# Hexnode UEM: Manage Device Reports and Inventory Audits

Introduction 
-------------

The ability to generate detailed Device Reports is critical for maintaining **regulatory compliance** and **operational efficiency**. These reports convert the dynamic state of your entire device fleet—spanning multiple OS platforms and ownership models—into verifiable, static data. By automating these reports, IT teams can proactively identify security risks (e.g., non-encrypted devices) and manage hardware lifecycles.

Initiating and Exporting a Device Report 
-----------------------------------------

To generate and export any Built-in Device Report from the Hexnode console:

1. **Login:** Access the Hexnode UEM portal using administrator credentials.
2. **Navigate:** Go to the **Reports** tab in the main console.
3. **Select Category:** Choose the **Built-in Reports** section, then select the Device category.
4. **Select Report:** Click on the specific report name.
    [![Built-in user reports in Hexnode](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/12/Built-in-reports-Device-Reports.png "Device Reports")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/12/Built-in-reports-Device-Reports.png)
5. **Apply Filters:** Use the available contextual filters to narrow the scope of the data. Available filters: 
    - **Ownership:** Corporate or Personal.
    - **Enrollment Status:** Disenrollment Pending, Disenrolled, Pre-approved, User deleted, or Enrolled.
    - **Activity status:** Active or Inactive.
    - **Device type:** Laptop, PC, Smartphone, Smart TV or Tablet.
    - **Platform:** Android, Windows, iOS, macOS, or Apple TV.
    - **Group Type:** Custom device group or Dynamic device group.
    - **Devices In School:** One-to-One or Shared.
6. **Export:** Click the Export button and choose the desired file format (PDF or CSV) to download the report file locally. **Or**,
    Click the [Schedule Report](https://www.hexnode.com/mobile-device-management/help/how-to-schedule-reports-on-hexnode-uem/) button to schedule reports to be sent to technicians.

Available Built-in Device Reports 
----------------------------------

### 1. Inventory & Lifecycle Status Reports 

These reports track the device’s state relative to the UEM portal, focusing on enrollment, activity, and device history.

Report NamePrimary Focus Key Status Indicator **All devices** A complete list of all devices in the console. Full Inventory/Baseline. **Enrolled devices** Devices currently under active management. Active Management Status. **Active devices**  Devices that have checked in recently (based on inactivity threshold configured in the Hexnode console). Device Activity Status. **Inactive devices**  Devices that have failed to report for a specified number of days. Device Inactivity Status. **Recently enrolled devices**  Devices onboarded recently. Enrollment Date/Time. **Devices with Agent Installed**  Devices that have the Hexnode UEM app installed. Agent Installation Status. **Disenrolled devices**  Devices that have been officially removed from the portal. Offboarding Audit Trail. **Disenrollment Pending devices**  Devices awaiting final removal from the console. Offboarding Process Status. ### 2. Security and Compliance Reports 

These reports are critical for auditing security posture, policy adherence, and managing endpoint risk.

Report NamePrimary Focus Key Compliance Indicator **Compliant devices**  Devices meeting all defined corporate compliance policies. Overall Compliance Status (Pass). **Non-compliant devices**  Devices failing one or more compliance policies, requiring remediation. Policy Violation Summary (Fail). **Password-protected devices**  Devices that meet the required passcode policy (complexity, length) and devices with already set passwords. Passcode Protected Status. **Non-encrypted devices**  Devices where disk or volume encryption is not active (e.g., BitLocker/FileVault). Encryption Status. **Policy free devices**  Devices that are not associated with any policy, posing an unmanaged security risk. Policy Association Status. **Bootstrap Token Missing devices**  macOS devices where the Bootstrap Token is missing. macOS Security Status. **Devices with Agent Installed**  Devices that have the Hexnode UEM agent app installed. Agent Installation Status. ### 3. Inventory & Ownership Reports

These reports segment the fleet based on physical device type and ownership classification.

