Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Compliance checks - Does anyone actually know how it works?

I'm puzzled.

Could someone please explain how compliance checks are carried out on iOS devices and whether the SMC app is a requirement?

For instance, I have configured a basic compliance rule stating devices must have a passcode, but removing the passcode from devices does not create a non-compliance situation no matter how long I wait.

Does the SMC app have to be installed for all aspects of compliance checks to work or only for certain features? If so is there any way to enforce the installation other than on "supervised" devices, after all we can't configure BYOD objects as "supervised".

Hopefully someone knows or is everyone as confused as I am.

Come on Sophos, the documentation and information around this is pretty poor.

:54397


This thread was automatically locked due to age.
Parents
  • Thanks Stefan,

    That's a great help.

    So, to recap the SMC server sends a sync request, default interval 24 hours, although for iOSdevices this can be changed during the EAS setup, via APNS. The device then responds via https and updates the SMC database. SMC runs compliance checks against the database, default interval 4 hours, again this can be changed during the EAS setup for iOS devices or using command bundles for Android and can be set in the client tab/general settings for Windows Phone 8 devices. These results are checked against the relevant compliance rule and the device is then flagged as compliant or not in the management console. In order for the device itself to indicate violations the SMC app must be installed. Adding the SMC app as a compliance requirement would block access to corporate email if the app was not installed, therefore compelling end-users to install the app.

    Regards.

    :54569
Reply
  • Thanks Stefan,

    That's a great help.

    So, to recap the SMC server sends a sync request, default interval 24 hours, although for iOSdevices this can be changed during the EAS setup, via APNS. The device then responds via https and updates the SMC database. SMC runs compliance checks against the database, default interval 4 hours, again this can be changed during the EAS setup for iOS devices or using command bundles for Android and can be set in the client tab/general settings for Windows Phone 8 devices. These results are checked against the relevant compliance rule and the device is then flagged as compliant or not in the management console. In order for the device itself to indicate violations the SMC app must be installed. Adding the SMC app as a compliance requirement would block access to corporate email if the app was not installed, therefore compelling end-users to install the app.

    Regards.

    :54569
Children
No Data