A managed device fleet that was correctly configured at deployment does not stay that way indefinitely. OS updates change the behavior of certain restrictions. Application updates modify permission requirements. Firmware changes affect hardware feature availability. In some cases, local access to a device results in settings being changed that were supposed to remain constant. And in every fleet, some devices experience enrollment issues, connectivity gaps, or hardware problems that result in configuration profiles not applying correctly.
Without continuous compliance monitoring, these deviations accumulate silently. A device at a remote location has been operating with a misconfigured kiosk lockdown for three weeks. An app update pushed two months ago applied correctly to 98 percent of the fleet but silently failed on four devices in two locations. A firmware change altered how a security restriction behaves on one hardware model, leaving those devices in a state that does not match the intended policy.
Moki’s compliance policy capabilities address this by continuously evaluating every enrolled device against the defined configuration standard and flagging any device that deviates from that standard. The deviation is surfaced as a compliance violation rather than discovered through a customer complaint, an audit finding, or a problem that has been quietly present for weeks.
What Compliance Policies Are and How They Work
A compliance policy in Moki is a defined set of conditions that describe the intended state of a managed device. The platform continuously checks enrolled devices against these conditions and marks any device that does not meet them as non-compliant. Non-compliant devices can trigger alerts, appear in compliance reports, and be targeted for remediation through configuration pushes.
Compliance policies operate at the device management layer rather than the application layer. They evaluate device-level conditions: whether the expected configuration profile is applied, whether kiosk mode is active, whether specified hardware features are in the correct state, whether the device is enrolled with the correct group assignment, and whether security settings meet defined requirements.
The continuous evaluation model is what makes compliance policies operationally valuable. A device that passes a spot check on Monday and drifts out of compliance by Thursday is caught automatically rather than waiting for the next manual review or the next scheduled audit.
What to Include in a Compliance Policy
The conditions that belong in a compliance policy are the device-level states that are required for the device to function correctly and securely in its intended role. For most kiosk and signage deployments, these fall into several categories.
Configuration profile assignment is the foundational compliance check. Every device in a fleet should be assigned to the correct configuration profile for its device type and location. A device that has lost its profile assignment, is assigned to the wrong profile, or has had its profile removed is in a fundamentally misconfigured state. The compliance policy should verify that the expected profile is applied and flag immediately if it is not.
Kiosk mode status is the most operationally critical compliance condition for customer-facing deployments. A device that is supposed to be in single-app kiosk lockdown but is not is a device that a customer or employee can navigate beyond its intended interface. This is both a brand experience failure and a security gap. The compliance policy should verify kiosk mode is active on every device where it is required and trigger an alert if any device exits the locked state unexpectedly.
Security configuration conditions verify that the device’s security settings meet the requirements defined for the deployment. For payment-adjacent devices, this includes verifying that camera access is restricted, screenshot capability is disabled, and network connections are limited to authorized endpoints. For healthcare patient-facing devices, it includes verifying that session data is not retained between users and that the device configuration meets the applicable data handling requirements. The specific conditions depend on the deployment context but should reflect every security setting that is required rather than just preferred.
Enrollment validity confirms that the device is properly enrolled in Moki and that its enrollment has not been compromised. A device that appears in the fleet inventory but has lost its enrollment connection is not being monitored or managed despite appearing to be under management.
Setting Alert Thresholds for Compliance Violations
Compliance violations should generate alerts that are routed to the appropriate team based on the severity and nature of the violation. Not all compliance violations warrant the same urgency, and the alert routing should reflect the operational priority of each condition.
Kiosk mode violations should generate immediate alerts with the same urgency as device offline alerts for customer-facing deployments. A kiosk that has exited lockdown during operating hours is an active customer-facing problem that requires immediate investigation and remediation.
Configuration profile violations should generate alerts with slightly lower urgency unless the missing profile is directly related to kiosk lockdown or security configuration. A device that has lost its general configuration profile may still be functioning acceptably in the short term while the issue is investigated, but the deviation should be visible and tracked.
Security configuration violations should generate alerts that route to the IT security team rather than the general operations team, since these conditions may have compliance or audit implications beyond operational functionality.
Using Compliance Reports to Identify Fleet-Wide Patterns
Beyond individual device alerts, compliance policy data provides fleet-wide visibility that point-in-time monitoring cannot deliver. Regular review of compliance reports surfaces patterns that individual alerts do not capture.
A compliance report that shows three devices at the same location consistently failing the same compliance check points toward an environmental issue at that location rather than individual device problems. A compliance check that is failing on one hardware model but not others suggests a firmware or OS compatibility issue specific to that hardware. A compliance violation that appeared simultaneously across a large number of devices points toward a platform-level change, such as an OS update that altered the behavior of a specific restriction.
These patterns are only visible when compliance data is reviewed systematically rather than only when individual alerts fire. Building a weekly or monthly compliance review into the operational cadence gives the team the fleet-level perspective that alert-by-alert response does not provide.
Automated Remediation for Common Compliance Violations
For compliance violations where the correct remediation is clear and consistent, Moki’s configuration push capabilities allow remediation to be initiated directly from the dashboard without requiring manual investigation at each affected device. A device that has lost its configuration profile can receive a profile push that restores the correct configuration. A device where a security setting has drifted can receive a targeted configuration update that restores the intended state.
This remediation workflow is particularly valuable when a compliance violation affects multiple devices simultaneously. Rather than addressing each device individually, the operations team can identify the affected device group, push the corrective configuration to all affected devices in a single operation, and verify through the compliance report that the remediation completed successfully across all targeted devices.
For violations that indicate a more complex underlying issue, the compliance data provides the context that makes targeted investigation efficient: the operations team knows exactly which devices are affected, what condition they have violated, and when the violation was first detected before any human noticed it.
Schedule a Moki demo to see compliance policy configuration and monitoring in action for your specific device types and deployment requirements, or start a free trial to begin defining compliance conditions and building the monitoring foundation for your fleet. Moki’s support team can advise on the right compliance policy structure for your specific use case and regulatory context.