Skip to main content

The Three Device Compliance Checks Explained

Hard Drive Encryption, Antivirus, and Screen Lock — what each one checks, why "Unavailable" isn't the same as failing, and how to cover a gap with manual evidence.

Written by Upendra Varma

Whether enrolled via the ComplyJet Agent or an MDM, every device is checked against the same three things, visible under Employee → Devices ("My Devices") or the admin-side Devices page:

  • Hard Drive Encryption — whether the disk is encrypted (FileVault on macOS, BitLocker on Windows).

  • Antivirus — whether antivirus/endpoint protection is installed and active.

  • Screen Lock — whether the device locks itself after inactivity.

"Unavailable" isn't the same as failing

Notice the Windows device above shows Compliant overall even though Antivirus and Screen Lock both read Unavailable — that's deliberate. "Unavailable" means the connected provider isn't reporting a signal for that check at all, which counts differently from an explicit fail. Only an explicit failing result (not simply missing data) marks the device non-compliant. If a check should be reporting and isn't, that's worth investigating with your provider connection rather than assuming it's failing silently.

Covering a gap with manual evidence

Expand any check to upload evidence directly, for situations your provider genuinely can't auto-report:

This fills the specific gap — it doesn't override a provider's own verdict if one exists. Use it when a check shows Unavailable (or you're on a device type your provider doesn't fully support) and you have another way to prove the requirement's actually met, like a screenshot of your encryption settings.

Did this answer your question?