INTRODUCTION
The compliance engine is an automated tool by Workspace ONE UEM that ensures all devices abide by policies that you define. These policies can include basic security settings such as requiring a passcode and enforcing certain precautions including passcode strength, deny-listing certain apps, and requiring device check-in intervals.
Once devices are non-compliant, the compliance engine warns users to prevent disciplinary action on the device by addressing compliance errors.
In addition, devices not in compliance cannot have device profiles assigned to it and cannot have apps installed on the device. If corrections are not made in the amount of time specified, the device loses access to certain content and functions that you define. The available compliance policies and actions vary by platform.
TASKS
STATE/ORGANIZATION MANDATE
Your organization has instituted a mobile device security mandate to limit the organizations exposure to compromise and data leakage. Among the requirements in the mandate, they need to ensure that all devices connecting to their network and accessing corporate data must have encrypted storage. Any device found to be in violation of this mandate must 1st be notified, then corporate email access should be removed. If after 3 days the user has not addressed the violate the device should be removed from management and have no further access to the organization's resources.
- WS1 Console, Click Groups & Settings --> All Settings
- Expand Device & Users
- Expand General
- Click Message Templates
- Click Filter and under Category Select Compliance
- Select the "Compliance Violation User Notification" Message Template
- Click Copy
- Append your Initials at the end of the Template Name
- In the message template Message body section add the following sentence under {PolicyViolationRules}
-
Please encrypt the local any removable storage attached your device. For further instructions, please see the link below
https://bit.ly/3pbp2l2
-
Please encrypt the local any removable storage attached your device. For further instructions, please see the link below
- Click SAVE to save the template
- Click the "X" to close the dialog
- In the WS1 Console, Click Devices --> Compliance Policies
- Click List View
- Click Add, to add a new Compliance Policy
- Select iOS
- Define the Policy Rule as follows:

- Click NEXT
- Uncheck "Default Template"
- Select your template from the dropdown list

- Click Add Escalation
- Chose Email
- Choose Block Email

- Click Add Escalation
- Set the Action delay to 2 days
- Choose Command
- Choose Enterprise Wipe
- Click NEXT

- Assign the policy to Employee Owned (xxxx / Employee Owned) Smart Group
- Click NEXT
- Click FINISH & ACTIVATE

0 Comments
Add your comment