Compliance enforcement

This configuration defines when non-compliant devices are blocked and wiped.

The Compliance enforcement configuration defines block and wipe actions for Android Enterprise devices that do not meet certain requirements of a policy. For each supported configuration, it can be defined after how many days of non-compliance the device is blocked and subsequently wiped.

The configuration is available for all Android Enterprise enrollment types and can only be added once per policy. Which enrollment type an individual rule applies to depends on its row (see below).


Default Behavior

Without a custom rule, Relution sets default rules for the monitored settings: non-compliant devices are blocked after 20 days and wiped after 30 days.

Custom rules can only shorten the periods: a maximum of 10 days is permitted for blocking and a maximum of 30 days for wiping.


Configuration Overview

The table in the form always contains the same four rows, one per configuration whose non-compliance can be enforced. The columns show the values of the respective rule: Block after days, Block scope, Wipe after days and Preserve factory reset protection.

RowMonitored settingsApplies to
Advanced security overridesDevice encryption policy from Advanced security overrides →all enrollment types
Device passcodePassword requirements from Device password → and Work profile passcode →fully managed devices, managed devices with a personal profile
Work profile passcodePassword requirements from Device password → and Work profile passcode →devices with a work profile
RestrictionPermitted input methods, Permitted accessibility services and Disable keyguard from Restrictions →all enrollment types; Disable keyguard only on fully managed devices

The Device passcode and Work profile passcode rows both refer to all password requirements of the device. Which of the two rows applies is determined solely by the enrollment type.

Two actions are available in the context menu of a row:

  • Configure opens the Configure rule dialog.
  • Reset removes the custom rule of the row. The default rule then applies again.

Configure Rule

Each rule always consists of a block action and a wipe action. A block without a subsequent wipe cannot be configured.

Block Action

  • Block after days
    Number of days the device must be non-compliant before the device or the work profile is blocked. The prefilled value is 10; values from 0 (immediate block) to 10 are permitted. The value must be smaller than Wipe after days. When the block takes effect, a notification is shown on the device that describes, where possible, how to resolve the non-compliance.

  • Block scope
    Defines what the block applies to. The setting only takes effect on company-owned devices. Unspecified is preselected.

    • Unspecified – equivalent to Work profile.
    • Work profile – only apps in the work profile are blocked; apps in the personal profile remain usable.
    • Device – the entire device is blocked, including apps in the personal profile.

Wipe Action

  • Wipe after days
    Number of days the device must be non-compliant before it is wiped. The prefilled value is 30; values from 0 to 30 are permitted. Company-owned devices are reset to factory settings; on devices with a work profile (BYOD), the work profile is removed.

  • Preserve factory reset protection
    Defines whether the factory reset protection (FRP) data is preserved when the device is reset. Off by default. The setting does not apply to work profiles.

Clicking Confirm adds the rule to the table. It is only saved together with the configuration.


Multiple Policies

If several policies of a device contain the Compliance enforcement configuration, the rule of the policy with the higher priority applies for each monitored setting. Settings without a custom rule keep the default rule.

Top