# How to create a compliance policy for devices?

Configuring compliance policies before enrolling devices lays a strong security foundation. If a device fails to meet the configured compliance criteria during its Mobile Device Management (MDM) lifecycle, it becomes non-compliant. Admins can effectively identify and address compliance violations from the device details page.

Compliance policies in Hexnode UEM allow administrators to define a set of rules and regulations that ensure devices comply with organizational requirements. These policies can be configured for multiple platforms, such as iOS, iPadOS, Windows, macOS, Android, visionOS, Linux, and ChromeOS.

Hexnode offers both basic and advanced compliance configuration settings. Basic settings allow administrators to select from a predefined set of compliance requirements, enabling quick detection of common device vulnerabilities. Advanced settings, on the other hand, offer granular control, allowing administrators to define custom compliance rules using a wide range of device attributes. It enables the creation of compliance policies tailored to each device platform.

This document will guide you through the process of creating and assigning compliance policies in Hexnode UEM.

 Note: 
When two conflicting compliance policies are associated with a device, the most recently applied policy will take effect.

 

Creating a Compliance policy in Hexnode 
----------------------------------------

To create a compliance policy in Hexnode UEM:

1. Log in to your Hexnode UEM console.
2. Navigate to **Policies > Compliance Policies**.
3. Choose an existing policy or click **New Policy** to create a new one.
4. Enter the basic details for the policy: 
    1. **Policy Name**: A name to identify the policy being configured. This is a mandatory field.
    2. **Description**: A brief description of the policy. This is optional, with a maximum character limit of 500.
5. You will then be presented with two types of settings: 
    1. **Basic Settings**: Admins are provided with a set of predefined compliance settings to choose from.
    2. **Advanced Settings**: These provide a wider range of configurable factors to define compliance criteria, also curated based on the selected platform.

 Note: 
Upon device enrollment, each platform is assigned a default compliance policy with all basic settings enabled. When an administrator applies a new compliance policy, it overrides the default compliance policy settings on the associated devices.

 

 SettingsDescriptionSupported DevicesMDM app/profile is removed from deviceDevice will be marked as non-compliant if the Hexnode MDM app is removed from the device.- Android

Device will be marked as non-compliant if the MDM profile is removed from the device.- iOS/iPadOS
- macOS
- Apple TV
- Windows
- visionOS

Policy is removed from deviceDevice will be marked as non-compliant if the policy is removed from the device.- macOS

Device becomes inactiveDevice will be marked as non-compliant if it has not been scanned for a particular number of days as specified under **Admin > General Settings > Inactivity Settings**.- All Devices

Device is not encryptedDevice will be marked as non-compliant if the device is not encrypted.- On iOS/iPadOS, the device data will be automatically encrypted when a password is set for the device.
- For devices running Android 6.0+, encryption will be turned on automatically.
- For devices prior to Android 6.0 and Windows devices, encryption has to be turned on manually.
- macOS
- Windows

Device is not password compliantDevice will be marked as non-compliant if there is no password set on the device or if the device does not meet the password requirements as per the password policy.- Android
- iOS/iPadOS
- macOS

Device is not application compliantDevice will be marked as non-compliant if any of the required apps are missing or if it has apps blocklisted in it.- All devices

Device moves out of geofenceDevice will be marked as non-compliant if the device moves out of the [Geofence](https://www.hexnode.com/mobile-device-management/help/geofencing-location-based-mdm-restriction/) as specified under **Admin > Geofencing**.- Android
- iOS/iPadOS
- Windows
- macOS

Device is jailbrokenDevice will be marked as non-compliant if the device is identified as jailbroken.- iOS/iPadOS

Device is not CIS compliantDevices will be marked as non-compliant if they have not been associated with CIS Benchmark Compliance policy.- macOS

Advanced Settings 
------------------

The Advanced settings provide administrators with granular controls over device compliance evaluation curated by various device attributes. The following table lists all the available device attributes along with their description.

AttributeDescriptionActivation LockIt represents whether Activation Lock is enabled or disabled on iOS and macOS devices.Agent Type (Android only)It represents the management framework such as General Android or Samsung Knox on Android devices.Agent VersionIt represents the version of the Hexnode agent app installed on the device.Available Internal Storage (GB)It represents the remaining storage capacity available for use on the device.Battery Level (percentage)It represents the current battery percentage remaining on the device.BitLocker (Windows only)It represents whether the device’s drive is encrypted using BitLocker.Blocklisted Apps CountIt represents the number of blocklisted applications installed on the device. Applicable only when a Blocklist policy is associated with the device.Chrome Version (ChromeOS only)It represents the version of the Chrome operating system running on the device.Device EncryptionIt represents the encryption status of the device.Device ModelIt represents the model identifier of the device hardware. *For example*:

The device model for the Samsung Galaxy M13 will appear as “SM-M135FU”. You can find the device model of a specific device on the device details page in the Hexnode UEM console.

