Iru Inspector Summary
Summary
| Property | Value |
|---|---|
| Production Status | Preview |
| Category | Apps & Services |
| Discovers | One child launchpoint per managed Apple device in the tenant |
Description
Monitors an Iru (formerly Kandji) Apple device management tenant — Mac/iOS/iPadOS/tvOS device inventory, FileVault and Supervised status, Blueprint assignments, Library Items, EDR threat events, vulnerability detections, and Apple Business Manager integration state.
Data View Information
Parent Overview Table
- Iru Tenant Summary
- Tenant URL
- Region
- Device Count
- Mac Count
- iPhone Count
- iPad Count
- Apple TV Count
- Blueprint Count
- Library Item Count
- FileVault Enabled Count
- FileVault Disabled Count
- Supervised Count
- Stale Check-in Count (>7d)
- Missing Device Count
- Active Threat Count
- Open Vulnerability Count
- Critical Vulnerability Count
Parent Data Tab Headers
- Overview
- Devices
- Blueprints
- Library Items
- Users
- Threats
- Vulnerabilities
- Apple Business Manager
Child Overview Table
- Device Summary
- Device Name
- Serial Number
- Platform
- Model
- OS Version
- Blueprint
- Assigned User
- FileVault Enabled
- Supervised
- Activation Lock Enabled
- Agent Version
- Last Check-in
Child Data Tab Headers
- Overview
- Library Items
- Hardware
- Network
Metrics
| Metric | Description |
|---|---|
| Iru: Tenant Device Count | Total managed Apple devices in the tenant. |
| Iru: Tenant Mac Count | Managed Macs in the tenant. |
| Iru: Tenant FileVault Disabled Count | Macs with FileVault disabled — encryption-posture gap. |
| Iru: Tenant Supervised Count | Devices in Supervised state. |
| Iru: Tenant Stale Check-in Count (>7d) | Devices with no check-in in more than 7 days. |
| Iru: Tenant Missing Device Count | Devices marked Missing. |
| Iru: Tenant Blueprint Count | Blueprints configured in the tenant. |
| Iru: Tenant Active Threat Count | Active EDR threat events returned this run; 0 when EDR is unlicensed. |
| Iru: Tenant Open Vulnerability Count | Open CVEs across the fleet; 0 when Vulnerability Management is unlicensed. |
| Iru: Tenant Critical Vulnerability Count | Open Critical-severity CVEs across the fleet. |
| Iru: Device FileVault Enabled | Whether FileVault is enabled on this device. |
| Iru: Device Supervised | Whether this device is Supervised. |
| Iru: Device Activation Lock Enabled | Whether Activation Lock is enabled on this device. |
| Iru: Device Agent Version | Iru agent version on this device. |
| Iru: Device OS Version | OS version reported by this device. |
| Iru: Device Last Check-in | Last check-in timestamp for this device. |
Actionable Alerts
| Rule | Trigger | Severity |
|---|---|---|
| FileVault Disabled on a Mac | Tenant FileVault Disabled Count increases | High |
| New Active Threat Detected | Active Threat Count increases | High |
| New Critical Vulnerability | Critical Vulnerability Count increases | High |
| Iru Agent Removed or Downgraded | Child agent is uninstalled, or Agent Version lowers | High |
| Device Supervision Lost | Child Supervised changes true → false | High |
| Device Marked Missing | Tenant Missing Device Count increases | Medium |
| Activation Lock Disabled | Child Activation Lock Enabled changes true → false | Medium |
| Device Blueprint Reassigned | Child Blueprint changes | Medium |
| ADE Token Expiring or Expired | Any Apple Business Manager token crosses its expiry threshold | Medium |
| Stale Check-in Population Growing | Tenant Stale Check-in Count (>7d) increases | Low |
Updated about 4 hours ago
Did this page help you?

