New Security Device Facts

Coming in the next Addigy update are 18 new security device facts. These new facts will give you even more power to monitor the current state of your fleet of devices and further leverage remediations when devices are not properly secured. These new facts include being able to quickly determine the status of firmware security on Mac devices, Passcode states on iOS devices, the type of enrollment methods for each devices, and more. 

The security Device Facts can be added to the Devices view table and appear in the GoLive Device Fact list on the Device Overview tab. The new Facts will also appear on the GoLive Device Security tab. Security Facts that do not apply to the device type being viewed on GoLive will not appear. Facts that do not apply to the current device will appear in the Devices view with a value of “n/a”. 

The New Facts

(note that these device facts are collected via MDM and require devices to be enrolled with Addigy MDM)

FactSupported OS, HardwareValues
External Boot Level macOS 15+ with T2Allowed, Disallowed, or Not supported
Secure Boot LevelmacOS 15+ with T2Off, Medium, Full, Not Supported
Hardware Encryption CapabilityiOSBlock-level encryption, File-level encryption, or Both. 
Enrolled via DEP (Automated Device Enrollment)iOS, iPadOS, macOSTrue or False
User Enrollment iOS and iPadOS 13+, macOS 15+True or False
Has MDM Profile ApprovediOS, iPadOS, macOSTrue or False
Passcode Present True of False 
Passcode Compliant with ProfilesiOS and iPadOSSet to true if the userʼs passcode is compliant with requirements from profiles
Passcode CompliantiOS and iPadOSSet to true if the userʼs passcode is compliant with all requirements on the device, including Exchange and other accounts.
Passcode Lock Grace Period Enforced **iOS and iPadOSThe current enforced value for the amount of time in seconds the device must be locked before unlock will require the device passcode.
Passcode Lock Grace Period **iOS and iPadOSThe user preference for the amount of time in seconds the device must be locked before unlock will require the device passcode. The minimum value is 0 and the maximum value is 14400 seconds.
Firewall Allowed ApplicationsmacOSList of apps allowed through enabled firewall
Firewall Block All Incoming ConnectionsmacOSTrue of False
Firewall EnabledmacOSTrue or False
Firewall Stealth Mode EnabledmacOSTrue or False
Firmware Password ExistsmacOSTrue or False
Firmware Password Change PendingmacOSTrue or False
Firmware Passwords Allow OramsmacOSTrue or False

** For Passcode Lock Grace Period values to report anything other than 0 (Immediate), Settings→ Touch ID & Passcode → iPhone Unlock must be disabled.

Additional Resources

The new security Device Facts are available to create Custom Monitoring and Alerting. See this KB article for details.

To add remediation to the alerts you have created, see this KB for details.

For additional details on these facts please see Apple’s MDM Protocol Reference.

Similar Posts