# Managing Audit Reports in Hexnode UEM

Audit reports in Hexnode UEM provide a complete, fully traceable history of activities within the management console, including technician actions and event occurred. These reports are essential for security auditing, compliance reviews, and troubleshooting system behavior.

1. Procedure: Generating an Audit Report
----------------------------------------

1. **Log In:** Log into your Hexnode UEM portal.
2. **Navigate:** Go to the **Reports** tab.
3. **Select:** Choose **Built-in Reports** from the left navigation.
4. **Access:** Click the **Audit** category.
![Create Audit Reports in Hexnode](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2025/12/Audit-reports-in-Hexnode-scaled.png "Audit Reports in Hexnode")

6. **Choose Report Type:** Select the desired audit report (e.g., Policy, App Management, Action History, etc.).
7. **Customize:** Click the edit icon to choose or omit required data columns.
8. **Generate:** Apply filters and generate the final report.Moreover, you can schedule reports at specific intervals to send to different recipients via email and also export the report to your device as a PDF or CSV file.

2. Audit Reports Categories
---------------------------

Hexnode UEM provides specific audit reports designed to track different types of security and management events.The Audit report categories are:

- Policy
- App Management
- Action History
- Integration Events
- Group Management
- User Management
- Directory Management
- Enrollment Activities
- Technicians & Roles
- Network Management
- System Events
- File Management
- Report Activity Log
- Live terminal
- Remote view/control
- Password History

1. Policy

### Policy

The **Policy** category audits device policies, compliance policies, and templates in Hexnode UEM. Following are the Policy reports:

Report NamePrimary Focus / Purpose**Policy Events**Tracks policy creation, edits, updates, and archiving to audit policy activity. - **When to use:** Use when investigating unexpected policy modifications or conducting a security audit.
- **Example:** A device suddenly loses its encryption settings. Use this report to find out which admin modified or archived the policy and when.

**Policy Association and Dissociation**Tracks policy associations and dissociations across target entities to troubleshoot assignment changes. - **When to use:** Use when troubleshooting devices or groups that are missing expected configurations.
- **Example:** Newly enrolled iPhones aren’t receiving corporate Wi-Fi credentials. Check this report to see if the Wi-Fi policy was assigned to the target group or accidentally disassociated.

**Templates**Tracks policy templates to manage baseline standards and track policy conversions. - **When to use:** Use when tracking changes to base policy templates or verifying when a template was saved as a policy.
- **Example:** A live policy applies wrong settings to devices. Check this report to see if an admin edited the base template or converted an old template into the active policy.

 

 

2. App Management

### App Management

The **App Management** category provides a complete audit trail of application activity across managed devices to help admins enforce compliance, troubleshoot deployment issues, and verify technician actions. Following are the App Management reports:

Report NamePrimary Focus / Purpose**Installation and Updates**Tracks app installations, updates, removals, and validations to monitor deployment progress and troubleshoot installation failures. - **When to use:** Use when tracking software deployment progress or investigating app installation failures.
- **Example:** An app update fails to install on 20 company laptops. Check this report to identify which specific devices encountered failure.

**Monitoring & Compliance**Tracks app compliance, blocklists, allowlists, and MDM agent uninstalls to detect non-compliant software and security breaches. - **When to use:** Use when auditing app compliance violations, agent uninstalls, or technician actions like clearing app data and scanning apps.
- **Example:** A managed device suddenly loses connection to the portal. Check this report to see if the user uninstalled the MDM agent and when the breach occurred.

**Remote App Launch**Tracks console-initiated remote app launches and feedback requests to monitor apps opened remotely on devices. - **When to use:** Use when checking if an admin remotely opened an app or requested user feedback on a device.
- **Example:** An employee claims an app opened unexpectedly on their Mac. Check this report to see which technician triggered the remote launch and at what time.

**App Group**Tracks app group creation, updates, and deletions to audit app group management. - **When to use:** Use when investigating missing app groups or tracking who created, updated, or deleted an app group.
- **Example:** Sales representatives report that mandatory CRM tools vanished from their phones. Check this report to see if an admin edited or deleted the app group.

