Skip to content

Device statuses

Every column on the Devices page is designed to be honest about what is known versus claimed. Statuses are reported by the agent itself; a device that has gone quiet reads as Unknown rather than as still doing whatever it last claimed.

Devices page

ColumnMeaningNotes
Device / Employee / PlatformIdentity and inventoryHostname and platform are self-reported by the agent
AgentThe version the agent last reported, and since whenA device quiet for too long shows stale/unknown rather than its last claim
PolicyThe governing template and convergenceup to date is an authoritative content match; pending / running vN means the device is converging on the latest version
ProxyWhether interception is configured and runningOn, degraded, error, disabled — self-reported per check-in
CA trustWhich trust tier holdsSee the table below
StatusThe revocation switchactive / deactivated
Enrolled / Last seenLivenessLast seen updates on every authenticated agent request

Ordered by precedence — a device matching several shows the most serious:

BadgeMeaningYour move
DeclinedThe employee said no to the trust promptA person made a choice — talk to them, or push the CA certificate profile
Awaiting approvalPrompted; no answer yetWait, or chase — an unanswered prompt can sit for days
MDM-enforcedTrusted via your MDM profile, outside employee reachThe strong posture; nothing to do
LocalTrusted via the employee’s own approvalA legitimate steady state — enforced, but employee-revocable
UnknownOld agent, never reported, or quiet too longUpdate the agent / investigate why the device is silent

Background on the two tiers: CA trust tiers.

  • History — the policy decisions that have governed this device over time.
  • MDM profile — downloads this device’s CA certificate profile. Audited; does not change the badge by itself (download ≠ install).
  • Deactivate — the revocation switch. The device’s next request is rejected: event upload and policy delivery stop until you reactivate it or it re-enrolls with a fresh credential. Note the agent keeps enforcing its last policy locally — deactivation cuts the device off from the backend; it does not switch off protection on the machine.

An offline Mac, a stopped agent, and a pre-release agent all read as Unknown. That is deliberate: Unknown means “not currently accounted for,” which on a fleet dashboard is actionable information. The product never paints a stale green over a device it cannot vouch for.