Device NameIt represents the name assigned to the device.Device StatusIt represents the activity status of the device, i.e., whether the device is active or not.Enterprise Management TypeIt represents the Android device’s management mode, such as Generic Android or Android Enterprise.FileVault (macOS only)It represents the FileVault encryption status on the macOS device.Firmware Version (ChromeOS only)It represents the firmware version installed on ChromeOS devices.GeofenceIt represents the geographical boundaries set for monitoring and managing device locations.Jailbreak (iOS)It represents whether the iOS device is jailbroken.Kiosk ModeIt represents whether the device is currently operating in kiosk mode, based on the applied kiosk policy.Location TrackingIt represents whether the device’s location services are enabled and being used for tracking.ManufacturerIt represents the name of the hardware manufacturer of the device.MDM ProfileIt represents whether a valid UEM/MDM profile is present and active on the device.Missing Apps CountIt represents the number of required applications that are currently missing from the device.OS NameIt represents the name of the operating system installed on the device.OS VersionIt represents the version of the operating system, including any security updates installed on the device.OwnershipIt represents whether the device is company-owned or personally-owned.Password ComplianceIt represents whether the device meets the configured password policy requirements.Platform VersionIt represents the underlying platform version of the device (e.g., Windows build version such as Windows 10, version 21H1).Policy (macOS only)It represents whether the device remains associated with the applied UEM policy for macOS devices.Processor NameIt represents the name or identifier of the processor used in the device.Supervision (iOS only)It represents whether the iOS device is supervised, indicating a higher level of management control.TPM Firmware VersionIt represents the firmware version of the Trusted Platform Module (TPM) installed on the device.TPM VersionIt represents the specification version of the TPM used.Wi-Fi SSIDIt represents the name (SSID) of the Wi-Fi network to which the device is currently connected.By configuring a combination of criteria, comparator, and appropriate values, admins can configure precise rules that mark devices as non-compliant upon meeting the criteria.

Multiple criteria can be added to a policy using the **Add Criteria** option. When multiple conditions are involved, administrators can use logical operators ‘**AND**’ and ‘**OR**’, to define how the system evaluates the rules. These operators appear to the left of every additional condition following the initial one:

- **AND** ensures that a device must meet all specified conditions to be considered non-compliant.
- **OR** allows a device to be marked non-compliant if it satisfies any one of the specified conditions.

The following tables list the supported criteria available for each platform, along with their respective comparators and values. Where applicable, fields may require manual input by the administrator if predefined options are not available.

### Android

Android

 CriteriaComparator(s)Possible ValuesAgent Type1. Is
2. Is not
1. General Android
2. Samsung Knox
Agent version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Agent version in decimals.Available internal storage (GB)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Internal storage value as an integer.Battery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.Blocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Device encryption1. Is
2. Is not
DisabledDevice model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveEnterprise Management Type1. Is
2. Is not
- Android Enterprise – Device Owner
- Android Enterprise – Profile Owner
- Android Enterprise – Work Profile on Company-Owned Device
- General Android – Device Owner
- Generic Android
- Kyocera – Device Owner
- LG GATE – Device Owner
- Samsung Knox – Device Owner

Geofence1. Is
2. Is not
DisabledKiosk mode1. Is
1. Active
2. Inactive
Location tracking1. Is
DisabledManufacturer1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the device manufacturer.Missing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal
Password compliance1. Is
DisabledWi-Fi SSID1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
SSID of the Wi-Fi network.

