Viewing Events by Device Risk

In addition to Events view, you can view the events according to device risk (not available when privacy mode is enabled):

This view shows all the necessary risk information per device in the system, and the number of the devices with a specific risk level.

The top table shows the list of devices with their risk levels and the number of devices.

Item Description
Device Risk

Device risk is determined by both the accumulative threats risk levels found on it and different settings present on the device. (Debugging tools, Jailbreak, Developer Tools, and so on).

Risk levels:

  • High - Indicates a device is in a malicious state and an immediate action is needed.

  • Medium - Indicates a potential threat by a legitimate application or configuration which contradicts the company policy.

  • Low - Indicates a device might present potential risky behavior caused by a legitimate application or configuration. This might be caused by a legitimate application which uses an unusual ad network or an application which has access to the device contacts with no reasonable explanation but no potential risk is applied.

  • None - Indicates a device has zero risk.

User Info

User name and email as configured in the devices screen.

Device Info

Device Info determined by the information received from the device post the Protect installation:

  • Device type (OS)

  • OS Version

  • Device details

Policy

The device policy, determined according to the device group. Can be Global or custom.

Member Of

The device groups.

Status

Indicates the device current state:

  • Processing - A temporary state that occurs between adding the device manually and the Registration Invitation has been sent.

  • User Notified - A Registration Invitation was sent, device has not yet registered.

  • Provisioned - Device was added via UEM, device has not yet registered.

  • Active - Mobile Security Protect app is installed, the device was successfully registered, and the device was successfully scanned.

  • Inactive - Mobile Security Protect app was installed, the device was registered with Mobile Security dashboard, and then Mobile Security Protect app was removed, or the device has not connected to the Dashboard in more than X days.

Last Seen

Last seen field indicates the last time the device communicated with Mobile Security servers.

You can filter every column in the table:

  1. Click Filter above the table.

  2. On the Filters pane on the right side, select the information you want to view.

  3. You can also export the mobile devices information from the table to CSV file, which creates a comma separated values file that can be opened in spreadsheet applications such as Microsoft Excel. Use filter to select the required information for the file. Later you can use those details to approach end-users and instruct them how to remove the risk off their mobile devices, or other related actions.

The lower table on the screen shows the chosen device row events details.

This table has two modes:

  1. Active Events (default): Shows only the active events on the device.

  2. All Events: Shows active and historic events.

You can filter every column in the table:

  1. Click Filter above the table.

  2. On the Filters pane on the right side, adjust information you want to view.