Common: Compliance profile settings

For each compliance rule that you select on the device tabs, choose the action that you want BlackBerry UEM to perform if a user's device is not compliant.

Compliance profile setting

Description

Prompt behavior

This setting specifies whether UEM prompts the user to correct a compliance issue and gives the user time to fix the issue before taking action, or whether UEM takes immediate action.

Prompt method

This setting specifies whether UEM prompts the user to correct a compliance issue by sending a device notification or an email message and a device notification.

BlackBerry Dynamics apps provide only device notifications, regardless of this setting. Device notifications are not supported on Windows 10 devices.

This setting is valid only if "Prompt behavior" is set to "Prompt for compliance."

Email template used when a compliance violation is detected

This setting specifies the email template to send to a user when the user's device is not compliant with the selected compliance rule. If you select "Use profile default", UEM sends the default email template that you configured for the profile (Email sent when violation is detected).

This setting is valid only if "Prompt method" is set to "Email and device notification".

Prompt count

This setting specifies the number of times the user is prompted to correct a compliance issue.

This setting is valid only if "Prompt behavior" is set to "Prompt for compliance."

Prompt interval

This setting specifies the amount of time between prompts, in minutes, hours, or days.

This setting is valid only if "Prompt behavior" is set to "Prompt for compliance."

Enforcement action for device

This setting specifies the action that UEM takes on devices that are not compliant. The available options may differ depending on the OS and the type of compliance rule:
  • Monitor and log: UEM identifies the compliance violation but takes no enforcement action on the device.
  • Untrust: The user cannot access work resources and apps on the device. Data and apps are not deleted. On iOS and iPadOS devices, the work email account is removed from the native email app. Users must restore the email account settings to the app after the device returns to compliance.
  • Delete only work data
  • Delete all data
  • Remove from server

This setting does not apply to devices activated with User privacy.

When UEM deletes device data from an iOS or Android device as the result of a compliance action, UEM will not delete eSIM information from the device.

On devices activated with "Work and personal - user privacy", you cannot delete all data on a user's device. If you select "Delete all data", UEM performs the same action as "Delete only work data".

For supervised iOS and iPadOS devices, enforcement actions for the "Restricted app is installed" rule are not applicable. Users are automatically prevented from installing restricted apps.

Enforcement action for BlackBerry Dynamics apps

This setting specifies what happens with BlackBerry Dynamics apps when a device is not in compliance:
  • Do not allow BlackBerry Dynamics apps to run
  • Delete BlackBerry Dynamics app data
  • Monitor and log: UEM identifies the compliance violation but takes no enforcement action.