 

 

### iOS

iOS

 CriteriaComparator(s)Possible ValuesActivation lock1. Is
DisabledAgent version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Agent version in decimals.Available internal storage (GB)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Internal storage value as an integer.Battery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.Blocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Device encryption1. Is
2. Is not
DisabledDevice model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveGeofence1. Is
2. Is not
DisabledJailbreak1. Is
2. Is not
EnabledKiosk mode1. Is
1. Active
2. Inactive
Location tracking1. Is
DisabledMDM profile1. Is
RemovedMissing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal
Password compliance1. Is
DisabledSupervision1. Is
2. Is not
1. Active
2. Inactive

 

 

### Windows 

Windows

 CriteriaComparator(s)Possible ValuesAgent version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Agent version in decimals.Available internal storage (GB)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Internal storage value as an integer.Battery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.BitLocker1. Is
DisabledBlocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Device encryption1. Is
2. Is not
DisabledDevice model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveGeofence1. Is
2. Is not
DisabledKiosk mode1. Is
1. Active
2. Inactive
Location tracking1. Is
DisabledManufacturer1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the device manufacturer.Missing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS name1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the Operating System.OS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal
Processor name1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the processor.TPM version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the Trusted Platform Module (TPM) version as a decimal number.Wi-Fi SSID1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
SSID of the Wi-Fi network.

 

 

### macOS 

macOS

 CriteriaComparator(s)Possible ValuesActivation lock1. Is
DisabledAgent version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Agent version in decimals.Available internal storage (GB)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Internal storage value as an integer.Battery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.Blocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Device model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveFileVault1. Is
DisabledGeofence1. Is
2. Is not
DisabledLocation tracking1. Is
DisabledMDM profile1. Is
RemovedMissing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal
Password compliance1. Is
DisabledPolicy1. Is
RemovedProcessor name1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the processor.

 

 

### Apple TV 

Apple TV

 CriteriaComparator(s)Possible ValuesDevice model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveKiosk mode1. Is
1. Active
2. Inactive
MDM profile1. Is
RemovedOS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal

 

 

### Linux 

Linux

 CriteriaComparator(s)Possible ValuesAgent version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Agent version in decimals.Available internal storage (GB)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Internal storage value as an integer.Battery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.Blocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Device model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveMissing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS name1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the Operating System.Processor name1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the processor.Wi-Fi SSID1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
SSID of the Wi-Fi network.

 

 

### visionOS

visionOS

 CriteriaComparator(s)Possible ValuesDevice status1. Is
InactiveGeofence1. Is
2. Is not
DisabledMDM profile1. Is
RemovedMissing apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Enter the limit for the number of required apps to be missing from the device for it to be non-compliant.OS version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Desired OS version.Ownership1. Is
1. Corporate
2. Personal

 

 

### ChromeOS 

ChromeOS

 CriteriaComparator(s)Possible ValuesBattery level (percentage)1. Equal to
2. Not equal to
3. Greater than
4. Less than
Battery percentage value as an integer.Blocklisted apps count1. Equal to
2. Not equal to
3. Greater than
4. Less than
Number of blocklisted apps as an integer.Chrome version1. Equal to
2. Not equal to
3. Greater than
4. Less than
Value of an appropriate ChromeOS version.Device model1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Identifier of the device model.Device status1. Is
InactiveFirmware version1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Value of an appropriate ChromeOS firmware version.Kiosk mode1. Is
1. Active
2. Inactive
Manufacturer1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Name of the device manufacturer.Ownership1. Is
1. Corporate
2. Personal
Platform version1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Platform version of the ChromeOS device.TPM firmware version1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
Enter the Trusted Platform Module (TPM) version as a decimal number.Wi-Fi SSID1. Is
2. Is not
3. Contains
4. Does not contain
5. Starts with
6. Does not start with
SSID of the Wi-Fi network.

 

 

Associating compliance policies with devices 
---------------------------------------------

Associating the compliance configurations with the targets:

- When the policy is not yet saved, 
    1. Go to **Policy Targets** within the Policies tab.
    2. Click on **Users > + Add Users**, select the required users and click **OK** to associate the policy with the target users. As a result, when a device is enrolled to a targeted user, the compliance policies will be automatically applied to that user’s devices.
    3. You can also associate the policy with **Devices, Device Groups, User Groups,** or **Domains** from the left pane of the **Policy Targets** tab.
- When the policy has already been saved, 
    1. From the ***Policies > Compliance Policies***, select the appropriate policy
    2. Then click on **Manage > Associate Targets** > choose the target users and click on **Associate** to associate the policy with the target users. Enroll a device to a targeted user to automatically apply the associated compliance policies.
    3. You can also associate the policy with **Devices, Device Groups, User Groups,** or **Domains**.

Policy Summary 
---------------

The Policy Summary includes the version of the policy, created date, modified date, target count, and configured settings. To view the Policy Summary:

1. Navigate to ***Policies > Compliance Policies***.
2. Click on the policy summary icon on the right side of the policy.
3. You can view the policy summary here.
4. Click **Manage** at the top right corner to modify or clone the policy.