Compliance enforcement
This configuration defines when non-compliant devices are blocked and wiped.
The Compliance enforcement configuration defines block and wipe actions for Android Enterprise devices that do not meet certain requirements of a policy. For each supported configuration, it can be defined after how many days of non-compliance the device is blocked and subsequently wiped.
The configuration is available for all Android Enterprise enrollment types and can only be added once per policy. Which enrollment type an individual rule applies to depends on its row (see below).
Default Behavior
Without a custom rule, Relution sets default rules for the monitored settings: non-compliant devices are blocked after 20 days and wiped after 30 days.
Custom rules can only shorten the periods: a maximum of 10 days is permitted for blocking and a maximum of 30 days for wiping.
Configuration Overview
The table in the form always contains the same four rows, one per configuration whose non-compliance can be enforced. The columns show the values of the respective rule: Block after days, Block scope, Wipe after days and Preserve factory reset protection.
| Row | Monitored settings | Applies to |
|---|---|---|
| Advanced security overrides | Device encryption policy from Advanced security overrides → | all enrollment types |
| Device passcode | Password requirements from Device password → and Work profile passcode → | fully managed devices, managed devices with a personal profile |
| Work profile passcode | Password requirements from Device password → and Work profile passcode → | devices with a work profile |
| Restriction | Permitted input methods, Permitted accessibility services and Disable keyguard from Restrictions → | all enrollment types; Disable keyguard only on fully managed devices |
The Device passcode and Work profile passcode rows both refer to all password requirements of the device. Which of the two rows applies is determined solely by the enrollment type.
Two actions are available in the context menu of a row:
- Configure opens the Configure rule dialog.
- Reset removes the custom rule of the row. The default rule then applies again.
Configure Rule
Each rule always consists of a block action and a wipe action. A block without a subsequent wipe cannot be configured.
Block Action
Block after days
Number of days the device must be non-compliant before the device or the work profile is blocked. The prefilled value is10; values from0(immediate block) to10are permitted. The value must be smaller than Wipe after days. When the block takes effect, a notification is shown on the device that describes, where possible, how to resolve the non-compliance.Block scope
Defines what the block applies to. The setting only takes effect on company-owned devices. Unspecified is preselected.- Unspecified – equivalent to Work profile.
- Work profile – only apps in the work profile are blocked; apps in the personal profile remain usable.
- Device – the entire device is blocked, including apps in the personal profile.
Wipe Action
Wipe after days
Number of days the device must be non-compliant before it is wiped. The prefilled value is30; values from0to30are permitted. Company-owned devices are reset to factory settings; on devices with a work profile (BYOD), the work profile is removed.Preserve factory reset protection
Defines whether the factory reset protection (FRP) data is preserved when the device is reset. Off by default. The setting does not apply to work profiles.
Clicking Confirm adds the rule to the table. It is only saved together with the configuration.
Multiple Policies
If several policies of a device contain the Compliance enforcement configuration, the rule of the policy with the higher priority applies for each monitored setting. Settings without a custom rule keep the default rule.