**App Catalog**Tracks app catalog configurations to audit custom enterprise app store distributions. - **When to use:** Use when employees cannot find required apps in their enterprise app store or after updating catalog layouts.
- **Example:** New hires report that a mandatory internal app is missing from their app store. Check this report to verify if recent catalog configuration changes were saved.

**App Configuration & Permissions**Tracks app settings, permissions, and associations to monitor app access controls and privacy settings. - **When to use:** Use when troubleshooting app crashes, denied device access rights (like camera or location), or misconfigured app settings.
- **Example:** A company app closes immediately upon opening because location access is blocked. Check this report to confirm if app permissions were properly assigned.

**App Install Scripts**Tracks the execution of app install scripts to troubleshoot deployment failures. - **When to use:** Use to confirm whether custom pre-install, post-install, or audit scripts were initiated during app deployments.
- **Example:** A custom app deployment fails. Check this report to confirm if the pre-install script was actually initiated.

**Kiosk Mode**Tracks kiosk mode configurations, profile assignments, and session exits to monitor dedicated device lockdowns. - **When to use:** Use when tracking kiosk profile assignments, enabling or disabling lockdown mode, or investigating kiosk exits.
- **Example:** A public display tablet breaks out of its locked storefront screen. Check this report to see who authorized the exit and at what timestamp.

 

 

3. Action History

### Action History

The **Action History** category provides a complete audit log of administrative and user-triggered device operations across managed endpoints, helping admins monitor real-time command execution, maintain security compliance, and troubleshoot device issues. Following are the Action History reports:

Report NamePrimary Focus / Purpose**Scan Actions**Tracks device, location, and update scan activities to verify system sync status and identify inactive endpoints. - **When to use:** Use when troubleshooting devices that are not updating their status or checking whether a manual scan command was requested.
- **Example:** A device shows as offline in the console despite being powered on. Check this report to see when the last device or location scan was initiated.

**Device Control Actions**Tracks device control actions, including Power Off, Restart, and Delete operations performed on devices to audit administrative power management and device removals. - **When to use:** Use when investigating sudden device disenrollments, unauthorized deletions, or unexpected remote reboots.
- **Example:** A digital display kiosk unexpectedly turns off during business hours. Check this report to identify which technician sent the remote restart or power-off command.

**Security Actions**Tracks device security actions such as Lock, Wipe, Set/Clear Password, Enable/Disable Lost Mode, Remote Ring, and Clear Activation Lock across devices, users, and groups to audit data protection and emergency response measures. - **When to use:** Use when responding to lost devices, emergency lockouts, or verifying high-risk data protection commands executed by technicians.
- **Example:** A lost corporate phone is recovered, but the employee cannot log in. Check this report to verify when the passcode reset command was executed and by whom.

**Script Execution**Tracks script execution activities on devices to audit automated tasks and custom script runs. - **When to use:** Use to confirm whether custom shell, PowerShell, or bash scripts were sent to devices and track their execution status.
- **Example:** An automated cleanup script fails to execute across a batch of MacBooks. Check this report to verify when the script execution command was pushed to those devices.

**Broadcast Message**Tracks console broadcast messaging activities to audit administrative alerts and user notifications. - **When to use:** Use to verify administrative notifications or emergency alerts sent directly to user screens from the console.
- **Example:** An IT maintenance warning was sent to all office workstations. Check this report to confirm when the message was broadcast and which technician sent it.

**Hexnode App Logs**Tracks app log and bug report requests to troubleshoot technical issues and audit diagnostic data sharing. - **When to use:** Use when troubleshooting agent sync failures with support or verifying diagnostic log collection from endpoints.
- **Example:** The Hexnode app on a Mac repeatedly fails to sync policies, and support requests troubleshooting logs. Check this report to verify whether the log collection request was sent and if the log file was successfully received by the portal.

**Device Configuration**Tracks device-level configuration changes and account syncs to monitor settings applied to managed devices. - **When to use:** Use when investigating unintended changes to device names, hostnames, system time zones, or account sync settings.
- **Example:** A shared workstation disconnects from network drives after its name changes unexpectedly. Check this report to see who modified the device configuration and when.

