Skip to main content

Configure Compliance Policy (Android Management)

The Compliance Policy in SureMDM allows administrators to define security requirements that devices must meet to remain compliant. If a device violates the configured rules, predefined Out of Compliance Actions are automatically enforced to protect corporate data and resources.

To create a compliance policy profile and deploy it to the device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Android > Add > Compliance Policy > Configure.

  2. Enter a Profile Name.

  3. In the Compliance Policy screen, the settings available are given below:

SettingsDescription
Password Policy
Device should be secured with passwordEnable this option to ensure that the device or work profile is protected with a password.
Block Device UsageBlocks device or work profile usage if it remains non-compliant after the specified delay (immediately or after defined days). Scope can be set to device or work profile.
Wipe DeviceFactory resets the device or deletes the work profile if non-compliance continues beyond the specified delay.
Encryption Policy
Device should be encryptedEnable this option to ensure device storage encryption. Options include Unspecified, With Password, or Without Password.
Block Device UsageBlocks device or work profile usage if encryption requirements are not met.
Wipe DeviceResets the device or removes the work profile if the device remains unencrypted after the defined delay.
Disable Keyguard
Device should not have keyguard customizationEnable this option to prevent unauthorized lock screen (keyguard) customizations.
Block Device UsageBlocks usage if keyguard customization policy is violated.
Wipe DeviceResets the device or work profile if non-compliance persists.
Permitted Input Methods
Device should have only permitted input methodsEnbale this option to restrict the device to approved keyboards/input methods only.
Block Device UsageBlocks usage if unauthorized input methods are detected.
Wipe DeviceResets the device or work profile if violation continues.
Permitted Accessibility Services
Device should have only permitted accessibility servicesEnable this option to allow only approved accessibility services on the device.
Block Device UsageBlocks usage if unauthorized accessibility services are enabled.
Wipe DeviceResets the device or work profile if non-compliance persists.
Minimum API Level
Device should have minimum API levelEnsures the device runs on the specified minimum Android API level. Set the Minimum API Level.
Block Device UsageBlocks usage if the device OS version is below the defined level.
Wipe DeviceResets the device or work profile if the device does not meet the minimum API requirement.
Device Posture Policy
Potentially CompromisedDefines actions for devices detected as high risk (e.g., unlocked bootloader or failed integrity checks).
At RiskDefines actions for devices with moderate security risks such as outdated software or weakened security settings.
Blocklist DeviceMoves the device to the blocklisted section, preventing access to corporate resources.
Wipe DeviceFactory resets the device or removes the work profile upon posture violation.