Live

Alert Rules

Configure which conditions trigger alerts and auto-create tickets

Back to Alerts

Disk encryption disabled

High Auto-ticket

FileVault (macOS) or BitLocker (Windows) is not enabled

encryption_off

Firewall disabled

High Auto-ticket

Application firewall is turned off

firewall_off

OS update overdue

Medium Auto-ticket

Device OS version is behind the target after the grace period

Grace period: 7 days after target version set

os_outdated

Device offline

Low Auto-ticket

Device has not checked in for over 48 hours

Threshold: 48h offline

device_offline

MDM unenrolled

High Auto-ticket

Device has been removed from MDM management

mdm_unenrolled

Profile installation failed

Medium Auto-ticket

A configuration profile failed to install

profile_failed

Certificate expiring soon

Medium Auto-ticket

APNs or SCEP certificate expires within 30 days

Warn: 30 days before expiry

cert_expiring

Prohibited application detected

Medium Auto-ticket

A blocklisted application is installed on the device

Blocklist: Tor Browser Transmission BitTorrent uTorrent
prohibited_app

Low disk space

Low Auto-ticket

Available storage is below 10%

Threshold: 10% free space

disk_space_low

Rules are evaluated after every telemetry update. Per-customer overrides can be configured in /certs-data/admin/alert_rules.json.