**Location & Geofencing**Tracks location tracking activities and geofencing configurations to monitor device mobility and detect spoofing attempts. - **When to use:** Use when investigating tracking discrepancies, perimeter breaches, or suspected GPS spoofing on mobile endpoints.
- **Example:** A field technician’s tablet triggers a geofence compliance alert. Check this report to review location tracking events and verify whether mock location tools were detected.

**Device Updates**Tracks OS and system update actions on devices to monitor patch management and enforce software compliance. - **When to use:** Use when tracking operating system patch rollouts or investigating why devices failed to install required OS updates.
- **Example:** A critical OS security patch is pushed to all Windows laptops, but several endpoints remain unpatched. Check this report to confirm whether the Update OS action was initiated on those devices.

**BitLocker Encryption**Tracks BitLocker encryption, decryption, and recovery actions to audit endpoint data protection and recovery. - **When to use:** Use during drive lockout incidents or security audits following technician offboarding to verify key access and rotation.
- **Example:** A system administrator leaves the company. Check this report to confirm whether BitLocker recovery keys were accessed and verify that key rotation was completed across company laptops.

**SIM Card Activity**Tracks SIM card additions, removals, changes, and deployments to detect unauthorized hardware tampering or SIM swapping. - **When to use:** Use when investigating sudden cellular network dropouts or tracking physical hardware modifications on mobile devices.
- **Example:** A company smartphone suddenly loses cellular data connectivity. Check this report to see if the SIM card was removed or replaced on the device.

**User Initiated Actions**Tracks actions performed directly by end users on their devices to audit self-enrollments, session activity, and user-driven security toggles. - **When to use:** Use when investigating user-driven compliance drops, self-enrollment attempts, or manual setting toggles on endpoints.
- **Example:** A field device unexpectedly stops transmitting GPS data to the portal. Check this report to determine if the user manually turned off location services directly from the device settings.

 

 

4. Integration Events

### Integration Events

The **Integration Events** category logs activities across third-party services, directory syncs, and API credentials to help admins monitor external integrations and troubleshoot connectivity. Following are the Integration Events reports:

Report NamePrimary Focus / Purpose**Hexnode API**Tracks the creation, renewal, expiration, and revocation of API keys and tokens to audit administrative API access. - **When to use:** Use when troubleshooting failing custom integrations, auditing administrative token lifecycle events, or verifying if revoked API keys can no longer access the portal.
- **Example:** A custom IT asset management script stops pulling device data. Check this report to see if the script’s API key expired, was revoked, or was regenerated by another administrator.

**Zendesk Support**Tracks device actions initiated directly through Zendesk tickets to audit device management from the helpdesk. - **When to use:** Use when evaluating helpdesk agent activity, auditing remote actions executed during support sessions, or investigating unauthorized actions triggered from Zendesk.
- **Example:** An employee claims their corporate phone was wiped during a routine support call. Check this report to confirm if the Wipe Device action originated from a Zendesk ticket and identify the technician who executed it.

**Microsoft Entra ID**Tracks domain additions, deletions, user enrollments, and directory sync statuses to monitor the Microsoft Entra ID connection. - **When to use:** Use when new users or groups fail to sync into Hexnode, when troubleshooting Entra ID enrollment errors, or during identity infrastructure audits.
- **Example:** Newly hired employees added to Microsoft Entra ID are not appearing in Hexnode to receive enrollment invites. Check this report to verify if directory sync failed or if the domain setup was altered.

**Windows Autopilot**Tracks Windows Autopilot configuration setups and deletions to audit automated Windows provisioning workflows. - **When to use:** Use when automated out-of-box provisioning fails on new Windows devices or when auditing who modified bulk deployment profiles.
- **Example:** A new batch of Windows laptops fails to trigger automated Hexnode enrollment during initial power-on. Check this report to verify if the Autopilot profile was deleted or modified.

**Okta**Tracks setup activities, authentication attempts, and API token lifecycles to audit Okta identity provider connections. - **When to use:** Use when users report single sign-on (SSO) enrollment failures, during identity provider setup, or to check if the Okta integration token is expiring.
- **Example:** Users receive access denied errors when enrolling devices via Okta SSO. Check this report to determine if the Okta integration setup failed.