Report NamePrimary Focus Key Status Indicator **Smartphones**  Lists all devices classified by the system as mobile phones. Device Form Factor. **Tablets**  Lists all devices classified by the system as tablets. Device Form Factor. **Personal devices**  Lists devices assigned the “Personal” (BYOD) ownership type. Device Ownership. **Corporate devices**  Lists devices assigned the “Corporate” ownership type. Device Ownership. ### 4. Configuration and Restriction Reports 

These reports track application restrictions, active Kiosk lockdown statuses, and unique device configurations/remote actions.

Report NamePrimary Focus Key Status/Restriction**Kiosk active**  Devices currently locked down into Kiosk Mode. Kiosk Lockdown Status. **Kiosk enabled**  Devices that have a Kiosk policy associated, regardless of current status. Kiosk Policy Association. **Kiosk exited**  Devices that have recently exited the Kiosk lockdown mode. Kiosk Status (Exited). **Device missing required apps**  Devices that lack required business applications. Application Compliance. **Devices with blocklisted apps**  Endpoints that have prohibited applications installed. Application Compliance. **Camera disabled**  Devices where the camera function has been disabled via a policy restriction. Hardware Restriction Status. ### Data Columns (Report Output Fields) 

Hexnode Device Reports allow administrators to select various data fields to provide a comprehensive inventory and audit record.

#### 1. Primary Device Identification & Inventory

These fields are essential for asset tracking and physical inventory management.

Data Field Category Output Column Examples Purpose**Identifiers**  Device Name (Mandatory), Device ID, Serial Number, UDID. Unique identification and friendly naming. **Hardware**  Device Model, Device Type (Smartphone, Tablet, PC, Laptop), Manufacturer, Processor Name, Installed RAM. Physical asset tracking and hardware inventory. **Operating System**  Platform (iOS, Android, Windows, macOS), OS Name, OS Version, OS Build. Software audit and patch management eligibility. **Network Address**  Wi-Fi IP Address, Ethernet IP Address, Wi-Fi MAC Address, Bluetooth MAC Address. Network access and connectivity troubleshooting. #### 2. Compliance, Security, & Enrollment Status 

These fields indicate the current security posture and the device’s relationship with the UEM system.

Data Field Category Output Column Examples Purpose**UEM Status**  Enrollment Status, Activity Status (Active/Inactive), Last Checked-in Time. Monitoring management status and connection health. **Compliance Status**  Compliance Status (Overall), Password Compliance Status, Application Compliance Status, Geofence Compliance Status. Auditing adherence to corporate security policies. **Encryption**  Encryption Status (Disk/Volume), FileVault Recovery Key (macOS), Bootstrap Token status (macOS). Verification of data protection mandates. **Security Features**  Root Access, Jailbroken, Kiosk Mode (Status), Lost Mode (Status), Rapid Security Response (iOS). Identifying high-risk or compromised devices. #### 3. User, Ownership, & Telecom Data 

These fields connect the hardware asset to the associated end-user and track mobile/telecom usage.

Data Field Category Output Column Examples Purpose**User Identity**  Enrollment Status, Activity Status (Active/Inactive), Last Checked-in Time. Personnel tracking and user-centric management. **Ownership**  Ownership (Corporate/Personal), Department, Office Location. Asset classification (BYOD vs. COPE). **Telecom**  Phone Number (SIM 1/2), IMEI (SIM 1/2), Current Carrier Network, ICCID. Mobile asset tracking and expense management. #### 4. Resource & Configuration Management 

These fields provide technical details about the device’s internal state and applied configurations.

