Device Posture
What a device has to be able to say about itself before it is trusted.
What a device must be able to say about itself before it is trusted, such as disk encryption, antivirus, and whether it is managed. Devices report their posture and appear as compliant, failing, or not yet reported.
Reading the list
Every enrolled device appears with one of three states. Compliant means it reported and met the rules. Failing means it reported and did not. Not reported means it has not said anything yet, which is not the same as failing and is worth treating differently: a device that has never checked in may simply not have run since you set the rules.
When something fails
The row says which check failed rather than only that one did, so the fix is usually obvious: encryption switched off, an antivirus product not running, a device that has left management. Posture is reported by the device itself, so correcting it on the machine and letting it check in again is what clears the row.
Untrusted certificates
Internal kit whose self-signed certificate is expected — a lab switch, a printer, an appliance nobody is going to re-issue a certificate for — can be listed as accepted. Listing it records a decision rather than silencing a finding: the certificate is still untrusted, and the list is what says somebody looked at it and decided it was fine.
Locations
A location is how a device knows it is at the office, and each list takes one entry per line.
Domains and networks: a device joined to any of these is at the office.
Corporate DNS servers are used to resolve the internal names below — primary, secondary and so on, in order.
Internal names: if any of these resolves through the corporate DNS above, the device is at the office.
Enforcement
One setting decides what posture does, and it has three positions.
Off collects nothing. No posture is gathered and no device is judged.
Report records what each device looks like and blocks nothing. Every device keeps its access whether it passes or fails, and the list tells you what would happen if you turned the setting up. This is where to start: switching straight to Block on a fleet nobody has measured takes access away from people who did not know they were failing.
Block withholds access from a device that fails. The device keeps reporting, so it returns on its own once whatever was wrong is put right — there is nothing to re-approve.
What happens when a device drifts
A device that stops matching the policy — disk encryption switched off, a firewall disabled, an OS version fallen behind — is handled by one setting with three positions.
Log records the change and does nothing else. The device keeps its access.
Approve holds the device until an administrator accepts it. Access continues meanwhile; what waits is the acknowledgement, not the person’s work.
Disable withdraws access until an administrator accepts the change. The strictest of the three, and the one to reach for when the setting that drifted is the reason the device was trusted.
Host firewall
Off leaves other interfaces unfiltered. Report records what would have been refused and refuses nothing. Enforce refuses inbound traffic on every interface that is not the mesh — the device answers Fowlguard and nothing else.