**Freshservice**Tracks Freshservice instance additions, activations, deactivations, and reconfigurations to monitor the Freshservice connection. - **When to use:** Use when ticket-based device actions fail to execute on endpoints, or when auditing Freshservice instance state changes (activations, deactivations, reconfigurations).
- **Example:** Technicians notice remote lock commands sent from Freshservice tickets are not reaching devices. Check this report to verify if the Freshservice instance was deactivated or reconfigured.

**Check Point Harmony**Tracks Check Point Harmony instance additions, activations, deactivations, and reconfigurations to audit the Check Point Harmony connection. - **When to use:** Use when security threat alerts stop syncing to the portal or during routine security audits to confirm your MTD connection is active.
- **Example:** Mobile security threat alerts stop appearing on the UEM dashboard. Check this report to confirm whether the Check Point Harmony integration lost authentication or was deactivated.

**Vanta**Tracks when Vanta instances are connected, reconfigured, deactivated, or deleted to monitor Vanta integration activity. - **When to use:** Use during compliance audits to verify continuous data syncing or when investigating missing endpoint compliance evidence in Vanta.
- **Example:** An auditor notices a gap in compliance tracking. Check this report to see if the Vanta integration was disconnected during the audited timeframe.

**SCCM**Tracks SCCM agent app downloads to monitor co-management agent distribution across Windows devices. - **When to use:** Use when tracking a co-management deployment rollout or investigating why Windows endpoints fail to install the SCCM agent.
- **Example:** Windows devices in a remote branch office are missing co-management policies. Check this report to verify if the SCCM agent download package was successfully downloaded.

**VPP**Tracks Apple Volume Purchase Program account additions, deletions, and configuration changes to audit app license management. - **When to use:** Use when managed Apple app distribution fails, when adding or removing VPP location accounts, or when auditing VPP token configuration updates.
- **Example:** Purchased iOS apps remain stuck in “Pending” across user devices. Check this report to verify if the VPP account was removed, reconfigured.

**Knox Platform for Enterprise**Tracks Samsung KPE Premium license key additions and removals to audit enterprise Knox feature licensing. - **When to use:** Use when advanced Samsung Knox policy controls fail to apply, or when verifying that Knox license key updates took effect across your Samsung fleet.
- **Example:** Advanced containerized security policies stop applying to corporate Samsung devices. Check this report to see if the KPE Premium license key was removed.

**APNs Certificate & Token Update**Tracks APNs certificate additions, renewals, removals, and token updates to ensure uninterrupted iOS/macOS management communications. - **When to use:** Use immediately when all Apple devices stop responding to remote management commands, or when auditing annual APNs certificate renewals and token updates.
- **Example:** iOS devices in the field stop executing remote lock, wipe, or policy sync commands. Check this report to verify if the APNs certificate expired, was removed, or was renewed with an incompatible Apple ID.

**FCM & WNS Token Update**Tracks token update events for Firebase Cloud Messaging (Android) and Windows Notification Service (Windows) to verify push notification delivery paths. - **When to use:** Use when diagnosing push notification delays or real-time policy sync failures on Android and Windows endpoints.
- **Example:** Policy changes made in the portal take hours to apply to Android or Windows devices. Check this report to confirm if FCM or WNS push tokens were updated successfully across endpoints.

 

 

5. Group Management

### Group Management

The **Group Management** category tracks device and user group updates to monitor group creation, membership, and sync status. Following are the Group Management reports:

Report NamePrimary Focus / Purpose**Device Group**Tracks device group management events, including group creation, updates, and deletions to monitor device groupings. - **When to use:** Use when auditing manual changes to device groups or troubleshooting why policies assigned to a specific group stopped applying.
- **Example:** A device group used to deploy software updates is deleted, causing updates to stop across those endpoints. Check this report to see who deleted the group and when.

**User Group**Tracks user group management, including group creation, deletion, and updates to audit user group organization. - **When to use:** Use when troubleshooting user-targeted app or policy deployments, or checking who modified user group setups.
- **Example:** Employees in a re-organized department stop receiving user-assigned Wi-Fi settings. Check this report to confirm if someone edited or deleted their user group.