Data Field Category Output Column Examples Purpose**Storage and Battery**  Total Internal Storage, Available Internal Storage, Battery Level, Battery Health. Capacity planning and hardware lifecycle monitoring. **UEM Configuration**  Device Configuration (Profile applied), UEM Profile Password, No. of Blocklisted Apps, No. of Missing Apps. Auditing specific policy settings enforced on the endpoint. Complete list of data columns

 Data columnsDescriptionDevice Name (Mandatory field)The name of the device.Device GroupList of all device groups associated with the device.Device ModelSpecific model of the device.OwnershipShows if the device is Corporate or Personal.PlatformThe operating system of the device.OS VersionCurrent operating system version of the device.ManufacturerThe manufacturer of the device (e.g., Apple, Samsung).SupervisionSupervision status for iOS, macOS, and Apple TV devices.Apple DEPIndicates whether the device is enrolled via Apple Device Enrollment Program (DEP).Device IDDevice ID assigned by the portal.Battery LevelCurrent battery level of the device.DepartmentDepartment associated with the device.Asset TagCustom label assigned to a device for identification.Device NotesCustom description added to a device.UDIDUnique Device Identifier used to map devices enrolled in UEM.MEIDMobile Equipment Identifier (a unique 14-digit number) for identifying a physical mobile device.Serial NumberThe serial number of the device.Enterprise Management TypeEnrollment type of device, specific to Android devices (e.g., Generic, Android Enterprise).Encryption StatusDisplays whether the device is encrypted or not.Bootstrap TokenToken used for securely starting up a macOS device in a supervised environment.FileVault Personal Recovery KeyDisplays the recovery key of a macOS device, if escrowed.TPM VersionThe version of the Trusted Platform Module (TPM) on the device.BitLocker Policy ComplianceIndicates whether the device complies with BitLocker encryption policy settings.Enrolled TimeDate and time when the device was enrolled.Disenrolled TimeDate and time when the device was disenrolled.Last checked-in TimeDate and time of the last check-in from the device.Available Internal StorageAmount of available internal storage on the device.Used Internal StorageAmount of internal storage currently used on the device.Total Internal StorageTotal internal storage capacity of the device.Installed RAMAmount of RAM installed on the device.Processor NameName of the device’s processor.OS NameName of the operating system installed on the device.Device TypeType of device (e.g., smartphone, tablet, PC, etc.).Device ConfigurationConfiguration profile or settings applied to the device.Rapid Security ResponseStatus of Apple’s Rapid Security Response on iOS devices for quick security updates.UEM Profile PasswordPassword used to remove the UEM profile on a macOS device.Agent TypeType of agent installed on Android devices (e.g., General Android, Samsung Knox).License Activation DateDate on which the Hexnode license was activated on the device.Enrollment TypeThe method used to enroll the device (e.g., manual, Apple DEP, Zero-touch).Build Version The software or firmware version currently running on the device. OU Name The Organizational Unit to which the device is assigned within the organization. OU(s) Google The device’s Organizational Unit in Google Workspace, if enrolled under Google Admin Console. UsernameThe username of the user associated with the device.EmailThe primary email address of the user associated with the device.Alternate EmailAlternate email address associated with the user.Domain NameDomain name associated with the user account or device.User TypeType of user (e.g., AD, Microsoft Entra ID, Google Workspace, local).sAMAccountNameSecurity Account Manager (SAM) account name associated with the user in Active Directory.Title (AD)Job title of the user as listed in Active Directory.Department (AD)Department of the user as listed in Active Directory.Office Location (AD)Office location of the user as listed in Active Directory.User GroupGroup to which the user belongs.Phone Number SIM 1Phone number associated with SIM card 1.IMEI SIM 1IMEI number associated with SIM card 1.Current Carrier Network SIM 1Wireless carrier network for SIM card 1.ICCID SIM 1ICCID number associated with SIM card 1.Phone Number SIM 2Phone number associated with SIM card 2.IMEI SIM 2IMEI number associated with SIM card 2.Current Carrier Network SIM 2Wireless carrier network for SIM card 2.ICCID SIM 2ICCID number associated with SIM card 2.IMSIInternational Mobile Subscriber Identity associated with the device’s SIM card.SIM Carrier NetworkCarrier network associated with the SIM card in the device.Subscriber Carrier Network (iOS)The cellular carrier network to which the iOS device’s subscriber belongs.Roaming EnabledIndicates if the device has roaming enabled.International Data RoamingStatus of international data roaming on the device.Home CarrierThe device’s home carrier network.Home CountryCountry of the device’s home carrier network.Last Connection DateDate of the device’s last network connection.Wi-Fi IP AddressIP address of the Wi-Fi network the device is connected to.Ethernet IP AddressIP address of the Ethernet network the device is connected to.Personal HotspotIndicates if the device’s personal hotspot feature is enabled.Bluetooth MAC AddressMAC address of the device’s Bluetooth interface.Ethernet MAC AddressMAC address of the device’s Ethernet interface.Wi-Fi MAC AddressMAC address of the device’s Wi-Fi interface.Wi-Fi SSIDSSID (Service Set Identifier) of the Wi-Fi network the device is connected to.Current MCCMobile Country Code of the current network the device is connected to.Current MNCMobile Network Code of the current network the device is connected to.Subscriber MCCMobile Country Code of the subscriber’s carrier network.Subscriber MNCMobile Network Code of the subscriber’s carrier network.Activity StatusDisplays whether the device is Active or Inactive.Enrollment StatusShows the current enrollment status of the device (e.g., enrolled, disenrolled).Compliance StatusIndicates whether the device is compliant or non-compliant with policies.Application Compliance StatusCompliance status based on the applications installed on the device.Password Compliance StatusCompliance status based on the device’s password settings.Geofence Compliance StatusCompliance status based on the device’s location in relation to geofencing policies.Kiosk ModeIndicates if the device is in kiosk mode.Lost ModeStatus of whether the device is in lost mode.JailbrokenIndicates if the device has been jailbroken.RootedIndicates if the device has been rooted.MDM ProfileIndicates if the MDM profile is installed on the device.Root AccessStatus of whether the device has root access.No. of Blocklisted AppsNumber of blocklisted apps on the device.No. of Missing AppsNumber of required apps missing on the device.

