
Supervision indicates whether a device is managed by your MDM. The status column reports:
- Supervised — Device is under MDM management
- Unsupervised — Device is not managed
- Unknown — No report received
Unsupervised devices have limited management capabilities. Certain security policies (e.g., Activation Lock bypass, forced passcode changes) require supervision.
Battery Level Monitoring
The battery level is displayed as a percentage alongside a visual indicator:
- Above 50% — Green
- 20% – 50% — Yellow
- Below 20% — Red
Low battery can interfere with critical management commands (e.g., remote wipe, software updates). Devices below 20% are flagged so you can prioritize charging before issuing commands.
Taking Action on Security Issues
From the device detail panel, the action menu provides:
- Enable FileVault — Send remote encryption command (macOS)
- Lock Device — Immediately lock the device and display a custom message
- Wipe Device — Factory reset the device (use with caution)
- Clear Activation Lock — Remove Activation Lock for supervised devices
- Sync Now — Force a check-in to refresh all security status fields
- Send Custom Command — Issue a raw MDM command for advanced workflows
Each action logs to the device's audit trail for compliance tracking.