**Dynamic Device Group**Tracks dynamic device group management, including group creation, deletion, and updates to audit automated device groupings. - **When to use:** Use when devices fail to automatically join a dynamic group or when auditing changes made to automated group rules.
- **Example:** Newly enrolled iPads fail to receive kiosk settings because they didn’t auto-populate into a group. Check this report to see if an admin altered the group’s rule criteria.

 

 

6. User Management

### User Management

The **User Management** category tracks user creation, profile updates, and credential modifications in Hexnode UEM. Following are the User Management reports:

Report NamePrimary Focus / Purpose**User Management**Tracks user creation, deletion, profile updates, and password changes to audit user lifecycles and credential modifications. - **When to use:** Use when auditing administrative changes to user accounts, verifying offboarding compliance, or investigating unexpected account lockouts and password resets.
- **Example:** An administrator gets locked out after their account credentials are altered. Check this report to identify who edited their profile or reset their password.

 

 

7. Directory Management

### Directory Management

The **Directory Management** category tracks domain settings, OU changes, and directory syncs to monitor directory activities. Following are the Directory Management reports:

Report NamePrimary Focus / Purpose**Directory Synchronization**Tracks synchronization activities with external directory services to monitor user and group directory syncs. - **When to use:** Use when new users or groups fail to sync from your external directory (such as Active Directory or Entra ID) or when verifying scheduled sync status.
- **Example:** Newly onboarded employees in Active Directory are missing from Hexnode. Check this report to see if the scheduled directory sync failed.

**Organizational Unit (OU) Management**Tracks the creation, update, deletion, and renaming of organizational units to audit organizational hierarchy changes. - **When to use:** Use when auditing structural edits to your directory hierarchy or troubleshooting policy assignment issues caused by modified OUs.
- **Example:** Endpoints assigned to a specific branch office stop receiving updated policies. Check this report to see if an administrator renamed or deleted that branch’s OU.

**Domain Configuration & Updates**Tracks domain settings, updates, deletions, and Active Directory or Microsoft Entra ID integrations to audit domain setups. - **When to use:** Use when troubleshooting domain-wide enrollment failures, auditing identity provider connection changes, or verifying domain additions.
- **Example:** Users across the organization fail to enroll devices using their domain credentials. Check this report to confirm if the domain configuration was altered or accidentally deleted.

 

 

8. Enrollment Activities

### Enrollment Activities

The **Enrollment Activities** category logs when devices are enrolled, re-enrolled, or removed to track device onboarding status. Following are the Enrollment Activities reports:

Report NamePrimary Focus / Purpose**Device Enrollment**Tracks device enrollment and re-enrollment into Hexnode UEM to monitor onboarding status. - **When to use:** Use when auditing newly onboarded endpoints, verifying successful re-enrollments, or confirming that assigned devices have successfully joined management.
- **Example:** A department receives 20 new laptops and technicians begin setup. Check this report to verify which laptops have successfully completed enrollment.

**Enrollment Profile**Tracks the creation, updates, and enrollment profile associations for iOS and macOS enrollment setups. - **When to use:** Use when Apple devices fail to receive expected enrollment settings or when auditing profile modification events.
- **Example:** Newly enrolled MacBooks are missing required restriction settings. Check this report to see if an admin recently updated, deleted, or re-associated the enrollment profile.

**Android Enterprise**Tracks Android Enterprise account configurations, organization updates, and profile management to audit enterprise Android setups. - **When to use:** Use when auditing Android Enterprise setup changes, verifying Work Profile enrollments, or tracking Android profile creations and deletions.
- **Example:** Employees report they can no longer enroll Android Work Profiles. Check this report to confirm if the Android Enterprise setup was disenrolled, updated, or if an enrollment profile was deleted.

**Custom ROM Configuration**Tracks the generation and download of custom ROM configuration files to audit specialized firmware deployments.**Automated Device Enrollment (ADE)**Tracks ADE account setups, updates, and synchronization for automated Apple deployment. - **When to use:** Use when automated Apple zero-touch enrollment fails or when auditing ADE account setup and sync history.
- **Example:** New company iPhones bypass automated enrollment during unboxing. Check this report to see if the ADE account failed to sync, was deleted, or was improperly updated.