 

 

Summary of Device Reports in Hexnode
------------------------------------

1. All Devices

### All Devices

Fetch a complete list of all the devices in Hexnode that are enrolled, pre-approved, user-deleted, or disenrollment-initiated.

Filters:

- Enrollment Status
- Device Inactivity
- Type
- Ownership
- Platform
- Device Groups
- Devices In School

 

 

 
2. Disenrollment pending devices

### Disenrollment pending devices

Fetch a list of all devices to be disenrolled from the Hexnode console, but the ‘Disenrolled’ action has not yet reached the device.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
3. Enrolled devices

### Enrolled devices

List of all devices that are currently enrolled with Hexnode.

Filters:

- Device Inactivity
- Type
- Ownership
- Platform
- Device Groups

 

 

 
4. Non-compliant devices

### Non-compliant devices

List of all devices that do not meet the [compliance policy](https://www.hexnode.com/mobile-device-management/help/how-to-create-a-compliance-policy-for-devices/).

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

5. Inactive devices

### Inactive devices

Generate a report of those devices that have device status marked as ‘Inactive’ based on *Inactivity Settings*.
[![Inactivity Settings from General Settings under Admin tab in Hexnode UEM console](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/09/Inactivity-Settings-under-Admin-tab-in-Hexnode-UEM-console.png "Inactivity Settings under Admin tab in Hexnode UEM console")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2024/09/Inactivity-Settings-under-Admin-tab-in-Hexnode-UEM-console.png)

Filters:

- Type
- Ownership
- Device Groups

 

 

 
6. Password protected devices

### Password protected devices

List of all devices that have been password protected. Includes devices with password policy applied and devices with already set passwords.

 Note: 
Displays the list of password-protected devices, excluding Windows, macOS devices, and devices running Android versions below 6.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

7. Non-encrypted devices 

### Non-encrypted devices 

List of all devices that have not been encrypted. Includes all devices on which data encryption is not enabled.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
8. Compliant devices

### Compliant devices

List of all devices that meet all the compliance requirements set under [Compliance Policies](https://www.hexnode.com/mobile-device-management/help/how-to-create-a-compliance-policy-for-devices/).

