Iru (formerly Kandji) (Beta)

👍

Quick Details

Recommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Iru Child Inspectors (one per managed device)
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 12 hours)
Data Summary: Iru Inspector Summary

Overview

Iru Inspector (Beta)

You can now use the Iru Inspector (Beta) to gain visibility into your managed customers' Apple device fleets directly from Iru (formerly Kandji), the Apple-first device management (UEM/MDM) platform. The inspector connects to a single Iru tenant and maps each managed Apple device to its own Liongard Environment, so you can track posture drift per device without extra configuration.

What you can monitor

The Iru Inspector collects fleet inventory and security posture data, including:

  • Apple device inventory — Macs, iPhones, iPads, and Apple TVs
  • FileVault encryption, Supervised, and Activation Lock status
  • Blueprint (configuration template) assignments
  • Library Items (profiles, apps, and scripts)
  • Iru agent version and last check-in
  • EDR threat events (when the tenant is licensed for Threat Detection)
  • Vulnerability (CVE) detections (when the tenant is licensed for Vulnerability Management)
  • Apple Business Manager (ADE) integration status

How it works

A parent launchpoint authenticates to a single Iru tenant using a tenant API URL and API token. Liongard automatically discovers each managed Apple device and creates a dedicated child launchpoint for it, giving each device its own Environment for independent tracking of posture and configuration.

Benefits

  • Catch a Mac whose FileVault is disabled or whose Supervision is lost.
  • Get alerted the moment a new active EDR threat or a new Critical CVE appears in a customer's fleet.
  • Track Iru agent removal or downgrade, and devices that stop checking in.
  • Watch Apple Business Manager (ADE) token expiry so enrollment doesn't silently break.

Inspector Setup Preparation

⚠️

Prerequisites & Access Requirements

To configure the Iru Inspector, ensure you have the following:

  • An Iru tenant with API access enabled — if it isn't enabled, contact your Iru Customer Success Manager
  • Admin rights in Iru to create an API token
  • The tenant's API URL, shown alongside the token when it's created

Inspector Setup:

Step 1: Create the API Token in Iru

  1. Sign in to Iru as a tenant administrator.
  2. Navigate to Settings → Access.
  3. Select Add API Token and name it (e.g., "Liongard Inspector").
  4. Grant the following read permissions:
    • Device list, device details, device library items, device parameters, and device status
    • Blueprint list and details
    • Library — List Custom Profiles
    • List users
    • Apple ADE list and details
    • If the tenant is licensed: Threat list/details and Vulnerability Management (Vulnerabilities and Detections)
  5. Create the token and copy the value immediately — Iru displays it only once.
  6. Note the API URL shown alongside the token:
    • US: https://<subdomain>.api.kandji.io
    • EU: https://<subdomain>.api.eu.kandji.io
⚠️

Licensed modules

Threat Detection and Vulnerability Management permissions only apply if the tenant is licensed for those modules. If a module isn't licensed, or the token lacks that scope, the corresponding Liongard views come back empty rather than failing the inspector run.

Step 2: Configure the Iru Inspector in Liongard

  1. Log in to the Liongard platform.
  2. In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Iru Inspector > Select Add System.

Since Iru is a multi-tenant system where a single tenant can manage many Apple devices, you'll set up a single "Parent" Inspector that will then auto-discover a "Child" Inspector for each device.

Fill in the following information:

  • Type of Inspector: Parent
  • Environment: Select your MSP's Environment
  • Friendly Name: Suggested Naming: [Customer Name] Iru Parent
  • Agent: Select the On-Demand Agent
  • Inspector Version: Latest
  • Iru API URL: The tenant API URL noted in Step 1 (US or EU host)
  • Iru API Token: The token generated in Iru under Settings → Access
  • Emit Per-Device Child Launchpoints: Leave at its default (on) unless the fleet is very large — turning this off collapses the inspector to tenant-only reporting with no per-device Environments
  • Scheduling: The Inspector will default to run once a day at the time it's set up. Here you can adjust the schedule
  • Select Save. The Inspector will now be triggered to run within the minute.

Step 3: Child Inspector Setup

After the first run of the Parent Inspector, each managed Apple device will be auto-discovered and surfaced in the Discovered Systems tab on the Inspectors > Iru Inspector page.

  • Activate or Archive your Discovered Systems by ensuring they're mapped to the correct Environment > Check the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints (or Archive Launchpoints).
  • Click Save.

Troubleshooting

  • 401 on connect: The API token is invalid or has been revoked — recreate it under Settings → Access.
  • 404 or redirect on connect: The wrong region host was entered — confirm US vs. EU (api.kandji.io vs. api.eu.kandji.io).
  • Threats or Vulnerabilities views are empty: The tenant isn't licensed for Threat Detection or Vulnerability Management, or the token lacks that scope.
⚠️

Known V1 Limitations

No write actions (no create, update, or delete). No per-device installed-apps enumeration. No Self Service category enumeration. No cross-tenant MSP umbrella view — Iru has no API for that, so one launchpoint is required per managed tenant.

Inspector FAQs


Did this page help you?