**Device Disenrollment**Tracks device disenrollment events across users, OUs, and domains to audit device offboarding and detect unauthorized removals. - **When to use:** Use when checking offboarded endpoints, investigating lost management control, or checking who triggered a disenrollment.
- **Example:** A company laptop stops taking management policies. Check this report to see if an admin initiated a disenrollment action or if the system disenrolled it.

**Migrate Windows to Hexnode**Tracks configuration file generation and status during Windows device migrations to Hexnode. - **When to use:** Use when moving Windows PCs from an existing management tool to Hexnode or troubleshooting missing migration files.
- **Example:** You are moving 200 Windows laptops from another MDM to Hexnode. Check this report to verify if the MSI migration package generated successfully before deploying it to users.

**Migrate macOS to Hexnode**Tracks migration file generation and execution statuses during macOS migrations to Hexnode. - **When to use:** Use when moving Mac computers from an existing management tool to Hexnode or troubleshooting migration file creation failures.
- **Example:** Your IT department is switching 50 MacBooks from another MDM to Hexnode. Check this report to see if the macOS migration file generation failed, or was re-initiated.

 

 

9. Technicians & Roles

### Technicians & Roles

The **Technicians & Roles** category tracks technician accounts, logins, roles, and security settings to monitor portal access and admin activity. Following are the Technicians & Roles reports:

Report NamePrimary Focus / Purpose**Technician Management**Tracks technician account creation, updates, and status changes to audit administrator access and account lifecycles. - **When to use:** Use when auditing administrator account additions, verifying offboarding compliance, or checking who modified an admin’s account details.
- **Example:** An IT team offboards a departing administrator. Check this report to verify who disabled or deleted the admin account and the exact time the status change occurred.

**Technician Login**Tracks technician login activities to monitor portal access, detect unusual sign-in attempts, and maintain sign-in audit trails. - **When to use:** Use when auditing administrator sign-in history, reviewing portal access logs, or investigating unauthorized portal logins.
- **Example:** Security alerts flag an unusual late-night login to the admin console. Check this report to identify which technician logged in and view their sign-in timestamp.

**Role Management**Tracks role creation, modification, and deletion activities to audit role-based access controls and privilege changes. - **When to use:** Use when auditing role permission edits, tracking role assignments, or investigating unexpected privilege escalations.
- **Example:** A helpdesk technician unexpectedly gains full administrative privileges in the portal. Check this report to see who updated their technician role or assigned them a new role.

**Super Admin**Tracks super admin activities and account changes to monitor top-level administrative actions. - **When to use:** Use when auditing top-level portal configuration changes or tracking actions executed by Super Admin accounts.
- **Example:** An organization replaces its primary portal owner with a new IT leader. Check this report to confirm when the Super Admin account was changed or who invited them.

**Technician Security**Tracks technician security configurations and authentication settings to enforce portal security policies and protect administrative accounts. - **When to use:** Use when auditing portal security rules, verifying 2FA/SSO policy updates, or checking technician password changes.
- **Example:** Administrators notice they are no longer prompted for two-factor authentication during portal sign-in. Check this report to confirm if an admin altered technician 2FA or login settings.

 

 

10. Network Management

### Network Management

The **Network Management** category tracks eSIM updates, hotspot status changes, and data roaming configurations to audit network connectivity and control cellular data usage. Following are the Network Management reports:

Report NamePrimary Focus / Purpose**Network Management**Tracks eSIM updates, hotspot status changes, and data roaming configurations to audit network connectivity and control cellular data usage. - **When to use:** Use when troubleshooting mobile connectivity, verifying carrier updates, or checking if Enable/Disable personal hotspot and data roaming actions were triggered on a device.
- **Example:** An admin restricts tethering on company phones to prevent unauthorized devices from consuming cellular data. Check this report to confirm if the Disable Personal Hotspot action was initiated for the device.