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
9. Smartphones

### Smartphones

List of all smartphones enrolled with Hexnode.

Filters:

- Device Inactivity
- Ownership
- Device Groups

 

 

10. Tablets

### Tablets

List of all tablets enrolled with Hexnode.

Filters:

- Device Inactivity
- Ownership
- Device Groups

 

 

 
11. Personal devices

### Personal devices 

List of all devices with **Ownership** set as **Personal** during enrolment.

Filters:

- Device Inactivity
- Type

 

 

 
12. Corporate devices

### Corporate devices

List of all corporate-owned devices enrolled with Hexnode.

Filters:

- Device Inactivity
- Type
- Device Groups

 

 

 
13. Devices missing required apps

### Devices missing required apps

A list of all devices on which the apps associated with the ‘Required Apps’ policy are absent i.e., apps have not been installed on the device or were uninstalled by the users.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
14. Devices with blocklisted apps

### Devices with blocklisted apps

List of all devices containing blocklisted apps.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
15. Camera disabled devices

### Camera disabled devices

List of all devices that have camera disabled in them.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

 
16. Recently Enrolled devices

### Recently Enrolled devices

List of all devices that have been enrolled recently.

Filters:

- Device Inactivity
- Type
- Ownership
- Device Groups

 

 

17. Policy free devices

### Policy free devices

List of all devices that are not associated with any policy.

Filters:

- Device Inactivity
- Ownership

 

 

18. Active devices

### Active devices

This report fetches a list of all active devices enrolled in the portal. These are devices that responds to a device scan within the specified number of days, hours, or minutes provided in **Admin > General Settings > Inactivity Settings**.

Filters:

- Type
- Ownership
- Device Groups

 

 

 
19. Kiosk active devices

### Kiosk active devices

Lists all the devices that are currently locked down into kiosk mode.

Filters:

- Device Inactivity
- Ownership
- Device Groups

 

 

20. Kiosk enabled devices

### Kiosk enabled devices

Lists all devices that have been assigned a kiosk policy but are not currently in kiosk mode. For example, a device that was inactive when the kiosk policy was applied to it.

Filters:

- Device Inactivity
- Ownership
- Device Groups

 

 

 
21. Kiosk exited devices

### Kiosk exited devices

List of all devices which have exited from the kiosk lockdown mode. This includes devices with kiosk policy removed and kiosk mode exited on the device by a user.

Filters:

- Device Inactivity
- Ownership
- Device Groups

 

 

22. Disenrolled devices

###  Disenrolled devices

List of all devices disenrolled from the portal.

Filters:

- Type
- Ownership
- Device Groups

 

 

23. Devices With Agent Installed

### Devices With Agent Installed

List of all devices that have the Hexnode Agent application installed on them. This report features an additional data field indicating the installed version of the Hexnode Agent app on the devices:

1. Agent Version

Filters:

- Device Inactivity
- Ownership
- Platform
- Device Groups

 

 

24. Lost mode enabled devices

### Lost mode enabled devices

List of all devices that have lost mode enabled on them.

Filters:

- Device Inactivity
- Type
- Ownership
- Platform
- Device Groups
- Devices In School

 

 

25. Bootstrap Token Missing Devices

### Bootstrap Token Missing Devices

List of all macOS devices where the bootstrap token is missing.

Filters:

- Ownership
- Activity status
- Device type

 

 

#### Frequently Asked Questions 

1. What key audit data and capabilities do Hexnode device reports offer? 

 Concept Definition Core Purpose **Device Reports**  A primary category within Hexnode’s Built-in Reports that provides a comprehensive, granular record of all managed hardware endpoints. Inventory Audit and Fleet Monitoring. **Data Scope**  Reports are generated based on device attributes, status, platform, and ownership information. Enables administrators to audit security compliance, track assets, and assess technical readiness. **Generation Type**  Reports are generated instantly (on the go) or scheduled for automated delivery. Supports both real-time audits and periodic tracking.