Working with Policies
This section contains the following topics:
Implement policies
Policies define requirements for devices, as well as what will happen if a device does not comply with requirements. Each policy consists of a rule and a compliance action (what happens if the rule is violated). Use the Policies page to select, set up, and distribute policies.
The following policy types are available:
Type |
What It Does |
||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Compromised Devices |
Flags devices that have been jailbroken (iOS) To view the violation reason why the system flagged an Android device as compromised due to rooting:
To view the violation reason why the system flagged an Android device as compromised due to rooting:
|
||||||||||||||||||||
Flags macOS devices that do not have a passcode or encryption enabled. |
|||||||||||||||||||||
Flags devices that might be incurring international roaming charges. Status is refreshed when the device checks in. For iOS, the service uses the roaming flag as set and reported by iOS. The compliance action is triggered by the first violation only. |
|||||||||||||||||||||
MDM/Device Administration Disabled |
If the device is MDM-disabled, then it will not be evaluated for any other policies or delta processing of configurations or apps further during check-ins. |
||||||||||||||||||||
Out of Contact |
Flags devices that have been out of contact with Ivanti Neurons for MDM for the specified time range. Choose the actions to take if the device has not checked in for a specified range of hours (2-3 to 23-24) or number of days. |
||||||||||||||||||||
MI Client Out of Contact (iOS only) |
Flags Ivanti Neurons for MDM clients that have been out of contact with Ivanti Neurons for MDM for the specified time range. Choose the actions to take if the client has not checked in for a specified range of hours (2-3 to 23-24) or number of days. This is also applicable for devices registered via iReg. The policy marks a device as non-compliant if there is no client or if the client has not checked-in for a defined period of time. |
||||||||||||||||||||
Flags devices that violate rules about which apps are allowed or required. |
|||||||||||||||||||||
Creates a custom policy based on conditions and related actions you specify. |
Compliance Actions
The following compliance actions are available:
Compliance Action |
What It Does |
---|---|
Monitor |
Flags the device in the Ivanti Neurons for MDM Devices page. By default, this action is turned on. |
Block |
Instructs Access and /or Sentry to block a device if the device tries to access a resource via Sentry or Access after the policy has been violated as of the last check-in details. |
Send message to user |
|
Quarantine |
|
Finding an existing policy
You can use filters and the search feature in the Policies page to find one or more existing policies.
Procedure
- Go to Policies.
- To filter a list of policies that match certain criteria, click Filters.
- Select one or more filter criteria.
- To search for an existing policy by its name, enter the policy name in the Search field.
Adding a policy
Procedure
-
Go to Policies.
-
Click +Add (upper right).
-
Select a policy type.
-
Complete the settings.
-
Select the device groups you want to receive this policy.
You can distribute to a maximum of 100 configuration files at once.
-
Click Done.
Editing a policy
Procedure
- Go to Policies.
- For the required policy, click the Edit (pencil) icon under the Actions column.
- Make your changes.
- Save the changes.
Deleting a policy
Procedure
- Go to Policies.
- For the required policy, click the Remove icon under the Actions column.
- Click Yes to confirm.
If you cannot see the Policies page, it might be that you do not have the required permissions. You need one of the following roles:
-
Device Management
-
Device Read Only
For more information, see Prioritize policies.