 

 

11. System Events

### System Events

The **System Events** category logs changes to portal settings, server configurations, licensing, and system communications to audit core console configurations. Following are the System Events reports:

Report NamePrimary Focus / Purpose**Communication Events**Tracks the configuration, update, and deletion of email and SMS server settings used for portal communications. - **When to use:** Use when troubleshooting portal message delivery issues or auditing changes to email and SMS server configurations.
- **Example:** Users stop receiving enrollment invitations via email and SMS. Check this report to verify if an administrator updated or removed the email server or SMS settings.

**Agent Management**Tracks Hexnode UEM AD Agent downloads, refreshes, and deletions to monitor Active Directory agent activity. - **When to use:** Use when auditing AD agent lifecycle events or troubleshooting user and group sync failures between Active Directory and the portal.
- **Example:** Active Directory user groups stop syncing with the console. Check this report to verify if an admin refreshed or deleted the Hexnode UEM AD Agent.

**System Configuration**Tracks server, network, certificate, branding, and API changes to audit core portal configurations. - **When to use:** Use when checking changes to main portal settings, SSL certificates, or server configurations.
- **Example:** Apple devices suddenly fail to sync or receive policies. Check this report to see if APNs settings, proxy configurations, or server certificates were recently updated.

**License Management**Tracks license updates and quota changes to monitor Hexnode UEM subscription status and device limits. - **When to use:** Use when verifying subscription renewals or auditing license quota updates in the portal.
- **Example:** Technicians encounter enrollment blocks after purchasing additional device seats. Check this report to confirm if the license details update event was recorded.

**Legal Agreements**Tracks End User License Agreement (EULA) additions and deletions to audit corporate compliance terms. - **When to use:** Use when auditing compliance terms or investigating changes to mandatory agreement screens during onboarding.
- **Example:** Newly enrolled users report that the company’s terms of service prompt disappeared during setup. Check this report to see if a new EULA was added or an existing one was deleted.

**Site & DAFS**Tracks site assignment executions and Device Auto-Fetch Service (DAFS) syncs to monitor multi-site management setups. - **When to use:** Use when verifying automatic device syncs from Apple Business Manager or tracking device assignments to specific office locations.
- **Example:** Newly purchased devices registered in Apple Business fail to appear in the portal. Check this report to verify if the DAFS sync completed or if the Add to Site action was executed.

 

 

12. File Management

### File Management

The **File Management** category tracks file uploads, edits, downloads, deletions, and remote file deployments to audit content management and device file distribution. Following are the File Management reports:

Report NamePrimary Focus / Purpose**File Management**Tracks file uploads, edits, downloads, deletions and remote deploy or remove file actions to audit content management and device file distribution. - **When to use:** Use when troubleshooting missing files on endpoints, auditing portal content changes, or verifying remote file deployments.
- **Example:** A technician pushes an updated employee handbook to company devices and removes the outdated version. Check this report to confirm if the deploy and remove file actions reached the devices.

 

 

13. Report Activity Log

### Report Activity Log

The **Report Activity Log** category logs when custom reports, scheduled reports, and templates are created, edited, or deleted. Following are the Report Activity Log reports:

Report NamePrimary Focus / Purpose**Custom Report**Tracks the creation, update, and deletion of custom reports to monitor custom report setups. - **When to use:** Use to audit changes made to custom reports or identify who created or deleted a custom report.
- **Example:** A custom device inventory report disappears from the portal. Check this report to see who deleted it and when.

**Scheduled Report**Tracks the creation, update, and deletion of scheduled reports to monitor automated report generation and delivery schedules. - **When to use:** Use to troubleshoot missing automated email reports or verify changes to report delivery schedules.
- **Example:** Managers stop receiving weekly compliance reports via email. Check this report to verify if the automated schedule was modified or deleted.

**Report Template**Tracks the creation, update, and deletion of report templates to audit saved reporting formats. - **When to use:** Use to investigate missing report templates or determine who modified a shared template layout.
- **Example:** An IT team’s custom asset layout was overwritten by mistake. Check this report to trace who edited or updated the template.

