Iru Inspector Summary

Summary

PropertyValue
Production StatusPreview
CategoryApps & Services
DiscoversOne child launchpoint per managed Apple device in the tenant

Description

Monitors an Iru (formerly Kandji) Apple device management tenant — Mac/iOS/iPadOS/tvOS device inventory, FileVault and Supervised status, Blueprint assignments, Library Items, EDR threat events, vulnerability detections, and Apple Business Manager integration state.


Data View Information

Parent Overview Table

  • Iru Tenant Summary
    • Tenant URL
    • Region
    • Device Count
    • Mac Count
    • iPhone Count
    • iPad Count
    • Apple TV Count
    • Blueprint Count
    • Library Item Count
    • FileVault Enabled Count
    • FileVault Disabled Count
    • Supervised Count
    • Stale Check-in Count (>7d)
    • Missing Device Count
    • Active Threat Count
    • Open Vulnerability Count
    • Critical Vulnerability Count

Parent Data Tab Headers

  • Overview
  • Devices
  • Blueprints
  • Library Items
  • Users
  • Threats
  • Vulnerabilities
  • Apple Business Manager

Child Overview Table

  • Device Summary
    • Device Name
    • Serial Number
    • Platform
    • Model
    • OS Version
    • Blueprint
    • Assigned User
    • FileVault Enabled
    • Supervised
    • Activation Lock Enabled
    • Agent Version
    • Last Check-in

Child Data Tab Headers

  • Overview
  • Library Items
  • Hardware
  • Network

Metrics

MetricDescription
Iru: Tenant Device CountTotal managed Apple devices in the tenant.
Iru: Tenant Mac CountManaged Macs in the tenant.
Iru: Tenant FileVault Disabled CountMacs with FileVault disabled — encryption-posture gap.
Iru: Tenant Supervised CountDevices in Supervised state.
Iru: Tenant Stale Check-in Count (>7d)Devices with no check-in in more than 7 days.
Iru: Tenant Missing Device CountDevices marked Missing.
Iru: Tenant Blueprint CountBlueprints configured in the tenant.
Iru: Tenant Active Threat CountActive EDR threat events returned this run; 0 when EDR is unlicensed.
Iru: Tenant Open Vulnerability CountOpen CVEs across the fleet; 0 when Vulnerability Management is unlicensed.
Iru: Tenant Critical Vulnerability CountOpen Critical-severity CVEs across the fleet.
Iru: Device FileVault EnabledWhether FileVault is enabled on this device.
Iru: Device SupervisedWhether this device is Supervised.
Iru: Device Activation Lock EnabledWhether Activation Lock is enabled on this device.
Iru: Device Agent VersionIru agent version on this device.
Iru: Device OS VersionOS version reported by this device.
Iru: Device Last Check-inLast check-in timestamp for this device.

Actionable Alerts

RuleTriggerSeverity
FileVault Disabled on a MacTenant FileVault Disabled Count increasesHigh
New Active Threat DetectedActive Threat Count increasesHigh
New Critical VulnerabilityCritical Vulnerability Count increasesHigh
Iru Agent Removed or DowngradedChild agent is uninstalled, or Agent Version lowersHigh
Device Supervision LostChild Supervised changes true → falseHigh
Device Marked MissingTenant Missing Device Count increasesMedium
Activation Lock DisabledChild Activation Lock Enabled changes true → falseMedium
Device Blueprint ReassignedChild Blueprint changesMedium
ADE Token Expiring or ExpiredAny Apple Business Manager token crosses its expiry thresholdMedium
Stale Check-in Population GrowingTenant Stale Check-in Count (>7d) increasesLow

Did this page help you?