Monitoring for Non-Compliant Mobile Devices

Technical Paper: Device Compliance with Microsoft Entra and Jamf Pro

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

When a mobile device falls out of the scope of the smart device group used to monitor compliance, it is no longer marked as compliant in Entra ID. Non-compliant mobile devices are unable to access company resources until they are brought back into compliance.

You can use a combination of smart device groups, mobile device apps, and configuration profiles in Jamf Pro to monitor non-compliant devices.

  1. In Jamf Pro, create a new smart device group for the compliance criteria you want to monitor.
    Example:

    You may want to create smart groups for mobile devices that do not have Slack installed or that have Do Not Disturb enabled.

  2. Alert users who fall into the scope of the groups you just created by making a mobile device app or configuration profile without payloads available in the Device Compliance category in Jamf Self Service for iOS.
    1. Use the Description field on the Self Service tab to include a message that explains requirements for device compliance.
    2. Add the related smart group you created in step 1 to the scope of the app or configuration profile.

      For more information, see the Content Distribution Methods in Jamf Pro or Mobile Device Configuration Profiles sections in the Jamf Pro Documentation.

  3. Create one additional smart device group to use for calculating device compliance:
    1. On the Mobile Device Group tab, select the Send email notification on membership change checkbox so that you are notified when a mobile device falls out of compliance.
    2. Click Criteria.
    3. Click Add .
    4. Click Show Advanced Criteria.
    5. Select Device Compliance Integration - Compliance Status from the list of criteria.
    6. From the Operator pop-up menu, choose "is".
    7. Select Non Compliant from the Value list.
    8. Click Add .
    9. Select Device Compliance Integration - Registration Status from the list of criteria and add each of the smart groups you created in step 1.
    10. From the Operator pop-up menu, choose "is".
    11. Select Registered from the Value list.
    12. Click Save .

You will now be notified by email of any change in compliance and your users will be able to take action to remediate their non-compliant mobile devices.

Update the smart device groups at any time to add or remove compliance criteria.