 

 

14. Live Terminal

### Live Terminal

The **Live Terminal** category tracks Live Terminal sessions initiated, restarted, and stopped to audit remote command-line access on managed devices. Following are the Live Terminal reports:

Report NamePrimary Focus / Purpose**Live Terminal**Tracks Live Terminal sessions initiated, restarted, and stopped to audit remote command-line access on managed devices. - **When to use:** Use to monitor active remote CLI sessions or audit technician access during remote troubleshooting.
- **Example:** An administrator uses Live Terminal to run diagnostic scripts on a remote device. Check this report to verify when the terminal session started and stopped.

 

 

15. Remote view/control

### Remote view/control

The **Remote view/control** category tracks remote view and control sessions initiated, restarted, and stopped to audit remote support activity on managed devices. Following are the Remote view/control reports:

Report NamePrimary Focus / Purpose**Remote View/Control**Tracks remote view and control sessions initiated, restarted, and stopped to audit remote support activity on managed devices. - **When to use:** Use to audit remote desktop support sessions or verify when a technician accessed a device screen.
- **Example:** A helpdesk technician remotely controls an employee’s screen to fix a setting issue. Check this report to confirm when the remote support session took place.

 

 

16. Password History

### Password History

The **Password History** category tracks UEM profile password history on macOS devices to audit credential changes and policy updates. Following are the Password History reports:

Report NamePrimary Focus / Purpose**UEM Profile Password History**Tracks UEM profile password history on macOS devices to audit credential changes and policy updates. - **When to use:** Use when auditing password payload modifications or reviewing past profile passwords applied to macOS devices.
- **Example:** An admin updates a password configuration policy on company MacBooks. Check this report to view the history of applied profile passwords and verify when changes took effect.

 

 

3. Data Columns and Filters
---------------------------

### Audit Reports Data Columns

The Audit report includes detailed data fields to trace the origin and context of any action.

**Data Column****Definition****Subject**The name of the entity on which the event occurred (e.g., Device Name).**Event**The specific action that took place (e.g., Policy associated, Device group synchronized).**Created Time**The precise date and time the event was logged.**Event Module**The area of the Hexnode portal where the event originated (e.g., Device, Policy, System).**Technician**The email of the administrator who triggered the event. (System for Hexnode server-triggered events).**Policy Type**The type of policy, either a device policy or a compliance policy.**Version**The version number of the policy.**Last Modified**The date and time when the configuration was last updated.**Target Type**The type of entity receiving the policy or action (e.g., Device, User, Device Group, User Group).**Target Name**The specific name of the group, user, or entity receiving the policy or action.**Device Name**The name of the device.**Username**The username of the user associated with the device.**App Name**The name of the software application.**App Version**The specific version number of the application.**Identifier**The unique identifier for the application (e.g., Bundle ID or Package Name).**App license type**The type of license assigned to the app (e.g., VPP).**Platform**The operating system of the device.**Action Status**The current state of the action (e.g., Success, Pending, Failed).**Initiated Time**The date and time when the action was triggered.**Finished Time**The date and time when the action was completed.**OS Version**Current operating system version of the device.**UEM Profile Password**Password used to remove the UEM profile on a macOS device.### Report Filters

Audit reports can be segmented using these filters to narrow search results:

- **Created Time:** Filter by time range (All, Today, Yesterday, Last 7 days, Last 30 days, or Custom duration).
- **Username:** Filters Network Management report events by the specific user account.
- **Platform:** Filters Network Management report events by the device platform.
- **OS Version:** Filters Network Management report events by specific OS versions.

### Frequently Asked Questions

**1. Why does the Technician column show ‘System’?**

‘System’ indicates that the event was automatically triggered by the Hexnode UEM server (e.g., a scheduled device scan, a server-side synchronization, or an automatic policy application).

**2. What is the purpose of the Audit History report?**

Its main purpose is non-repudiation and compliance. It creates a verifiable record to prove who did what and when within the UEM console.

**3. How can admins check for unauthorized remote access?**

Use the dedicated Remote View/Control report to review the complete history of initiated, stopped, and restarted remote sessions, including the technician’s identity and the event time.

**4. Can admins track changes to the password used to remove the MDM profile?**

Yes, the UEM Profile Password History report specifically logs every time the password for removing the MDM profile on macOS devices is updated or changed.