Events and Alerts

The Events & Alerts tab shows an audit trail of incidents and actions that occurred on the devices, for example, Application installation and Profiles detected on devices.

By default, the table displays all events for devices registered in your tenant. To view only the events that require remediation, click the Active events tab at the top.

Events & Alerts table:
Item Description
Date/Time

Displays the date and time when the event occurred.

Severity level
  • Critical:

    • Indicates a malicious threat (such as a malware application) that has immediate impact on the device and sensitive corporate data.

    • Requires immediate action.

    • Triggers an alert on the user device to remediate the threat (for example, remove the malware, disconnect from the infected Wi-Fi network).

    • Sends an email/SMS alert to the administrators (if you define in the dashboard settings).

  • Warning: Indicates a potential threat by a legitimate application, configuration or company policy violation.

    Examples:

    • Backup tools (Application) might be legitimate for personal use but will risk the organization if extracts information to unknown destinations.

    • Enable USB Debugging on Android might be legitimate for developers but is a potential risk for regular users.

  • Information - Indicates that no further action is required. Appears most often when an Application is removed.

Note:

Low risk events do not trigger an alert on the end-user devices.

Attack Vector

Specifies the nature of the Event/Alert:

  • Application

  • Cellular network

  • Device

  • Network Security

  • OS Exploits

  • Text message

  • WiFi network

  • iOS profiles

Threat Factors

Specifies the threat factor for the event that occurred. Explains the reason for the severity level.

Event

Specifies the user or the action taken by the Mobile Security solution.

  • Noncompliant

  • Compliant

  • Policy changed

  • Active (Device is active)

  • Inactive (Device is inactive)

  • Disconnected

  • Detected

  • Ended

  • Installed

  • Removed

  • Blocked

  • Prevented

  • Deleted

  • Approved

  • Enabled

  • Disabled

Event Details

Additional details about the Event, such as name of application installed or removed Wi-Fi SSID or Identifying information, and so on. Event Details can link to an iOS Profile detail, Network detail, or App Analysis detail.

OS

Operating System of the device (iOS/Android). It is determined by the information received from the device when the application is installed.

Policy

Policy enforced on the device.

Device ID

The device ID in the Mobile Security dashboard.

Device S/N

Serial number of the device.

User email

Device user's email address. It is manually set by the Admin or automatically by UEM when the devices are provisioned.

Note:

For Android devices, you get a Phishing alert on the dashboard when Mobile Security detects and blocks a SMS phishing attempt on the mobile device. This feature works only if the end-user has granted access to Mobile Security Protect app to scan the SMS received on the device.

For more information on how to grant the access on the device: