BES10_Cloud logo
 

Create a compliance profile

  1. On the menu bar, click Policies and Profiles.
  2. Click the + icon beside Compliance.
  3. Type a name and a description for the compliance profile.
  4. Perform one of the following actions:
    • To configure compliance conditions for iOS devices, click the iOS tab.
    • To configure compliance conditions for Android devices, click the Android tab.
  5. Perform any of the following actions:
    • If you want jailbroken or rooted devices to be considered non-compliant, select the Jailbroken or rooted device check box.
    • If you want devices with applications that you did not install to be considered non-compliant, select the Non-assigned application is installed check box.
    • If you want devices that do not have a required application to be considered non-compliant, select the Required application is not installed check box.
  6. For each condition you selected in step 5, choose the action that you want BES10 Cloud to perform when a user's device is non-compliant, and complete the steps:

    Action

    Steps

    Automatically notify the user that their device is non-compliant, and carry out an enforcement action if the user does not correct the issue.

    1. In the Enforcement action drop-down list, click Prompt for compliance.
    2. In the Prompt method drop-down list, click the type of message to send to the user.
    3. In the Prompt count field, type the number of times the notification message is sent before BES10 Cloud carries out the action.
    4. In the Prompt interval field and drop-down list, specify the time between prompts.
    5. In the Prompt interval expired action drop-down list, click the action that you want BES10 Cloud to take when the prompt period expires:
      • If you do not want an enforcement action, select None.
      • To prevent the user from accessing work resources and applications from the device, select Untrust. Data and applications are not deleted from the device.
      • To delete work data from the device, select Delete only work data.
      • To delete all data from the device, select Delete all device data.

    Prevent the user from accessing work resources and applications from the device. Data and applications are not deleted from the device.

    1. In the Enforcement action drop-down list, click Untrust.

    Delete work data from the device.

    1. In the Enforcement action drop-down list, click Delete only work data.

    Delete all data from the device.

    1. In the Enforcement action drop-down list, click Delete all device data.
  7. Repeat steps 4 to 6 if you want to configure the compliance conditions for a different device type.
  8. If you chose to send a notification message to users when their devices become non-compliant, perform any of the following actions:
    • To change the email notification, expand Email notification sent out when violation is detected. Change the subject and message.
    • To change the device notification, expand Device notification sent out when violation is detected. Change the message.

    If you want to use variables to populate notifications with user, device, and compliance information, see Using variables in compliance notifications. You can also define and use your own custom variables using the administration console. For more information, see Custom injection variables.
  9. Click Add.
After you finish: Rank profiles.