Skip to content
IT Atlas

Endpoints · Compliance

Device Compliance

Evaluating whether a device meets defined security requirements and turning that verdict into an access decision.

IntermediateUpdated 2026-09-01

Overview

A compliance policy states measurable requirements: encryption enabled, minimum OS version, EDR healthy, firewall on, no jailbreak, password or PIN configured. The management service evaluates them and records a compliant or non compliant state against the device identity.

Compliance only has teeth when access policy consumes it. Reporting alone changes nothing; requiring compliance for data access changes behaviour immediately.

Security considerations

  • Keep grace periods short and communicate remediation steps in the user facing message.
  • Include EDR health and patch currency, not just encryption and passcode.