# Actions Management Source: https://docs.iru.com/en/compliance/actions-management Create, assign, and track compliance actions in Iru. Link controls to evidence, set deadlines, and monitor completion status across frameworks. The **Actions** page lists the work that turns each control into something you can assign, track, and prove. Every action states what to do, who owns it, when it is due, and how evidence should attach, including when a **Source** should fetch it for you. On the left navigation bar, expand **Compliance** and select **Actions**. Who can view, create, or change actions is set by role. See [Compliance Permissions](/en/compliance/compliance-permissions). Left navigation: Compliance expanded, Actions selected Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## How It Works Iru creates actions from your frameworks’ controls (from AI setup, CSV, or migration). You can add or edit actions when something is missing. **Action descriptions** drive automation. When a description names a system and the type of evidence you need (for example "SSO policy from Okta"), integrations can pull the right artifacts from **Sources** and reduce manual uploads. If you connect or remove a **Source**, or publish or retire a policy artifact, Iru AI may recommend new control or action wording so descriptions still match your environment. Publish and update policies in [Policies Management](/en/compliance/policies-management). You approve those edits in [Adaptive Compliance](/en/compliance/adaptive-compliance); unapproved items stay as they are. ## Capabilities ### Create and Edit Actions * Actions are generated from framework controls. * Only **Admin** and **Compliance Admin** can manually **create** an action. **Update** and **delete** are available to **Admin**, **Compliance Admin**, **Standard**, **Compliance Collaborator**, **Help Desk**, and **Secrets Auditor**; **Auditor**, **Compliance Auditor**, and **Iru Support** cannot change actions. See the **Actions** table in [Compliance Permissions](/en/compliance/compliance-permissions). ### Descriptions and Automation * The description tells the product what to collect and, when applicable, which **Source** to use. * Example: control “All employees must use MFA” → action “Collect MFA enforcement policy from identity provider” with a description that points at **Okta**, **Microsoft Entra ID**, or another connected system. Spell out which system and what artifact you need in the description. Vague text makes automation and audits harder. ### Assign, Comment, and Track * Owners complete the task and upload or confirm artifacts. * Assign an **owner** or **delegate** so responsibility is clear. * Use **comments** for questions, handoffs, or auditor notes. * The **activity log** records assignments, uploads, comments, and status changes. Compliance action events also appear on the tenant-wide [Unified Activity](/en/iru/platform-overview/unified-activity). ### Status and Validation * Actions move through statuses such as **Not Started**, **In Progress**, and **Completed** as evidence lands and validation passes (labels can vary slightly by screen). * When required artifacts are in place and valid, readiness for the related control updates. ### Automated Collection If a **Source** is on and the action description matches that system and evidence type, the product may attach artifacts without a manual upload. If nothing appears, check that the source is **Active**, the description is specific, and the integration has the right permissions. See [Sources Management](/en/compliance/sources-management). ## Related Articles Recommended order for profile, frameworks, sources, and actions. Policy library, publishing, and attaching policies to actions as evidence. Review Iru AI updates to control and action text after integrations or policies change. Connector guides by category and how evidence is collected. Uploads, validation, and linking evidence to actions. # Adaptive Compliance Source: https://docs.iru.com/en/compliance/adaptive-compliance Review and approve Iru AI recommendations that update compliance control and action wording when connected Sources or policy artifacts change. When your **Sources** or policy **artifacts** change, control and action text can fall out of step with how you actually operate. **Adaptive Compliance** is Iru AI monitoring those changes and proposing updates to control and action wording. You review each recommendation in a side-by-side diff and approve only what you want applied. Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## How It Works Iru AI runs on a daily schedule and reviews changes to connected **Sources** (new connections, removed integrations, configuration updates) and policy **artifacts** (published, edited, or retired). It compares that activity to the controls and actions in each framework and creates a **Control Update** recommendation when wording should change to match how you operate. Recommendations usually appear within 24 hours of the triggering activity. Nothing in your frameworks changes until you approve it. You review each recommendation in a side-by-side diff, choose which changes to include, and confirm. Approved updates apply to the control or action text you selected; rejected or unchecked items stay as they are. ## Capabilities #### Where Recommendations Appear The same recommendation can open from any of these entry points: When a recommendation is pending, an **Insights** card appears at the top of **Home** (select **Home** in the left navigation bar). The card summarizes the framework and how many controls Iru AI suggests updating. Select **Review Control Updates** to open the review panel. Home page Insights cards recommending framework control updates with Review Control Updates buttons On the left navigation bar, expand **Compliance** and select **Frameworks**. Frameworks with pending recommendations show an Iru AI indicator on the card. Select **Review Control Updates** on the card to open the review panel. Frameworks page showing ISO 42001 and SOC 2 cards with Review Control Updates buttons On a framework’s detail page, use **Review Control Updates** in the page header (next to the framework name and audit details). SOC 2 framework detail showing readiness progress and controls with Review Control Updates #### Review and Approve Control Updates From **Home** → **Insights**, **Frameworks**, or a framework detail page, select **Review Control Updates**. The header summarizes the recommendation. On the right: * **Reject all**: dismiss every proposed change in this recommendation * **Approve all (N)**: apply every checked change Control update review panel showing side-by-side diffs and Approve all and Reject all actions Each control with proposed changes appears as its own section: * **Current text** (left): existing control or action wording * **Proposed text** (right): suggested wording, with additions and removals highlighted **Control Action Updates** listed under a control have their own diffs when action text would change. Each proposed change has a checkbox. All are checked by default. * Leave a box checked to include that change when you approve * Clear a box to keep the existing text for that control or action * Use **All recommended updates** to select or clear everything at once * **Approve all (N)**: applies every checked change. The recommendation is removed from **Insights** and the framework. * **Reject all**: dismisses the full recommendation, including unchecked items. Iru AI may surface a new recommendation later if signals continue. If you close the panel without approving or rejecting, the recommendation stays on **Insights** and the framework until an **Admin** or **Compliance Admin** acts on it. ## Considerations Iru AI does not edit controls on its own. You must select **Approve** (or approve individual checked items) for text to change. Only control and action **text** updates. Framework configuration (including **audit period** and auditor details), evidence attachments, and readiness calculations tied to completed actions are outside this workflow. Today, recommendations react to **Source** and policy artifact changes (see [Policies Management](/en/compliance/policies-management)); more signal types may be added in later releases. You cannot edit Iru AI’s proposed wording in the review panel in this release. If a suggestion is close but not right, clear that checkbox, approve the rest, then edit the control or action directly on the framework. See [Frameworks Management](/en/compliance/frameworks-management). Approving or rejecting recommendations requires **Admin** or **Compliance Admin** access in Compliance (see [Compliance Permissions](/en/compliance/compliance-permissions)). Other roles may see that a recommendation exists but cannot approve or reject it. Approvals and rejections are recorded with the acting user. Open the framework’s history to review past control update decisions. **Home** → **Insights** cards for control updates follow the same Iru AI access rules as other insights. Disabling Iru AI for the tenant removes the chat interface and general **Insights**; Compliance features that rely on Iru AI may still run. See [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview). ## Troubleshooting Recommendations run on a daily schedule, so wait up to 24 hours after the change. If nothing appears, confirm the integration or artifact change completed successfully and that your role can view frameworks. If you published or updated a policy, confirm the change in [Policies Management](/en/compliance/policies-management). If integrations and policies have been stable, there may be no signal for Iru AI to act on yet. Only **Admin** or **Compliance Admin** can approve or reject **Control Update** recommendations. Confirm your role on the **Access** page. See [Compliance Permissions](/en/compliance/compliance-permissions). A rejected recommendation does not return on its own. Edit the control or action directly on the framework if you need to restore or adjust text. If drift continues, Iru AI may generate a new recommendation on a later daily run. The recommendation remains on **Home** → **Insights** and on the framework until you or another **Admin** or **Compliance Admin** approves or rejects it. Uncheck specific items before you approve, or edit the control or action after approval on the framework detail page. Inline editing inside the review panel is not available in this release. ## Related Articles Add frameworks, edit controls, and track readiness. Recommended setup order for frameworks, sources, and actions. Connect and remove integrations that can trigger control update recommendations. Policy artifacts and other evidence tied to controls. Create, publish, and update security and compliance policies. Action descriptions that sources and Adaptive Compliance may reference. How frameworks, sources, actions, and evidence connect over time. # Artifacts Management Source: https://docs.iru.com/en/compliance/artifacts-management Upload, organize, and manage compliance artifacts and evidence in Iru. Attach files to actions, validate evidence, and prepare for audits. The **Artifacts** page is the home for compliance evidence: files, exports, and records linked to **actions** and **controls**. Use it to upload proof, review what **Sources** attached, and filter the list when you prepare for an audit. On the left navigation bar, expand **Compliance** and select **Artifacts**. Left navigation: Compliance expanded, Artifacts selected Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## Where Evidence Comes from * **Manual uploads**: Policies (create and publish them in [Policies Management](/en/compliance/policies-management), or upload them as artifacts from **Artifacts**), screenshots, signed attestations, spreadsheets, PDFs, and similar files from **Artifacts** or an action or control when the UI offers an upload. * **Connected sources**: Integrations that attach artifacts when **action** descriptions and source permissions allow. See [Sources Management](/en/compliance/sources-management). * **Validation**: Where supported, the product checks that an artifact fits the linked control or action before it counts toward readiness. Common examples include **policies and procedures**, **configuration exports**, **logs and reports**, **training completion records**, and **screenshots**. One artifact can support multiple controls when it satisfies more than one requirement. Publishing, editing, or retiring policy artifacts is one of the signals Iru AI uses for [Adaptive Compliance](/en/compliance/adaptive-compliance), alongside changes to connected **Sources**. Create and publish policies in [Policies Management](/en/compliance/policies-management); uploaded policy files also appear as artifacts. Recommendations update control and action text only after an admin approves them in the review panel. On **Artifacts**, use **Search by artifact name or filename** and the **Type**, **Source**, and **Category** filters. Use **Manage categories** and **Columns** when you need different grouping or table columns. ## How It Works Use **Artifacts** to see evidence across frameworks in one list, open files for preview where supported, and confirm which **controls** and **actions** each item supports. New uploads may show a short notice while the file is processed; the row appears when it is ready. When Iru can check that the artifact fits the linked requirement, validation runs. Failed checks include a short reason so you can replace or supplement the file. Manual uploads and connector-supplied files can sit on the same action. Use whichever path matches where the evidence lives. ## Capabilities ### Adding Artifacts * From **Artifacts**, choose **+ Add artifact(s)** (or **+ Add artifact** when the list is empty). You can also start from an **Action** or **Control** detail page when the product links uploads there. * In **Artifact Details**, drag and drop a file or select **attach a file**, then choose **Add artifact** (or **Cancel** to close without saving). * If an artifact is expected from an integration, it may appear automatically when the source is **Active** and the action text is specific enough. Each upload must be **50MB** or smaller. If a file exceeds the limit, the modal shows an error naming the file and the maximum size; split or compress the file and try again. ### Validation When an artifact is added, the platform can automatically check: * **Relevance** to the linked control or action. Artifacts that pass are marked **Valid**. Those that fail are flagged with an explanation (for example wrong file type, outdated, or incomplete). ### Linking to Controls and Actions * Each artifact attaches to the action or control it supports. * Users can view mappings from the artifact detail panel. * One artifact may support multiple controls when it satisfies more than one requirement. ### Managing Existing Artifacts Users can **open any artifact** to: * Change the **title** or **description** for clarity. * **Preview** attached documents without downloading. * See which **controls** and **actions** the artifact supports. ## Related Articles How artifacts fit with frameworks, actions, and sources. Create, publish, and track acknowledgements for security and compliance policies. Control update recommendations when policy artifacts or sources change. Assign work and attach evidence to actions. Connect systems that auto-collect artifacts mapped to actions. # Compliance Permissions Source: https://docs.iru.com/en/compliance/compliance-permissions Configure role-based access controls for Iru Compliance. Assign permissions to team members for frameworks, actions, evidence, and Trust Center. ### About Compliance Roles Iru Compliance uses role-based access control. The [permissions overview](#permissions-overview) spells out what each role can open or change: search, actions, frameworks (controls and control-linked evidence), artifacts, sources, policies, Trust Center, and related areas. Behavior varies by role. In the tables, **Compliance Admin**, **Compliance Collaborator**, and **Compliance Auditor** sit next to **Admin**, **Standard**, and **Auditor** so you can compare Compliance-only assignments to the same permission pattern. Users with **Read activity logs** can review compliance and tenant activity on the [Unified Activity](/en/iru/platform-overview/unified-activity). Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ### Access Levels #### Admin Full access to all compliance functionality, including framework management, settings configuration, and administrative controls. #### Standard Most of the same permissions as **Admin**, with limits on framework and settings management. #### Help Desk Operational access for day-to-day compliance work, including managing actions, artifacts, and evidence collection. #### Secrets Auditor Read-only access with the ability to generate automated artifacts and assess artifact relevance. #### Auditor Read-only access for audit and review. In the **Frameworks** matrix, **Auditor** does not have **View controls** (the control definitions in a framework) but does have **View control action** and **View control artifact**, so reviewers can still follow actions and evidence tied to controls without editing control definitions. See the matrix for the full list. #### Iru Support Read-only access to support customer issues and troubleshooting. ### Compliance-Only Roles These roles apply **only** within Iru Compliance. The **Compliance Admin**, **Compliance Collaborator**, and **Compliance Auditor** columns match **Admin**, **Standard**, and **Auditor**; they do not grant access outside the Compliance area. For tenant-wide roles across Endpoint, Identity, and the rest of the platform, see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). #### Compliance Admin Administrator-level access in Iru Compliance only. Matches the **Admin** column in the [permissions overview](#permissions-overview). This is not tenant-wide **Administrator** access across products. #### Compliance Collaborator Matches the **Standard** column for team members whose access is limited to Iru Compliance. #### Compliance Auditor Matches the **Auditor** column for team members whose access is limited to Iru Compliance. Under **Frameworks**, **Compliance Auditor** behaves like **Auditor**: no **View controls**, with **View control action** and **View control artifact** for reviews. #### Compliance Employee Access limited to acknowledging company policies. This role has its own view in Compliance and does not include Iru AI access. See [Iru AI](#iru-ai). ### Permissions Overview #### General | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ---------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Search | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | #### Actions | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | -------------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | View list | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | View action details | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Create | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Update | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Delete | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Upload artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Delete artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Generate automated artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Generate automated artifact bulk | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Assess artifact relevance | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Read comments | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Create comment | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Update comment | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Delete comment | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Read activity logs | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | #### Frameworks | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ------------------------ | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | List frameworks | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | View framework details | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | View framework readiness | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Add frameworks | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Remove frameworks | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | View controls | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Add controls | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Edit control | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Remove controls | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | View control action | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Add control action | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Edit control actions | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Remove control action | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | View control artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Upload control artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Remove control artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | #### Artifacts | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ---------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | View list of artifacts | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | View artifact details | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Edit artifact details | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Upload artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Replace file | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Remove artifact | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | #### Sources | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | -------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | View list of sources | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Connect source | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | Disconnect source | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | #### Policies Use **Compliance → Policies** to create, publish, and track acknowledgements for security and compliance policies. See [Policies Management](/en/compliance/policies-management) for the library, template generation, editor, and workforce acknowledgement flows. | Capability | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ----------------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | View published policies | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Create and edit policies | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | | Publish and delete policies | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Manage policy owners and categories | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | View acknowledgements (admin tab) | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ❌ | **Standard** and **Compliance Collaborator** can create and edit draft policies but cannot publish or delete them, and cannot manage tenant-level policy settings such as owners and categories. **Auditor** and **Compliance Auditor** can view published policies and acknowledgement progress but cannot change policy content. Workforce users are not Compliance administrators. When a policy is published, every user in the tenant sees assignments in **My Policies** and can acknowledge policies assigned to them. That portal is separate from the Compliance **Policies** admin view. #### Trust Center: Editor | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | --------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Read settings | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Create settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Update settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Upload logo | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Remove logo | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Upload NDA | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Remove NDA | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Read certifications | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Upload certification icon | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete custom certification | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | #### Trust Center: Answers | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ----------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Read answers | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Update answers | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete answers | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Read answers category | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Create answers category | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Update answers category | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete answers category | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | #### Trust Center: Artifacts | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | ------------------------ | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Read document category | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Update document category | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete document category | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | #### Trust Center: Accounts | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | --------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Read accounts | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Read pending accounts | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Get signed NDA download URL | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Approve account | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete account | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | #### Trust Center: Questionnaires | Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support | | -------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- | | Read questionnaire list | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Read questionnaire details | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Update questionnaire | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Add questionnaire | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | | Delete questionnaire | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | #### Iru AI Compliance-only roles reach the Compliance and Trust Center agents only. They do not have endpoint, vulnerability, or EDR entitlement, so Iru AI does not answer questions about the device fleet for these roles. For tenant-wide roles (Owner, Admin, Standard, and others), see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). | Permission | Compliance Admin | Compliance Collaborator | Compliance Auditor | Compliance Employee | | ----------------------------------------- | ---------------- | ----------------------- | ------------------ | ------------------- | | Access Iru AI | ✅ | ✅ | ✅ | ❌ | | Documentation & Support Q\&A | ✅ | ✅ | ✅ | ❌ | | Compliance Agent | ✅ | ✅ | Limited | ❌ | | Trust Center Agent | ✅ | ✅ | ✅ | ❌ | | Endpoint Management / Vulnerability / EDR | ❌ | ❌ | ❌ | ❌ | | Recommendations | ❌ | ❌ | ❌ | ❌ | | Execute Iru AI Actions | ❌ | ❌ | ❌ | ❌ | | Audit event history | ❌ | ❌ | ❌ | ❌ | **Limited (Compliance Auditor):** The Compliance agent runs, but control definitions are withheld. Linked actions and artifacts are still available. This matches **Auditor** and **Compliance Auditor** under **Frameworks** (**View controls** is off). **Compliance Admin** and **Compliance Collaborator** receive full Compliance and Trust Center answers, including control definitions. Audit event history is not available through Iru AI to any compliance role. For how agents work and how to enable Iru AI for the organization, see [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview). ### Common Permission Issues Use this section when a control is missing or a button has no effect. Only **Admin** or **Compliance Admin** can add or remove frameworks. **Standard**, **Compliance Collaborator**, and **Help Desk** cannot. The **Frameworks** matrix sets **View controls** to off for **Auditor** and **Compliance Auditor**, while **View control action** and **View control artifact** stay on so reviewers can follow actions and evidence without editing control definitions. This is expected. Only **Admin** or **Compliance Admin** can edit existing controls. Other roles may add controls or edit control actions only where the **Frameworks** matrix allows. Iru AI **Control Update** recommendations (from **Home** → **Insights**, **Frameworks**, or a framework detail page) require permission to approve or reject proposed control and action text. View-only roles may see that a recommendation exists but cannot act on it. See [Adaptive Compliance](/en/compliance/adaptive-compliance) for the review workflow and who can approve changes in your tenant. **Auditor**, **Compliance Auditor**, and **Iru Support** cannot manage sources. Use **Admin**, **Compliance Admin**, **Standard**, **Compliance Collaborator**, or **Help Desk** as listed under **Sources**. **Auditor** and **Compliance Auditor** are read-only for uploads. Use **Admin**, **Compliance Admin**, **Standard**, **Compliance Collaborator**, **Help Desk**, or **Secrets Auditor** as allowed in the **Actions** table. Only **Admin** or **Compliance Admin** can publish or delete policies and manage policy owners and categories. **Standard** and **Compliance Collaborator** can create and edit drafts. See the **Policies** table and [Policies Management](/en/compliance/policies-management). Trust Center **Editor**, **Answers**, and **Questionnaires** changes are **Admin** or **Compliance Admin** only unless the matrix shows otherwise. If controls or actions look wrong for your access level, open the **Access** page to confirm your role ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). ## Related Articles Core concepts and what you can do in Compliance. Policy library, publishing, and acknowledgements. Who can add or change frameworks by role. Approving or rejecting Iru AI control and action updates. External sharing and Trust Center permissions. How Iru AI agents work and how to enable Iru AI for the organization. Tenant-wide roles in Iru (alongside the Compliance roles on this page). # Frameworks Management Source: https://docs.iru.com/en/compliance/frameworks-management Add, configure, and manage compliance frameworks in Iru. Map controls to actions, track progress, and maintain audit-ready documentation. The **Frameworks** page is where you pick the standards your organization tracks, such as **SOC 2**, **ISO 27001**, **ISO 42001**, **HIPAA**, and others your tenant lists. Use **Add framework** and **Select your \[framework] starting point** to generate, import, or build **controls**. **Actions** and evidence collection follow. You can also import from another tool or upload a CSV when you migrate. Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## How It Works Pick a standard (or a custom framework), then generate tailored controls from your **organization profile**, import controls, or build them manually. Iru maps what you define to the framework’s requirements. You can run built-in standards side by side with custom frameworks when you need internal policies that are not in the catalog. When your integrations or policy artifacts change, Iru AI may surface **Control Update** recommendations on framework cards, on the framework detail page, or in **Home** → **Insights**. Publish and update policies in [Policies Management](/en/compliance/policies-management). You review side-by-side diffs and approve what to apply; nothing changes until you confirm. See [Adaptive Compliance](/en/compliance/adaptive-compliance). ## Capabilities #### Add a Framework On the left navigation bar, expand **Compliance** and select **Frameworks**. Left navigation: Compliance expanded, Frameworks selected The main area is titled **Frameworks**. Use **+ Add framework** (top right) when you are ready to add a program (next step). Each framework already in scope appears as a **card** with the framework **name**, a short **description**, **Select audit period** for the audit window, **artifacts mapped**, and how **controls** roll up. For **SOC 2**, the card can show counts by **Trust Services Criteria** (**Security**, **Availability**, **Confidentiality**, **Processing integrity**, **Privacy**); other frameworks may show a single **controls** total and progress. **View controls** opens that framework’s detail work. The **…** (**More**) menu on a card lists **Additional actions**: **Edit audit details** and **Delete framework**. Frameworks page showing Add framework, framework cards, audit period, controls, and actions menu Click **Add framework** to open the **Add a new framework** modal. In **Add a new framework**, pick from **Active** frameworks you can add now. Additional frameworks may appear under **Coming soon** until they are available for your tenant. After you choose a framework, **Select your \[framework] starting point** opens. The title includes the framework you picked (for example **Select your ISO 27001 starting point**). Pick how to build your control set: * **Iru AI**: **Generate tailored controls** (labeled **Recommended**). Answer questions about your company, goals, and context so Iru generates controls. * **Migrate**: **Migrate from Vanta** (and similar options when your tenant lists them). Import controls you already maintain in Vanta. * **Manual**: **Use a generic control framework**, **Upload pre-filled CSV**, or **Start from scratch**. Click **Back** to return and pick a different framework or path. #### Tailor with AI When you choose **Generate tailored controls** in **Select your \[framework] starting point**, work through the prompts (company profile, goals, stack, and other questions Iru asks for that framework). Iru then generates **tailored controls** and actions mapped to the framework’s requirements. #### Import Frameworks or Controls Use this section when you pick **Upload pre-filled CSV**, **Migrate from Vanta**, or **Use a generic control framework** in **Select your \[framework] starting point**, or when you open **Frameworks** → **Import** and your tenant lists additional providers (for example **Drata**, **Secureframe**, or **Sprinto**). * Imported data is normalized to align with Iru mappings where the integration supports it. * **Upload pre-filled CSV:** Download the CSV template, fill it out, and upload; you can add, edit, or delete controls afterward. * **Migrate from another tool:** Requires an API key from the source product where applicable: * **Vanta:** [Vanta API access](https://developer.vanta.com/docs/api-access-setup) * **Drata:** [Drata public API](https://help.drata.com/en/articles/6695964-drata-public-api) * **Secureframe**, **Sprinto:** Use **Frameworks** → **Import** when your tenant lists these providers. **Migration behavior (high level)** * **SOC 2:** Migrations from supported vendors typically bring across requirements and internal controls in a form that maps to Iru’s structure. * **ISO 27001 and ISO 42001:** Behavior depends on the source: * **Vanta:** Full migration of requirements and controls is supported. * **Drata, Secureframe, Sprinto:** ISO imports are often limited because those products model ISO controls differently than Iru (for example one control per requirement). Importing ISO wholesale can produce a rigid control set that does not match Iru’s tailored controls. If you are moving **ISO** from **Drata**, **Secureframe**, or **Sprinto**, choose **Use a generic control framework** in **Select your \[framework] starting point** instead of importing ISO controls directly when you want Iru to generate a tailored set from your organization profile. You can still reference existing documentation outside the import. To add a fully **custom framework** (internal policies or standards not in the catalog), use **Add framework** and the path your tenant provides for custom programs, or define controls manually after you create the framework record. #### Manage Frameworks After you open a framework from the list (**View controls**), you can: * See **Readiness** and overall progress for that framework * Choose **Export** or **Add a control** in the page header * See the full **list of controls** generated or imported * Search and filter **All controls** (for example by **Status**) while controls finish generating * **Customize controls** (edit, add, or remove based on company context) * View the **specific framework requirements** each control is mapped to * See the **list of actions** attached to each control * Review **artifacts** that are linked to actions and controls * **Track readiness** across all controls within the framework in one place * Open **Review Control Updates** from the framework header or card when Iru AI has pending control and action text recommendations (same workflow as **Home** → **Insights**). See [Adaptive Compliance](/en/compliance/adaptive-compliance). ## Related Articles Frameworks, actions, artifacts, and sources. Policy library, publishing, and acknowledgements. Approve or reject Iru AI control and action updates after integrations or policies change. Connector guides by category and how evidence is collected. How evidence ties to controls and actions. # Getting Started with Compliance Source: https://docs.iru.com/en/compliance/getting-started-with-compliance Get started with Iru Compliance: frameworks, controls, actions, evidence, sources, and Trust Center. Follow the recommended setup order and core concepts. Iru Compliance helps you run frameworks such as **SOC 2** or **ISO 27001**, collect evidence against controls, and publish a **Trust Center** for customers and auditors when your subscription includes it. Follow **Recommended setup** below: complete **Organization profile**, add frameworks, connect **Sources**, and work **Actions**. For who can add frameworks, connect integrations, edit Trust Center, and other tasks, see [Compliance Permissions](/en/compliance/compliance-permissions). Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## About Iru Compliance You can add standards such as **SOC 2**, **ISO 27001**, **ISO 42001**, and **HIPAA** in your tenant. Other catalogs (for example **GDPR**, **NIST CSF**) appear when your tenant makes them available. Open **Frameworks** to see what you can add. Iru uses your **organization profile** (industry, company size, tech stack, and security tooling) so generated **controls** match how you work. After setup, when connected **Sources** or policy **artifacts** change, [Adaptive Compliance](/en/compliance/adaptive-compliance) can propose updates to control and action text so your frameworks stay aligned with how you operate. Use [Policies Management](/en/compliance/policies-management) to draft, publish, and track acknowledgement of security and compliance policies. **Trust Center** is optional: it publishes approved certifications and documents externally. See [Trust Center Management](/en/compliance/trust-center/trust-center-management). ## Recommended Setup In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Select **Organization** to open **Organization profile**. Iru may prompt you while you add a framework. Account menu with Organization option highlighted On **Organization profile**, click **Edit** at the top right. Fill in the fields that apply. For example: **company logo**, **company name**, **business description**, **industry**, **business type**, **company size**, **company language**, whether you have an **IT department**, and **security team size**. Keep this information current as your environment changes. Click **Save changes**. On the left navigation bar, expand **Compliance** and select **Frameworks**. Use AI-assisted setup, CSV import, migration from a supported product, or a custom framework. See [Frameworks Management](/en/compliance/frameworks-management). Expand **Compliance** and select **Sources**. Turn on the **toggle** for each integration that should supply evidence (identity, HR, cloud, code hosts, and others). See [Sources Management](/en/compliance/sources-management). Expand **Compliance** and select **Actions**. Review **actions**, assign owners, set due dates, and attach or confirm evidence. See [Actions Management](/en/compliance/actions-management). ## Core Concepts **Frameworks**\ Standards your organization tracks. You can run several at once; one piece of evidence can cover more than one obligation when requirements overlap. **Controls**\ Requirements mapped to the framework. They may come from AI generation, import, or manual entry. **Actions**\ Tasks linked to controls. Descriptions tell the product and connected **Sources** what evidence to collect. **Artifacts**\ Files and records (policies, exports, screenshots, logs, reports) tied to actions and controls. See [Artifacts Management](/en/compliance/artifacts-management). For the **Policies** module (library templates, drafts, publishing, and workforce acknowledgement), see [Policies Management](/en/compliance/policies-management). **Sources**\ Integrations that pull or attach evidence for the actions they support. See [Sources Management](/en/compliance/sources-management). ## What You Can Do Next * Turn framework language into controls and actions with owners and due dates. * Draft and publish security policies from the library or uploads; track workforce acknowledgement. See [Policies Management](/en/compliance/policies-management). * Gather evidence manually or through **Sources**; validate artifacts where the product supports it. * Track readiness from framework and action views. * Review Iru AI control update recommendations when integrations or policies change. See [Adaptive Compliance](/en/compliance/adaptive-compliance). * Publish selected content through **Trust Center** when your plan includes it. ## Related Articles Add frameworks, imports, and migrations. Policy library, publishing, acknowledgements, and linking policies to actions. Review and approve Iru AI recommendations when controls should reflect new integrations or policies. How profile, frameworks, sources, actions, and evidence connect. Connector guides by category (use search and **Category** on **Sources**). ## Related Product Documentation How Endpoint, Identity, Compliance, Trust Center, and Iru AI fit together. Endpoint setup from foundation through platform setup, Blueprints and Library, and enrollment; pair with the Iru Endpoint Compliance source when controls need device evidence. Connect Endpoint to Compliance for device evidence. Organization roles (alongside Compliance Permissions). # Platform Workflows Source: https://docs.iru.com/en/compliance/platform-workflows How frameworks, controls, actions, and evidence fit together in Iru Compliance: setup, assignments, sources, readiness, and audit-ready reporting. These workflows show how **frameworks**, **controls**, **actions**, and **artifacts** connect in Iru Compliance, from choosing a standard through evidence collection and readiness. Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## How It Works You select frameworks, refine controls and actions, attach evidence (manually or from **Sources**), and track readiness in framework and action views. Integrations can attach evidence automatically when they are connected and **action** descriptions name the system and evidence type clearly. As integrations and policy artifacts change, [Adaptive Compliance](/en/compliance/adaptive-compliance) can propose updates to control and action text. Publish and update policies in [Policies Management](/en/compliance/policies-management). You review each recommendation and approve only the changes you want; audit periods and uploaded evidence are not changed by that workflow. ## Core Workflow: From Framework to Compliance #### Framework Setup In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu) (same flow as **Recommended setup** in [Getting Started With Compliance](/en/compliance/getting-started-with-compliance)). Select **Organization** to open **Organization profile**. Iru may also prompt for this during framework setup. Account menu with Organization option highlighted On **Organization profile**, click **Edit** at the top right. Fill in the fields that apply. For example: **company logo**, **company name**, **business description**, **industry**, **business type**, **company size**, **company language**, whether you have an **IT department**, and **security team size**. Keep this information current as your environment changes. Click **Save changes**. On the left navigation bar, expand **Compliance** and select **Frameworks**. Left navigation: Compliance expanded, Frameworks selected Click **Add framework**, choose a standard, then complete **Select your \[framework] starting point** (generate, migrate, CSV, or manual). See [Frameworks Management](/en/compliance/frameworks-management). Frameworks page with Add framework, framework cards, audit period, and controls Review and edit generated or imported controls and actions as needed. #### Control Management Open each framework and review generated or imported controls. Edit wording, add controls, or remove items so they match how your organization operates. When **Sources** or policy artifacts change later, check **Home** → **Insights** or **Review Control Updates** on a framework for Iru AI recommendations. Update policies in [Policies Management](/en/compliance/policies-management). See [Adaptive Compliance](/en/compliance/adaptive-compliance). Confirm each control still maps to the right framework requirement and that owners and evidence expectations are clear. #### Action Execution Assign actions to owners and set due dates. Owners read the action text and confirm what evidence is required. Upload artifacts or let connected **Sources** attach them when descriptions and permissions allow. Use comments and delegation when work needs to move between people. Watch status and deadlines on the **Actions** views and framework readiness. #### Evidence Management Add files from **Artifacts** or from an action or control when the UI offers an upload. Connect **Sources** so integrations can attach artifacts when action text and permissions align. Let validation run where the product supports it, then confirm artifacts sit on the right actions and controls. Before an audit window, spot-check that required evidence is present and current. #### Readiness Assessment Use framework and action views to see what is still open. Fix missing actions, weak evidence, or failed validation before you report readiness. Export or summarize status for stakeholders using the reports your tenant provides. ## Integration Workflows #### Automated Evidence Collection Expand **Compliance**, select **Sources**, and turn on the **toggle** for each integration. See [Sources Management](/en/compliance/sources-management) for connector guides. Left navigation: Compliance expanded, Sources selected In each action, name the system and evidence type so connectors know what to fetch (see [Actions Management](/en/compliance/actions-management)). Sources refresh on a schedule; status and last sync appear on each source card. New, updated, or removed connections can prompt control update recommendations within about a day. See [Adaptive Compliance](/en/compliance/adaptive-compliance). Review attached artifacts and validation results on the action or control. #### Manual Evidence Upload Pick policies, exports, screenshots, or other files that satisfy the action or control. Create policies in [Policies Management](/en/compliance/policies-management) or upload files from **Artifacts**. Add titles and descriptions when prompted, then upload (see [Artifacts Management](/en/compliance/artifacts-management)). Address any failed validation or replace files that are out of date. ## Collaboration Workflows #### Team Coordination Give actions to owners; reassign or delegate when responsibility shifts. Use comments for questions and the activity log to see what changed. For a tenant-wide view of compliance activity, see [Unified Activity](/en/iru/platform-overview/unified-activity). Track due dates and notifications so work does not stall. #### Audit Preparation Confirm each required control has supporting artifacts in Iru. Upload missing files, fix failed validation, or adjust actions before the audit. Export or hand off bundles your auditor expects (reports, folders, or Trust Center links, depending on your process). ## Related Articles Recommended setup order. Policy library, publishing, and acknowledgements. Uploads, validation, and linking evidence to actions. Assign work and attach evidence to actions. Review control and action updates after source or policy changes. # Policies Management Source: https://docs.iru.com/en/compliance/policies-management Create, publish, and track security and compliance policies in Iru with the policy library, template generation, drafts, and workforce acknowledgements. The **Policies** page is where admins create, publish, and track acknowledgements for security and compliance policies. On the left navigation bar, expand **Compliance** and select **Policies**. Left navigation: Compliance expanded, Policies selected Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## Policies Management The **Policies** module manages your organization's security and compliance policy documents from draft through publication and workforce acknowledgement. You can add a policy from the **Policy Library** (templates aligned to common frameworks), generate a first draft with **Iru AI** from a template using your organization profile and setup form, or upload an existing PDF or DOCX. Drafts stay editable until you publish. When you publish, the policy is assigned to every user in your tenant for acknowledgement. Policies connect to your compliance program through **Actions**. Attach a published or uploaded policy to an Action to use it as framework evidence. See [How policies relate to frameworks](#how-policies-relate-to-frameworks). Admins work on **Compliance → Policies** (**My policies** and **Users** tabs). Workforce users read and acknowledge assigned policies from **My assigned policies**, separate from the admin view. See [Policy Acknowledgements](#policy-acknowledgements). Who can create, publish, or view policies depends on role. See [Compliance Permissions](/en/compliance/compliance-permissions). ### The Policies page Open **Policies** from the left navigation. The page has two tabs: * **My policies**: every policy in your organization, grouped by category. * **Users**: acknowledgement progress by person. See [Policy Acknowledgements](#policy-acknowledgements). The category sidebar filters policies by the same nine categories shown in the library: Governance & Risk, Access Control & Identity, Data Protection & Privacy, Security Operations, Vendor & Third-Party, Infrastructure & Network, Software Development, People & Workforce, and Business Continuity. Use **Search by policy name or filename...** to find a policy by name. ### Policy status Every policy is either **Draft** or **Published**. | Status | What it means | | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Draft** | Work in progress. Editable, deletable, not visible to your workforce. | | **Published** | Live. Auto-assigned to every user in your tenant and available for acknowledgement. Published policies may display as **Sent to recipients** on the **My policies** list. | Use the **Audit log** on the policy detail page to see who changed the policy and when. ### What happens when you publish When you click **Publish**, three things happen: The policy status flips to Published. The current content becomes the canonical, citable version. The policy is auto-assigned to every user in your tenant. Each user sees it under **Assigned** in **My assigned policies** until they acknowledge it. A publish event is written to the audit log, recording who published and when. Users see the new assignment the next time they open **My assigned policies**. Acknowledgement counts on the policy detail page and **My policies** cards update immediately (for example, 2 of 85 acknowledged). Users added to your tenant after a policy is published are not automatically back-assigned to existing policies. To bring them in, publish the policy again the next time you make a change. ### Ways to add a policy You can add a policy from the library, by uploading a file, or from **Artifacts**. Each path starts in a different place in the UI: | Path | When to use it | Entry point | | -------------------------- | ------------------------------------------------------------ | ------------------------------------------------------------------------------ | | **Generate from template** | You want Iru to draft policy content from a library template | Policies → **+ Add a policy** → hover template card → **Use this template** | | **Upload policy** | You already have the policy written as a PDF or DOCX | Policies → **+ Add a policy** → hover template card → **Upload policy** | | **Upload a custom policy** | Your document doesn't match any library template | Policies → **+ Add a policy** → **+ Start custom policy** (bottom of the page) | | **Upload from Artifacts** | You are adding a policy while uploading other evidence | Artifacts → **+ Add artifact(s)** | #### Complete the setup form and generate Before you can generate a policy from a template: * **Organization Profile** must be filled in. Iru uses it to pre-populate the setup form. If required fields are missing, you'll be prompted to complete them before generation starts. * You need permission to create and edit draft policies. See [Compliance Permissions](/en/compliance/compliance-permissions). ### Generate from template The Policy Library has pre-built templates for topics common in SOC 2, ISO 27001, GDPR, HIPAA, CIS, and other frameworks. From **Policies → My policies**, click **+ Add a policy** in the top-right. The library opens in place of the policy list. The category sidebar filters templates: **All**, Governance & Risk, Access Control & Identity, Data Protection & Privacy, Security Operations, Vendor & Third-Party, Infrastructure & Network, Software Development, People & Workforce, and Business Continuity. Use **Search by policy template name...** to find a template by name (for example, "Incident Response" or "Encryption"). Each template card shows the policy name, a short description, framework labels, and **In use** or **Not used**. Hover over a card to see **Use this template** and **Upload policy**: * Framework labels, for example, SOC 2 • ISO 27001. They show which frameworks the template was written for. They don't link your policy to those frameworks. Attach the published policy to Actions after publishing. * **In use** or **Not used**: whether your organization already has a policy from this template. Iru doesn't block duplicates; **In use** means a policy from this template already exists. Open **Policies → + Add a policy**, find the template you want in the library, hover over it, and click **Use this template**. In **Policy settings**, confirm or update the fields for this template. Toggle **Optional sections to include in generation** if you want extra sections in the draft. Review **Policy type settings** and **All policies settings**. Change anything that doesn't match your org. Click **Generate policy**. Click **Load all**, or use **Load next section** and **Finish** after the last section loads. Review the draft, edit as needed (see [Edit a generated draft](#edit-a-generated-draft)), then click **Publish**. #### About the generated draft | It does | It does not | | ----------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | | Assemble a structured first draft from your profile data and setup inputs. | Publish automatically. Generated policies stay in Draft until you click **Publish**. | | Tag each paragraph with the input that produced it. | Map the policy to framework controls automatically. Attach to Actions after publishing. | | Keep generation inputs on the draft so you can re-generate with different settings. | Generate content outside the template library. Use [Upload a custom policy](#upload-a-custom-policy) for that. | #### Edit a generated draft After you load every section, review the draft before you publish. Check that roles and tooling match your org and that the exception process reflects your defaults. The policy detail page shows **Generating policy...** until sections are ready. The **Generation inputs** card lists the setup form answers used for this draft. Use the up and down arrows at the top right to move between policies without returning to **My policies**. You can edit a generated draft in two ways: **Inline intake swaps.** Spans from your setup form selections (scope, classification, owner, review frequency, and similar fields) appear with a gradient highlight. Hover or click a highlighted span to open a popover where you can swap to a different option from the same intake field (e.g. Quarterly → Annual) or see which intake field the text came from (e.g. "Review frequency"). Each swap is recorded to the policy's audit log. **Free-text editing.** Click anywhere in a paragraph, heading, or list item and start typing. Editing a highlighted span removes the gradient. Once you've rewritten generated text in your own words, it becomes regular body text. Free-text edits are recorded to the audit log. After the first section loads, a toolbar appears above the editor: | Control | What it does | | --------------------------------- | ----------------------------------------------- | | **H1, H2, H3** | Apply heading levels. | | **Bold, Italic, Strikethrough** | Inline text styles. | | **Bulleted list / Numbered list** | Convert the current block to a list. | | **Undo / Redo** | Step backward or forward through your edits. | | **Zoom** | Shrink or enlarge the document preview (− / +). | When your cursor is in a paragraph or heading, an insert button appears in the left margin next to the block. Click it to add a paragraph, heading, or list below the current block. Drafts auto-save as you edit. When every section is loaded and the draft is ready, click **Publish**. See [What happens when you publish](#what-happens-when-you-publish). ### Upload policy Use this path when your policy is already written and saved as a PDF or DOCX. You upload the finished file; Iru does not generate content from the template. Pick a template card in the same category as your document so Iru files the policy under the right topic. Open **Policies → + Add a policy**. Hover over a template card in the same category as your policy and click **Upload policy**. In the upload panel, set **Artifact type** to **Policy**, choose **Policy type** if needed, review **Mapped action(s)**, then click **Add policy**. The upload creates a **Draft** policy (see [Policy status](#policy-status)). The file opens as a read-only preview on the policy detail page. To change the content later, edit the source file in your authoring tool, then add a new policy with the updated file. You cannot re-upload on an existing record. When the new version is ready, **Unpublish policy** or **Delete upload** on the original. ### Upload a custom policy Use this path when your document doesn't match any library template. A custom policy is a policy you upload that isn't based on a Policy Library template. You can still file it under any policy category (or **Custom**). At the bottom of **Add a policy**, below the template categories, is an **Upload a custom policy** tile. Click **+ Start custom policy** to open the upload panel. The result is a policy with category **Custom** unless you choose another category on the policy detail page. The upload creates a **Draft** policy. It appears in both places at once: * **Artifacts tab**: filterable by Type = Policy. * **Policies → My policies**: shows the policy with category **Custom** (or whichever category you chose). If you didn't pick one of the nine sidebar categories, use **All** or search to find it. Edits in either view update the same record. **Category**: editable from the policy detail page while the policy is in Draft. Admins can pick any category or move it back to Custom. The dropdown is hidden once the policy is Published. **Type**: changeable from the Artifacts tab after upload: * Demoting to another type (Procedure, Register, Other) removes the Policy record and hides it from the Policies tab. * Promoting a non-policy artifact to a policy is only allowed if the file is a PDF or DOCX. Other formats must be replaced first. To update the file, edit it locally, upload it as a new policy, then **Unpublish policy** or **Delete upload** on the original. ### Upload from Artifacts From **Artifacts**, click **+ Add artifact(s)**, attach a PDF or DOCX, and set **Artifact type** to **Policy**. Choose **Policy type** (any library category or **Custom**), review **Mapped action(s)**, then click **Add artifact**. * **Pick a category**: the policy is filed under that category. * **Leave it blank or pick Custom**: Iru files the policy under the Custom category. The upload creates a **Draft** policy and appears on **Policies → My policies** and the **Artifacts** tab, the same as [Upload a custom policy](#upload-a-custom-policy). See [Artifacts Management](/en/compliance/artifacts-management) for general artifact uploads. ### The policy detail page Open any policy from **My policies**. At the top of the page you'll see the policy name, status (**Draft** or **Published**), category, description, and badges for attached Actions. Change the category while the policy is still in **Draft**; click a badge to open that Action. **Publish** appears on drafts. Open the **ellipsis** (⋯) menu for draft actions: **Delete** on a generated draft, **Delete upload** on an uploaded or custom draft. On a published policy, choose **Unpublish generated policy** or **Unpublish policy** to return it to draft. The up and down arrows move to the previous or next policy in the list without returning to **My policies**. The policy document sits below that header. Uploaded PDFs and DOCX files open as read-only previews. Policies generated from a template open in the editor; see [Edit a generated draft](#edit-a-generated-draft). On the right, **Policy lifecycle** tracks generation or draft status, then acknowledgement progress after publish (for example, 2 of 85 acknowledged). **Owner** shows who maintains the policy. **Audit log** records who changed the policy and when. On generated drafts, the **Generation inputs** card shows the setup form answers used to create the policy. ### How policies relate to frameworks A policy isn't linked to a framework directly. The link runs through Actions: Policy → attached to → Action → belongs to → Control → belongs to → Framework For a policy to count toward a framework, attach it to one or more Actions in that framework. Attached policies show up as evidence on each Action's detail page. Those Actions appear as badges on the policy detail page. #### How attachments get created Iru creates these attachments in two ways: * **Automatically, on upload.** When you upload a file as a policy (from **Artifacts**, **Upload policy** on a template card in the library, or **Upload a custom policy**), Iru matches the file against Actions in your active frameworks and attaches it where it fits. Review attachments on the upload panel or policy detail page; remove any that don't apply or add more manually. * **Manually, at any time.** From any Action's detail page, attach an existing policy (or other artifact) as evidence. Use this for Actions Iru missed, or for policies that weren't uploaded through Iru. Generated policies don't auto-attach to Actions when you publish yet. Attach them manually from each Action's detail page after publishing. Auto-attach for generated policies is expected to follow. #### Where frameworks show up * In the Policy Library, each template card shows "SOC 2 • ISO 27001" or similar. That's catalog metadata. It describes which frameworks the template was written for, not a link to your active frameworks. * In the setup form, the **Compliance frameworks** step shapes generated content (for example, GDPR-specific clauses when GDPR is selected) and saves a snapshot on the draft. It doesn't link the published policy to those frameworks. * On the policy detail page, the framework link is the row of Action badges. Each badge shows an attached Action and its framework. ### Deleting a policy Deleting a policy is permanent. Open the **ellipsis** (⋯) menu and choose **Delete** on a generated draft or **Delete upload** on an uploaded or custom draft. That removes the file, the policy record, and any audit history for that artifact. There's no undo. To revert a published policy to draft, open the **ellipsis** (⋯) menu and choose **Unpublish generated policy** or **Unpublish policy**. ## Policy Acknowledgements When you publish a policy, Iru assigns it to every user in your tenant and records who acknowledges it and when. Track progress on **Policies → Users** and on each published policy's detail page. ### The Users tab Every published policy is assigned to **every user in your tenant** when you publish. There's no per-policy recipient picker. Users added to your tenant after a policy is published are not automatically back-assigned. To bring them in, publish the policy again the next time you make a change. Open **Policies → Users** (the second tab). The table lists each user with acknowledgement progress: | Column | What's in it | | ---------------- | ------------------------------------------------------------------------ | | **Name** | User display name. | | **Email** | User email address. | | **Acknowledged** | Ratio of acknowledged policies to assigned policies (for example, 0/10). | | **Policies** | Color-coded chips for each assigned policy. | Use **Search by name or email** to filter the table. Two dropdown filters sit next to the search bar: * **Role**: filter by tenant role (**Admin**, **Auditor**, **Collaborator**, or **Employee**). Open the dropdown, select one or more roles, and use **Clear** to reset the filter. * **Policy**: filter to users assigned a specific policy. Open the dropdown, search or select one or more policies by name, and use **Clear** to reset the filter. You can combine search, role, and policy filters. Click **Export** to download a CSV of the current filtered list: * **Export by user**: one row per user. Columns include **Name**, **Email**, **Acknowledged**, **Total assigned**, and one column per assigned policy. A policy column shows the acknowledgement date when the user has acknowledged that policy; it is blank otherwise. * **Export by policy**: one row per policy. Columns include **Policy**, **Total users assigned**, **Total users acknowledged**, and **Acknowledged users** (name and email of each user who acknowledged). The **Acknowledged** column shows how many assigned policies each user has completed (N / total). The acknowledgement summary also appears on each published policy's detail page, in the **Lifecycle** card on the right sidebar (for example, 7 of 10 acknowledged). Click **My assigned policies →** in the top-right of **Policies** to preview the workforce view. Click **← Back to admin view** to return. ### My assigned policies When a policy is assigned to you, it appears here the next time you open the view. Open **My assigned policies** from the **Policies** page (**My assigned policies →**) or from your workforce navigation entry point, if your tenant exposes one. | Group | What's in it | | ---------------- | ------------------------------------------------ | | **All** | Every policy assigned to you, in any state. | | **Assigned** | Policies you still need to read and acknowledge. | | **Acknowledged** | Policies you've already signed off on. | #### Acknowledging a policy Click an assigned policy to open it. Read the full document. The Acknowledge button is disabled until you've scrolled to the end. Click Acknowledge. The policy moves to your Acknowledged group and Iru records the timestamp. If multiple policies are waiting, Iru takes you to the next one automatically after each acknowledgement. ## Related Articles Who can create, publish, and view policies by role. Upload custom policies and other evidence from the Artifacts tab. Attach published policies to Actions as framework evidence. Active frameworks that Actions and controls belong to. Recommended setup order for Compliance. # Sources Management Source: https://docs.iru.com/en/compliance/sources-management Manage Iru Compliance evidence sources: connector setup, authentication, troubleshooting, and enabling or removing integrations under Compliance Sources. **Sources** connect Iru Compliance to systems you already use, such as identity, code hosts, monitoring, HR, cloud, and more. After a source is **Active**, Iru can **discover and attach artifacts** to the actions and controls they support, which keeps evidence tied to your frameworks and reduces manual uploads. Iru records each source connection or disconnection on the [Unified Activity](/en/iru/platform-overview/unified-activity). To see how Compliance fits with Endpoint and Identity, read [Iru Overview](/en/iru/platform-overview/iru-overview). On the left navigation bar, expand **Compliance** and select **Sources**. Turn on the **toggle** on a source’s card, then complete authentication in the wizard (OAuth, API keys, bearer tokens, or vendor-specific steps). When an action names a system and evidence type, automation can use that mapping to decide what to collect. Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## Sources Page Once you are on **Sources** (same sidebar path as above), **Refresh all evidence** is at the **top right**. Use it to refresh evidence from your connected sources. Use **Search by name or description** and the **Category** dropdown to narrow the list. **Amazon Web Services** connectors appear under **Amazon sources** inside each relevant category (**Security**, **Developer tools**, **Databases**, **Monitoring**, or **Storage**). Each **Amazon sources** row scrolls horizontally. Use the **arrow** controls to see every card. ## How It Works Each connector article covers **authentication**, **in-product steps** (including the Iru connector wizard where applicable), **troubleshooting**, and **vendor documentation** links. Read the article for your system before you turn the source **on** in **Sources**. ## Connector Articles The sidebar **Compliance → Sources** tree follows the same **Category** labels as Iru (**Analytics**, **Cloud infrastructure**, **Communications**, **CRM**, **Databases**, **Developer tools**, **HRIS**, **Marketing**, **Monitoring**, **Productivity**, **Project management**, **Security**, **Storage**, **Support**), with **Amazon sources** nested where the product groups AWS connectors. Browse sources by theme below (accordion sections mirror connector families such as **Amazon Web Services** for documentation). Expand a section to see **Integration** links to full guides and **What it covers** summaries. In Iru, expand **Compliance**, open **Sources**, and use each card’s **toggle**; your tenant controls which connectors are listed. | Integration | What it covers | | ------------------------------------------------------ | -------------------------------------------------------------------------------------------------- | | [Databricks](/en/compliance/sources/databricks-source) | Users, groups, workspace permissions, cluster settings, and secret scope ACLs (not secret values). | | [Fivetran](/en/compliance/sources/fivetran-source) | Connectors and pipeline metadata for data-movement governance. | | [Segment](/en/compliance/sources/segment-source) | Sources, destinations, and workspace settings for customer-data pipelines. | | Integration | What it covers | | -------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | | [Google Cloud Platform](/en/compliance/sources/google-cloud-sources) | Service account and JSON key for BigQuery, IAM, KMS, Logging, Storage, and Compute Engine evidence. | | Integration | What it covers | | -------------------------------------------------------- | -------------------------------------------------------------------------------- | | [Aircall](/en/compliance/sources/aircall-source) | Voice and messaging platform metadata for communications controls. | | [RingCentral](/en/compliance/sources/ringcentral-source) | Voice, messaging, and account configuration for communications controls. | | [Slack](/en/compliance/sources/slack-source) | Workspace membership, channels, and app integrations for collaboration controls. | | Integration | What it covers | | ------------------------------------------------------ | ------------------------------------------------------------------------------- | | [Attio](/en/compliance/sources/attio-source) | CRM records and workspace structure for customer-data controls. | | [Freshsales](/en/compliance/sources/freshsales-source) | Users, roles, territories, and field-level permissions for CRM access controls. | | [WordPress](/en/compliance/sources/wordpress-source) | Users, roles, and REST-accessible site metadata for CMS controls. | #### Amazon Sources | Integration | What it covers | | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | | [Amazon Redshift Data API](/en/compliance/sources/amazon-redshift-data-api-source) | Data API usage and SQL-layer inventory for Redshift governance. | | [Amazon Redshift Serverless](/en/compliance/sources/amazon-redshift-serverless-source) | Serverless workgroups, namespaces, and related configuration. | | [AWS DynamoDB](/en/compliance/sources/amazon-dynamodb-source) | Tables, indexes, and backup settings (configuration and inventory, not item data). | | [AWS RDS](/en/compliance/sources/amazon-relational-database-service-rds-source) | DB instances, Aurora clusters, snapshots, and encryption settings (no query data). | | [AWS Redshift](/en/compliance/sources/amazon-redshift-source) | Provisioned clusters, subnet groups, snapshots, and encryption posture. | #### Other Integrations | Integration | What it covers | | ---------------------------------------------------- | --------------------------------------------------------------------------------- | | [Snowflake](/en/compliance/sources/snowflake-source) | ACCOUNT\_USAGE metadata, roles, and warehouses via read APIs (not arbitrary SQL). | #### Amazon Sources | Integration | What it covers | | ----------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- | | [AWS CodeCommit](/en/compliance/sources/aws-codecommit-source) | Git repositories, branches, and pull-request settings for change management. | | [AWS Elastic Kubernetes Service (EKS)](/en/compliance/sources/amazon-elastic-kubernetes-service-eks-source) | Clusters, node groups, and Kubernetes inventory for container security. | | [AWS Elastic Compute Cloud (EC2)](/en/compliance/sources/amazon-elastic-compute-cloud-ec2-source) | Instances, security groups, VPC layout, and AMI metadata. | | [AWS Elastic Container Service (ECS)](/en/compliance/sources/amazon-elastic-container-service-ecs-source) | Services, tasks, and cluster configuration for container compliance. | | [AWS Elastic Load Balancing (ELB)](/en/compliance/sources/elastic-load-balancing-elb-source) | Listeners, rules, target groups, and health checks for ingress controls. | | [AWS Lambda](/en/compliance/sources/aws-lambda-source) | Functions, triggers, and IAM attachments for serverless governance. | | [AWS Organizations](/en/compliance/sources/aws-organizations-source) | Accounts, OUs, roots, and SCP evidence for landing-zone controls. | | [AWS Auto Scaling](/en/compliance/sources/aws-auto-scaling-source) | Scaling groups, policies, and capacity evidence across compute. | #### Microsoft Azure | Integration | What it covers | | -------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ | | [Microsoft Azure Authorization](/en/compliance/sources/microsoft-azure-authorization-source) | Role assignments and RBAC policy administration for resources and resource groups. | | [Microsoft Azure Key Vault](/en/compliance/sources/microsoft-azure-key-vault-source) | Key Vault inventory and access policies via the management API (not secret values). | | [Microsoft Azure Monitor](/en/compliance/sources/microsoft-azure-monitor-source) | Diagnostic settings and export of resource logs and metrics to supported destinations. | | [Microsoft Azure Network](/en/compliance/sources/microsoft-azure-network-source) | Virtual networks, subnets, interfaces, public IPs, NSGs, load balancers, VPN gateways, and related networking resources. | | [Microsoft Azure Storage](/en/compliance/sources/microsoft-azure-storage-source) | Storage accounts and configuration within an Azure subscription. | #### Other Integrations | Integration | What it covers | | ------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------- | | [Bitbucket](/en/compliance/sources/bitbucket-cloud-source) | Repositories, branch policies, and workspace access for code governance. | | [Contentful](/en/compliance/sources/contentful-source) | Content models, entries, and roles for CMS access controls. | | [DigitalOcean](/en/compliance/sources/digitalocean-source) | Droplets, Kubernetes, databases, and networking inventory where enabled. | | [Doppler](/en/compliance/sources/doppler-source) | Projects and sync metadata for secrets governance (not secret values). | | [Drupal](/en/compliance/sources/drupal-source) | JSON:API users, roles, and content metadata for web CMS controls. | | [Figma](/en/compliance/sources/figma-source) | Projects, files, org membership, and OAuth-scoped design-system evidence. | | [GitHub](/en/compliance/sources/github-source) | Orgs, repos, branch protection, teams, and audit-oriented settings. | | [GitLab](/en/compliance/sources/gitlab-source) | Groups, projects, CI/CD configuration, and membership for DevOps controls. | | [Heroku](/en/compliance/sources/heroku-source) | Apps, pipelines, collaborators, and add-ons for PaaS evidence. | | [Jenkins](/en/compliance/sources/jenkins-source) | Jobs, plugins, and CI configuration for build and deployment controls. | | [Microsoft Azure DevOps](/en/compliance/sources/microsoft-azure-devops-source) | Projects, repos, branch policies, pull requests, pipelines, permissions, and organization audit activity via Microsoft Entra ID OAuth. | | [OpenAI](/en/compliance/sources/openai-source) | Org and project metadata for AI usage and access governance. | | [PagerDuty](/en/compliance/sources/pagerduty-source) | Services, incidents, schedules, and escalation evidence for incident response. | | [Postman](/en/compliance/sources/postman-source) | Workspaces, collections, and API governance surfaces exposed by API. | | Integration | What it covers | | -------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | | [BambooHR](/en/compliance/sources/bamboohr-source) | Employee records and HR workflows for workforce compliance evidence. | | [Checkr](/en/compliance/sources/checkr-source) | Background screening status and employment verification records. | | [Deel](/en/compliance/sources/deel-source) | Worker roster, org structure, and time-off records for onboarding and offboarding evidence. | | [HiBob](/en/compliance/sources/hibob-source) | Employee roster, lifecycle events, and org structure via a service user. | | [Lattice](/en/compliance/sources/lattice-source) | Reviews, goals, and HR program metadata tied to people compliance. | | [Sage HR](/en/compliance/sources/sage-hr-source) | HR employee and absence metadata available via API for workforce evidence. | | [Workable](/en/compliance/sources/workable-source) | Jobs, candidates, and recruiting pipeline metadata for HR compliance. | | [Workday Report](/en/compliance/sources/workday-report-source) | Custom HR reports via Workday RaaS for payroll and workforce evidence. | | Integration | What it covers | | ------------------------------------------------ | ---------------------------------------------------------------------------- | | [Klaviyo](/en/compliance/sources/klaviyo-source) | Account users, API key inventory with scopes, and list and segment metadata. | #### Amazon Sources | Integration | What it covers | | ----------------------------------------------------------------- | ----------------------------------------------------------------------- | | [AWS CloudWatch](/en/compliance/sources/amazon-cloudwatch-source) | Metrics, alarms, and monitoring configuration for operational controls. | #### Other Integrations | Integration | What it covers | | ------------------------------------------------ | ------------------------------------------------------------------------------ | | [Datadog](/en/compliance/sources/datadog-source) | Monitors, users, integrations, and security-related configuration via API. | | [Sentry](/en/compliance/sources/sentry-source) | Projects, releases, and error-tracking configuration for application security. | | Integration | What it covers | | ------------------------------------------------------------ | --------------------------------------------------------------------------------- | | [Confluence](/en/compliance/sources/confluence-cloud-source) | Spaces, pages, and Atlassian access for documentation governance. | | [Docusign](/en/compliance/sources/docusign-source) | Envelopes, recipients, and audit metadata for e-signature controls. | | [Envoy](/en/compliance/sources/envoy-source) | Workplace visitors and location settings where applicable to physical security. | | [Notion](/en/compliance/sources/notion-source) | Pages, databases, users, and workspace structure for knowledge governance. | | [Reach 360](/en/compliance/sources/reach-360-source) | Training enrollments, completions, content, and groups from Articulate Reach 360. | | Integration | What it covers | | ------------------------------------------------------ | ------------------------------------------------------------------------------------- | | [Aha!](/en/compliance/sources/aha-ideas-source) | Roadmaps, ideas, and workspace metadata for product governance evidence. | | [Asana](/en/compliance/sources/asana-source) | Workspaces, projects, and tasks for access and collaboration reviews. | | [ClickUp](/en/compliance/sources/clickup-source) | Workspaces, lists, tasks, and members for operational evidence. | | [Jira](/en/compliance/sources/jira-source) | Projects, issues, workflows, and service-management evidence. | | [Shortcut](/en/compliance/sources/shortcut-source) | Stories, epics, and workflow metadata for engineering governance. | | [Smartsheet](/en/compliance/sources/smartsheet-source) | Users, licenses, sheet sharing permissions, and workspace membership (not cell data). | | [Trello](/en/compliance/sources/trello-source) | Boards, lists, cards, and members for lightweight project evidence. | | Integration | What it covers | | ------------------------------------------------------------- | -------------------------------------------------------------------------- | | [Iru Endpoint](/en/compliance/sources/iru-endpoint-source) | Device enrollment, posture, and endpoint inventory from Iru Endpoint. | | [1Password](/en/compliance/sources/1password-business-source) | Audit and access events from your password manager (Events Reporting API). | #### Amazon Sources | Integration | What it covers | | ---------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ | | [Amazon Inspector](/en/compliance/sources/amazon-inspector-source) | EC2 and container vulnerability and assessment findings. | | [AWS CloudTrail](/en/compliance/sources/aws-cloudtrail-source) | Management events and trail configuration for API audit evidence. | | [AWS Config](/en/compliance/sources/aws-config-source) | Resource inventory, rules, and configuration timeline per Region. | | [AWS GuardDuty](/en/compliance/sources/amazon-guardduty-source) | Threat-detection findings and detector configuration. | | [AWS IAM](/en/compliance/sources/aws-identity-and-access-management-iam-source) | Users, roles, policies, MFA, and credential reports for access reviews. | | [AWS IAM Identity Center (Identity Store)](/en/compliance/sources/aws-iam-identity-center-identity-store-source) | Directory users, groups, and memberships (`identitystore:` APIs). | | [AWS IAM Identity Center (SSO)](/en/compliance/sources/aws-iam-identity-center-sso-source) | Permission sets, assignments, and SSO applications (`sso:` APIs). | | [AWS Key Management Service (KMS)](/en/compliance/sources/aws-key-management-service-kms-source) | CMK metadata, rotation settings, and key policy evidence (not cleartext keys). | | [AWS Secrets Manager](/en/compliance/sources/aws-secrets-manager-source) | Secret rotation metadata and inventory (not secret values). | | [AWS Security Hub](/en/compliance/sources/aws-security-hub-source) | Aggregated controls and findings across integrated AWS security services. | #### Other Integrations | Integration | What it covers | | ---------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | | [Arnica](/en/compliance/sources/arnica-source) | Secret-detection findings, repository inventory, developer risk, and security policy status. | | [Cloudflare](/en/compliance/sources/cloudflare-source) | DNS, WAF, and edge security configuration for perimeter controls. | | [HashiCorp Vault](/en/compliance/sources/hashicorp-vault-source) | Policies, mounts, and metadata for secrets-engine governance (not secret payloads). | | [JumpCloud](/en/compliance/sources/jumpcloud-source) | Directory, SSO, MDM, and device inventory for unified identity evidence. | | [KnowBe4](/en/compliance/sources/knowbe4-source) | Training campaigns and phishing simulation completion records. | | [Okta](/en/compliance/sources/okta-source) | Users, groups, MFA, apps, and SSO policies for identity evidence. | | [Semgrep](/en/compliance/sources/semgrep-source) | Static analysis findings, projects, and policies from Semgrep Cloud. | #### Amazon Sources | Integration | What it covers | | ---------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | | [AWS Elastic File System (Amazon EFS)](/en/compliance/sources/amazon-elastic-file-system-efs-source) | File systems, mounts, and encryption posture for shared storage. | | [AWS S3](/en/compliance/sources/amazon-simple-storage-service-s3-source) | Bucket policies, encryption, logging, and public-access blocks (not object bodies). | #### Other Integrations | Integration | What it covers | | ---------------------------------------- | ----------------------------------------------------------- | | [Box](/en/compliance/sources/box-source) | Enterprise content, folders, and collaboration permissions. | | Integration | What it covers | | ---------------------------------------------------------- | ---------------------------------------------------------------------------- | | [Freshservice](/en/compliance/sources/freshservice-source) | Tickets, changes, incidents, CMDB assets, and agent roles for ITSM evidence. | | [Intercom](/en/compliance/sources/intercom-source) | Workspace apps, conversations metadata, and admin surfaces exposed by API. | ## Enable a Source On the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find the source card (use **Search by name or description** or **Category** if you need to narrow the list). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard (OAuth, API key, IAM role, or other prompts depending on the integration). Complete the wizard until the card shows **Active**. See the connector article for your system if you need field-level detail. If nothing opens when you turn the **toggle** on, check **pop-up blocker** settings for the Iru site and try again. ## Disable or Remove a Source When a source is already **Active**, click its **toggle** again. Iru prompts you to confirm that you want to **remove** that source. Select **Yes, remove** to disable the integration and turn the source off. Select **Cancel** to dismiss the prompt and leave the source **Active**. Connecting, updating, or removing a source is one of the signals Iru AI uses for [Adaptive Compliance](/en/compliance/adaptive-compliance). Within about a day, you may see a **Control Update** recommendation on **Home** → **Insights**, on the **Frameworks** list, or on a framework’s detail page. These recommendations keep control and action text aligned with how you collect evidence. If expected artifacts do not appear after the source is **Active**, confirm your **actions** describe which evidence should come from that system and that the connected account has the **scopes** or permissions the connector needs. ## Related Articles Frameworks, actions, and artifacts. Review control and action updates after source or policy changes. Create, publish, and track security and compliance policies. Uploads, validation, and organizing evidence. # 1Password Business Source: https://docs.iru.com/en/compliance/sources/1password-business-source Connect 1Password Business to Iru Compliance with a JWT bearer token to collect sign-in attempts, item usage, and audit events as evidence. ### About 1Password Business The **1Password** connector reads audit and access events from your **1Password Business** account and surfaces them in Iru Compliance as artifacts you can attach to actions and controls. The integration uses 1Password’s **Events Reporting API** and is **read-only**. Iru does not change vaults, items, or users in 1Password. ### How It Works Iru authenticates with a **bearer token** (JWT-SA) that you issue in the 1Password admin experience. Events are read from the **events** hostname that matches your account region (US, EU, CA, Enterprise, and so on). Sign-in attempts, item usage, and audit events can all feed compliance evidence when your token includes those event types. | Detail | Value | | ------------------ | ------------------------------------------------------------------------------------------------------- | | **Category** | Security | | **Authentication** | Bearer token (JWT-SA) | | **1Password plan** | Business (Events Reporting requires Business; Teams and individual plans do not include the Events API) | For setup steps on the 1Password side, see [Get started with 1Password Events Reporting](https://support.1password.com/events-reporting/) and the [Events API](https://developer.1password.com/docs/events-api/) in 1Password’s developer documentation. ### Prerequisites * A **1Password Business** subscription. * A user who is an **Owner**, **Administrator**, or a member of a group with **View Administrative Sidebar**. * A few minutes to create the integration, issue a token, and complete the Iru connector. ### Connect 1Password to Iru Configure Events Reporting and the token in **1Password Business**, then use **Complete the connector in Iru** for **Iru Compliance**. #### Create an Events Reporting integration Sign in at [1Password.com](https://1password.com) with an administrator who can manage **Integrations** and **Events Reporting**. In the sidebar, select **Integrations**. Find the **Events Reporting** section (sometimes under **Reporting** or **Security**, depending on 1Password UI updates). Select **Add integration** (or **Connect**). Pick your SIEM category if it is listed; otherwise choose **Other** so you can point events at Iru’s collector model. Enter a clear name (for example **Iru Compliance**) so operators can distinguish this integration from other SIEM or webhook destinations. Select **Add integration** (or **Save**) to create the integration record. You will issue the bearer token in the next section. #### Issue the bearer token On the integration page, begin configuring the new token. Enter a **token name** you will recognize (for example **Iru production**). Set **expiration** up to **180 days** (the maximum allowed). Enable **Sign-in attempts**, **Item usages**, and **Audit events**. All three are needed for full coverage in Iru. Select **Issue token**, then copy the JWT. It is shown **once**; store it in your vault and treat it like any other secret. #### Complete the connector in Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **1Password** (set **Category** to **Security** or use **Search by name or description**). On that card, turn on the **toggle**. A new browser tab opens the connector approval flow (`connect/approve?link=…`). Pick the host that matches where your 1Password account sends Events API traffic: | Option | URL | | -------------------- | ---------------------------------- | | 1Password Enterprise | `https://events.ent.1password.com` | | 1Password (default) | `https://events.1password.com` | | 1Password CA | `https://events.1password.ca` | | 1Password EU | `https://events.1password.eu` | Select **Confirm server**. You should see confirmation that the server was saved. In the connector wizard (opened from Iru), paste the JWT into the **Token** field when prompted and submit. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **1Password** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. The token expired or was revoked. Issue a new token in 1Password and submit it again in the connector. Confirm the token includes **all three** event types. A token limited to sign-ins only will not return item-usage or audit evidence. Turn the source off on **Sources**, turn it on again, and select the correct events host before submitting the token. Events Reporting requires **1Password Business**. Other plans do not expose this API. ### Considerations Tokens expire on a schedule (up to **180 days**). Plan rotation before expiry to avoid gaps in evidence collection. Connectivity is **outbound HTTPS** from Iru to your chosen `events.*` host. You do not need to allow inbound access from Iru into 1Password. Iru only **reads** events. It cannot create, edit, or delete 1Password data. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Aha! Ideas Source: https://docs.iru.com/en/compliance/sources/aha-ideas-source Connect Aha! Ideas to Iru Compliance with a Bearer API key and your account subdomain to collect roadmap, release, and idea evidence for audits. ### About Aha! Ideas Iru calls the **Aha! REST API** with **`Authorization: Bearer`** using a **personal API key**. Keys inherit the **creating user’s** product permissions - prefer a **service account** so churn does not break compliance sync. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_KEY ``` | Detail | Value | | ------------------ | ------------------------ | | **Category** | Project management | | **Authentication** | Bearer (account API key) | Host pattern: **`https://YOUR_SUBDOMAIN.aha.io`**. Official references: [API keys](https://secure.aha.io/settings/api_keys) (swap subdomain), [API reference](https://www.aha.io/api). ### Prerequisites * User with access to the **products** you must evidence (often **Owner**, **Administrator**, or **Reviewer**). * Your **`subdomain`** (`acme` from `https://acme.aha.io`). ### Connect Aha! to Iru Complete this tab before you connect the source in Compliance. In Aha!, click your **avatar** (profile menu) in the product chrome. Choose **Settings**, then open the **Personal** section (or equivalent) so you are editing your own account, not only a single product. Select **Developer** (or **Developer settings**), then **API keys** (labels can vary slightly by Aha! edition). Select **Generate API key** (or **Create API key**). Enter a name you will recognize later, such as **Iru Compliance**. Copy the key value **once** when Aha! shows it and store it in your vault. You will paste it into Iru as the **Bearer** token; you typically cannot view the same secret again after you leave the page. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Aha!**](#aha) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Aha!** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Set **`domain`** to the **subdomain only** (for example `acme`), not the full URL. Confirm server variables when the wizard shows a preview. Paste the **Bearer** token when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Aha!** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. User deactivated or key deleted - regenerate from active service account. Wrong **subdomain** string. Issuing user lacks workspace access - adjust Aha! membership or key owner. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Aircall Source: https://docs.iru.com/en/compliance/sources/aircall-source Connect Aircall to Iru Compliance with HTTP Basic auth (api_id and api_token) to collect call activity, user, and team membership evidence. ### About Aircall Aircall is a cloud-based business phone system and call-center platform. The **Aircall** source pulls **call**, **user**, and **team** activity into Iru so you can attach evidence to compliance frameworks. Authentication uses **HTTP Basic** against the **Aircall Public API** (`api_id` as username, `api_token` as password). ### How It Works Iru calls the **Aircall Public API** over HTTPS using **HTTP Basic**: **`api_id`** as the **username** and **`api_token`** as the **password** (see [Basic authentication](https://developer.aircall.io/tutorials/basic-authentication)). | Detail | Value | | ------------------ | ---------------------------------------------------------------- | | **Category** | Communications | | **Authentication** | HTTP Basic (**Username** = `api_id`, **Password** = `api_token`) | | **Vendor plan** | Any **paid** Aircall plan (API access included) | Official references: [Basic authentication](https://developer.aircall.io/tutorials/basic-authentication), [API references](https://developer.aircall.io/api-references/). ### Prerequisites * **Admin** or **Owner** on the Aircall account (standard users cannot create API keys). * About **5 minutes** for setup. * **HTTPS** for Aircall API traffic. * Browser **pop-ups** allowed so the connector wizard can open. ### Connect Aircall to Iru Complete this tab before you connect the source in Compliance. Open the [Aircall Dashboard](https://dashboard.aircall.io) and sign in with an account that has **Admin** or **Owner** rights (only those roles can create API keys). In the left sidebar, select **Integrations & API** (wording may vary slightly by Aircall UI version). Open the **Aircall API** section or the **API Keys** tab, depending on how your workspace labels it. Choose **Add a new API Key** or **Generate an API Key**. Enter a clear name (for example **Iru Compliance**) and confirm so Aircall creates the key pair. Aircall shows **`api_id`** and **`api_token`** together. Copy both to a secure place: you will use **`api_id`** as the **Username** and **`api_token`** as the **Password** in Iru’s **Basic Authentication** step. **`api_token`** appears **only once**. If you lose it, delete this key in Aircall and create a new one, then update Iru with the new values. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Aircall**](#aircall) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Aircall** (set **Category** to **Communications** or use **Search by name or description**). On the **Aircall** card, turn on the **toggle**. A **new browser tab** may open for the wizard. On **Enter Basic Authentication**, put **`api_id`** in **Username** and **`api_token`** in **Password**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Aircall** card is **Active**. ### Considerations * **Account-wide keys:** API keys apply to the **account**, not a single user. The integration can keep working if the person who created the key leaves, unless your team rotates or deletes the key in Aircall. * **Rate limits:** Aircall’s Public API default is **60 requests per minute**. Iru applies **backoff** when limits are hit. Unusually frequent **manual** evidence refreshes could still trigger **429** responses. See troubleshooting. * **Access mode:** Iru uses this connection for **read-oriented** compliance evidence. The **`api_token`** still grants the access level Aircall assigns to that key. **Store and rotate it like a secret**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. The **`api_token`** may be wrong, or the key was **deleted** in Aircall. Create a new API key in Aircall and submit the new **`api_id`** / **`api_token`** in Iru. You hit Aircall’s rate limit (**60 requests per minute** by default). Iru **backs off** automatically. If **429** persists, contact **Aircall support** about a higher limit. Only **Admin** or **Owner** can create keys. Ask an Aircall administrator to create the key, or have your role updated. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon CloudWatch Source: https://docs.iru.com/en/compliance/sources/amazon-cloudwatch-source Connect Amazon CloudWatch to Iru Compliance with a cross-account IAM role to collect metric, alarm, and Logs metadata as monitoring evidence for audits. ### About Amazon CloudWatch This connector spans **CloudWatch metrics/alarms** *and* **CloudWatch Logs**. **`CloudWatchReadOnlyAccess` alone omits Logs** - attach **`CloudWatchLogsReadOnlyAccess`** too, **or** consolidate into one inline JSON covering both **`cloudwatch:`** and **`logs:`** read APIs. ### How It Works Iru runs in its own AWS account. It **assumes a role** in your account (via **`sts:AssumeRole`** and the wizard **External ID**) to read **CloudWatch metrics and alarms** and **CloudWatch Logs**. **`CloudWatchReadOnlyAccess` alone does not include Logs**. Attach **`CloudWatchLogsReadOnlyAccess`** as well, or use one inline policy that covers both **`cloudwatch:`** and **`logs:`** read actions, as on the [**AWS**](#aws) tab. Paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Monitoring | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles**. ### Connect AWS CloudWatch to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS CloudWatch** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS CloudWatch** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Either attach **both** **`CloudWatchReadOnlyAccess`** and **`CloudWatchLogsReadOnlyAccess`**, **or** attach one inline policy: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "cloudwatch:Describe*", "cloudwatch:Get*", "cloudwatch:List*", "logs:Describe*", "logs:Get*", "logs:FilterLogEvents", "logs:List*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. You attached only **`CloudWatchReadOnlyAccess`** - add Logs coverage. External ID mismatch. ### Considerations Querying large log volumes can be expensive, so scope log groups intentionally when possible. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon DynamoDB Source: https://docs.iru.com/en/compliance/sources/amazon-dynamodb-source Connect Amazon DynamoDB to Iru Compliance with a cross-account IAM role to collect table inventory, encryption settings, and control-plane metadata. ### About Amazon DynamoDB The **Amazon DynamoDB** connector inventories **tables**, **capacity settings**, **indexes**, and related resources for compliance mapping. Iru assumes an **IAM role** in your account (**`sts:AssumeRole`** + **external ID**) and does **not** bulk-export item payloads as evidence - focus stays on configuration and inventory APIs. ### How It Works Iru runs in its own AWS account. To read **DynamoDB** table and index metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`dynamodb:`** permissions appropriate for inventory (not bulk item export unless you add those actions). Paste the role’s **ARN** back into Iru. Use **`AmazonDynamoDBReadOnlyAccess`**, or the inline policy below if you want explicit actions (includes **`PartiQLSelect`** / **`Query`** / **`Scan`** read paths present in the managed policy set - align with your security review). | Detail | Value | | ------------------ | ---------------------- | | **Category** | Databases | | **Authentication** | Cross-account IAM role | References: [AmazonDynamoDBReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonDynamoDBReadOnlyAccess.html), [Security and IAM](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/security-iam.html). ### Prerequisites * IAM rights to create **roles** and **inline policies**. * Connector **principal** and **external ID** from Iru. ### Connect AWS DynamoDB to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS DynamoDB** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS DynamoDB** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonDynamoDBReadOnlyAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "dynamodb:BatchGetItem", "dynamodb:Describe*", "dynamodb:Get*", "dynamodb:List*", "dynamodb:Query", "dynamodb:Scan", "dynamodb:PartiQLSelect" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Validate **Trust relationships** against the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID mismatch. Tables live in specific Regions - ensure the role’s account matches asset ownership. Managed policy includes DAX reads; custom policies may need **`dax:Describe*`** / **`dax:List*`**. ### Considerations Global tables and related resources may appear per replica Region. Scope IAM to what audits truly need - narrower policies reduce accidental data-plane reads. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Elastic Compute Cloud (EC2) Source: https://docs.iru.com/en/compliance/sources/amazon-elastic-compute-cloud-ec2-source Connect Amazon EC2 to Iru Compliance with a cross-account IAM role to collect instance inventory, security groups, and VPC network metadata as evidence. ### About Amazon Elastic Compute Cloud (EC2) The **Amazon EC2** connector collects **instance inventory**, **security groups**, **VPC topology**, **AMI metadata**, and related **compute** details from your AWS account so you can attach them to controls in Iru Compliance. Iru calls AWS APIs using **`sts:AssumeRole`** into an **IAM role you create** in your account. The role trusts Iru’s AWS principal and enforces an **external ID** that the connector wizard shows you. Access is **read-only**, so Iru does not start, stop, or terminate instances through this source. ### How It Works Iru runs in **Iru’s AWS account**. You create a **customer-managed IAM role** in **your** account that: 1. **Trusts** Iru’s role ARN (shown in the wizard) only when **`sts:ExternalId`** matches the value Iru displays. 2. **Allows** read-only EC2 and supporting calls, typically via **`AmazonEC2ReadOnlyAccess`**, or a tighter inline policy if your security team prefers least privilege. You copy the role **ARN** back into the connector. Iru then assumes that role and reads regional EC2 data (Iru walks enabled Regions). | Detail | Value | | ------------------ | ------------------------------------------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role (`sts:AssumeRole` + external ID) | References: [AmazonEC2ReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonEC2ReadOnlyAccess.html), [EC2 IAM](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-iam.html). ### Prerequisites * IAM rights to **create roles** and attach policies (for example **`IAMFullAccess`** or a narrower admin role). * The **Iru principal ARN** and **external ID** from **your** tenant’s connector screen (not the sample values in examples below unless they match what Iru shows you today). ### Connect Amazon EC2 to Iru Start here: open the source wizard and review the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Elastic Compute Cloud (EC2)** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard asks for a role ARN and displays the **trust policy** your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role**](#create-the-iam-role)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** into the **Role ARN** field. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **EC2** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role Sign in to the AWS account that owns your EC2 workload. Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter Iru’s AWS account ID (**`753695775620`** unless the wizard shows a different value). Enable **Require external ID** and paste the **external ID** from the Iru wizard. On **Permissions**, attach **`AmazonEC2ReadOnlyAccess`**. If your security team does **not** use the managed policy, attach an **inline policy** with the JSON below instead. The JSON is an **example** least-privilege alternative; tighten or expand actions after your team’s review. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ec2:Describe*", "ec2:Get*", "elasticloadbalancing:Describe*", "cloudwatch:ListMetrics", "cloudwatch:GetMetricStatistics", "cloudwatch:Describe*", "autoscaling:Describe*" ], "Resource": "*" } ] } ``` Finish the wizard and name the role (for example **`IruEC2ReadOnly`**). Open the new role and copy the **Role ARN** from the top of the summary page. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Open the role’s **Trust relationships** tab and confirm the JSON matches what Iru displayed. Typos in the external ID are the most common cause of **`AccessDenied`** on **`AssumeRole`**. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Verify the **external ID** and **principal** on the trust policy match Iru’s wizard character-for-character. Confirm the role lives in the **same account** as your instances and that instances exist in Regions you expect. Ensure `ec2:Describe*` coverage (managed policy already includes these). Custom policies need matching `Describe*` actions. ### Considerations EC2 APIs are **Regional**, so first sync may take longer across many Regions. `AmazonEC2ReadOnlyAccess` also covers related **ELB** and **Auto Scaling** reads for a fuller picture. This integration never mutates instances; it only **describes** them. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Elastic Container Service (ECS) Source: https://docs.iru.com/en/compliance/sources/amazon-elastic-container-service-ecs-source Connect Amazon ECS to Iru Compliance with a cross-account IAM role to collect cluster inventory, task definitions, and service configuration evidence. ### About Amazon Elastic Container Service (ECS) The **Amazon ECS** connector collects **clusters**, **services**, **tasks**, **task definitions**, and **container instance** metadata for compliance evidence. AWS does not ship a single-purpose **ECS read-only** managed policy for this pattern. Use the **`ecs:Describe*`** / **`ecs:List*`** inline JSON below unless your cloud team supplies an equivalent. ### How It Works Iru runs in its own AWS account. To read **Amazon ECS** control-plane metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`ecs:`** permissions. Paste the role’s **ARN** back into Iru. Standard **`sts:AssumeRole`** trust toward Iru plus inline permissions covering ECS control-plane reads. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** and **inline policies**. * At least one **ECS cluster** if you expect immediate non-empty results. ### Connect AWS ECS to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS ECS** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS ECS** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Add this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ecs:Describe*", "ecs:List*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID mismatch. Confirm clusters exist in scanned Regions and the inline policy is actually attached. ### Considerations Covers **ECS APIs**, not workload logs inside tasks - pair with logging sources if audits require runtime proof. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Elastic File System (EFS) Source: https://docs.iru.com/en/compliance/sources/amazon-elastic-file-system-efs-source Connect Amazon EFS to Iru Compliance with a cross-account IAM role to collect file system inventory, encryption status, and mount target metadata. ### About Amazon Elastic File System (EFS) The **Amazon Elastic File System** connector documents **file systems**, **mount targets**, **access points**, and **lifecycle** settings across Regions. Iru assumes an **IAM role** you control (**`sts:AssumeRole`** + **external ID**) and never mounts shares - it only calls AWS control-plane APIs. ### How It Works Iru runs in its own AWS account. To read **Amazon EFS** metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`elasticfilesystem:`** (plus supporting **`ec2:`** / **`cloudwatch:`** where needed). Paste the role’s **ARN** back into Iru. Prefer **`AmazonElasticFileSystemReadOnlyAccess`**, or apply the inline JSON below for tighter **`elasticfilesystem`** reads plus supporting **`ec2:Describe*`** / **`cloudwatch`** calls used when correlating network context. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Storage | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to create roles. * At least one **EFS** file system if you expect non-empty evidence immediately. * Live connector **principal** and **external ID**. ### Connect AWS EFS to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS EFS** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS EFS** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonElasticFileSystemReadOnlyAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "elasticfilesystem:Describe*", "elasticfilesystem:List*", "cloudwatch:DescribeAlarms", "cloudwatch:GetMetricStatistics", "cloudwatch:ListMetrics", "ec2:DescribeVpcs", "ec2:DescribeSubnets", "ec2:DescribeSecurityGroups" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID mismatch. File systems are Regional resources - ensure roles and assets align per Region. ### Considerations Evidence reflects **API-visible configuration**, not file contents. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Elastic Kubernetes Service (EKS) Source: https://docs.iru.com/en/compliance/sources/amazon-elastic-kubernetes-service-eks-source Connect Amazon EKS to Iru Compliance with a cross-account IAM role to collect cluster inventory, node group configuration, and add-on metadata as evidence. ### About Amazon Elastic Kubernetes Service (EKS) The **Amazon EKS** connector gathers **cluster**, **node group**, **add-on**, and **access entry** metadata exposed through the **EKS AWS API** (distinct from Kubernetes RBAC inside the data plane). Authentication is **`sts:AssumeRole`** into a customer role with **`eks:Describe*`** / **`eks:List*`** coverage. ### How It Works Iru runs in its own AWS account. To read **Amazon EKS** cluster and add-on metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only permissions on the **`eks:`**, **`ec2:`**, and related APIs your security team approves. Paste the role’s **ARN** back into Iru. There is no single AWS-managed **“EKS read-only everything”** policy for every API surface - start from the inline JSON below unless your platform team publishes a curated variant. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to manage roles. * At least one **EKS cluster** if you expect immediate inventory. ### Connect AWS EKS to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS EKS** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS EKS** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Add this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "eks:Describe*", "eks:List*" ], "Resource": "*" } ] } ``` Name the role (for example **`IruEKSReadOnly`**), create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID mismatch. New EKS APIs appear frequently - wildcards keep policies forward-compatible; tighten only with testing. ### Considerations This covers **AWS-side** EKS APIs - **pod-level** evidence still belongs to Kubernetes auditing/logging pipelines. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon GuardDuty Source: https://docs.iru.com/en/compliance/sources/amazon-guardduty-source Connect Amazon GuardDuty to Iru Compliance with a cross-account IAM role to collect detector configuration, finding metadata, and threat-intel settings. ### About Amazon GuardDuty The **Amazon GuardDuty** connector collects **detectors**, **findings**, and **member-account** relationships for threat-detection evidence. **GuardDuty must be enabled** per Region - otherwise APIs legitimately return nothing. Authentication uses **`sts:AssumeRole`** into your role (typically in the **administrator** or **delegated admin** account). ### How It Works Iru runs in its own AWS account. To read **GuardDuty** detector and finding metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`guardduty:`** permissions. Paste the role’s **ARN** back into Iru. Use **`AmazonGuardDutyReadOnlyAccess`**, or the **`guardduty:`** inline JSON below. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** where GuardDuty is centrally managed. * **Detectors enabled** in Regions you expect evidence from. ### Connect AWS GuardDuty to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS GuardDuty** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS GuardDuty** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonGuardDutyReadOnlyAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "guardduty:Describe*", "guardduty:Get*", "guardduty:List*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Enable GuardDuty detectors there first. External ID mismatch. ### Considerations Detections can be **cross-account** - align role placement with your org’s delegated-admin pattern. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Inspector Source: https://docs.iru.com/en/compliance/sources/amazon-inspector-source Connect Amazon Inspector v2 to Iru Compliance with a cross-account IAM role to collect vulnerability findings, scan coverage, and assessment metadata. ### About Amazon Inspector **Inspector v2** uses the **`inspector2:`** action namespace (not legacy **`inspector:`**). Enable Inspector in **each Region** where you expect findings. **`AmazonInspector2ReadOnlyAccess`** is the fastest attach; least-privilege mirrors **`List*`**, **`Get*`**, **`Describe*`**, **`BatchGet*`**, and **`Search*`**. ### How It Works Iru runs in its own AWS account. To read **Amazon Inspector v2** data in your account, you create an **IAM role** with a **trust policy** (Iru’s principal and **`sts:AssumeRole`** with the wizard **External ID**) and a **permissions policy** that grants read-only **`inspector2:`** access. The inline body below is a typical least-privilege shape; you can attach **`AmazonInspector2ReadOnlyAccess`** instead if your team allows the managed policy. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "inspector2:List*", "inspector2:Get*", "inspector2:Describe*", "inspector2:BatchGet*", "inspector2:Search*" ], "Resource": "*" } ] } ``` | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * **Inspector v2** activated per Region under review. * IAM rights to **create roles**. ### Connect Amazon Inspector to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Amazon Inspector** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Amazon Inspector** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonInspector2ReadOnlyAccess`**, **or** attach an inline policy matching the JSON under **How it works** above. Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. **Activate** Inspector v2 in that Region (**Account management**). Switch to **`inspector2:`** APIs. Deploy the role in the **delegated administrator** account when Org-wide administration applies. External ID mismatch. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Redshift Data API Source: https://docs.iru.com/en/compliance/sources/amazon-redshift-data-api-source Use a cross-account IAM role so Iru Compliance can read Redshift Data API statement and schema metadata for clusters and serverless workgroups. ### About Amazon Redshift Data API The **Data API** exposes **statement**, **database**, **schema**, and **table** listings without JDBC shells. Iru needs **`redshift-data:`** read actions plus **`redshift:DescribeClusters`** for provisioned clusters and **`redshift-serverless:List*`** helpers when workgroups are in scope. **`AmazonRedshiftDataFullAccess`** is convenient but includes **`ExecuteStatement`**; prefer the **inline** policy below for least privilege. ### How It Works Iru runs in its own AWS account. To call the **Redshift Data API** on your behalf, you create an **IAM role** in your AWS account with two parts: a **trust policy** that allows Iru’s principal to call **`sts:AssumeRole`**, gated by the **External ID** from the wizard, and a **permissions policy** with read-only **`redshift-data:`** actions (plus the supporting **`redshift:`** / **`redshift-serverless:`** calls the connector needs, as in the inline example on the [**AWS**](#aws) tab). You then paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Databases | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** in the account that owns Redshift resources. ### Connect Amazon Redshift Data to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Amazon Redshift Data** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role**](#create-the-iam-role)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Amazon Redshift Data** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach an **inline policy** (recommended over **`AmazonRedshiftDataFullAccess`** for least privilege). The JSON below is an **example** of the permissions shape; adjust if your security team requires fewer actions. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "redshift-data:DescribeStatement", "redshift-data:DescribeTable", "redshift-data:GetStatementResult", "redshift-data:ListDatabases", "redshift-data:ListSchemas", "redshift-data:ListStatements", "redshift-data:ListTables" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "redshift:DescribeClusters", "redshift-serverless:ListNamespaces", "redshift-serverless:ListWorkgroups" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Required when resolving **cluster IDs** - add the **`redshift:`** statement block. Extend with **`redshift-serverless:Get*`** per **[Amazon Redshift Serverless](/en/compliance/sources/amazon-redshift-serverless-source)**. External ID mismatch. ### Related Articles Connect and manage the related source in Compliance. Connect and manage the related source in Compliance. Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. # Amazon Redshift Serverless Source: https://docs.iru.com/en/compliance/sources/amazon-redshift-serverless-source Connect Amazon Redshift Serverless to Iru Compliance with a cross-account IAM role to collect namespace, workgroup, snapshot, and access metadata. ### About Amazon Redshift Serverless **Redshift Serverless** APIs use the **`redshift-serverless:`** prefix, distinct from **`redshift:`** for provisioned clusters. There is **no** dedicated AWS managed **read-only** policy; attach an **inline** policy covering **`List*`** and **`Get*`** for namespaces, workgroups, snapshots, and usage limits. ### How It Works Iru runs in its own AWS account. It **assumes a role** in your account, gated by an **External ID**, to read Redshift Serverless metadata through the API. AWS does not ship a managed read-only policy scoped only to Redshift Serverless, so you attach an **inline** (or equivalent customer-managed) policy. The permission statement usually matches the following: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "redshift-serverless:ListNamespaces", "redshift-serverless:ListWorkgroups", "redshift-serverless:ListSnapshots", "redshift-serverless:ListUsageLimits", "redshift-serverless:GetNamespace", "redshift-serverless:GetWorkgroup", "redshift-serverless:GetSnapshot", "redshift-serverless:GetUsageLimit" ], "Resource": "*" } ] } ``` | Detail | Value | | ------------------ | ---------------------- | | **Category** | Databases | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** in the account hosting **Serverless** workgroups. ### Connect Amazon Redshift Serverless to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Amazon Redshift Serverless** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role**](#create-the-iam-role)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Amazon Redshift Serverless** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. For permissions, reuse the inline policy JSON under **How it works** on this article (or an equivalent customer-managed policy). #### Create the IAM role Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Create an **inline policy** using the JSON under **How it works** at the top of this article (or save it as a customer-managed policy and attach it to the role). Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Serverless requires **`redshift-serverless:`**. **`Resource: "*"`** is typical; scoped ARNs need explicit enumeration. External ID mismatch. ### Related Articles Connect and manage the related source in Compliance. Connect and manage the related source in Compliance. Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. # Amazon Redshift Source: https://docs.iru.com/en/compliance/sources/amazon-redshift-source Connect Amazon Redshift provisioned clusters to Iru Compliance with a cross-account IAM role to collect cluster configuration, snapshot, and parameter metadata. ### About Amazon Redshift This connector targets **provisioned Redshift clusters** - parameter groups, subnet groups, snapshots, logging status, and encryption flags via **`redshift:Describe*`** / **`ListRecommendations`**. For **Redshift Serverless** or the **Data API** statement layer, use the dedicated **[Amazon Redshift Serverless](/en/compliance/sources/amazon-redshift-serverless-source)** and **[Amazon Redshift Data](/en/compliance/sources/amazon-redshift-data-api-source)** sources. ### How It Works Iru runs in its own AWS account. To read **provisioned Redshift** metadata in your account, you create an **IAM role** with two parts: a **trust policy** that allows Iru’s principal to call **`sts:AssumeRole`**, gated by the **External ID** from the wizard, and a **permissions policy** that grants read-only **`redshift:Describe*`** (and related) access to cluster configuration. You then paste the role’s **ARN** back into Iru. Attach **`AmazonRedshiftReadOnlyAccess`**, **or** least-privilege: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["redshift:Describe*", "redshift:ListRecommendations"], "Resource": "*" } ] } ``` | Detail | Value | | ------------------ | ---------------------- | | **Category** | Databases | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM admin rights in the **account** that hosts clusters. ### Connect AWS Redshift to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Redshift** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role**](#create-the-iam-role). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role**](#create-the-iam-role)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Redshift** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonRedshiftReadOnlyAccess`**, **or** attach an inline policy matching the JSON under **How it works** at the top of this article. Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Use **Amazon Redshift Serverless** source (`redshift-serverless:*`). Confirm **`redshift:DescribeClusterSnapshots`** is allowed (included in **`Describe*`**). External ID mismatch. ### Related Articles Connect and manage the related source in Compliance. Connect and manage the related source in Compliance. Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. # Amazon Relational Database Service (RDS) Source: https://docs.iru.com/en/compliance/sources/amazon-relational-database-service-rds-source Connect Amazon RDS to Iru Compliance with a cross-account IAM role to collect database instance configuration, cluster, and snapshot inventory metadata. ### About Amazon Relational Database Service (RDS) The **Amazon RDS** connector collects **instance and Aurora cluster settings**, **parameter groups**, **subnet groups**, **snapshots**, **backups**, and **encryption posture** without connecting to databases or running queries. Authentication is a **cross-account IAM role** with **`sts:AssumeRole`** and an **external ID**. ### How It Works Iru runs in its own AWS account. To read **RDS** configuration in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`rds:Describe*`** (and related) permissions. Paste the role’s **ARN** back into Iru. Attach **`AmazonRDSReadOnlyAccess`** for simplicity, or paste the inline JSON below for a narrower **`rds:Describe*`** footprint. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Databases | | **Authentication** | Cross-account IAM role | References: [AmazonRDSReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonRDSReadOnlyAccess.html), [RDS IAM](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAM.html). ### Prerequisites * IAM rights to **create roles** and policies. * Live **principal** + **external ID** from your connector tab. ### Connect AWS RDS to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS RDS** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS RDS** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AmazonRDSReadOnlyAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "rds:Describe*", "rds:ListTagsForResource" ], "Resource": "*" } ] } ``` Name the role (for example **`IruRDSReadOnly`**), create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Fix external ID / principal typos. Ensure `rds:DescribeDBClusters` is allowed (`Describe*` covers it). Confirm `DescribeDBSnapshots` / cluster snapshot APIs match your engine types. ### Considerations RDS APIs are **Regional**; inventory spans enabled Regions. Evidence is **infrastructure metadata**, not SQL result sets. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Amazon Simple Storage Service (S3) Source: https://docs.iru.com/en/compliance/sources/amazon-simple-storage-service-s3-source Connect Amazon S3 to Iru Compliance with a cross-account IAM role to collect bucket inventory, encryption, public-access blocks, and policy metadata. ### About Amazon Simple Storage Service (S3) The **Amazon S3** connector inventories **bucket configuration**: policies, encryption, versioning, logging, notifications, public-access blocks, and related settings without reading **object payloads**. Iru assumes an **IAM role** you create in your account (`sts:AssumeRole` with an **external ID**). This keeps evidence focused on **how buckets are configured**, not on stored file contents. ### How It Works Iru runs in its own AWS account. To inventory **S3** bucket configuration (not object payloads by default), you create an **IAM role** whose **trust policy** references Iru’s AWS principal and **mandates** the **External ID** from the wizard, and whose **permissions policy** grants only the **metadata** reads your team approves. Prefer the **inline policy** below instead of **`AmazonS3ReadOnlyAccess`** alone. The managed policy includes **`s3:GetObject`**, which many teams disallow for metadata-only integrations. Paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Storage | | **Authentication** | Cross-account IAM role | References: [S3 user guide](https://docs.aws.amazon.com/AmazonS3/latest/userguide/), [Access management](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-management.html). ### Prerequisites * IAM rights to **create roles** and attach inline policies. * The live **principal** + **external ID** pair from **your** connector - not necessarily the sample IDs printed in older screenshots. ### Connect Amazon S3 to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS S3** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS S3** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the value from Iru. Advance past the managed policy picker **without** attaching **`AmazonS3ReadOnlyAccess`** if you plan to use the metadata-only inline policy in the next step. Create the role with a placeholder name if required, then open the role → **Permissions** → **Create inline policy** → JSON editor. Paste: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:ListAllMyBuckets", "s3:GetBucketLocation", "s3:GetBucketPolicy", "s3:GetBucketPolicyStatus", "s3:GetBucketAcl", "s3:GetBucketVersioning", "s3:GetBucketTagging", "s3:GetBucketLogging", "s3:GetBucketNotification", "s3:GetBucketPublicAccessBlock", "s3:GetEncryptionConfiguration", "s3:GetLifecycleConfiguration", "s3:GetReplicationConfiguration", "s3:GetBucketCORS", "s3:GetBucketWebsite", "s3:GetBucketObjectLockConfiguration" ], "Resource": "*" } ] } ``` Save the inline policy. This policy intentionally **excludes** `s3:GetObject` and related object-read APIs so Iru cannot pull object bodies - only bucket-level metadata. Copy the role **ARN** from the role summary page. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Open **Trust relationships** and confirm the JSON matches the wizard - external ID typos are the usual cause of **`AssumeRole`** failures. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID mismatch - re-copy from Iru without stray spaces. Bucket resource policies can deny cross-account reads even when IAM allows them. Confirm `s3:GetEncryptionConfiguration` stayed in the inline policy. ### Considerations Buckets are **regional**, but `ListAllMyBuckets` is global - expect multi-Region follow-up calls during inventory. Explicit **Deny** statements in bucket policies block reads regardless of IAM allows - document expectations with auditors. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Arnica Source: https://docs.iru.com/en/compliance/sources/arnica-source Connect Arnica to Iru Compliance with a scoped read-only API key to collect secret-detection findings, repository inventory, developer risk, and security policy status. ### About Arnica Iru reads **findings**, **repository inventory**, **security policies**, and **developer risk** data from Arnica's REST API using a **Bearer** API key created in the Arnica web platform under **Admin** → **API**. Keys are **scope-bound** at creation. Grant only the **read** scopes your controls require, and avoid write scopes entirely. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_TOKEN ``` Arnica's API is served from `https://api.app.arnica.io` at version **v1**. Keys are created per-scope in the Arnica dashboard, so a key that is missing a scope returns an error rather than a partial result. Arnica returns **`403`**, not `401`, for every authentication and authorization failure. An invalid key, a revoked key, and a key missing a required scope all look the same. Iru stores the API key only; there is no host or subdomain to configure. | Detail | Value | | ------------------ | ----------------------- | | **Category** | Security | | **Authentication** | Bearer (scoped API key) | Official references: [Arnica documentation](https://docs.arnica.io/), [API reference (Swagger)](https://api.app.arnica.io/swagger). ### Prerequisites * **Arnica admin** access. Only admins can open **Admin** → **API** to create a key. * Decide which repositories are in scope. Arnica lets you exclude repositories, and excluded repositories produce no evidence. Iru cannot tell whether a repository has no findings or was never scanned. ### Connect Arnica to Iru Complete this tab before you connect the source in Compliance. Sign in to Arnica at [https://app.arnica.io](https://app.arnica.io) with an account that has the **admin** role. Go to **Admin** → **API**. Select **Create a New API Key**. Enter a name such as **Iru Compliance** so you can identify this key later. Select **read-only** scopes that cover your compliance program: `risks:read`, `products:read`, `inventory:read`, `policies:read`, and `status-checks:read`. Add `groups:read` if your controls cover developer group membership. Do **not** grant `risks:write` or any other write scope. Select **Create**, then copy the token value **once** while Arnica displays it. Store it securely until you paste it into Iru as the **Bearer** token. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Arnica**](#arnica) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Arnica** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Arnica** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Arnica returns `403` rather than `401` for auth failures, so this covers an invalid, expired, or revoked key as well as a missing scope. Regenerate the key, confirm you pasted the full string, and re-check the scope list. Either the key lacks `risks:read` or `inventory:read`, or those repositories are **excluded** in Arnica. Excluded repositories are invisible to Iru. Arnica is polled on a schedule rather than on demand. Allow a full collection cycle before investigating. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Asana Source: https://docs.iru.com/en/compliance/sources/asana-source Connect Asana to Iru Compliance with OAuth so Iru can collect workspace inventory, team and project membership, and access-control evidence for audits. ### About Asana The **Asana** connector pulls **workspace**, **team**, **project**, and **membership** information your controls need for access reviews and operational evidence. The integration uses **OAuth 2.0** (authorization code). The Asana user who completes consent must already **see** the workspaces and teams you expect to audit - otherwise collections will look incomplete even after a successful login. ### How It Works Iru redirects you through Asana’s OAuth screen and stores tokens so **refresh** can happen without asking you to sign in every hour. Scopes are **read-oriented** - they let Iru enumerate teams, users, projects, workspaces, and memberships appropriate for compliance reporting. | Detail | Value | | ------------------ | ------------------------------------------------------------------------------------------------ | | **Category** | Project management | | **Authentication** | OAuth 2.0 | | **Plans** | Premium, Business, or Enterprise tiers align with API capabilities Asana exposes to integrations | Documentation: [Asana OAuth](https://developers.asana.com/docs/oauth), [API docs](https://developers.asana.com/docs), [Developer console](https://app.asana.com/0/my-apps). ### Prerequisites * An Asana account with visibility into the **workspaces**, **teams**, and **projects** you want evidence for (often a workspace admin). * Browser **pop-ups allowed** for your Iru hostname - the OAuth window opens as a popup. ### Connect Asana to Iru Complete this tab before you enable the source in **Iru Compliance**, so the right user is ready for OAuth. Open [asana.com](https://asana.com) and sign in with the account you will use in the OAuth popup (often a **workspace admin** with broad visibility). Open each **workspace**, **team**, and **project** your compliance program expects in evidence. If this user cannot browse it in the Asana UI, Iru cannot read it either. Skim [Asana OAuth](https://developers.asana.com/docs/oauth) so you know which read scopes the consent screen will reference. In the browser profile you will use for Compliance, allow **pop-ups** for your **Iru** hostname so the Asana OAuth window is not blocked. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Asana**](#asana) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Asana** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. On the connector screen, review the **required read scopes** (teams, users, projects, workspaces, memberships). Select **Launch OAuth authentication**. When Asana opens, sign in if prompted. Review the permissions and select **Allow**. When the Asana window closes and Iru finishes the token exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Asana** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Allow pop-ups for your Iru domain, disable the source, then enable it again. Re-authorize with a user who can see the missing workspaces or teams. Confirm the authorizing user belongs to real teams/projects - brand-new accounts may have nothing to read. Tokens expire roughly hourly; Iru refreshes automatically unless the authorizing user was deactivated - re-run OAuth with an active account. ### Considerations The connection **follows** whichever Asana user authorized it - transfer ownership before that person offboards. Asana **rate limits** large workspaces; first sync can take several minutes. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Attio Source: https://docs.iru.com/en/compliance/sources/attio-source Connect Attio to Iru Compliance with a workspace admin access token using least-privilege read scopes to collect CRM workspace, member, and object metadata. ### About Attio Iru reads **workspace**, **object**, **record**, and **membership** data from Attio’s REST API using a **Bearer** token created under **Workspace Settings → Developers**. Tokens are **scope-bound** at creation - grant **read** paths your controls require and avoid unnecessary **write** scopes. ### How It Works ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` | Detail | Value | | ------------------ | ------------------------------- | | **Category** | CRM | | **Authentication** | Bearer (workspace access token) | Official references: [REST overview](https://docs.attio.com/rest-api/overview), [Authentication](https://developers.attio.com/docs/authentication), [Generating an API key](https://attio.com/help/apps/other-apps/generating-an-api-key). ### Prerequisites * **Workspace admin**: only admins create tokens. ### Connect Attio to Iru Complete this tab before you connect the source in Compliance. In Attio, open the **Workspace** menu (workspace name or icon), then choose **Workspace Settings**. Select **Developers** (or **Developer settings**) for the workspace you want Iru to read. Select **New access token** (or **Create token**). When prompted, enter a name such as **Iru Compliance** so you can audit the integration later. Enable **read** scopes that cover the objects your compliance program needs (for example records, lists, or notes; match your Attio plan and internal policy). Avoid write scopes unless your security team explicitly requires them. Create the token and copy the value **once** when Attio displays it. Store it securely; you will paste it into Iru as the **Bearer** token. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Attio**](#attio) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Attio** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Attio** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Regenerate token; paste full string. Create a token with broader **read** scopes for those objects. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Auto Scaling Source: https://docs.iru.com/en/compliance/sources/aws-auto-scaling-source Connect AWS Auto Scaling to Iru Compliance with a cross-account IAM role to collect EC2 and Application Auto Scaling group configuration and activity. ### About AWS Auto Scaling AWS exposes **two** scaling planes: **EC2 Auto Scaling** (`autoscaling:`) for **Auto Scaling groups** and **Application Auto Scaling** (`application-autoscaling:`) for **ECS, DynamoDB, Aurora, Spot Fleet**, and similar. Iru needs **both** read paths for full coverage. ### How It Works Iru runs in its own AWS account. To read **EC2 Auto Scaling** and related scaling metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`autoscaling:`** / **`application-autoscaling:`** permissions. Paste the role’s **ARN** back into Iru. Attach **`AutoScalingReadOnlyAccess`**, then add an **inline** policy for **`application-autoscaling:Describe*`** (see below). The role is **global**; resources are **Regional**. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** and attach the managed + inline policies below. ### Connect AWS Auto Scaling to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Auto Scaling** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Auto Scaling** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach the AWS managed policy **`AutoScalingReadOnlyAccess`**. Add an **inline policy** with this JSON: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "application-autoscaling:DescribeScalableTargets", "application-autoscaling:DescribeScalingActivities", "application-autoscaling:DescribeScalingPolicies", "application-autoscaling:DescribeScheduledActions" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. You only attached **`AutoScalingReadOnlyAccess`** - add the **`application-autoscaling`** inline policy. External ID mismatch. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS CloudTrail Source: https://docs.iru.com/en/compliance/sources/aws-cloudtrail-source Connect AWS CloudTrail to Iru Compliance with a cross-account IAM role to collect management event history, trail configuration, and event selectors. ### About AWS CloudTrail **CloudTrail** evidence typically includes **management events** via **`LookupEvents`** plus configuration metadata for trails. **`LookupEvents` covers roughly the last 90 days** - older analytics require **S3 archive** permissions (**`s3:GetObject`**) and possibly **`kms:Decrypt`** when trails use customer-managed CMKs. ### How It Works Iru runs in its own AWS account. To read **CloudTrail** trail and logging metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`cloudtrail:`** (and **`s3:`** / **`kms:`** only if your trails require those reads). Paste the role’s **ARN** back into Iru. Attach **`AWSCloudTrail_ReadOnlyAccess`**. Add the optional inline **`kms:Decrypt`** statement **only** when you deliberately ingest encrypted trail archives from S3. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles**. * Awareness whether audits demand **API lookups only** vs **S3 archive** depth. ### Connect AWS CloudTrail to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS CloudTrail** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS CloudTrail** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AWSCloudTrail_ReadOnlyAccess`**. If your trail archives use a customer-managed KMS key, add an **inline policy** (replace **REGION**, **ACCOUNT**, **CMK-ID**): The JSON below is an **example** of an optional **inline policy** fragment for KMS decrypt; replace **REGION**, **ACCOUNT**, and **CMK-ID** with your values. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["kms:Decrypt"], "Resource": "arn:aws:kms:REGION:ACCOUNT:key/CMK-ID" } ] } ``` Finish the role, then copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Use S3 archive ingestion paths - requires **`s3:GetObject`** + optional **`kms:Decrypt`**. External ID mismatch. ### Considerations Multi-Region / Organization trails affect where APIs must run - mirror AWS best practices for centralized logging. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS CodeCommit Source: https://docs.iru.com/en/compliance/sources/aws-codecommit-source Connect AWS CodeCommit to Iru Compliance with a cross-account IAM role to collect repository inventory, branch protection, and pull request history. ### About AWS CodeCommit **CodeCommit** is **Regional**, so Iru walks enabled Regions. Attach **`AWSCodeCommitReadOnly`**, which includes **`codecommit:GitPull`**, **`BatchGet*`**, **`Describe*`**, **`Get*`**, **`List*`**, and pull-request approval evaluation. If repositories use a **customer-managed KMS** key, add **`kms:Decrypt`** for that key’s ARN. ### How It Works Iru runs in its own AWS account. To read **CodeCommit** repositories and related metadata in your account, you create an **IAM role** that Iru can **assume** via **`sts:AssumeRole`**, gated by the wizard **External ID**, with read-only **`codecommit:`** permissions (for example **`AWSCodeCommitReadOnly`** or the inline JSON on the [**AWS**](#aws) tab). You then paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles**. * At least one CodeCommit repository where you expect evidence. ### Connect AWS CodeCommit to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS CodeCommit** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS CodeCommit** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AWSCodeCommitReadOnly`**. If repositories use a customer-managed KMS key, add an **inline policy** (replace **REGION**, **ACCOUNT**, **CMK-ID**): ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["kms:Decrypt"], "Resource": "arn:aws:kms:REGION:ACCOUNT:key/CMK-ID" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Add **`kms:Decrypt`** for that repository’s CMK. Confirm the **Region** you use in AWS matches where repos exist. External ID mismatch. ### Considerations CodeCommit was announced for **end of new customer access** in **July 2024** - plan migrations and retire this source when repos move. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Config Source: https://docs.iru.com/en/compliance/sources/aws-config-source Connect AWS Config to Iru Compliance with a cross-account IAM role to collect Config rules, conformance packs, and resource configuration history evidence. ### About AWS Config **AWS Config** evidence includes **resource inventory**, **compliance evaluations**, and **configuration timeline** data - assuming Config recorders are actually **enabled** in each Region you care about. Iru assumes a **cross-account IAM role** with read-only Config APIs. ### How It Works Iru runs in its own AWS account. To read **AWS Config** recorder and rule metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`config:`** / related permissions. Paste the role’s **ARN** back into Iru. Attach **`AWSConfigUserAccess`** for parity with AWS documentation for interactive Config usage, **or** paste the **`config:`** + **`tag:`** inline JSON below for tighter scope. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles**. * **AWS Config enabled** per Region - otherwise APIs return empty sets legitimately. ### Connect AWS Config to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Config** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Config** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AWSConfigUserAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "config:Describe*", "config:Get*", "config:List*", "config:Select*", "tag:GetResources", "tag:GetTagKeys" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Enable Config recorders + delivery channels there first. External ID mismatch. ### Considerations Config is **Regional**. Repeat enablement steps where audits apply. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS IAM Identity Center (Identity Store) Source: https://docs.iru.com/en/compliance/sources/aws-iam-identity-center-identity-store-source Use a cross-account IAM role so Iru Compliance can read IAM Identity Center directory users and groups via the Identity Store API. ### About AWS IAM Identity Center (Identity Store) This source reads **users**, **groups**, and **memberships** through the **`identitystore:`** API - the directory layer behind **IAM Identity Center**. **Permission sets**, **account assignments**, and **SSO applications** live under **`sso:`** and are covered by **[IAM Identity Center (SSO)](/en/compliance/sources/aws-iam-identity-center-sso-source)**. Create the role in your **organization management** or **delegated administrator** account where Identity Center is enabled. AWS does not ship a minimal managed policy **only** for Identity Store. Use the inline JSON below. ### How It Works Iru runs in its own AWS account. To read **Identity Store** users, groups, and memberships, you create an **IAM role** with a **trust policy** (**`sts:AssumeRole`** + wizard **External ID**) and read-only **`identitystore:`** permissions. AWS does not publish a minimal managed policy only for Identity Store; the inline JSON on the [**AWS**](#aws) tab matches what Iru calls. Paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * **IAM Identity Center** enabled; role in **management** or **delegated admin** account. * **`d-xxxxxxxxxx`** Identity Store ID is discoverable in console **Settings** once Iru connects. ### Connect Identity Store to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS IAM Identity Center (Identity Store)** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Identity Store** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS In the **management** or **delegated administrator** account, open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Advance without attaching **`AWSSSOReadOnly`** unless your team standardized on it - Identity Store reads are narrower. Create an **inline policy** with this JSON: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "identitystore:Describe*", "identitystore:Get*", "identitystore:List*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Wrong account - use management or delegated admin where Identity Center runs. Use **`identitystore:`**, not **`sso:`**. External ID mismatch. ### Considerations Identity Center **home Region** is fixed per organization; evidence reflects that deployment model. ### Related Articles Connect and manage the related source in Compliance. Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. # AWS IAM Identity Center (SSO) Source: https://docs.iru.com/en/compliance/sources/aws-iam-identity-center-sso-source Use a cross-account IAM role so Iru Compliance can read IAM Identity Center permission sets, assignments, and SSO application metadata. ### About AWS IAM Identity Center (SSO) This connector targets **`sso:`** APIs - **permission sets**, **account assignments**, **instances**, and **SSO applications**. **Users and groups** come from **[Identity Store](/en/compliance/sources/aws-iam-identity-center-identity-store-source)** (`identitystore:`). **`AWSSSOReadOnly`** exists but often needs supplementation; the inline policy below tracks **`Describe*`**, **`Get*`**, **`List*`**, and **`Search*`** on **`sso:`**. Deploy the role in the **management** or **delegated administrator** account. ### How It Works Iru runs in its own AWS account. To read **IAM Identity Center** SSO configuration (permission sets, assignments, instances, applications), you create an **IAM role** in your **management** or **delegated administrator** account with a **trust policy** (**`sts:AssumeRole`** + wizard **External ID**) and read-only **`sso:`** permissions. **`AWSSSOReadOnly`** exists but does not always cover every action Iru needs, so the inline policy on the [**AWS**](#aws) tab is the reliable default. Paste the role’s **ARN** back into Iru. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * **IAM Identity Center** enabled for the organization. * Permissions to **create roles** in management or delegated admin. ### Connect IAM Identity Center (SSO) to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS IAM Identity Center (SSO)** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS IAM Identity Center (SSO)** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS In the **management** or **delegated administrator** account, open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Skip attaching only **`AWSSSOReadOnly`** if it misses APIs your audit needs - create an **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "sso:Describe*", "sso:Get*", "sso:List*", "sso:Search*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Member-account roles **cannot** see org SSO config - use management/delegated admin. Confirm **`sso:List*`** / **`sso:Describe*`** coverage (wildcard above). SSO management uses **`sso:`**, not **`identitycenter:`** for these reads. External ID mismatch. ### Related Articles Connect and manage the related source in Compliance. Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. # AWS Identity and Access Management (IAM) Source: https://docs.iru.com/en/compliance/sources/aws-identity-and-access-management-iam-source Connect AWS IAM to Iru Compliance with a cross-account IAM role to collect users, roles, policies, MFA status, and credential-report evidence for audits. ### About AWS Identity and Access Management (IAM) The **IAM** connector inventories **users**, **roles**, **groups**, **policies**, **access keys**, **MFA devices**, and **credential reports**. High sensitivity data used for access-review evidence. The integration uses **`sts:AssumeRole`**. **`IAMReadOnlyAccess`** is simplest; the inline JSON below narrows to **`Get*`** / **`List*`** plus **`GenerateCredentialReport`** / **`GenerateServiceLastAccessedDetails`**. Treat the **cross-account role ARN** like infrastructure secrets - limit who edits trust relationships. ### How It Works Iru runs in its own AWS account. To read **IAM** data in your account, you create an **IAM role** with a **trust policy** that allows Iru’s principal to call **`sts:AssumeRole`**, gated by the **External ID** from the wizard, and a **permissions policy** that grants read-only access to IAM resources (for example **`IAMReadOnlyAccess`** or the tighter inline JSON on the [**AWS**](#aws) tab). You then paste the role’s **ARN** back into Iru. **`IAMReadOnlyAccess`** exposes identities, policy documents, and access-key metadata by design, so treat the role and its ARN as sensitive. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM admin rights in the **same account** whose IAM plane you want evidence for. ### Connect AWS IAM to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS IAM** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** into the field the wizard provides. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS IAM** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS In the account whose IAM data you need, open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the account ID Iru shows). Enable **Require external ID** and paste the value from Iru. Attach **`IAMReadOnlyAccess`**, **or** add this **inline policy** if you cannot use the managed policy. The JSON below is an **example**; tighten actions if your security team requires it. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "iam:Get*", "iam:List*", "iam:GenerateCredentialReport", "iam:GenerateServiceLastAccessedDetails" ], "Resource": "*" } ] } ``` Name the role (for example **`IruIAMReadOnly`**), create it, and copy the **Role ARN** from the role summary. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). On **Trust relationships**, verify the JSON matches Iru’s wizard exactly. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Prime **`GenerateCredentialReport`** manually once via console/CLI. Wildcards must cover **`Get*`** / **`List*`** for each resource type you expect. ### Considerations IAM is **global** within an account - single scan covers all Regions’ IAM APIs. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Key Management Service (KMS) Source: https://docs.iru.com/en/compliance/sources/aws-key-management-service-kms-source Connect AWS KMS to Iru Compliance with a cross-account IAM role to collect key inventory, rotation status, and grant metadata without decrypt privileges. ### About AWS Key Management Service (KMS) The **AWS Key Management Service** connector gathers **key metadata**, **aliases**, **policies**, **grants**, **tags**, and **rotation status** so controls can prove how keys are governed. Iru uses **`sts:AssumeRole`** with an **external ID**. The recommended inline policy below avoids **`kms:Decrypt`** and other cryptographic data operations (metadata only). ### How It Works Iru runs in its own AWS account. To read **KMS** key metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`kms:`** permissions appropriate for inventory (avoid policies that bundle write-style capabilities). Paste the role’s **ARN** back into Iru. Skip **`AWSKeyManagementServicePowerUser`** for this use case - it bundles write-style capabilities. Use the explicit inline JSON from the wizard path or the template below. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | References: [KMS developer guide](https://docs.aws.amazon.com/kms/latest/developerguide/), [IAM policies for KMS](https://docs.aws.amazon.com/kms/latest/developerguide/iam-policies.html). ### Prerequisites * IAM admin rights to publish roles. * Live connector strings (**principal**, **external ID**). ### Connect AWS KMS to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS KMS** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS KMS** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (unless your wizard lists another ID). Enable **Require external ID** and paste the external ID from Iru. Advance without attaching **`AWSKeyManagementServicePowerUser`** or other broad KMS write-capable policies. Add this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "kms:ListKeys", "kms:ListAliases", "kms:DescribeKey", "kms:GetKeyPolicy", "kms:GetKeyRotationStatus", "kms:ListGrants", "kms:ListKeyPolicies", "kms:ListResourceTags" ], "Resource": "*" } ] } ``` No **`kms:Decrypt`**, **`kms:Encrypt`**, or **`GenerateDataKey`**. Iru cannot use your keys to process ciphertext. Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Fix external ID drift. Resource policies on individual keys may deny **`DescribeKey`** - adjust key policies if auditors require full visibility. Always listed but sometimes less introspectable than customer-managed keys - expected per AWS behavior. ### Considerations Keys are **Regional**; inventory spans enabled Regions. Works purely off **API metadata** - no key material leaves KMS through decrypt calls from this connector. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Lambda Source: https://docs.iru.com/en/compliance/sources/aws-lambda-source Connect AWS Lambda to Iru Compliance with a cross-account IAM role to collect function inventory, runtime, IAM role binding, and layer configuration metadata. ### About AWS Lambda The **AWS Lambda** connector collects **function configuration**, **layers**, **event source mappings**, **concurrency settings**, and related metadata across Regions without invoking functions or downloading deployment packages. Iru uses **`sts:AssumeRole`** into a role you create, gated by an **external ID** from the wizard. ### How It Works Iru runs in its own AWS account. To read **Lambda** configuration in your account, you create an **IAM role** that trusts Iru’s principal (**`sts:AssumeRole`** + wizard **External ID**) with read-only **`lambda:`** permissions. Paste the role’s **ARN** back into Iru. Create an IAM role that trusts Iru’s principal and attach **`AWSLambda_ReadOnlyAccess`**, or use the tighter inline policy below if your security team prefers least privilege. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | References: [AWSLambda\_ReadOnlyAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AWSLambda_ReadOnlyAccess.html), [Lambda security](https://docs.aws.amazon.com/lambda/latest/dg/lambda-security.html). ### Prerequisites * IAM permission to **create roles** and attach policies. * **Principal** and **external ID** values copied from **your** live connector (samples like account `753695775620` may differ per tenant). ### Connect AWS Lambda to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Lambda** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Keep the wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Lambda** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** unless the wizard differs. Enable **Require external ID** and paste the external ID from Iru. Attach **`AWSLambda_ReadOnlyAccess`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "lambda:Get*", "lambda:List*" ], "Resource": "*" } ] } ``` The managed policy covers actions such as `GetFunction`, `ListFunctions`, `GetFunctionConfiguration`, layers, aliases, and mappings; the inline variant relies on `Get*` / `List*` wildcards. Name the role (for example **`IruLambdaReadOnly`**), create it, and copy its **ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. External ID or principal mismatch - re-copy from Iru. Confirm functions exist in enabled Regions and the role targets the right account. Read-only APIs may not expose ciphertext details - metadata still evidences configuration presence. ### Considerations Lambda is **Regional**; first scans walk every enabled Region. Iru **does not invoke** functions or extract ZIP artifacts - configuration evidence only. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Organizations Source: https://docs.iru.com/en/compliance/sources/aws-organizations-source Connect AWS Organizations to Iru Compliance with a cross-account IAM role in the management account to collect OU structure, account, and SCP metadata. ### About AWS Organizations **AWS Organizations** evidence includes **accounts**, **OUs**, **roots**, **SCPs**, and related policies. The role **must** live in the **management account** - member accounts cannot enumerate the full org graph via these APIs. ### How It Works Iru runs in its own AWS account. To read **AWS Organizations** structure and settings in your management account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and read-only **`organizations:`** permissions. Paste the role’s **ARN** back into Iru. Attach **`AWSOrganizationsReadOnlyAccess`**, or narrow to **`organizations:Describe*`** / **`organizations:List*`** via inline JSON. | Detail | Value | | ------------------ | ------------------------------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role (management account) | ### Prerequisites * IAM admin rights in the **management account** (not a workload member account). * Connector **principal** + **external ID**. ### Connect AWS Organizations to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in the management account**](#create-the-iam-role-in-the-management-account). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Organizations** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in the management account**](#create-the-iam-role-in-the-management-account). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in the management account**](#create-the-iam-role-in-the-management-account)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Organizations** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Create the role in the **Organizations management account** using the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in the management account In the **management account**, open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`AWSOrganizationsReadOnlyAccess`**, **or** attach this **inline policy**. The JSON below is an **example** least-privilege alternative; align actions with what your compliance program needs. ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "organizations:Describe*", "organizations:List*" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm role creation happened in the **management** account. External ID mismatch. ### Considerations Org APIs evolve - wildcard **`Describe*`** / **`List*`** pairs reduce churn when AWS ships new read operations. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Secrets Manager Source: https://docs.iru.com/en/compliance/sources/aws-secrets-manager-source Connect AWS Secrets Manager to Iru Compliance with a cross-account IAM role to inventory secrets, rotation schedules, and tags without reading secret values. ### About AWS Secrets Manager This connector enumerates **secret metadata**, **rotation configuration**, **resource policies**, and **tags** - but **never** calls **`GetSecretValue`**. Avoid **`SecretsManagerReadWrite`** because it grants **`GetSecretValue`**. Use the inline JSON below unless your cloud security group publishes an audited equivalent. ### How It Works Iru runs in its own AWS account. To read **Secrets Manager** metadata in your account, you create an **IAM role** with **`sts:AssumeRole`** trust (wizard **External ID**) and **`secretsmanager:`** permissions scoped to **metadata** reads (not retrieving secret **values**, unless you deliberately add those actions). Paste the role’s **ARN** back into Iru. Standard **`sts:AssumeRole`** trust plus explicit **`secretsmanager`** actions that skip value retrieval. | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM rights to **create roles** and **inline policies**. ### Connect AWS Secrets Manager to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Secrets Manager** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. The wizard shows the **trust policy** JSON your IAM role must use (**Principal** and **sts:ExternalId**). Below is an **example** of the structure; **copy the live JSON from your wizard** so the account, principal ARN, and external ID match exactly. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to the Iru wizard tab. Paste the **Role ARN** where the connector prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Secrets Manager** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Add this **inline policy** (do **not** attach **`SecretsManagerReadWrite`**): ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "secretsmanager:DescribeSecret", "secretsmanager:ListSecrets", "secretsmanager:ListSecretVersionIds", "secretsmanager:GetResourcePolicy" ], "Resource": "*" } ] } ``` **`GetSecretValue`** is intentionally omitted. Iru cannot fetch cleartext secrets with this policy. Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Secret resource policies may deny cross-account principals - adjust policies cautiously with security stakeholders. External ID mismatch. ### Considerations Secrets are **Regional**; inventory spans enabled Regions. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # AWS Security Hub Source: https://docs.iru.com/en/compliance/sources/aws-security-hub-source Connect AWS Security Hub to Iru Compliance with a cross-account IAM role to collect findings, control status, and standard subscriptions as posture evidence. ### About AWS Security Hub **AWS Security Hub** aggregates findings and compliance posture across enabled Regions. **Security Hub must be turned on** where you expect evidence. Iru assumes a **cross-account IAM role** and reads **`securityhub:`** metadata APIs. ### How It Works Iru runs in its own AWS account. To read **Security Hub** findings and configuration in your account, you create an **IAM role** with a **trust policy** (**`sts:AssumeRole`** + wizard **External ID**) and read-only **`securityhub:`** permissions. You then paste the role’s **ARN** back into Iru. Attach **`AWSSecurityHubReadOnlyAccess`** or use: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "securityhub:Get*", "securityhub:List*", "securityhub:BatchGet*", "securityhub:Describe*" ], "Resource": "*" } ] } ``` | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM admin rights. * **Security Hub enabled** per Region under review. ### Connect AWS Security Hub to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **AWS Security Hub** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. Copy the **trust policy** exactly as shown in the wizard. The JSON below is an **example** of the shape IAM expects for the role **Trust policy** editor (full document with `Version` and `Statement`). **Always use the principal and external ID from your live wizard** if they differ: ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. Return to Iru. Paste the **Role ARN** into the connector where the wizard prompts for it. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS Security Hub** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the value from Iru. Attach **`AWSSecurityHubReadOnlyAccess`**, **or** attach an inline policy matching the JSON under **How it works** above. Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Confirm **Trust relationships** matches the wizard JSON. Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Enable Security Hub there first. External ID mismatch. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # BambooHR Source: https://docs.iru.com/en/compliance/sources/bamboohr-source Connect BambooHR to Iru Compliance using HTTP Basic Auth with your API key as the username to collect employee directory, status, and onboarding evidence. ### About BambooHR BambooHR’s REST API uses **HTTPS** and **HTTP Basic**: **username** = **API key**, **password** = literal **`x`** (or any non-empty string BambooHR ignores). Requests target **`https://YOUR_SUBDOMAIN.bamboohr.com/api/...`**. Iru stores **`subdomain`** first, then credentials. ### How It Works BambooHR’s REST API uses **HTTP Basic** over HTTPS: **username** = your **API key**, **password** = the literal **`x`** (BambooHR ignores the password field beyond requiring it to be non-empty). Requests target **`https://{subdomain}.bamboohr.com/api/gateway.php/{subdomain}/v1/`**. The wizard collects **subdomain** first, then the key. | Detail | Value | | ------------------ | --------------------- | | **Category** | HRIS | | **Authentication** | Basic (API key + `x`) | Official references: [Getting started](https://documentation.bamboohr.com/docs/getting-started), [API reference](https://documentation.bamboohr.com/reference). ### Prerequisites * Your **subdomain** (`acme` from `https://acme.bamboohr.com`). * Ability to create an **API key** under your BambooHR profile. ### Connect BambooHR to Iru Complete this tab before you connect the source in Compliance. Sign in at your company subdomain (for example `https://yourcompany.bamboohr.com`) with an account allowed to manage API keys. Click **your name** in the upper-right (or the profile menu BambooHR shows for your account). Select **API Keys** (sometimes under **Account** or **My settings**, depending on your BambooHR layout). Choose **Add a New Key** (or **Generate new key**). Enter a label such as **Iru Compliance** so operators know what uses this key. Generate the key and copy the value **immediately**. BambooHR uses this value as the HTTP Basic **username** in Iru; the **password** is the literal **`x`** as described on the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**BambooHR**](#bamboohr) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **BambooHR** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **subdomain** only (for example `acme`). Confirm if the wizard shows a preview URL. Enter **Username** = API key and **Password** = **`x`** (literal). Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **BambooHR** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Full API key; regenerate if unsure. Fix **subdomain** and reconnect. API inherits **user permissions** - connect with an HR-privileged account if needed. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Bitbucket Cloud Source: https://docs.iru.com/en/compliance/sources/bitbucket-cloud-source Connect Bitbucket Cloud to Iru Compliance with an Atlassian API token using HTTP Basic auth to collect workspace, repository, and pull request review evidence. ### About Bitbucket Cloud The **Bitbucket Cloud** connector collects **repository**, **workspace**, **project**, and **team** metadata your audits expect around change management and access reviews. Iru authenticates with **HTTP Basic Auth**: your **Atlassian account email** as the username and an **Atlassian API token** as the password (plain passwords are rejected). ### How It Works Clients send Base64-encoded credentials: ```http theme={null} Authorization: Basic base64(email:api_token) ``` Atlassian is **deprecating app passwords** - create **API tokens** for new work and migrate anything still using legacy secrets before they sunset. | Detail | Value | | ------------------ | ------------------------------ | | **Category** | Developer tools | | **Authentication** | Basic auth (email + API token) | Documentation: [Manage API tokens](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/), [Bitbucket API tokens](https://support.atlassian.com/bitbucket-cloud/docs/create-an-api-token/), [REST intro](https://developer.atlassian.com/cloud/bitbucket/rest/intro/). ### Prerequisites * Access to Bitbucket **workspaces** you expect evidence from. * Permission to create **API tokens** on your Atlassian ID. ### Connect Bitbucket Cloud to Iru Complete this tab before you connect the source in Compliance. While signed in to Bitbucket Cloud (or any Atlassian app in the same Atlassian account), select your **profile icon**, then **Account settings** (sometimes labeled **Atlassian account**). Choose **Security**, then **Create and manage API tokens** (wording may read **API tokens**). Select **Create API token with scopes** (or the closest equivalent). You are creating an Atlassian API token Bitbucket will accept for Basic auth in Iru. Give the token a label (for example **Iru Compliance**). Choose an expiry (tokens last up to **365 days**). Grant **read** scopes on repositories, workspaces, and teams so they align with what your controls reference. Create the token and copy the value **immediately**; Atlassian shows it once. You will use it with your Atlassian email in Iru’s **Submit Credentials** step. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Bitbucket Cloud**](#bitbucket-cloud) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Bitbucket** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. When the wizard asks for Basic authentication, enter your **Atlassian email** as the username and the **API token** as the password. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Bitbucket** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Use **email + API token**, not Bitbucket username and not your Atlassian password. Mint a new token under Account settings and update Iru. Ensure the Atlassian account belongs to every workspace you expect data from. Replace with API tokens - app passwords are deprecated. ### Considerations Tokens expire - calendar reminders prevent silent outages. Read scopes keep Iru from mutating repos or pull requests. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Box Source: https://docs.iru.com/en/compliance/sources/box-source Connect Box to Iru Compliance through OAuth to collect enterprise file and folder inventory, user and group access, and sharing-policy configuration. ### About Box Iru uses **OAuth 2.0** (**authorization code**) to read **files**, **folders**, **users**, **groups**, and **enterprise** metadata. The **authorizing Box user** must be able to see the content your audit program cares about - prefer **admin-level** visibility when you need org-wide evidence. ### How It Works Iru uses Box’s **OAuth 2.0 authorization code** grant. You sign in at Box through the wizard’s **popup**, review scopes, and approve access; Box returns a code that Iru exchanges for tokens used on subsequent REST calls. | Detail | Value | | ------------------ | ----------------------------------------- | | **Category** | Storage | | **Authentication** | OAuth 2.0 | | **Typical plans** | Business or Enterprise (full API surface) | Scopes commonly include **read** access to files/folders plus **enterprise** administration where applicable - exact strings appear on Box’s consent screen. Official references: [OAuth 2.0](https://developer.box.com/guides/authentication/oauth2/), [Scopes](https://developer.box.com/guides/api-calls/permissions-and-errors/scopes/), [Developer docs](https://developer.box.com/). ### Prerequisites * Browser **popups** allowed for your Iru domain. * A Box account with sufficient rights for the folders and users under review. ### Connect Box to Iru Complete this tab before you enable **Box** in **Iru Compliance**, so the right user is ready for OAuth. Open [box.com](https://www.box.com) and sign in with the account you will use in the OAuth popup (prefer **co-admin** or **admin** visibility for org-wide evidence). Browse **Admin Console** (or equivalent) and spot-check **users**, **groups**, and **folders** your audit program must cover. If this user cannot see an object in Box, Iru cannot read it either. Skim Box’s [OAuth 2.0](https://developer.box.com/guides/authentication/oauth2/) and [Scopes](https://developer.box.com/guides/api-calls/permissions-and-errors/scopes/) docs so the consent screen matches your expectations. In the browser profile you will use for Compliance, allow **pop-ups** for your **Iru** hostname so the Box consent window is not blocked. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Box**](#box) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Box** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Choose **Launch OAuth** (or the equivalent control) in the connector wizard. Complete Box login, review scopes, and select **Grant access to Box** (wording may read **Grant**). Close the popup when the wizard tells you to. When the Box popup closes and Iru finishes the token exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Box** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Allow popups; toggle source off/on. Re-authorize with a user who can access missing enterprise objects. Access tokens are short-lived; Iru refreshes automatically - if refresh fails after **60 days** idle or consent changes, **re-authorize**. ### Considerations Tokens are tied to the authorizing user - **deactivation** may break sync until someone reconnects. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Checkr Source: https://docs.iru.com/en/compliance/sources/checkr-source Connect Checkr to Iru Compliance using HTTP Basic Auth with your secret API key to collect background check report status and candidate workflow evidence. ### About Checkr Iru reads **candidate**, **report**, and **package** metadata from Checkr’s REST API using **HTTP Basic**: **username** = **Secret API key**, **password** empty - effectively **`base64(api_key:)`**. ### How It Works Checkr’s REST API uses **HTTP Basic** over HTTPS: the **Secret API key** is the **username** and the **password** is left **empty**, so the header is **`Authorization: Basic base64(api_key:)`**. | Detail | Value | | ------------------ | -------------------------------- | | **Category** | HRIS | | **Authentication** | Basic (API key + empty password) | Official references: [Checkr API docs](https://docs.checkr.com/), [API keys](https://help.checkr.com/s/article/14966447719703-Manage-API-keys-and-webhooks). ### Prerequisites * **Dashboard** access to copy **production** vs **staging** keys as appropriate. ### Connect Checkr to Iru Complete this tab before you connect the source in Compliance. Sign in to the [Checkr Dashboard](https://dashboard.checkr.com) with an account that can view API credentials. From the Dashboard, go to **Account Settings** (or the gear **Settings** entry your tenant uses for organization-wide configuration). Select **Developer Settings** (or **API** / **Developers**, depending on Checkr UI labels). Confirm whether Iru should use **production** or **staging** data, then locate the **Secret Key** (or **Secret API key**) for that same environment. Copy the **Secret Key** and store it like a password. In Iru you will paste it as the **Username** for HTTP Basic auth and leave **Password** blank, as on the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Checkr**](#checkr) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Checkr** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter the Secret Key in the **Username** field. Leave **Password** **blank**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Checkr** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Correct environment key; no stray spaces. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # ClickUp Source: https://docs.iru.com/en/compliance/sources/clickup-source Connect ClickUp to Iru Compliance with a personal API token sent in the Authorization header (no Bearer prefix) to collect workspace, team, and task evidence. ### About ClickUp Iru reads **workspaces**, **spaces**, **folders**, **lists**, **tasks**, and **members** from the ClickUp API. ClickUp **personal tokens** look like **`pk_…`** and must be sent as the **raw** **`Authorization`** header value - **do not** prefix **`Bearer`**, or authentication fails. ### How It Works ```http theme={null} Authorization: pk_XXXXXXXXXXXXXXXX ``` | Detail | Value | | ------------------ | --------------------------- | | **Category** | Project management | | **Authentication** | Personal API token (`pk_…`) | Official references: [Authentication](https://developer.clickup.com/docs/authentication), [API reference](https://developer.clickup.com/reference), [Help Center](https://help.clickup.com/hc/en-us/articles/6303426241687-Use-the-ClickUp-API). ### Prerequisites * ClickUp user who is a member of every **workspace** you want evidence for. ### Connect ClickUp to Iru Complete this tab before you connect the source in Compliance. Open [ClickUp](https://clickup.com) and sign in with a user who is a member of every **workspace** Iru should read. Select your **Avatar** (profile photo or initials) in the lower-left or header, depending on your ClickUp layout. Choose **Settings**, then **Apps** (or **ClickApps** / **Integrations** if your tenant routes API tokens there; use the path that exposes **API Token**). Select **API Token** to view existing tokens and the control to create a new one. Select **Generate** (or **Create token**) to mint a new **`pk_…`** token. Copy the full **`pk_`** string. **Regenerate** invalidates the prior token, so update Iru the same day if you rotate. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**ClickUp**](#clickup) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **ClickUp** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste **`pk_…`** into the **Authorization** field **without** **`Bearer`**. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **ClickUp** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Remove **`Bearer`** - only the token string belongs in the header. Token’s user must join that workspace. Paste the **new** `pk_` token in Iru. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Cloudflare Source: https://docs.iru.com/en/compliance/sources/cloudflare-source Connect Cloudflare to Iru Compliance with a scoped API token to collect zones, DNS records, security settings, WAF rules, and account membership. ### About Cloudflare Iru reads **zones**, **DNS**, **security and WAF settings**, **firewall rules**, and **account** membership via the Cloudflare API using a **scoped API token** sent as **Bearer** authorization. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_TOKEN ``` | Detail | Value | | ------------------ | ------------------ | | **Category** | Security | | **Authentication** | API token (Bearer) | Prefer **Account API tokens** (Manage Account → API Tokens) for long-lived automation; **User** tokens follow individual users. Official references: [Create a token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/), [Restrict tokens](https://developers.cloudflare.com/fundamentals/api/how-to/restrict-tokens/), [API](https://developers.cloudflare.com/api/). ### Prerequisites * **Admin** or **Super Administrator** (or equivalent) on the Cloudflare account. ### Connect Cloudflare to Iru Complete this tab before you connect the source in Compliance. Open the [Cloudflare dashboard](https://dash.cloudflare.com) and sign in with an **Admin** or **Super Administrator** account. Decide whether Iru should use an **account API token** (**Manage Account** → **API Tokens**) or a **user API token** tied to your profile (**My Profile** → **API Tokens**). Account tokens are common for org-wide evidence; user tokens follow one operator’s access. Select **Create Token**. Prefer a **Read** template such as **Read all resources** unless your security team publishes a tighter **custom** policy. If you use a **custom** token, grant **read** (or equivalent) on **Account**, **Zone**, and **User** objects Iru needs for your frameworks. Avoid write permissions unless policy requires them. Set **TTL** (time to live) and **IP allowlists** if your security program expects them. Note any expiry date in your rotation calendar. Create the token and copy the secret **once** when Cloudflare displays it. Store it in a vault; you will paste it into Iru as the **Bearer** token. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Cloudflare**](#cloudflare) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Cloudflare** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer token** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Cloudflare** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Verify with `GET https://api.cloudflare.com/client/v4/user/tokens/verify`; check TTL and revocation. Token scope - recreate with correct account and zone resources. If you set TTL, rotate before expiry and update Iru. ### Considerations Iru uses **read** permissions only - it does not change DNS, rules, or zones. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Confluence Cloud Source: https://docs.iru.com/en/compliance/sources/confluence-cloud-source Connect Confluence Cloud to Iru Compliance with your Atlassian subdomain and an API token to collect spaces, page hierarchy, and access-permission evidence. ### About Confluence Cloud The **Confluence Cloud** connector gathers **space**, **page**, and **membership** data you need for access-review and change-management evidence. The wizard is two parts: first you provide your **`*.atlassian.net`** subdomain so Iru can reach `https://YOUR_SUBDOMAIN.atlassian.net/wiki/api/v2`, then you supply **HTTP Basic** credentials built from your **Atlassian email** and **API token**. ### How It Works REST calls use Basic authentication: ```http theme={null} Authorization: Basic base64(email:api_token) ``` Passwords are not accepted - only API tokens. | Detail | Value | | ------------------ | --------------------------------------------------------- | | **Category** | Productivity | | **Authentication** | Basic auth (email + Atlassian API token) | | **Scope** | **Confluence Cloud** REST API v2 (not Data Center/Server) | Documentation: [Basic auth for Confluence Cloud](https://developer.atlassian.com/cloud/confluence/basic-auth-for-rest-apis/), [REST v2 intro](https://developer.atlassian.com/cloud/confluence/rest/v2/intro/), [API tokens](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/). ### Prerequisites * Access to the **spaces** you want evidence from. * Your **subdomain** - the label before **`.atlassian.net`** (for example `acme` when users visit `https://acme.atlassian.net/wiki`). ### Connect Confluence Cloud to Iru Complete this tab before you connect the source in Compliance. In a browser, go to **[id.atlassian.com/manage/api-tokens](https://id.atlassian.com/manage/api-tokens)** while signed in to the **same Atlassian account** you use for Confluence Cloud. Select **Create API token** (or **Create token**). Atlassian may ask you to sign in again or confirm your identity. Enter a label such as **Iru Compliance** so you can revoke the right credential later without guessing. Choose an expiry up to **365 days** (Atlassian’s maximum for this token type at the time of writing). Shorter expiries reduce blast radius if a secret leaks. Finish creation and copy the token value **once** when Atlassian shows it. You will combine it with your Atlassian account email in Iru’s Basic auth step on the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Confluence Cloud**](#confluence-cloud) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Confluence** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter your **Confluence** subdomain (for example `acme`). Confirm the preview URL matches `https://acme.atlassian.net/wiki/api/v2`, then continue. When the wizard asks for Basic authentication, provide your **Atlassian email** and **API token**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Confluence** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Refresh the wizard by toggling the source off/on if the deep link expired. Email must match your Atlassian ID; password field must contain an API token. Token inherits your space permissions - grant the account access or switch identities. Double-check the hostname your users rely on - typos break routing immediately. ### Considerations Tokens expire yearly - rotate ahead of deadlines. Data Center / Server APIs differ - this connector targets **Cloud** only. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Contentful Source: https://docs.iru.com/en/compliance/sources/contentful-source Connect Contentful to Iru Compliance with a Content Management API personal access token to collect spaces, content models, environments, and team membership. ### About Contentful Iru reads **spaces**, **content models**, **environments**, and **membership** via the **Content Management API (CMA)** using a **Personal Access Token** (**PAT**) sent as **`Authorization: Bearer`**. Do **not** use **Content Delivery API (CDA)** preview tokens - they lack management scope. ### How It Works ```http theme={null} Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN ``` | Detail | Value | | ------------------ | ------------------------- | | **Category** | Developer tools | | **Authentication** | CMA personal access token | Official references: [Authentication](https://www.contentful.com/developers/docs/references/authentication/), [Personal access tokens](https://www.contentful.com/help/token-management/personal-access-tokens/), [CMA reference](https://www.contentful.com/developers/docs/references/content-management-api/). ### Prerequisites * Contentful user with access to the **spaces** you need for evidence. ### Connect Contentful to Iru Complete this tab before you connect the source in Compliance. Open the [Contentful web app](https://app.contentful.com) and sign in with a user who can access the **spaces** Iru should read. Select **Settings** (gear or workspace settings, depending on your UI) for the organization or space that owns the token. Choose **CMA tokens** (Content Management API tokens) or the equivalent **Personal access tokens** screen. Select **Create personal access token** (or **Generate token**). Enter a name such as **Iru Compliance**. If Contentful offers **expiration**, set a date aligned with your key-rotation policy, or leave unset only if your security team allows non-expiring tokens. Generate the token and copy the value **once**. Store it securely; you will paste it into Iru as the **Bearer** token. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Contentful**](#contentful) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Contentful** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the PAT into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Contentful** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. PAT not CDA token; paste exact string. Rotate at **Settings** → **CMA tokens**, update Iru. PAT inherits user membership - grant space access first. ### Considerations Revoke leaked tokens immediately and recreate - **PUT** revoke endpoint documented by Contentful for automation. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Databricks Source: https://docs.iru.com/en/compliance/sources/databricks-source Connect Databricks to Iru Compliance with a workspace URL and a read-only access token to collect user and group inventory, workspace permissions, cluster security settings, and secret scope access controls. ### About Databricks Iru reads **users and groups**, **workspace permissions**, **cluster configurations**, **secret scopes**, and **Unity Catalog permissions** (where Unity Catalog is in use) from the Databricks REST API. Authentication uses a **Bearer** token: either a **personal access token** created under **User Settings** → **Developer** → **Access tokens**, or a **service principal** token. Requests target your workspace host, so Iru stores the **workspace URL** first, then the token. ### How It Works ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` Databricks is **per-workspace**: each workspace has its own host (for example `https://dbc-1234abcd-5e6f.cloud.databricks.com` on AWS, or `https://adb-1234567890.12.azuredatabricks.net` on Azure) and its own tokens. A token is valid only against the workspace that issued it, so connect one source per workspace you need evidence from. Iru reads **secret scope names and their access control lists**. It does not read **secret values**. | Detail | Value | | ------------------ | --------------------- | | **Category** | Analytics | | **Authentication** | Bearer (access token) | Official references: [REST API reference](https://docs.databricks.com/api/workspace/introduction), [Authentication](https://docs.databricks.com/aws/en/dev-tools/auth/). ### Prerequisites * Your **workspace URL**, copied from the browser when signed in to the workspace. * **Workspace admin** access. Token creation can be restricted by workspace settings, and a non-admin token returns only the permissions and clusters that account can already see. * Personal access tokens **enabled** for the workspace. If admins have disabled them, use a **service principal** instead. * Decide what is in scope. Databricks lets you exclude workspaces or secret scopes, and excluded objects produce no evidence. ### Connect Databricks to Iru Complete this tab before you connect the source in Compliance. Sign in to the Databricks workspace you want Iru to read, using an account with the **admin** role. Select your **username** in the top bar, then **Settings**. Go to **Developer**, then select **Manage** beside **Access tokens**. Select **Generate new token**. Enter a **Comment** such as **Iru Compliance**, and set a **Lifetime** your team can track. Collection stops when a token expires. Leaving the lifetime blank creates a non-expiring token, which some security policies disallow. Select **Generate**, then copy the token value **once** while Databricks displays it. Copy the **workspace URL** from your browser's address bar (the scheme and host only, with no trailing path). Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Databricks**](#databricks) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Databricks** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter the **workspace URL**. Confirm the preview URL if the wizard shows one. Paste the token into the **Bearer** field. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Databricks** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the token was created in the **same workspace** as the URL you entered. Tokens are not portable between workspaces. A workspace admin has disabled personal access tokens. Either re-enable them or authenticate with a **service principal**. The token belongs to a non-admin account and is returning only what that account can see. Recreate it from a workspace admin. This is expected if the workspace does not use Unity Catalog. Iru collects Unity Catalog data only when it is present. The token's **Lifetime** has elapsed. Generate a new one and reconnect. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Datadog Source: https://docs.iru.com/en/compliance/sources/datadog-source Connect Datadog to Iru Compliance with API and application key credentials to collect monitor configuration, user inventory, and security-posture evidence. ### About Datadog The **Datadog** connector reads account configuration and security-oriented data: monitors, users and teams, integrations posture, and related settings. You can attach this evidence to controls in Iru Compliance. Transport uses Datadog’s HTTP APIs with your **API key** (`DD-API-KEY`). Some read paths may also require an **application key** (`DD-APPLICATION-KEY`); the in-product wizard reflects what Iru needs for your tenant. ### How It Works Datadog separates keys by purpose: * **API keys** authenticate data plane traffic and many configuration reads via `DD-API-KEY`. * **Application keys** pair with API keys for certain configuration APIs via `DD-APPLICATION-KEY`. The connector focuses on **read** operations for compliance evidence. **Iru does not ship custom metrics or logs** into Datadog as part of this source. | Detail | Value | | ------------------ | ------------------------------------------------------------------------------------------------------ | | **Category** | Monitoring | | **Authentication** | API key (and application key when required) | | **Region** | Datadog is **region-specific** (US, EU, and so on). Use the org and endpoints that match your account. | Documentation: [API and application keys](https://docs.datadoghq.com/account_management/api-app-keys/), [Authentication](https://docs.datadoghq.com/api/latest/authentication/), [Rate limits](https://docs.datadoghq.com/api/latest/rate-limits/). ### Prerequisites * **Org Admin** (or equivalent) access to create keys in Datadog. * Awareness of your **Datadog site** (`datadoghq.com`, `datadoghq.eu`, FedRAMP variants, and so on). ### Connect Datadog to Iru Complete this tab before you connect the source in Compliance. Open your org’s Datadog URL (for example **`app.datadoghq.com`**, **`app.datadoghq.eu`**, or your **FedRAMP** / **Gov** host). Sign in with a role that can manage **Organization Settings**. From the left nav or avatar menu, choose **Organization Settings** (sometimes under **Access** or **Administration**, depending on layout). Select **API Keys**. You should see existing keys and a control to create a new one (path similar to **Organization Settings** → **API Keys**). Select **New Key**. Enter a name such as **Iru Compliance** and create the key. Datadog caps **API keys per organization** (commonly **50**). Delete unused keys if you are near the limit. **Copy** the key value immediately and store it like a password until you paste it in **Iru Compliance**. Datadog may show the full value only at creation. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Datadog**](#datadog) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Datadog** (set **Category** to **Monitoring** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. When the wizard asks for it, paste your Datadog **API key**. If the wizard asks for an **application key**, create one in Datadog under **Organization Settings** → **Application Keys**, then paste it (and the API key if asked again) in the wizard. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Datadog** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Validate the API key string. Confirm you are using keys from the **same org and site** your tenant expects. Some endpoints require **both** API and application keys. Supply both if prompted. Back off and retry; large accounts may need wider sync windows. Check Datadog’s rate-limit headers on failing calls. Align endpoints with your Datadog site (US vs EU vs other). ### Considerations API keys **do not auto-expire**. Rotate on your own schedule and update Iru when you rotate. Rate limits vary by endpoint; initial backfills can take time on busy organizations. Evidence reflects APIs your keys can access. Least-privilege keys may intentionally return narrower data. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Deel Source: https://docs.iru.com/en/compliance/sources/deel-source Connect Deel to Iru Compliance with a scoped organization API token to collect worker roster, organization structure, and time-off records for onboarding and offboarding evidence. ### About Deel Iru reads **workers**, **organization and legal entity structure**, and **time-off records** from the Deel API. Authentication uses an **organization API token** created in the **Developer Center** in your Deel dashboard. Tokens are **scope-bound** at creation. Grant only the **read** scopes your controls require. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_TOKEN ``` Deel authenticates with a **Bearer** token against `https://api.letsdeel.com/rest`. There is no subdomain to configure. Deel offers **organization** and **personal** tokens. A **personal token** is tied to the person who created it and **expires when that person leaves your company**, which can stop evidence collection without warning, including during offboarding. An **organization token** is not tied to an individual and does not expire. Use an organization token. | Detail | Value | | ------------------ | ------------------------------- | | **Category** | HRIS | | **Authentication** | Bearer (organization API token) | Official references: [Authentication](https://developer.deel.com/api/authentication), [How to use the Deel API](https://help.letsdeel.com/hc/en-gb/articles/8801712601233-How-To-Use-Deel-API). ### Prerequisites * An **Org Admin** or **IT Developer Admin** role in Deel. Only these roles can generate API tokens. * Decide which scopes to grant. Deel scopes are read-specific, so you can collect roster and offboarding evidence without exposing compensation data. ### Connect Deel to Iru Complete this tab before you connect the source in Compliance. Sign in to Deel as an **Org Admin** or **IT Developer Admin**. Go to **Apps & Integrations** → **Developer Center**. Select **Create API Token** and choose **Organization** as the token type. Do not choose **Personal**. A personal token expires when its owner leaves the company. Enter a token name such as **Iru Compliance**, then continue. Select **read-only** scopes covering the evidence you need: `people:read` for the worker roster, `organizations:read` for legal entity and org structure, and `time-off:read` if a control depends on leave records. Grant `payslips:read` only if a control requires payroll data. Select **Generate**, then copy the token value **once** while Deel displays it. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Deel**](#deel) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Deel** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Deel** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Your Deel role is not **Org Admin** or **IT Developer Admin**. Ask someone with one of those roles to generate the token. Confirm the token is complete and has not been revoked, and check that the value was not truncated on copy. The token lacks the matching read scope. Deel scopes are fixed at creation. Generate a new token with the scopes you need. A **personal** token was used and expired with its owner. Replace it with an **organization** token. ### Considerations Use an **organization** token, not a **personal** token. Personal tokens expire when their owner leaves the company and can stop evidence collection during offboarding. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # DigitalOcean Source: https://docs.iru.com/en/compliance/sources/digitalocean-source Connect DigitalOcean to Iru Compliance with a scoped personal access token to collect Droplet inventory, networking, and team-account metadata as evidence. ### About DigitalOcean Iru reads **Droplets**, **VPCs**, **firewalls**, **team** membership, and **account** settings via the DigitalOcean API using a **personal access token** as a **Bearer** credential. ### How It Works ```http theme={null} Authorization: Bearer YOUR_TOKEN ``` | Detail | Value | | ------------------ | ------------------------------ | | **Category** | Developer tools | | **Authentication** | Personal access token (Bearer) | Official references: [Personal access tokens](https://docs.digitalocean.com/reference/api/create-personal-access-token/), [API reference](https://docs.digitalocean.com/reference/api/api-reference/). ### Prerequisites * Access to **API** token creation for your team. ### Connect DigitalOcean to Iru Complete this tab before you connect the source in Compliance. Open [cloud.digitalocean.com](https://cloud.digitalocean.com) and sign in with a team member who can create **API** tokens. In the **Control Panel**, open **API** from the left navigation or account menu (labels vary slightly by DO UI version). Select **Generate New Token** (or **Create token**) to begin the token wizard. Enter a name such as **Iru Compliance**. Set **expiration** if your policy requires it; otherwise choose the shortest practical lifetime your team allows. Enable **read** (or read-only) scopes for each resource class Iru must evidence, commonly **Droplets**, **VPC**, **Firewalls**, **Account**, and related objects your controls reference. Create the token and **copy** it once. DigitalOcean shows it only at creation. Store it in a vault until you paste it into Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**DigitalOcean**](#digitalocean) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **DigitalOcean** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **DigitalOcean** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Token copied fully; not revoked. Create a new token with broader **read** scopes. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Docusign Source: https://docs.iru.com/en/compliance/sources/docusign-source Connect Docusign to Iru Compliance using OAuth JWT Grant with an integration key, RSA keypair, and consent to collect envelope and account evidence. ### About Docusign Iru calls the **eSignature REST API** using **OAuth 2.0 JWT Grant**: you register an **Integration Key** (**client ID**), upload an **RSA public key**, grant **impersonation consent** for a service user, and Iru exchanges a **signed JWT** for **access tokens**. This suits **server-to-server** automation without interactive consent each hour. ### How It Works DocuSign supports several OAuth 2.0 grant types; for Iru’s **server-to-server** connector, **JWT Grant** is the right model: you create an **Integration Key** (**client ID**), configure an **RSA keypair**, grant **impersonation consent** once for the user Iru acts as, and Iru exchanges a **signed JWT** for **access tokens** against the eSignature REST API. | Detail | Value | | ------------------ | ------------------- | | **Category** | Productivity | | **Authentication** | OAuth 2.0 JWT Grant | High-level steps: **Apps and Keys** → create **Integration Key** → **JWT** auth → generate or upload **RSA** → capture **Integration Key**, impersonated user **GUID**, **account base URI**, and **private key** per Iru’s wizard. Official references: [Platform auth](https://developers.docusign.com/platform/auth/), [JWT Grant](https://developers.docusign.com/platform/auth/jwt/jwt-get-token/), [Build integration](https://developers.docusign.com/platform/build-integration/), [eSignature REST](https://developers.docusign.com/docs/esign-rest-api/). ### Prerequisites * **Administrator** access in Docusign. * **developers.docusign.com** access to manage integrations. * Clear choice of **demo** vs **production** keys and OAuth hosts (`account-d.docusign.com` vs `account.docusign.com`). ### Connect Docusign to Iru Complete this tab before you connect the source in Compliance. Sign in to the correct Docusign environment (**demo** vs **production**). Open **Settings** → **Apps and Keys** (wording can vary slightly by account type). Select **Add App and Integration Key** (or **Create app**). Name the app so operators recognize it (for example **Iru Compliance**). Copy the **Integration Key**; this is your OAuth **client ID** for JWT. In the app’s authentication settings, enable **JWT Grant** for server-to-server use. Save changes if Docusign prompts you. Under **Service Integration**, choose **Generate RSA** (or upload your public key per Docusign’s docs). Download the **private key** immediately and store it in a vault. You cannot retrieve the private key from Docusign later. Open the **consent URL** Docusign provides for JWT (scopes typically include **`signature`** and **`impersonation`**). Sign in as the **user to impersonate** and click **Allow**. Complete any redirect your app registration requires. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Docusign**](#docusign) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Docusign** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. In the wizard, paste the **Integration Key** (**client ID**) and the impersonated user **ID** (**GUID**) for the account Docusign should act as. Paste the **RSA private key** and the **REST base URI** for your account (for example `https://na4.docusign.net/restapi`). If you are unsure of the base URI, discover it via **`/oauth/userinfo`** as Docusign documents. **Submit** the configuration (match the label in your wizard; the vendor flow calls this **Submit the configuration**). When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Docusign** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Finish browser consent for impersonation. Private key matches uploaded public key; server clock accurate. Resolve regional **`restapi`** host from Docusign account metadata. Keys and OAuth hosts must match the environment. ### Considerations Access tokens expire about hourly - **JWT Grant** re-runs automatically; protect the **RSA private key** like a production secret. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Doppler Source: https://docs.iru.com/en/compliance/sources/doppler-source Connect Doppler to Iru Compliance with a service or personal API token to collect project, environment, and secret-metadata evidence. ### About Doppler Iru calls the Doppler API with a **Bearer** token (**Service Token** or **Personal Token**). Evidence includes **projects**, **environments**, **secret metadata** (names, versions, change history), and **team** structure. Iru does **not** retrieve or store **plaintext secret values** - only metadata needed for compliance visibility. ### How It Works ```http theme={null} Authorization: Bearer YOUR_TOKEN ``` | Detail | Value | | ------------------ | ---------------------------------- | | **Category** | Developer tools | | **Authentication** | Bearer token (Service or Personal) | * **Service Token**: Scoped to a **specific project and config**; use for narrow audits. * **Personal Token**: Follows your user’s access across projects; use for org-wide visibility. Official references: [Authentication](https://docs.doppler.com/reference/auth), [API reference](https://docs.doppler.com/reference/api), and [API tokens](https://docs.doppler.com/docs/api-tokens). ### Prerequisites * Doppler access to the projects and environments your program covers. ### Connect Doppler to Iru Complete this tab before you connect the source in Compliance. Open the [Doppler dashboard](https://dashboard.doppler.com) and sign in with a user who can create **API** tokens for the workplace or project Iru will read. Navigate to **API** for your workplace (URL pattern similar to `https://dashboard.doppler.com/workplace/api`). Select **Generate Token** (or **Create token**) to open the creation form. Enter a label such as **Iru Compliance** so you can revoke the correct credential during audits. Pick **Service Token** when you want a narrow, project/config-scoped secret, or **Personal Token** when the integration should inherit **your** user access. Align the choice with least-privilege policy. Generate the token and **copy** it once. Doppler shows it only at creation. Tokens do not expire unless revoked; keep them in a secrets manager until you paste into **Iru Compliance**. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Doppler**](#doppler) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Doppler** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer token** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Doppler** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. No extra spaces; confirm the token was not revoked in Doppler. **Service Tokens** are single-project - use a **Personal Token** or additional scoped tokens per project. Revoke in Doppler, issue a new token, update Iru. ### Considerations If a **Personal Token**’s user loses workspace access, the token stops working - reconnect with an active account. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Drupal Source: https://docs.iru.com/en/compliance/sources/drupal-source Connect Drupal to Iru Compliance over JSON:API using HTTP Basic Auth with a read-only service account to collect site, user, and role configuration evidence. ### About Drupal Iru consumes **Drupal core JSON:API** (`/jsonapi`) for **content types**, **nodes**, **users**, **roles**, and related metadata. **Drupal 8.7+** ships JSON:API in core - enable it under **Extend**. Authentication uses **HTTP Basic** (**username** + **password**). Serve the site over **HTTPS** so credentials are not sent in clear text. ### How It Works ```http theme={null} Authorization: Basic base64(username:password) ``` | Detail | Value | | ------------------ | ------------------- | | **Category** | Developer tools | | **Authentication** | Basic (Drupal user) | Official references: [JSON:API module](https://www.drupal.org/docs/core-modules-and-themes/core-modules/jsonapi-module), [Permission model](https://www.drupal.org/docs/administering-a-drupal-site/managing-users). ### Prerequisites * **JSON:API** enabled; **`https://YOUR_HOST/jsonapi`** returns resource discovery JSON. * Drupal user whose role may **GET** the bundles you care about. ### Connect Drupal to Iru Complete this tab before you connect the source in Compliance. Sign in to your Drupal site with a user who can install modules and change configuration (**Administrator** or equivalent). Go to **Manage** → **Extend** (or **Administration** → **Extend**, depending on your admin theme). Locate the **JSON:API** module. Enable it and apply any configuration import or cache rebuild Drupal prompts for. Ensure the integration user or role Iru will use can **GET** JSON:API resources your controls need (often **Anonymous** is too broad; prefer a dedicated service account with minimal read). In a browser or with `curl`, request your site’s discovery document (for example **`https://YOUR_HOST/jsonapi`**) and confirm Drupal returns JSON (not **403** or **404**). Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Drupal**](#drupal) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Drupal** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **hostname** only (for example **`cms.example.com`**). Confirm variables if the wizard shows a preview. Enter **username** and **password** for the integration account. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Drupal** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Enable JSON:API module. Grant **view** permissions on relevant entity types. Correct password; Drupal is case-sensitive. ### Considerations Prefer a **read-only** service account scoped to required content types. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Elastic Load Balancing (ELB) Source: https://docs.iru.com/en/compliance/sources/elastic-load-balancing-elb-source Connect Elastic Load Balancing to Iru Compliance with a cross-account IAM role to collect ALB, NLB, and Classic Load Balancer configuration and listeners. ### About Elastic Load Balancing (ELB) The **Elastic Load Balancing** connector inventories **listeners**, **rules**, **target groups**, and **health checks** for **Application**, **Network**, and **Classic** load balancers. Iru uses **`sts:AssumeRole`** with your **IAM role** and an **external ID** (no traffic manipulation), metadata only. ### How It Works Iru runs in its own AWS account. To read **Elastic Load Balancing** configuration in your account, you create an **IAM role** with a **trust policy** (**`sts:AssumeRole`** + wizard **External ID**) and read-only **`elasticloadbalancing:`** (and supporting **`ec2:Describe*`** where needed). You paste the role’s **ARN** back into Iru. Attach **`ElasticLoadBalancingReadOnly`**, or use the inline policy below (`elasticloadbalancing:Describe*` plus supporting **`ec2:Describe*`** calls ELB consoles typically need). | Detail | Value | | ------------------ | ---------------------- | | **Category** | Developer tools | | **Authentication** | Cross-account IAM role | ### Prerequisites * IAM admin rights in the account that owns load balancers. * Connector **principal** + **external ID** from Iru. ### Connect Elastic Load Balancing to Iru Start here: open the source wizard and copy the **trust policy** (and note the **external ID**). When you are ready to create the role in AWS, switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). After you have the **Role ARN**, return to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru) below. #### Get the trust policy from Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Elastic Load Balancing** or **AWS ELB** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. Leave the **Iru is requesting access to external services** wizard tab open. Copy the **trust policy** exactly as shown in the wizard. The JSON below is an **example** of the shape IAM expects for the role **Trust policy** editor (full document with `Version` and `Statement`). **Always use the principal and external ID from your live wizard** if they differ. ```json copy=false lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::753695775620:role/IruConnect" }, "Condition": { "StringEquals": { "sts:ExternalId": "YOUR_EXTERNAL_ID" } }, "Action": "sts:AssumeRole" } ] } ``` Keep the Iru wizard tab open for reference, then switch to the [**AWS**](#aws) tab and follow [**Create the IAM role in AWS**](#create-the-iam-role-in-aws). #### Submit the role ARN in Iru Finish the [**AWS**](#aws) tab first (through [**Create the IAM role in AWS**](#create-the-iam-role-in-aws)) so you have the **Role ARN** from the new role. In the wizard tab from Iru, paste the **Role ARN** you copied from AWS into the field the wizard provides. Click **Submit Role**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **AWS ELB** card is **Active**. Complete [**Get the trust policy from Iru**](#get-the-trust-policy-from-iru) on the [**Iru Compliance**](#iru-compliance) tab before you create this role. Use the **external ID** and trust policy from the live wizard when you configure **Trusted entity**. #### Create the IAM role in AWS Open **IAM** → **Roles** → **Create role**. Choose **AWS account** → **Another AWS account**. Enter **`753695775620`** (or the ID Iru shows). Enable **Require external ID** and paste the external ID from Iru. Attach **`ElasticLoadBalancingReadOnly`**, **or** attach this **inline policy**: ```json lines theme={null} { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "elasticloadbalancing:Describe*", "ec2:DescribeInstances", "ec2:DescribeSecurityGroups", "ec2:DescribeSubnets", "ec2:DescribeVpcs" ], "Resource": "*" } ] } ``` Name the role, create it, and copy the **Role ARN**. Switch back to the [**Iru Compliance**](#iru-compliance) tab and complete [**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru). Continue on the [**Iru Compliance**](#iru-compliance) tab to paste the **Role ARN** and finish the wizard ([**Submit the role ARN in Iru**](#submit-the-role-arn-in-iru)). ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Fix external ID typos. Ensure Describe coverage spans the balancer generations you still run. ### Considerations Inventory work is **Regional**, so every enabled Region may be queried. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Envoy Source: https://docs.iru.com/en/compliance/sources/envoy-source Connect Envoy to Iru Compliance through OAuth to collect visitor logs, invites, locations, and employee directory metadata as physical-security evidence. ### About Envoy Iru reads **visitor entry logs**, **invites**, **locations**, and **employee** directory metadata via Envoy’s API using **OAuth 2.0** (**authorization code**). Typical scopes include **`entry_logs.read`**, **`invites.read`**, **`locations.read`**, **`employees.read`**, plus **`refresh_tokens`** so Iru can rotate access tokens without repeated logins. ### How It Works Iru uses Envoy’s **OAuth 2.0 authorization code** flow. When you enable the source, a **browser popup** redirects to Envoy’s authorization server. You sign in, review scopes, and grant access; Envoy returns a code that Iru exchanges for an **access token** and **refresh token**. | Detail | Value | | ------------------ | ------------------------------------ | | **Category** | Productivity | | **Authentication** | OAuth 2.0 | | **Typical plans** | Premium or Enterprise for API access | Official references: [Developer hub](https://developers.envoy.com/hub/docs), [Authorization](https://developers.envoy.com/hub/docs/authorization), [Scopes](https://developers.envoy.com/hub/docs/scopes). ### Prerequisites * **Admin** or **Global Admin** in Envoy. * Browser **popups** enabled. ### Connect Envoy to Iru Complete this tab before you enable **Envoy** in **Iru Compliance**, so the right administrator completes OAuth. Open your Envoy dashboard (for example [dashboard.envoy.com](https://dashboard.envoy.com) or the URL your workplace uses) and sign in with **Admin** or **Global Admin** rights. Envoy’s developer APIs require a plan that exposes the scopes Iru requests. Confirm your subscription matches **Prerequisites** in this article. Skim [Envoy authorization](https://developers.envoy.com/hub/docs/authorization) and [Scopes](https://developers.envoy.com/hub/docs/scopes) so the consent screen matches your security review. In the browser profile you will use for Compliance, allow **pop-ups** for your **Iru** hostname so the Envoy OAuth window is not blocked. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Envoy**](#envoy) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Envoy** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. In the OAuth popup, complete Envoy login if you are prompted. In Envoy’s OAuth popup, click **Authorize** (or the equivalent approval control). When the popup closes and Iru finishes the token exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Envoy** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Allow popups for your Iru origin; retry. Insufficient Envoy role - use Admin/Global Admin. **Standard** plan may lack API - upgrade per Envoy licensing. Deactivated admin - **re-authorize** with an active account. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Figma Source: https://docs.iru.com/en/compliance/sources/figma-source Connect Figma to Iru Compliance through OAuth to collect organization, team, file, and library inventory along with member and access-control evidence. ### About Figma Iru uses **OAuth 2.0** (**authorization code**). When you enable the source, a **browser popup** sends you to Figma to sign in and approve scopes (files, projects, org, teams, components, webhooks, analytics, etc.). Some scopes (**for example `variables:read`**) require **Enterprise** - lower tiers simply omit those datasets rather than failing outright. ### How It Works Iru uses Figma’s **OAuth 2.0 authorization code** flow. When you turn the source on, a **browser popup** sends you to Figma; you sign in, review scopes, and grant access. Figma returns an **authorization code** that Iru exchanges for an **access token** (and refresh where applicable). | Detail | Value | | -------------------- | ------------------------------------------------- | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 | | **Recommended plan** | Organization or Enterprise for broad API coverage | Representative scopes include **`files:read`**, **`projects:read`**, **`org:read`**, **`org_teams:read`**, **`components:read`**, **`webhooks:write`** (for incremental updates), and **`analytics:read`** - exact lists follow the Figma authorization screen. Official references: [Authentication](https://www.figma.com/developers/api#authentication), [Scopes](https://www.figma.com/developers/api#scopes), [REST API](https://www.figma.com/developers/api). ### Prerequisites * **Admin** or **Owner** on the Figma **organization** you want Iru to read. ### Connect Figma to Iru Complete this tab before you enable **Figma** in **Iru Compliance**, so the right org member completes OAuth. Open [figma.com](https://www.figma.com) and sign in with an **Admin** or **Owner** on the **organization** Iru should read. Open **teams**, **projects**, and **files** your compliance program expects in evidence. Enterprise-only scopes (for example some **variables** reads) require the right plan and role. Skim [Figma authentication](https://www.figma.com/developers/api#authentication) and [Scopes](https://www.figma.com/developers/api#scopes) so the consent screen matches your expectations. In the browser profile you will use for Compliance, allow **pop-ups** for your **Iru** hostname so the Figma OAuth window is not blocked. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Figma**](#figma) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Figma** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Start the OAuth flow from the connector wizard (after pop-ups are allowed). Complete Figma login if prompted. Review the scopes and select **Allow access** (or **Authorize**). When the Figma popup closes and Iru finishes the OAuth exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Figma** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Allow popups for Iru; toggle source off/on. Authorize with **Org Admin**/**Owner**; Editors may lack org scopes. Re-authorize with a user who can access those teams/projects. Re-run the OAuth flow from Iru. ### Considerations Removing the authorizing user from the org can invalidate access - reconnect with a durable admin account. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Fivetran Source: https://docs.iru.com/en/compliance/sources/fivetran-source Connect Fivetran to Iru Compliance using HTTP Basic Auth with your REST API key and secret to collect connector, destination, and group-membership evidence. ### About Fivetran Iru reads **connector** definitions, **destination** settings, **team** membership, and **audit** logs via the Fivetran REST API. **HTTP Basic** authentication uses the **API key** as **username** and the **API secret** as **password**. ### How It Works Fivetran’s REST API uses **HTTP Basic**: the **API key** is the **username**, the **API secret** is the **password**, and the pair is sent as **`Authorization: Basic base64(key:secret)`** on each request. Keys are created in the Fivetran account and inherit that account’s readable resources. | Detail | Value | | ------------------ | ----------------------------------------------- | | **Category** | Analytics | | **Authentication** | Basic (API key + secret) | | **Typical plan** | Starter or higher (per Fivetran product policy) | Official references: [Authentication](https://fivetran.com/docs/rest-api/api-config#authentication), [REST API](https://fivetran.com/docs/rest-api), [API config](https://fivetran.com/docs/rest-api/api-config). ### Prerequisites * **Account Administrator** or **Owner** (or equivalent) to generate API credentials. ### Connect Fivetran to Iru Complete this tab before you connect the source in Compliance. Open the [Fivetran dashboard](https://fivetran.com/dashboard) and sign in with an **Account Administrator** or **Owner** (or equivalent) who can view API credentials. Open your **avatar** or **account** menu, then choose **API Key**, **Account settings**, or **API Config** (exact labels depend on Fivetran UI; you are looking for the REST API key and secret pair). If a key already exists and your policy allows reuse, open **View** or **Show** for that key. Otherwise start **Generate** / **Create** to mint a new key and secret pair. Copy the **API key** string to your vault first. Some screens hide the key after you navigate away. Copy the **API secret** when Fivetran displays it. The secret is shown **only once**; if you regenerate it, update Iru immediately or the connection will fail. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Fivetran**](#fivetran) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Fivetran** (set **Category** to **Analytics** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **API Key** in **Username** and **API Secret** in **Password**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Fivetran** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Exact copy of key/secret; confirm key was not regenerated elsewhere. Elevate account role (Administrator/Owner). Regenerate pair in Fivetran, update Iru immediately. ### Considerations Fivetran applies **rate limits** - large backfills may pace over time. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Freshsales Source: https://docs.iru.com/en/compliance/sources/freshsales-source Connect Freshsales to Iru Compliance with an API key and bundle alias to collect user roles, permission matrices, and territory-based access controls. ### About Freshsales Iru reads **users with their roles**, **roles with permissions**, **territories**, and **field-level permissions for sensitive data** from the Freshsales (Freshworks CRM) API. Authentication uses an **API key** together with your **bundle alias**, both found under **Profile Settings** → **API Settings**. Requests target `https://YOUR_BUNDLE_ALIAS.myfreshworks.com/crm/sales/api`. The connector wizard collects the **API key** first, then the **bundle alias**. Freshsales and **Freshservice** are different products with **different authentication schemes**. If you are connecting IT service management data, use the [Freshservice](/en/compliance/sources/freshservice-source) article instead. ### How It Works ```http theme={null} Authorization: Token token=YOUR_API_KEY ``` Freshsales does **not** use Basic auth or a Bearer prefix. The key goes in the `Authorization` header in the literal form `Token token=YOUR_API_KEY`. The API is **unversioned**. There is no version header or dated revision. The **bundle alias** selects which CRM account to read when your Freshworks organization has more than one. That is why the field is required. An API key is **per user** and inherits **exactly that user's role**, with no per-endpoint scopes. | Detail | Value | | ------------------ | ------------------------------ | | **Category** | CRM | | **Authentication** | Token (API key + bundle alias) | Official references: [Freshworks CRM API](https://developers.freshworks.com/crm/api/). ### Prerequisites * Your **bundle alias** and **API key**, both on the same **API Settings** page. * A **dedicated admin-level CRM user** to generate the key from. The key inherits that user's role and has no scopes, so a key from a sales user with territory restrictions returns an incomplete permission picture. ### Connect Freshsales to Iru Complete this tab before you connect the source in Compliance. Sign in to your Freshsales account as the **admin-level user** whose access the integration should inherit. Select your **profile picture** in the top-right corner, then **Profile Settings**. Select the **API Settings** tab. Copy the value shown under **Your API key**. Copy the **Bundle alias**, shown on the same tab just below the API key. If your organization has only one CRM account this is still required. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Freshsales**](#freshsales) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Freshsales** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. The first wizard step is **Enter API Key (Authorization)**. Paste the API key into the **Authorization** field. The wizard shows the header format `Token token=`. Click **Submit API Key**. Enter the **bundle alias** only (for example `acme`, not the full `myfreshworks.com` URL). Confirm the preview URL if the wizard shows one. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Freshsales** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the API key is complete and that the **bundle alias** matches the CRM account the key belongs to. A valid key against the wrong bundle host fails the same way an invalid key does. The two products issue different credentials and authenticate differently. A Freshservice key will not work here. The key belongs to a user whose own role cannot see them. Regenerate from an admin-level user. The bundle alias is the subdomain only. Do not include `https://` or `.myfreshworks.com`. ### Related Articles Browse and manage every Compliance source. Connect Freshservice for ITSM evidence. Frameworks, actions, and **Artifacts**. Upload, review, and organize evidence from sources and actions. # Freshservice Source: https://docs.iru.com/en/compliance/sources/freshservice-source Connect Freshservice to Iru Compliance using HTTP Basic Auth with your API key as the username to collect change approvals, incident resolution times, ticket records, and CMDB asset inventory. ### About Freshservice Iru reads **tickets**, **changes** (with approval status and implementation dates), **incidents**, **problems**, **assets from the CMDB**, and **agents with their roles** from the Freshservice API v2. Authentication uses your **API key**, found under **Profile Settings**. Requests target your account domain at `https://YOUR_DOMAIN.freshservice.com/api/v2`. The connector wizard collects **Basic credentials** first, then the **domain**. ### How It Works ```http theme={null} Authorization: Basic BASE64("YOUR_API_KEY:X") ``` Freshservice uses **HTTP Basic** over HTTPS: the **username** is your **API key** and the **password** is any non-empty string, conventionally the literal `X`. Iru handles the encoding. Username-and-password Basic auth was **deprecated on May 31, 2023** and now fails, so the API key is the only supported method. An API key carries **exactly the permissions of the agent who generated it**, and there are no per-endpoint scopes. A key from a limited-permission agent returns a partial view of tickets and changes. Use a dedicated admin-level service account so evidence stays complete. | Detail | Value | | ------------------ | --------------------- | | **Category** | Support | | **Authentication** | Basic (API key + `X`) | Official references: [API v2 reference](https://api.freshservice.com/v2/), [Where to find your API key](https://support.freshservice.com/support/solutions/articles/50000000306-where-do-i-find-my-api-key-). ### Prerequisites * Your **domain** (`acme` from `https://acme.freshservice.com`). * An **admin-level agent account** to generate the key from. A personal agent account ties evidence collection to one person's permissions and breaks when they are offboarded. * Decide what is in scope. Freshservice lets you exclude ticket types, skip asset inventory, or filter by department. When underlying data is excluded, Iru marks affected controls as unable to verify. ### Connect Freshservice to Iru Complete this tab before you connect the source in Compliance. Sign in to `https://YOUR_DOMAIN.freshservice.com` as the **admin-level agent** whose permissions the integration should inherit. Select your **profile avatar** in the top right, then **Profile Settings**. Locate **Your API Key** on that page and copy it. Freshservice displays the key on the profile page rather than generating a new one each time, so you can return for it later. The **password** for Basic auth is the literal `X`. Enter it in Iru, not in Freshservice. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Freshservice**](#freshservice) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Freshservice** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. The first wizard step is **Enter Basic Authentication**. Enter **Username** = your **API key** and **Password** = `X` (literal). The password field is not validated by Freshservice. Any non-empty dummy value works. Click **Submit Credentials**. Enter the **domain** only (for example `acme`, not the full URL). Confirm the preview URL if the wizard shows one. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Freshservice** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. An email address and password were used instead of the API key. That method was removed on May 31, 2023. Use the key as the **username**. Paste the full API key and confirm the **password** field contains a non-empty value such as `X`. An empty password fails. The agent who generated the key lacks permission for changes, assets, or problems. Regenerate from an admin-level agent. Either the CMDB is out of scope for this connection or the agent cannot read assets. Iru cannot tell those cases apart. Fix the **domain** and reconnect. The domain is the subdomain only, not the full URL. ### Related Articles Browse and manage every Compliance source. Connect Freshsales for CRM evidence. Frameworks, actions, and **Artifacts**. Upload, review, and organize evidence from sources and actions. # GitHub Source: https://docs.iru.com/en/compliance/sources/github-source Connect GitHub to Iru Compliance with a personal access token to collect repository inventory, branch protection, organization membership, and audit logs. ### About GitHub The **GitHub** connector reads repository metadata, branch protection, team membership, organization settings, audit logs, and related security configuration from your **GitHub organization**. That data appears in Iru Compliance as artifacts you can map to actions and controls. The integration is **read-only**. Iru does not open pull requests, change settings, or modify repositories beyond what the GitHub API allows for the scopes you grant. ### How It Works Iru calls the GitHub REST API using a **personal access token (PAT)** sent as a **Bearer** token: ```http theme={null} Authorization: Bearer github_pat_XXXX ``` **Fine-grained PATs** (recommended) let you scope repositories and permissions narrowly. **Classic PATs** work but are broader and harder to least-privilege. If your organization enforces **SAML SSO**, you must **authorize** the PAT for the organization after you create it, or API calls for org-level data will fail. | Detail | Value | | ------------------ | --------------------------------------------------------------------------------------------------------- | | **Category** | Developer tools | | **Authentication** | Bearer token (fine-grained or classic PAT) | | **GitHub plan** | Compatible with GitHub Free, Team, or Enterprise (subject to GitHub’s own API and audit-log availability) | Official references: [Managing personal access tokens](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens), [REST authentication](https://docs.github.com/en/rest/authentication/authenticating-to-the-rest-api), and [Rate limits](https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api). ### Prerequisites * GitHub access as a member (or owner) of the organization you want Iru to read. * **Owner** access on that organization if you need audit logs and org-wide security settings (depending on what your compliance program expects). * A PAT with **read** permissions aligned to the tables below (fine-grained PAT shown). **Minimum fine-grained PAT permissions (typical)** | Area | Permissions | | ---------------- | ------------------------------------------------------------------- | | **Repository** | **Contents** (read), **Metadata** (read), **Administration** (read) | | **Organization** | **Members** (read), **Administration** (read) | Adjust upward only if your controls require additional read scopes. ### Connect GitHub to Iru #### Create a fine-grained personal access token Sign in to GitHub. Select your profile picture → **Settings** → **Developer settings** → **Personal access tokens** → **Fine-grained tokens**. Select **Generate new token**. Set a clear **name** (for example **Iru Compliance**) and an **expiration** (fine-grained PATs can run up to **366 days** - set a reminder to rotate early). Under **Resource owner**, choose your **organization** when you need organization-level data. Under **Repository access**, choose **All repositories** or only what compliance covers. Under **Permissions**, enable at least the repository and organization **read** permissions listed under **Prerequisites** above. Generate the token and copy it immediately. It is shown once. If your org uses **SAML SSO**, open **Settings** → **Developer settings** → **Personal access tokens**, find the token, select **Configure SSO**, and **Authorize** it for your organization. #### Complete the connector in Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **GitHub** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A new tab opens the connector wizard. When you see the bearer token step, paste your PAT into the **Token** field and submit. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **GitHub** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the PAT was copied in full, has not expired, and was not revoked. For org-wide reads, the PAT’s **resource owner** must be the organization - not only your personal account. Create a new PAT if needed. Authorize the PAT for SAML SSO (see **Create a fine-grained personal access token**). Regenerate the PAT with the repository and organization permissions your controls require. Authenticated REST requests share GitHub’s rate limits (see GitHub’s docs). Iru batches work within those limits; sustained spikes can delay sync. ### Considerations Prefer **fine-grained PATs** with the smallest repository set and read scopes that still satisfy your controls. Rotate PATs before expiry and update the connector so evidence collection does not stall. Iru reads metadata and configuration exposed by the APIs you allow - it does not bypass GitHub permissions your org enforces. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # GitLab Source: https://docs.iru.com/en/compliance/sources/gitlab-source Connect GitLab to Iru Compliance with a personal access token to collect project inventory, branch protection, group membership, and audit-event evidence. ### About GitLab The **GitLab** connector reads project metadata, group membership, branch protection, CI/CD configuration, and (where your plan and token allow) audit-oriented events from your **GitLab.com group** or **self-managed** instance. Data appears as artifacts in Iru Compliance for mapping to actions and controls. Iru sends credentials using GitLab’s **`PRIVATE-TOKEN`** header - typically with a **personal access token** so reads can span the groups and projects you choose. ### How It Works GitLab’s REST API authenticates with the **`PRIVATE-TOKEN`** header: ```http theme={null} PRIVATE-TOKEN: glpat-XXXXXXXXXXXXXXXXXXXX ``` Personal access tokens are usually the best fit because they can cover multiple projects and groups. Project-scoped or group-scoped tokens work but may narrow what evidence Iru can collect. | Detail | Value | | ------------------ | ---------------------------------------------------------- | | **Category** | Developer tools | | **Authentication** | `PRIVATE-TOKEN` header (personal access token recommended) | | **Hosting** | GitLab SaaS or self-managed | Documentation: [Personal access tokens](https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html), [REST authentication](https://docs.gitlab.com/ee/api/rest/authentication.html), [Token scopes](https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html#personal-access-token-scopes). ### Prerequisites * GitLab access to the **groups and projects** compliance cares about. * Group **Owner** or **Maintainer** where you need membership and audit-style reads (exact needs depend on your controls). * For **self-managed** GitLab, confirm Iru targets your instance **base URL** (not only `gitlab.com`). **Starting point for scopes** | Scope | Purpose | | ----------------- | -------------------------------------------------------------------------------- | | `read_api` | Broad read access to API endpoints used for inventory and configuration evidence | | `read_repository` | Repository metadata aligned to branch protection and repo settings | | `read_user` | User profile reads needed for membership evidence | Add scopes only when your security team requires deeper reads. ### Connect GitLab to Iru Complete this tab before you connect the source in Compliance. Open your GitLab instance (**gitlab.com** or self-managed URL) and sign in with a user who can create **personal access tokens** for the namespaces Iru should read. Select your **avatar** in the upper-right, then choose **Edit profile** (or **Preferences** on some versions). In the left sidebar of your profile, select **Access Tokens** (sometimes under **User settings** → **Access Tokens**). Select **Add new token** (or **Create personal access token**). Enter a **name** (for example **Iru Compliance**). Set an **expiration** (GitLab requires one; maximum duration may be limited by your administrator). Choose the **read** scopes listed under **Prerequisites** in this article. Create the token and **copy it immediately**. GitLab shows it once. Tokens typically begin with **`glpat-`**. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**GitLab**](#gitlab) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **GitLab** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. When the wizard asks for the **`PRIVATE-TOKEN`** value, paste your token and submit. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **GitLab** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the full token string, check expiry, and verify the account still has access to target groups. Increase scopes or elevate project/group role - your token cannot read endpoints your account cannot access. Ensure the integration points at your instance hostname and that network paths allow Iru’s outbound calls. Some audit APIs require **Premium/Ultimate** features - compare your GitLab tier to the evidence your framework expects. ### Considerations Tokens expire on a schedule - rotate early and update the connector. GitLab applies **rate limits**; large groups may take longer during first sync. Iru reads configuration exposed by the API - it does not rewrite pipelines or repository settings. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Google Cloud Platform Source: https://docs.iru.com/en/compliance/sources/google-cloud-sources Connect Google Cloud Platform to Iru Compliance using a read-only service account and JSON key to collect IAM, storage, logging, and network evidence. ### About Google Cloud Platform Iru connects to your **Google Cloud** project with a **service account** and a **JSON key**. Create the account once, grant the **read-only** roles you need, then upload the key in Iru. Iru collects configuration and inventory evidence. It does **not** change resources in your project. ### How It Works Iru authenticates with the service account **JSON key** you upload in the connector wizard. Grant roles at the **project** level so Iru can read resources in that project. | Detail | Value | | ------------------ | ------------------------ | | **Category** | Cloud infrastructure | | **Authentication** | Service account JSON key | #### What Iru collects | Source | Evidence Iru collects | | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | | Google BigQuery | Dataset and table inventory, dataset access, encryption, and expiration settings | | Google Cloud IAM | Principals, service accounts, custom roles, and role bindings across the resource hierarchy | | Google Cloud Key Management Service | Key rings and keys, including protection level, rotation schedule, and state | | Google Cloud Logging | Log sinks, retention settings, and admin activity records (excluding logs with private contents) | | Google Cloud Storage | Bucket inventory and settings such as public access prevention, uniform bucket-level access, versioning, retention, encryption, and access logging | | Google Compute Engine | VPC networks, subnets, firewall rules, and routes | #### Read-only roles Add each role you need. All of these roles are read-only. | Role | Role ID | What it covers | | ---------------------- | ----------------------------- | ---------------------------------------------------------------------------------- | | Security Auditor | `roles/iam.securityAuditor` | IAM: resources, folder and project hierarchy, policies, and security configuration | | BigQuery Data Viewer | `roles/bigquery.dataViewer` | BigQuery: datasets and their contents | | Cloud KMS Viewer | `roles/cloudkms.viewer` | Cloud KMS: get and list on keys and key rings | | Compute Network Viewer | `roles/compute.networkViewer` | Compute Engine: read-only networking resources | | Logs Viewer | `roles/logging.viewer` | Cloud Logging: view logs except those with private contents | | Storage Bucket Viewer | `roles/storage.bucketViewer` | Cloud Storage: buckets and metadata (excluding IAM policies) | Official references: [Service accounts](https://cloud.google.com/iam/docs/service-account-overview), [Create service account keys](https://cloud.google.com/iam/docs/keys-create-delete), [Organization policies for service accounts](https://docs.cloud.google.com/iam/docs/service-accounts-custom-constraints). ### Prerequisites * Permission in Google Cloud to create **service accounts** and **service account keys** in the project you want Iru to monitor (for example **Service Account Admin** and **Service Account Key Admin**). * **Admin** access to the Iru web app. * The Google Cloud **project** you want Iru to monitor. Grant roles on that project so evidence covers its resources. ### Connect Google Cloud Platform to Iru Create the service account and JSON key in **Google Cloud**, then upload the key in **Iru Compliance**. Complete this tab before you turn on **Google Cloud Platform** in **Iru Compliance**. #### Create the service account and grant roles Open the [Google Cloud console](https://console.cloud.google.com/) and select the **project** Iru should monitor. In the navigation menu, go to **IAM & Admin** → **Service Accounts**. Google Cloud console navigation showing IAM and Admin with Service Accounts selected Click **Create service account**. Enter a **Service account name** (for example **Iru Compliance**). Google fills in the service account ID and email. Click **Create and continue**. In the **Permissions** step, add each role from the [**Read-only roles**](#read-only-roles) table that you need, then click **Continue** and **Done**. Google Cloud Permissions step with Security Auditor, BigQuery Data Viewer, Cloud KMS Viewer, Compute Network Viewer, Logs Viewer, and Storage Bucket Viewer roles You can grant only the roles you need now. Adding all six means you do not have to return to the console later. #### Create and download the JSON key Go to **IAM & Admin** → **Service Accounts**, then open the account you created. Select the **Keys** tab. Click **Add key**. Google Cloud service account Keys tab with Add key for Iru Compliance Click **Create new key**. Select **JSON**, then click **Create**. The key file downloads to your computer. Create private key dialog for Iru Compliance with JSON selected Google cannot recover this file if you lose it. Anyone with the file has the service account’s access. Store it in a password manager or secrets vault, and delete your local copy after you connect the source in Iru. Some organizations limit which predefined roles an admin can grant. Build a custom role with the same read-only permissions instead: 1. Go to **IAM & Admin** → **Roles** and click **Create role**. 2. Add the permissions you need. Use the role IDs in [**Read-only roles**](#read-only-roles) as a reference for what each predefined role includes. 3. Assign the custom role to the service account instead of the predefined roles. If you prefer the CLI, run this with **gcloud** while signed in as a user who can create service accounts and keys in the project. Set `PROJECT_ID`, then run the script. ```bash theme={null} # Set these two values, then run the script. PROJECT_ID="your-project-id" SA_NAME="iru-compliance" SA_EMAIL="${SA_NAME}@${PROJECT_ID}.iam.gserviceaccount.com" gcloud config set project "$PROJECT_ID" # 1. Create the service account gcloud iam service-accounts create "$SA_NAME" \ --display-name="Iru Compliance" # 2. Bind the read-only roles at the project level for ROLE in \ roles/iam.securityAuditor \ roles/bigquery.dataViewer \ roles/cloudkms.viewer \ roles/compute.networkViewer \ roles/logging.viewer \ roles/storage.bucketViewer do gcloud projects add-iam-policy-binding "$PROJECT_ID" \ --member="serviceAccount:${SA_EMAIL}" \ --role="$ROLE" done # 3. Create the JSON key in the current directory gcloud iam service-accounts keys create iru-compliance-key.json \ --iam-account="$SA_EMAIL" ``` The script writes `iru-compliance-key.json` to the directory you run it from. Upload that file in the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Google Cloud**](#google-cloud) tab first so you have the JSON key file. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Google Cloud Platform** (set **Category** to **Cloud infrastructure** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. On the setup screen, click **Choose File** and select the JSON key you downloaded. The contents of the file appear in the field below. Click **Save**, then click **Connect**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Google Cloud Platform** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. If **Create** returns a policy error, your organization may enforce `constraints/iam.disableServiceAccountKeyCreation`. An organization policy administrator must add an exception for your project before you can download a key. See Google’s guide to [organization policies for service accounts](https://docs.cloud.google.com/iam/docs/service-accounts-custom-constraints). Confirm the JSON key belongs to the service account in the correct **project**, and that the account has the roles listed under [**Read-only roles**](#read-only-roles) for the evidence you need. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # HashiCorp Vault Source: https://docs.iru.com/en/compliance/sources/hashicorp-vault-source Connect Vault to Iru Compliance with a client token and least-privilege policy for mounts, policies, and audit configuration evidence. ### About HashiCorp Vault Iru reads **secrets engine mounts**, **auth method configuration**, **named policies**, **audit devices**, and related **sys/** metadata using the Vault HTTP API. Each request sends your **client token** in **`X-Vault-Token`**. Iru collects **configuration evidence** - not **secret plaintext** values. Works with **Vault OSS**, **Enterprise** (namespaces may need extra setup), and **HCP Vault**. ### How It Works ```http theme={null} X-Vault-Token: hvs.xxxxxxxx ``` Tokens come from any Vault **auth method** (Token, AppRole, LDAP, etc.). The wizard first stores **`vault_addr`** (for example `https://vault.example.com:8200`), then accepts the token. | Detail | Value | | ------------------ | ------------------------------ | | **Category** | Security | | **Authentication** | Client token (`X-Vault-Token`) | Official references: [Auth concepts](https://developer.hashicorp.com/vault/docs/concepts/auth), [HTTP API](https://developer.hashicorp.com/vault/api-docs), [Policies](https://developer.hashicorp.com/vault/docs/concepts/policies), [AppRole](https://developer.hashicorp.com/vault/docs/auth/approle). ### Prerequisites * A Vault cluster **reachable from Iru** (network / firewall / PrivateLink as applicable). * Permission to create a **policy** and **token** (or AppRole) with read-only **`sys/`** access as in the example below. ### Example Read-Only Policy (HCL) Save as a `.hcl` file and apply with **`vault policy write iru-compliance your-file.hcl`**. ```hcl lines theme={null} path "sys/mounts" { capabilities = ["read", "list"] } path "sys/auth" { capabilities = ["read", "list"] } path "sys/policy" { capabilities = ["read", "list"] } path "sys/policies/acl/*" { capabilities = ["read", "list"] } path "sys/audit" { capabilities = ["read", "list"] } path "auth/token/lookup-self" { capabilities = ["read"] } ``` ### Connect HashiCorp Vault to Iru #### Apply the policy and issue a token Use a jump host or admin workstation that can reach **`VAULT_ADDR`** over TLS and has the **Vault CLI** installed (`vault` binary). Sign in with your org’s supported method (**`vault login`**, OIDC, etc.) so subsequent commands run with enough privilege to write policies and create tokens. Save the example policy from above as an `.hcl` file on that machine (for example `iru-compliance.hcl`). Run **`vault policy write iru-compliance`** with your policy file path. Create a **renewable** token bound to that policy (for example **`vault token create -policy=iru-compliance -ttl=720h -renewable=true`**). Copy the **`hvs.`** token value. For production, prefer **AppRole** or another automated flow instead of long-lived static tokens. #### Complete the connector in Iru In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **HashiCorp Vault** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **`vault_addr`** (for example `https://vault.example.com:8200`) and confirm server variables when prompted. Paste the token into the **`X-Vault-Token`** field when prompted. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **HashiCorp Vault** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Refresh the wizard by toggling the source; re-enter **`vault_addr`**. Attach **`iru-compliance`** policy to the token; check **Enterprise namespaces**. Issue a new token and update Iru; enable **renewal** or use AppRole rotation. Hostname, port (**8200**), TLS, and outbound routes from Iru. **Unseal** Vault before testing. ### Considerations Vault **Enterprise** **namespaces** may require paths or settings beyond this baseline - coordinate with your Vault admins. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Heroku Source: https://docs.iru.com/en/compliance/sources/heroku-source Connect Heroku to Iru Compliance with a Platform API token to collect app, pipeline, add-on, team-access, and dyno configuration evidence for audits. ### About Heroku Iru reads **app** and **dyno** configuration, **pipelines**, **add-ons**, and **team** access metadata via the **Heroku Platform API** using a **Bearer** token (CLI authorization or account API key). ### How It Works ```http theme={null} Authorization: Bearer YOUR_TOKEN ``` | Detail | Value | | ------------------ | --------------------------- | | **Category** | Developer tools | | **Authentication** | Platform API token (Bearer) | Heroku tokens are **not** finely scoped; they inherit everything the generating account can access. Prefer a **dedicated** account with minimal team membership. Official references: [Authentication](https://devcenter.heroku.com/articles/authentication), [Platform API](https://devcenter.heroku.com/articles/platform-api-reference), [CLI](https://devcenter.heroku.com/articles/heroku-cli). ### Prerequisites * Access to the **Heroku CLI** **or** dashboard **API Key** section. * Awareness of **SSO**: tokens may align to shorter session windows. See Heroku docs for **`--expires-in`**. ### Connect Heroku to Iru Complete this tab before you connect the source in Compliance. Most teams use the **Heroku CLI** so the token is scoped as an **authorization**. If you cannot use the CLI, use the dashboard **API Key** path in the steps below instead. On a trusted workstation, run **`heroku login`** (or **`heroku login -i`** for CI-style flows) and complete authentication with an account that can create authorizations. Run **`heroku authorizations:create --description "Iru Compliance"`**. Default expiry is often **one year**; SSO orgs may see shorter lifetimes. Add **`--expires-in`** when your policy requires a shorter TTL. Copy the **Token** string from the command output and store it in a vault until you paste it into Iru. In the [Heroku Dashboard](https://dashboard.heroku.com), select your **avatar** → **Account settings** (or **Account**). Open the **API Key** section. Use **Reveal** to copy the existing account-wide key, or **Regenerate** to issue a new one. **Regenerate** invalidates the prior key everywhere, so update every integration that used the old key, not only Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Heroku**](#heroku) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Heroku** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Heroku** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Full token; SSO session may require a fresh authorization. Dashboard regeneration invalidates old tokens. Update Iru. Token’s account must belong to the right **teams**. ### Considerations Iru is **read-only**; no deploys, scales, or restarts. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # HiBob Source: https://docs.iru.com/en/compliance/sources/hibob-source Connect HiBob to Iru Compliance using HTTP Basic Auth with a service user ID and token to collect employee roster, lifecycle events, and organizational structure evidence. ### About HiBob Iru reads the **employee roster** (including status, start date, and termination date), **lifecycle events**, **departments and reporting lines**, and **metadata fields** from HiBob's public API. Authentication uses an **API service user** created under **Settings** → **Integrations** → **Service Users**. A service user is not an employee and cannot sign in to Bob. It exists only to authenticate API requests. ### How It Works ```http theme={null} Authorization: Basic BASE64("SERVICE-USER-ID:TOKEN") ``` HiBob uses **HTTP Basic** over HTTPS, where the **username** is the service user's **ID** and the **password** is its **token**. Iru handles the encoding. You paste the two values separately. Requests target `https://api.hibob.com/v1`; there is no subdomain to configure. Service user permissions are **granular and additive**: each data category is granted separately through a permission group, and an endpoint returns nothing until its category is granted. HiBob **discontinued API Access Tokens on October 31, 2024**. Service users are the only supported method for customer-built integrations. | Detail | Value | | ------------------ | ------------------------------- | | **Category** | HRIS | | **Authentication** | Basic (service user ID + token) | Official references: [API service users](https://apidocs.hibob.com/docs/api-service-users), [Building the authorization header](https://apidocs.hibob.com/reference/authorization), [Permissions](https://apidocs.hibob.com/reference/permissions). ### Prerequisites * A **Bob admin** account, or an admin who can generate the credentials for you. Only admins can create service users. * Ability to create a **permission group** and assign the service user to it. Creating the service user alone is not enough. Without a permission group, authentication succeeds and returns no data. ### Connect HiBob to Iru Complete this tab before you connect the source in Compliance. Sign in to Bob as an **admin**. Go to **Settings** → **Integrations** → **Service Users**. Create a **new service user**, and name it something like **Iru Compliance** so you can identify it later. Copy the **service user ID** and **token** immediately. The token is shown **only once**. If you lose it, refresh the service user's token and reconnect. Create a **permission group** (or edit an existing one) and add the new service user to it. Grant the group **read** permissions for the categories your compliance program needs. **People - Read** is the minimum for roster and offboarding evidence. Do not grant write or delete permissions. Grant **Payroll - Read** only if a control requires compensation data. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**HiBob**](#hibob) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **HiBob** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **Username** = the **service user ID** and **Password** = the **service user token**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **HiBob** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. The ID and token are mismatched or the token has been refreshed. Generate a new token in HiBob and reconnect. Confirm you have not swapped the two fields. The **ID** is the username. The service user is not in a **permission group**, or the group lacks **People - Read**. This is the most common HiBob setup issue, because authentication passes cleanly either way. These stopped working on **October 31, 2024**. Migrate to a service user. Confirm the collection includes inactive records; HiBob excludes them by default on some endpoints. ### Considerations Creating the service user alone is not enough. Without a **permission group** that includes **People - Read**, authentication succeeds and returns no employees. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Intercom Source: https://docs.iru.com/en/compliance/sources/intercom-source Connect Intercom to Iru Compliance with an access token and the regional API host that matches your workspace to collect admin, team, and conversation evidence. ### About Intercom Iru reads **contacts**, **conversation metadata**, **teams**, **tags**, and **workspace** settings through the Intercom REST API. You must pick the **regional base URL** (**US**, **EU**, or **Australia**) that matches **data residency**, then supply a **Bearer** token from the **Developer Hub** (app access token or equivalent). ### How It Works ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` | Detail | Value | | ------------------ | ------------ | | **Category** | Support | | **Authentication** | Bearer token | | Region | Base URL | | ---------------- | ---------------------------- | | **US (default)** | `https://api.intercom.io` | | **EU** | `https://api.eu.intercom.io` | | **Australia** | `https://api.au.intercom.io` | Official references: [Authentication](https://developers.intercom.com/docs/build-an-integration/learn-more/authentication), [Developer Hub](https://app.intercom.com/a/developer-signup), [REST API](https://developers.intercom.com/docs/). ### Prerequisites * **Admin** or sufficient rights to create or view app tokens in the **Developer Hub**. ### Connect Intercom to Iru Complete this tab before you connect the source in Compliance. Sign in to Intercom and open **[Developer Hub](https://app.intercom.com/a/developer-signup)** with a user who can manage developer apps. Open the **app** (workspace connector) you want Iru to use. If none exists yet, create an app and give it a clear name such as **Iru Compliance**. In the app, go to **Authentication** (or **Configure** → **Authentication**, depending on Intercom’s UI). Create an **Access Token** if you do not already have one for this integration, or open the existing token if your security policy allows reuse. **Copy** the token immediately. You may not be able to see the full value again after you leave the page. Store it in a vault until you paste it into Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Intercom**](#intercom) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Intercom** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Select the **server** endpoint for your region (**US**, **EU**, or **Australia**). Confirm before entering credentials. Paste the **Bearer** access token when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Intercom** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Token copied fully; belongs to this workspace. EU/AU workspaces **must** use the matching host - not the generic US route. Extended scopes may require Intercom approval. Check app permissions in Developer Hub. ### Considerations Deep conversation scopes sometimes need Intercom review (can take several business days). ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Iru Endpoint Source: https://docs.iru.com/en/compliance/sources/iru-endpoint-source Connect Iru Endpoint to Iru Compliance using the Iru Endpoint API. Select your API region, configure your tenant URL, and authenticate with a Bearer token. ### About Iru Endpoint **Iru Endpoint** manages **Apple**, **Windows**, and **Android** devices. Apple coverage includes macOS, iOS, iPadOS, tvOS, and visionOS. Turn on Windows and Android in your tenant to use enrollment and policies there. For setup order and prerequisites, see **[Getting Started](/en/endpoint/getting-started/getting-started)**. Endpoint includes zero-touch deployment, app and OS patch management, compliance templates, threat detection, and APIs for automation. With this source **on**, Compliance can collect **Artifacts** about **how devices are managed** and **how policy lines up with what is deployed**, based on what your framework actions ask for. ### What You May See Collected Depending on product configuration, examples include: * Device enrollment and management records * Configuration or policy enforcement signals exposed to Compliance * Endpoint compliance or posture summaries * Inventory and assignment context relevant to controls ### Typical Control Themes * Endpoint management and asset inventory * Device security configuration * Operational visibility over managed endpoints ### Endpoint Documentation Configure devices, policies, and agents using the **[Getting Started](/en/endpoint/getting-started/getting-started)** path: foundation setup, platform setup, **Blueprints and Library**, and enrollment. Map Compliance **actions** to the **Artifacts** your security team expects (for example enrollment proof, configuration exports, or reports). ### Prerequisites * An **Iru API** token from **Iru Endpoint** with **GET** / **Read** enabled for every API permission your security policy allows. This connector only reads from **Iru Endpoint**; when your policy permits broader **GET** access, **Iru Compliance** can attach more **Artifacts** automatically. When you use the **Iru Endpoint** source with **Iru Compliance**, your API token is used on the **Iru Endpoint Management API** to gather **Artifacts**, and those requests count toward your tenant's rate limit. See **[Considerations](/en/endpoint/api/iru-api-overview#considerations)** in [Iru API Overview](/en/endpoint/api/iru-api-overview) (open **Rate limits**). ### Connect Iru Endpoint to Iru Complete this tab before you connect the source in Compliance. Before you connect, read **[Iru API Overview](/en/endpoint/api/iru-api-overview)** for bearer authentication, how to create tokens, and where your tenant **Iru API URL** appears (US vs EU). Your **`app`** value is the base-domain segment in that URL. It is the segment immediately before `.api.kandji.io`, `.api.eu.kandji.io`, or `.api.iru.com`. You’ll enter the same **region** and **`app`** in the Compliance connector wizard. In the **Iru Endpoint** web app, open **Access** from the account menu. Select **Add Token**, enter a **Name** and **Description**, then create the token and copy the **API token** (the bearer credential **Access** shows once) to a secure place. In the Compliance connector wizard you paste that same value into the input labeled **Bearer JWT**. That text is the **field label** for where the bearer token is entered, not a separate credential type from the API token in [Iru API Overview](/en/endpoint/api/iru-api-overview). In **Access**, open the **API tokens** tab and find **Your organization's API URL**. Use that hostname to double-check **US vs EU** and the **`app`** segment when you run the Compliance wizard (**Select API region** and **Configure the app variable**). For the new token, open **Configure** and set **Permissions**: turn on **GET** for every API permission your security policy allows. **GET** is equivalent to **Read** in this model. Compliance collection is read-only, so you do not need the other permission levels for this connector. The more **GET** coverage the token has, the more **Artifacts** Iru can discover and attach from this source automatically. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Iru Endpoint**](#iru-endpoint) tab first so you have the **API token** from **Access** (you will paste it into the wizard field labeled **Bearer JWT**), the **`app`** segment, **US** or **EU** host, and **GET** permissions before you turn on the source here. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Iru Endpoint** (set **Category** to **Security** or use **Search by name or description**). On that card, turn on the **toggle**. A **new browser tab** opens for **Iru is requesting access to external services** (the connector wizard). Sources list with Iru Endpoint card and enable toggle **Select a server:** Choose **Iru API URL (US)** or **Iru API URL (EU)** to match where your tenant is hosted, then **Confirm Server**. Here `{app}` is the base domain segment for the Iru API. Connector wizard select Iru API URL US or EU server In the **`app`** field, enter only the subdomain from your **Iru API URL** (the part before `.api.` in the hostname). For example, if the API URL is `accuhive.api.kandji.io`, enter `accuhive`. Continue with **Configure Server Variables**. Connector wizard Configure Server Variables with app preview On **Enter Bearer Token**, the wizard shows an input labeled **Bearer JWT**. Paste the **API token** you copied from **Access** there. The field name describes where the bearer token is entered; the value is the same token where you enabled **GET** / **Read** in **Configure GET permissions for Compliance**. Connector wizard Enter Bearer Token and submit Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Iru Endpoint** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the token is complete, not expired, and includes **GET** (**Read**) access for the API permissions **Iru Compliance** needs for this source. Verify the **US vs EU** server choice and the **`app`** value (the base domain for the Iru API) match **[Iru API Overview](/en/endpoint/api/iru-api-overview)**. If **Artifacts** from **Iru Endpoint** are slow to show up or stop updating, work through these checks: * **Rate limits:** Your tenant might be hitting the **Iru Endpoint API rate limit**. **Iru Compliance** uses your token on the same hourly quota as your other scripts and integrations, so bursts elsewhere can leave this source waiting until usage falls. See **Rate limits** under **[Considerations](/en/endpoint/api/iru-api-overview#considerations)** in [Iru API Overview](/en/endpoint/api/iru-api-overview). * **Permissions:** The token might be missing **GET** access for routes this source needs. In **Iru Endpoint**, open **Access**, select the token, and review what is enabled under **Edit** against what your framework actions expect. * **Timing:** **Artifacts** refresh when **Iru Compliance** runs this source on its schedule, so new Endpoint data is not always visible immediately. If you have already ruled out rate limits and permissions, wait for the next collection cycle and check the **Artifacts** page again. ### Related Articles Bearer tokens, tenant **Iru API URL**, and API permissions. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Browse and manage every Compliance source. # Jenkins Source: https://docs.iru.com/en/compliance/sources/jenkins-source Connect Jenkins to Iru Compliance using HTTP Basic Auth with a username and API token to collect job configuration, build history, and plugin evidence. ### About Jenkins Iru calls the Jenkins remote API with **HTTP Basic** authentication: **username** plus an **API token** as the **password** (preferred over a real password). The wizard first stores **`jenkins_host`** (hostname and optional context path only), then collects credentials. ### How It Works ```http theme={null} Authorization: Basic base64(username:api_token) ``` | Detail | Value | | ------------------ | ------------------------ | | **Category** | Developer tools | | **Authentication** | Basic (user + API token) | Official references: [Scripted clients](https://www.jenkins.io/doc/book/system-administration/authenticating-scripted-clients/), [API tokens](https://www.jenkins.io/blog/2018/07/02/new-api-token-system/), [Remote API](https://www.jenkins.io/doc/book/using/remote-access-api/). ### Prerequisites * Jenkins reachable from **Iru’s network** (firewall / VPN / allowlist as needed). * A user with **Overall/Read** and job-level **read** access for the scope you audit. * **HTTPS** strongly recommended for the controller. ### Connect Jenkins to Iru Complete this tab before you connect the source in Compliance. Open your Jenkins controller URL and sign in with a user who has at least **Overall/Read** and the job read access your compliance scope needs. Click your **username** in the upper-right (or the **People** link, then your user), depending on your Jenkins theme. Select **Configure** for your user account so you can edit personal settings. Scroll to the **API Token** section (or **API Token** / **Add new Token**, depending on Jenkins version). If you do not see it, your administrator may restrict token creation. Choose **Add new Token**, enter a name such as **Iru Compliance**, then select **Generate** (or **Create**). Copy the token **once** when Jenkins shows it. Optional **expiry** may apply; Jenkins also surfaces aging tokens in the UI so you can rotate before they lapse. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Jenkins**](#jenkins) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Jenkins** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **`jenkins_host`** as **`jenkins.example.com`** or **`jenkins.example.com/jenkins`** (**without** `https://`). Confirm server variables. Enter **username** and paste the **API token** into the password field. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Jenkins** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Toggle source off/on for a fresh wizard session. Correct user/token; user needs **read** permissions on target jobs. Routing, TLS, VPN, or allowlist for Iru egress. Include context path if Jenkins is not at domain root. ### Considerations Use a **read-only** service user scoped to the folders or views you need. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Jira Source: https://docs.iru.com/en/compliance/sources/jira-source Connect Jira Cloud to Iru Compliance with OAuth to collect projects, issues, workflows, change tickets, and Jira Service Management request evidence for audits. ### About Jira The **Jira** source pulls **project configuration**, **issue metadata**, **workflow definitions**, **user and assignee information**, and **Jira Service Management** request data from **Jira Cloud** into Iru Compliance, where it becomes evidence you can tie to actions and controls. Iru connects through **Atlassian’s three-legged OAuth 2.0 (3LO)** authorization code flow. The integration is **read-only**: Iru does not create or change issues, projects, or workspace settings. This connector is for **Jira Cloud** only. **Jira Data Center** (self-hosted) uses a different authentication model and is **not** supported by this source. ### How It Works After you provide your **Cloud ID**, the connector wizard sends you to Atlassian to sign in and consent. Iru receives a short-lived **access token** and a **rotating refresh token**, and renews tokens automatically on sync cycles. | Scope | What it allows | | ------------------------ | ----------------------------------------------------- | | `read:jira-work` | Read issues, projects, workflows, and attachments | | `read:jira-user` | Read user profiles and assignee information | | `read:jira-service-desk` | Read Jira Service Management requests and SLA metrics | | Detail | Value | | ------------------ | --------------------------------------------------------------------------------------------------- | | **Category** | Project management | | **Authentication** | OAuth 2.0 (Jira Cloud 3LO) | | **Vendor plan** | **Paid** Jira Cloud plan (**Free** tier does not support the OAuth API access this connector needs) | Documentation hub: [Atlassian Support - Jira](https://support.atlassian.com/jira/). OAuth: [Jira Cloud OAuth 2.0 (3LO)](https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/), [OAuth 2.0 scopes](https://developer.atlassian.com/cloud/jira/platform/scopes-for-oauth-2-3LO-and-forge-apps/). Cloud ID: [Retrieve your Atlassian Cloud ID](https://support.atlassian.com/jira/kb/retrieve-my-atlassian-sites-cloud-id/). ### Prerequisites * A **paid** Jira Cloud site (**Free** does not support the OAuth API access required here). * Your **Jira Cloud ID** (UUID). See **Find your Jira Cloud ID** below. * Browser **pop-ups** allowed for your **Iru** domain so the OAuth step can open. * The signing-in user does **not** have to be a Jira admin, but Iru can only read data that user can access. For broad evidence collection, use an account with at least: * **Browse projects** on every project you want Iru to read. * **Browse users and groups** (global permission) if you need user and assignee metadata. A **dedicated service account** with read access across the right projects is often the easiest way to keep scope stable. ### Connect Jira to Iru Complete this tab before you connect the source in Compliance. #### Find your Jira Cloud ID Your **Cloud ID** is the UUID Iru uses with `https://api.atlassian.com/ex/jira/{cloudId}`. This connector supports **Jira Cloud** with a **paid** plan that allows the OAuth API access Iru needs. Confirm you are not on a **Free** site that blocks the integration. In a browser, open your Jira Cloud URL (for example `https://yoursite.atlassian.net`) so you know the **subdomain** you will substitute in the steps below. Use **Option A** for a quick JSON lookup, or **Option B** if you already live in **Atlassian Admin**. In a new browser tab, open (replace `yoursite` with your Jira subdomain): `https://yoursite.atlassian.net/_edge/tenant_info` In the JSON response, copy the value of **`cloudId`**. Sign in at [admin.atlassian.com](https://admin.atlassian.com), select your organization, and find the Cloud ID in the browser URL (it appears after `/s/`). Keep the UUID somewhere safe until you paste it into the Iru connector wizard’s **cloudId** field on the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Jira**](#jira) tab first so you have your **Cloud ID** for the connector wizard. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Jira** (set **Category** to **Project management** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab opens the connector wizard. Enter your **Cloud ID** in the **cloudId** field, then select **Configure Server Variables**. Wait for confirmation that server variables updated successfully before continuing. Select **Launch OAuth Authentication**. When the Atlassian popup opens, sign in and click **Accept** to grant the requested permissions. When the popup closes, Iru completes the OAuth exchange. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Jira** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try **Launch OAuth Authentication** again. The wizard link may have expired. Turn **Jira** off and back on in **Sources**, then enter your **Cloud ID** again. The account that completed OAuth may lack **Browse projects** on some spaces. Adjust Jira permissions or connect with a **service account** that has the read coverage you need. Jira Cloud uses a **rotating refresh token** with a **90-day** validity window. If the connection is idle longer than that, complete the OAuth flow again from the **Jira** source card. The **Free** tier does not support the OAuth API access this connector requires. Use a **paid** Jira Cloud plan to connect. Confirm the **Cloud ID** matches the site you intend (see **Find your Jira Cloud ID**). A mismatch points Iru at the wrong tenant. ### Considerations Iru refreshes access tokens on sync cycles. If sync does not run for **90 days**, plan to **re-authenticate** through the source card. Large projects produce large histories. Narrow project scope where you can, and align **retention** and **privacy** policies before relying on workflow evidence in audits. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # JumpCloud Source: https://docs.iru.com/en/compliance/sources/jumpcloud-source Connect JumpCloud to Iru Compliance with an Admin API key in the x-api-key header and the regional API host to collect user, device, and policy evidence. ### About JumpCloud Iru calls JumpCloud HTTP APIs with: ```http theme={null} x-api-key: YOUR_API_KEY ``` A **Billing Admin** must **enable API access** before keys work. Choose the **US** or **EU** **console** / **insights** base URL that matches **data residency**. Keys support **optional expiration** (policies may require max **365 days** for new keys). ### How It Works JumpCloud accepts an **Admin API key** in the **`x-api-key`** header. Keys inherit the associated admin’s visibility; **API access** must be enabled by a **Billing Admin** before keys work. The connector wizard asks you to pick the **regional API host** that matches your org’s **data residency**, then collects the key. | Detail | Value | | ------------------ | --------------------- | | **Category** | Security | | **Authentication** | API key (`x-api-key`) | Official references: [Admin API keys](https://jumpcloud.com/support/manage-admin-accounts), [Docs](https://docs.jumpcloud.com/), [Directory Insights](https://docs.jumpcloud.com/api/insights/directory/1.0/index.html). ### Prerequisites * **Admin** (or **Billing Admin** for org-wide API enablement). ### Connect JumpCloud to Iru Complete this tab before you connect the source in Compliance. Open the [JumpCloud Admin Console](https://console.jumpcloud.com) and sign in with an administrator who can create **API keys** (and ensure **API access** is enabled for your org if your tenant requires it). Select your **account name** or **avatar** in the console header to open the account menu. Choose **My API Key** (or **API Settings** → **API key**, depending on JumpCloud UI labels). Select **Generate** (or **Generate new API key**). Pick an **expiration** if JumpCloud prompts for one, aligned with your rotation policy. Copy the **Admin API key** value **once** when JumpCloud displays it. Store it in a vault; you will paste it into Iru’s **`x-api-key`** field on the [**Iru Compliance**](#iru-compliance) tab. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**JumpCloud**](#jumpcloud) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **JumpCloud** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Choose **server** options that match your program: **US** vs **EU**, and **console** vs **insights** as the wizard lists them. Paste your **`x-api-key`** value when prompted. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **JumpCloud** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Expired key; API access disabled org-wide. Switch **US**/**EU** host. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Klaviyo Source: https://docs.iru.com/en/compliance/sources/klaviyo-source Connect Klaviyo to Iru Compliance with a scoped read-only private API key to collect account user access, API key inventory with scopes, and list and segment metadata. ### About Klaviyo Iru reads **account users and their permissions**, **API keys with their scopes**, **list and segment metadata**, and **integration connections** from Klaviyo's API. Authentication uses a **private API key** created under **Settings** → **API keys**. Klaviyo private keys are **scoped at creation**. Grant read-only access to the objects your controls cover. Iru reads **metadata only**. List and segment names and configuration are collected; the **profiles inside them are not**. ### How It Works ```http theme={null} Authorization: Klaviyo-API-Key YOUR_PRIVATE_API_KEY revision: 2024-10-15 ``` Klaviyo uses a **custom authorization scheme**: the header value is prefixed with `Klaviyo-API-Key`, not `Bearer`. Every request also requires a **`revision`** header with an ISO 8601 date that pins the API version. Klaviyo versions its API by dated revisions rather than a path segment, and a request without a valid revision is rejected. Iru sets the revision; you supply only the key. Requests target `https://a.klaviyo.com/api`. There is no subdomain or account host to configure. The **public** API key (a short company ID used in client-side subscription calls) is a different credential and will not authenticate here. | Detail | Value | | ------------------ | --------------------------------- | | **Category** | Marketing | | **Authentication** | Klaviyo-API-Key (private API key) | Official references: [Authenticate API requests](https://developers.klaviyo.com/en/docs/authenticate_), [API versioning and deprecation policy](https://developers.klaviyo.com/en/docs/api_versioning_and_deprecation_policy). ### Prerequisites * An account role that can **manage API keys** in Klaviyo. * Decide what is in scope. Klaviyo lets you exclude list and segment monitoring, and excluded objects produce no evidence. ### Connect Klaviyo to Iru Complete this tab before you connect the source in Compliance. Sign in to Klaviyo with an account that can manage API keys. Open the **account menu** in the lower left, then select **Settings**. Go to **API keys**. Select **Create private API key**. Enter a label such as **Iru Compliance** so you can audit the integration later. Set the key's access to **read-only**. Use **custom scopes** and grant read access only to the objects your compliance program covers. Accounts, Lists, and Segments cover the evidence Iru collects. Do not grant full access or any write scope. Create the key and copy the value **once** while Klaviyo displays it. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Klaviyo**](#klaviyo) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Klaviyo** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **private API key**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Klaviyo** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm you created a **private** key, not a public one. The public key is a short company ID used for client-side calls and will not authenticate a server-to-server request. The private key was created with **custom scopes** that exclude them. Klaviyo scopes are fixed at creation. Create a new key with the scopes you need. Either the key lacks read access to them or list and segment monitoring is out of scope for this connection. This is expected. Iru collects list and segment **metadata**, not the profiles within them. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # KnowBe4 Source: https://docs.iru.com/en/compliance/sources/knowbe4-source Connect KnowBe4 KMSAT to Iru Compliance with a read-only API token sent as a Bearer token to collect security awareness training and phishing test evidence. ### About KnowBe4 Iru collects **training campaigns**, **phishing simulations**, **enrollments**, and **completion** status via the KnowBe4 API using **`Authorization: Bearer`**. **API access** requires **Platinum** or **Diamond**; tokens **must** include an **expiration** date at creation. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_TOKEN ``` | Detail | Value | | ------------------ | ------------------- | | **Category** | Security | | **Authentication** | Bearer token | | **Plans** | Platinum or Diamond | Official references: [Product API overview](https://support.knowbe4.com/hc/en-us/articles/10495383627155-Product-API-Overview), [Developer portal](https://developer.knowbe4.com/). ### Prerequisites * **Admin** role in KMSAT. * **API** section visible under **Account Settings** (tier-dependent). ### Connect KnowBe4 to Iru Complete this tab before you connect the source in Compliance. Open your KnowBe4 **KMSAT** admin experience and sign in with a user who can manage **Account Settings** and **API** tokens. From the main navigation, open **Account Settings** (or **Settings** → **Account**, depending on your KnowBe4 layout). Select **API**. Confirm your subscription tier exposes API access; if the section is missing, contact KnowBe4 support or upgrade per your contract. Select **Create New API Token** (or equivalent). Enter a name such as **Iru Compliance** so auditors can map the credential to this integration. Set access to **Read Only** (or the least-privilege read mode KnowBe4 offers for this integration). Set an **expiration**; KnowBe4 requires one for many token types. Select **Create**, then **copy** the token value once. KnowBe4 shows it only at creation. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**KnowBe4**](#knowbe4) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **KnowBe4** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **raw token** - the wizard formats **`Bearer`** for you. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **KnowBe4** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Token expired - rotate before deadline. Confirm **Platinum/Diamond** subscription. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Lattice Source: https://docs.iru.com/en/compliance/sources/lattice-source Connect Lattice to Iru Compliance with an Admin API key used as a Bearer token to collect employee directory, review cycles, and feedback workflow evidence. ### About Lattice Iru reads **employees**, **reviews**, **goals**, **surveys**, and **org** structure via Lattice’s Public API using **`Authorization: Bearer`**. Keys are created under **Admin** → **Platform** → **API Keys** and do not auto-expire - **revoke** manually when rotating. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_KEY ``` | Detail | Value | | ------------------ | ---------------- | | **Category** | HRIS | | **Authentication** | Bearer (API key) | Official references: [Public API](https://help.lattice.com/hc/en-us/articles/360059449534-Lattice-s-Public-API), [Docs](https://docs.lattice.com/). ### Prerequisites * **Admin** access in Lattice. ### Connect Lattice to Iru Complete this tab before you connect the source in Compliance. Open [Lattice](https://lattice.com) and sign in with an **Admin** (or equivalent) account. From the product chrome, select **Admin** (sometimes **Settings** → **Admin**, depending on your Lattice edition). Choose **Platform** (or **Organization** / **Company settings**) until you see workspace-wide configuration categories. Select **API Keys** to view existing keys and the control to create a new one. Select **Generate API key**, enter a name (for example **Iru Compliance**), and confirm creation. **Copy** the key value once. Lattice shows it only at creation. Keys do not auto-expire; revoke when you rotate. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Lattice**](#lattice) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Lattice** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **Bearer** API key when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Lattice** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Key revoked - issue new key. Admin visibility into teams/reviews. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure Authorization Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-authorization-source Connect Microsoft Azure role-based access control and Azure Policy to Iru Compliance using OAuth and the Azure Resource Manager API. ### About Microsoft Azure Authorization The **Microsoft Azure Authorization** source reads **Azure RBAC** role assignments and role definitions, plus **Azure Policy** definitions and assignments, from the subscription you connect. Evidence in Iru reflects **who can access what** and **which policies are assigned**; Iru does not write changes back to Azure. Iru uses **delegated OAuth 2.0** against **Azure Resource Manager** on behalf of the user who signs in, so collections respect that user’s existing Azure permissions. ### How It Works Iru uses Microsoft’s **OAuth 2.0 authorization code flow** (delegated permissions) against **Azure Resource Manager** (`management.azure.com`). After you sign in and consent in the pop-up, Iru receives a short-lived access token and renews it automatically (including rotating refresh tokens where applicable). The OAuth scope requested is: `https://management.azure.com/user_impersonation` That grants **read** access to ARM APIs **as the signed-in user**, limited by that user’s RBAC on the subscription. | Detail | Value | | ------------------ | ------------------------------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID, Azure Resource Manager) | | **Vendor plan** | Any Azure subscription | #### What Iru collects | Data type | Azure ARM resource type | | -------------------------------------- | ------------------------------------------- | | Role assignments | `Microsoft.Authorization/roleAssignments` | | Role definitions (built-in and custom) | `Microsoft.Authorization/roleDefinitions` | | Azure Policy definitions | `Microsoft.Authorization/policyDefinitions` | | Azure Policy assignments | `Microsoft.Authorization/policyAssignments` | Iru does **not** modify role assignments or policy configuration. Official references: [Azure RBAC documentation](https://learn.microsoft.com/azure/role-based-access-control/overview), [REST API](https://learn.microsoft.com/rest/api/authorization/), [List role assignments (concept)](https://learn.microsoft.com/azure/role-based-access-control/role-assignments-list-rest), [Built-in roles](https://learn.microsoft.com/azure/role-based-access-control/built-in-roles), [OAuth 2.0 auth code flow](https://learn.microsoft.com/entra/identity-platform/v2-oauth2-auth-code-flow). ### Prerequisites * **Microsoft Entra ID** account that can sign in at the [Azure portal](https://portal.azure.com). * At minimum the built-in **Reader** role (or equivalent read access) on the **subscription** you want Iru to read. That includes `Microsoft.Authorization/*/read` for assignments, definitions, and policy metadata. * Browser **pop-ups** allowed so the connector wizard can open when you enable the source. To confirm access: **Subscriptions** → your subscription → **Access control (IAM)** → **View my access**, and check for **Reader** (or higher) at that scope. If you need a role assignment, your subscription administrator can use Azure CLI (replace placeholders): ```bash theme={null} az role assignment create \ --assignee \ --role "Reader" \ --scope /subscriptions/ ``` ### Connect Microsoft Azure Authorization to Iru Use **Microsoft Azure** first to confirm portal access and **Reader** coverage, then complete OAuth in **Iru Compliance**. The wizard shows **Step 1 of 1: Perform OAuth Authentication**. Complete this tab before you start OAuth in **Iru Compliance**. Open [portal.azure.com](https://portal.azure.com) and sign in with the **Microsoft Entra ID** account you will use in the Iru wizard (same tenant you want Iru to read). Search for **Subscriptions**, open the **subscription** whose **Authorization** metadata (role assignments, definitions, policy) Iru should collect. In the subscription, open **Access control (IAM)** → **View my access**. Confirm you see **Reader** (or another role that includes `Microsoft.Authorization/*/read` at this scope), as described under **Prerequisites**. Allow **pop-ups** for your **Iru** hostname so the Microsoft consent screen can open from the connector wizard. If your company uses several Entra tenants, sign out of personal Microsoft accounts in the same browser profile, or use a private window, so the OAuth popup picks the **correct** work account. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Microsoft Azure**](#microsoft-azure) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure Authorization** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle** to start the connector wizard. Select **Launch OAuth Authentication**. When the Microsoft window opens, sign in with the same account you verified in the Azure portal and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure Authorization** card is **Active**. Authorization metadata is read at **subscription** scope. To cover **multiple subscriptions**, repeat the flow per subscription or use an account with **Reader** on each subscription you need. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the authenticating account has the **Reader** role on the **subscription** (see **Prerequisites**). If your organization has several tenants, sign **out** of the Microsoft pop-up and sign in with the account for the **correct** tenant. Access tokens renew about every hour while the connection is active. If refresh is interrupted (for example after long inactivity), the card may show **Broken**. Turn the source **off** and **on**, then complete OAuth again. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure DevOps Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-devops-source Connect Microsoft Azure DevOps to Iru Compliance with Microsoft Entra ID OAuth to collect project settings, repositories, branch policies, pull requests, pipelines, permissions, and organization audit activity. ### About Microsoft Azure DevOps Iru reads **projects**, **repositories**, **branch policies**, **pull requests**, **build and release pipelines**, **users and groups**, **service connections**, and **audit log events** from the Azure DevOps REST API. Authentication is delegated **OAuth 2.0** through **Microsoft Entra ID**, using the same **Launch OAuth Authentication** wizard as the other Microsoft Azure sources. You sign in with a work account. Iru does not ask for a personal access token. Collection is limited to the organizations and projects that account can already see. Pipeline **variable names** are collected; **secret values are not**. ### How It Works ```http theme={null} OAuth 2.0 authorization code flow (Microsoft Entra ID) ``` Iru uses Microsoft’s OAuth 2.0 authorization code flow against Azure DevOps. After you sign in and consent in the pop-up, Iru receives a short-lived access token and renews it automatically. The requested scopes follow the Azure DevOps permission model (read access such as `vso.code`, `vso.build`, `vso.release`, `vso.graph`, and `vso.audit_log`). Do not create or paste a personal access token. The wizard will not accept one. | Detail | Value | | ------------------ | ------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID) | Official references: [REST API overview](https://learn.microsoft.com/en-us/rest/api/azure/devops/), [Authorize access to REST APIs with OAuth 2.0](https://learn.microsoft.com/en-us/azure/devops/integrate/get-started/authentication/oauth). ### Prerequisites * A **Microsoft Entra ID** account that can sign in to the Azure DevOps organization you want Iru to read (`contoso` from `https://dev.azure.com/contoso`). * Visibility of every project you want Iru to read. OAuth is delegated, so Iru inherits that account’s project access. An account that cannot see a project returns nothing for it. * Browser **pop-ups** allowed for the Iru site, so the Microsoft consent screen can open. Decide project scope: if branch policies are out of scope, Iru cannot verify code-review or approval controls. ### Connect Microsoft Azure DevOps to Iru Complete this tab before you connect the source in Compliance. Sign in to `https://dev.azure.com/{your-organization}` with the **Microsoft Entra ID** account you will use in the Iru wizard (same tenant and organization you want Iru to read). Confirm you can open every in-scope project. Iru can only collect what this account can already access. Allow **pop-ups** for your Iru hostname so the Microsoft consent screen can open from the connector wizard. If your company uses several Entra tenants, sign out of personal Microsoft accounts in the same browser profile, or use a private window, so the OAuth popup picks the correct work account. Iru authenticates with OAuth 2.0. Do not paste a PAT into the wizard. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Azure DevOps**](#azure-devops) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure DevOps** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Select **Launch OAuth Authentication**. The wizard shows **Perform OAuth Authentication**. When the Microsoft window opens, sign in with the same Entra account you verified in Azure DevOps and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. If the wizard also asks for an **organization** name, enter the name only (for example `contoso`, not the full URL). Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure DevOps** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Check **pop-up blocker** settings, then sign in with the work account for the correct Entra tenant. The signing-in account lacks read access to those objects. Sign in with an account that can see every in-scope project, or have an admin grant that access and reconnect. The account that completed OAuth cannot see that project. Reconnect with an account that has access to every in-scope project. Access tokens renew while the connection is active. If refresh is interrupted, turn the source off and on, then complete OAuth again. This is not a PAT expiry. Iru does not use a personal access token for this source. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure Key Vault Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-key-vault-source Connect Azure Key Vault to Iru Compliance via OAuth to collect vault, key, secret, and certificate metadata for audits without exposing actual secret values. ### About Microsoft Azure Key Vault The **Microsoft Azure Key Vault** source reads **vault configuration** and **metadata** for keys, secrets, and certificates through **Azure Resource Manager**. **Iru does not read secret values, key material, or private keys**; it collects only names, attributes, expiry, access configuration, and similar fields the management API exposes. Iru authenticates with **delegated OAuth 2.0** (Microsoft Entra ID) as the user who completes the wizard. Anything that user cannot read in Azure will not appear in Iru. ### How It Works Iru uses Microsoft’s **OAuth 2.0 authorization code flow** against **Azure Resource Manager**. The requested scope is: `https://management.azure.com/user_impersonation` | Detail | Value | | ------------------ | ------------------------------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID, Azure Resource Manager) | | **Vendor plan** | Any Azure subscription that has Key Vault resources | #### What Iru collects | Data type | Notes | | ----------------------- | ------------------------------------------------------------------------------- | | Key vault configuration | Name, location, SKU (standard or premium), soft-delete, purge protection | | Keys (metadata) | Identifiers, permitted operations, enabled state, expiry (**not** key material) | | Secrets (metadata) | Names, content type, enabled state, expiry (**not** secret values) | | Certificates (metadata) | Identifiers, issuer, validity (**not** private keys) | | Access policies / RBAC | Which principals have which permissions on each vault | Iru does **not** modify vaults, objects, or access policies. Official references: [Azure Key Vault documentation](https://learn.microsoft.com/azure/key-vault/), [Key Vault REST API](https://learn.microsoft.com/rest/api/keyvault/), [Key Vault RBAC guide](https://learn.microsoft.com/azure/key-vault/general/rbac-guide), [Built-in roles for security](https://learn.microsoft.com/azure/role-based-access-control/built-in-roles/security). ### Prerequisites * **Microsoft Entra ID** sign-in to the [Azure portal](https://portal.azure.com). * The built-in **Key Vault Reader** role (recommended) or **Reader**, assigned at **subscription** scope for the broadest coverage across vaults, or at individual vault scope if you intentionally limit visibility. **Key Vault Reader** includes vault read and metadata reads for keys, secrets, and certificates **without** secret or key material access. * Browser **pop-ups** allowed so the connector wizard can open when you enable the source. Confirm access: **Subscriptions** → your subscription → **Access control (IAM)** → **View my access**. Example role assignment (replace placeholders): ```bash theme={null} az role assignment create \ --assignee \ --role "Key Vault Reader" \ --scope /subscriptions/ ``` ### Connect Microsoft Azure Key Vault to Iru Use **Microsoft Azure** first to confirm portal access and **Key Vault Reader** (or **Reader**) coverage, then complete OAuth in **Iru Compliance**. The wizard shows **Step 1 of 1: Perform OAuth Authentication**. Complete this tab before you start OAuth in **Iru Compliance**. Open [portal.azure.com](https://portal.azure.com) and sign in with the account you will use in the Iru wizard. Search for **Subscriptions**, then open the subscription that contains (or parents) the **Key Vaults** Iru should read. Open **Access control (IAM)** → **View my access**. Confirm **Key Vault Reader** on specific vaults or **Reader** at subscription scope, per **Prerequisites**. Allow **pop-ups** for your **Iru** hostname so the Microsoft consent window can open. If you use multiple tenants, use a clean browser session so OAuth signs in to the **work** tenant that owns the vaults. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Microsoft Azure**](#microsoft-azure) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure Key Vault** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle** to start the connector wizard. Select **Launch OAuth Authentication**. When the Microsoft window opens, sign in with the same account you verified in the Azure portal and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure Key Vault** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. The signed-in account may lack **Key Vault Reader** or **Reader** on the subscription or vaults. Verify **IAM** assignments (see **Prerequisites**). Sign **out** of the Microsoft pop-up and sign in with the account for the **correct** tenant. Turn **Microsoft Azure Key Vault** **off** and **on** in **Sources**, then complete OAuth again. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure Monitor Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-monitor-source Connect Azure Monitor to Iru Compliance for diagnostic settings, activity logs, alerts, and Log Analytics workspace configuration via OAuth. ### About Microsoft Azure Monitor The **Microsoft Azure Monitor** source pulls **diagnostic settings**, **subscription activity logs**, **metric and log alert rule** configuration, and **Log Analytics workspace** settings from the connected subscription. Data is read through **Azure Resource Manager** with **delegated OAuth** as the signing-in user. Iru does **not** create or change diagnostic settings, alert rules, or workspaces. **Activity log** visibility follows Azure’s default retention (**about 90 days** at the subscription). Iru reads what Azure exposes for that window. For longer retention, export activity logs to a **Log Analytics** workspace or **storage** in Azure. ### How It Works Iru uses Microsoft’s **OAuth 2.0 authorization code flow** against **Azure Resource Manager**. The requested scope is: `https://management.azure.com/user_impersonation` | Detail | Value | | ------------------ | ------------------------------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID, Azure Resource Manager) | | **Vendor plan** | Any Azure subscription | #### What Iru collects | Data type | Notes | | ------------------------ | ----------------------------------------------------------------------------------- | | Diagnostic settings | Log categories, retention, destinations (storage, event hub, Log Analytics) | | Activity logs | Subscription-level audit events (create, delete, policy, role changes, and similar) | | Metric alert rules | Definitions, thresholds, evaluation frequency | | Log alert rules | Scheduled query rules and activity log alert configuration | | Log Analytics workspaces | Workspace configuration and data retention settings | Official references: [Azure Monitor documentation](https://learn.microsoft.com/azure/azure-monitor/), [Diagnostic settings](https://learn.microsoft.com/azure/azure-monitor/essentials/diagnostic-settings), [Activity log](https://learn.microsoft.com/azure/azure-monitor/essentials/activity-log), [Roles and permissions](https://learn.microsoft.com/azure/azure-monitor/fundamentals/roles-permissions-security), [Diagnostic settings REST API](https://learn.microsoft.com/rest/api/monitor/diagnostic-settings). ### Prerequisites * **Microsoft Entra ID** sign-in to the [Azure portal](https://portal.azure.com). * The built-in **Monitoring Reader** role at **subscription** scope (or **Reader**, which includes the needed read paths). **Monitoring Reader** grants `Microsoft.Insights/*/read` for diagnostic settings, alert rules, and activity log access **without** write permissions. * Browser **pop-ups** allowed so the connector wizard can open when you enable the source. Confirm access: **Subscriptions** → your subscription → **Access control (IAM)** → **View my access**. Example role assignment (replace placeholders): ```bash theme={null} az role assignment create \ --assignee \ --role "Monitoring Reader" \ --scope /subscriptions/ ``` ### Connect Microsoft Azure Monitor to Iru Use **Microsoft Azure** first to confirm portal access and **Monitoring Reader** (or **Reader**) coverage, then complete OAuth in **Iru Compliance**. The wizard shows **Step 1 of 1: Perform OAuth Authentication**. Complete this tab before you start OAuth in **Iru Compliance**. Open [portal.azure.com](https://portal.azure.com) and sign in with the account you will use in the Iru wizard. Search for **Subscriptions**, then open the subscription whose **Monitor** diagnostics and metrics Iru should read. Open **Access control (IAM)** → **View my access**. Confirm **Monitoring Reader** or subscription **Reader**, per **Prerequisites**. Allow **pop-ups** for your **Iru** hostname so the Microsoft consent window can open. If you use multiple tenants, use a clean browser session so OAuth signs in to the tenant that owns the subscription. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Microsoft Azure**](#microsoft-azure) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure Monitor** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle** to start the connector wizard. Select **Launch OAuth Authentication**. When the Microsoft window opens, sign in with the same account you verified in the Azure portal and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure Monitor** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. The signed-in account may lack **Monitoring Reader** (or **Reader**) at **subscription** scope. Verify **IAM** (see **Prerequisites**). Azure retains subscription **activity logs** for about **90 days** by default. Iru reflects what is available in that window unless you have extended retention via export to Log Analytics or storage. Sign **out** of the Microsoft pop-up and sign in with the account for the **correct** tenant. Turn **Microsoft Azure Monitor** **off** and **on** in **Sources**, then complete OAuth again. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure Network Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-network-source Connect Azure Network management APIs to Iru Compliance for VNets, NSGs, firewalls, routes, load balancers, and public IPs via OAuth. ### About Microsoft Azure Network The **Microsoft Azure Network** source reads **virtual network** layout, **network security groups**, **Azure Firewall** policy, **route tables**, **load balancers**, and **public IP** configuration from your subscription through **Azure Resource Manager**. Authentication is **delegated OAuth 2.0** (Microsoft Entra ID) as the user who completes the wizard. Iru does **not** change network resources. For **subscription-wide** visibility, assign **Reader** at **subscription** scope. Roles granted only on individual resource groups can hide resources outside those groups. ### How It Works Iru uses Microsoft’s **OAuth 2.0 authorization code flow** against **Azure Resource Manager**. The requested scope is: `https://management.azure.com/user_impersonation` | Detail | Value | | ------------------ | ------------------------------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID, Azure Resource Manager) | | **Vendor plan** | Any Azure subscription with network resources | #### What Iru collects | Data type | Notes | | ------------------------------ | ------------------------------------------------------- | | Virtual networks (VNets) | Address spaces, subnets, DNS settings, peering | | Network security groups (NSGs) | Inbound and outbound rules, associated subnets and NICs | | Azure Firewalls | Rules, threat intelligence, DNS proxy settings | | Route tables | User-defined routes and subnet associations | | Load balancers | Front-end IPs, backend pools, rules, health probes | | Public IP addresses | Allocation method, DNS labels, associations | The built-in **Reader** role at subscription scope includes `Microsoft.Network/*/read` for these resource types (no write permissions). Official references: [Virtual Network documentation](https://learn.microsoft.com/azure/virtual-network/), [Network security groups](https://learn.microsoft.com/azure/virtual-network/network-security-groups-overview), [Networking built-in roles](https://learn.microsoft.com/azure/role-based-access-control/built-in-roles/networking), [Network REST API](https://learn.microsoft.com/rest/api/virtualnetwork/). ### Prerequisites * **Microsoft Entra ID** sign-in to the [Azure portal](https://portal.azure.com). * **Reader** (or higher) on the **subscription** you connect. Assign at **subscription** scope for full inventory. * Browser **pop-ups** allowed so the connector wizard can open when you enable the source. Confirm access: **Subscriptions** → your subscription → **Access control (IAM)** → **View my access**. Example role assignment (replace placeholders): ```bash theme={null} az role assignment create \ --assignee \ --role "Reader" \ --scope /subscriptions/ ``` ### Connect Microsoft Azure Network to Iru Use **Microsoft Azure** first to confirm portal access and **Reader** coverage on the subscription, then complete OAuth in **Iru Compliance**. The wizard shows **Step 1 of 1: Perform OAuth Authentication**. Complete this tab before you start OAuth in **Iru Compliance**. Open [portal.azure.com](https://portal.azure.com) and sign in with the account you will use in the Iru wizard. Search for **Subscriptions**, then open the subscription whose **virtual networks**, **NSGs**, and related networking resources Iru should read. Open **Access control (IAM)** → **View my access**. Confirm **Reader** (or equivalent read) at subscription scope, per **Prerequisites**. Allow **pop-ups** for your **Iru** hostname so the Microsoft consent window can open. If you use multiple tenants, use a clean browser session so OAuth signs in to the tenant that owns the subscription. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Microsoft Azure**](#microsoft-azure) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure Network** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle** to start the connector wizard. Select **Launch OAuth Authentication**. When the Microsoft window opens, sign in with the same account you verified in the Azure portal and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure Network** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm **Reader** is assigned at **subscription** scope if you expect a full subscription view. **Reader** scoped only to a **resource group** may omit resources in other groups. Sign **out** of the Microsoft pop-up and sign in with the account for the **correct** tenant. Turn **Microsoft Azure Network** **off** and **on** in **Sources**, then complete OAuth again. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Microsoft Azure Storage Source: https://docs.iru.com/en/compliance/sources/microsoft-azure-storage-source Connect Azure Storage management APIs to Iru Compliance via OAuth to collect storage account and container configuration without reading blob or file contents. ### About Microsoft Azure Storage The **Microsoft Azure Storage** source reads **storage account** settings, **blob container** metadata, **container access policies**, **lifecycle management** rules, and **network rules** through **Azure Resource Manager**. **Iru does not read blob contents, file share data, queue messages, or table rows**; it collects only configuration and container-level metadata the management API returns. Authentication is **delegated OAuth 2.0** (Microsoft Entra ID) as the user who completes the wizard. Iru does **not** modify storage accounts, containers, or policies. For a full **subscription** inventory, assign **Reader** at **subscription** scope. **Reader** scoped only to a **resource group** can hide accounts in other groups. ### How It Works Iru uses Microsoft’s **OAuth 2.0 authorization code flow** against **Azure Resource Manager**. The requested scope is: `https://management.azure.com/user_impersonation` | Detail | Value | | ------------------ | ------------------------------------------------------ | | **Category** | Developer tools | | **Authentication** | OAuth 2.0 (Microsoft Entra ID, Azure Resource Manager) | | **Vendor plan** | Any Azure subscription with storage resources | #### What Iru collects | Data type | Notes | | ----------------------------- | ---------------------------------------------------------------------------------- | | Storage accounts | Name, location, SKU (LRS, GRS, ZRS), kind, access tier, TLS version, network rules | | Blob containers | Container names, public access settings, metadata | | Container access policies | Stored access policies and their permissions | | Lifecycle management policies | Tier transitions and deletion rules | | Network rules | Firewall rules, service endpoints, private endpoints | **Reader** at subscription scope includes `Microsoft.Storage/*/read` for account and container metadata through ARM, **not** data-plane access to object contents. Official references: [Azure Storage documentation](https://learn.microsoft.com/azure/storage/), [Storage Resource Provider REST API](https://learn.microsoft.com/rest/api/storagerp/), [Storage built-in roles](https://learn.microsoft.com/azure/role-based-access-control/built-in-roles/storage), [Authorize access with Azure RBAC](https://learn.microsoft.com/azure/storage/blobs/authorize-access-azure-active-directory). ### Prerequisites * **Microsoft Entra ID** sign-in to the [Azure portal](https://portal.azure.com). * **Reader** (or higher) on the **subscription** you connect. Assign at **subscription** scope for complete visibility. * Browser **pop-ups** allowed so the connector wizard can open when you enable the source. Confirm access: **Subscriptions** → your subscription → **Access control (IAM)** → **View my access**. Example role assignment (replace placeholders): ```bash theme={null} az role assignment create \ --assignee \ --role "Reader" \ --scope /subscriptions/ ``` ### Connect Microsoft Azure Storage to Iru Use **Microsoft Azure** first to confirm portal access and **Reader** coverage on the subscription, then complete OAuth in **Iru Compliance**. The wizard shows **Step 1 of 1: Perform OAuth Authentication**. Complete this tab before you start OAuth in **Iru Compliance**. Open [portal.azure.com](https://portal.azure.com) and sign in with the account you will use in the Iru wizard. Search for **Subscriptions**, then open the subscription whose **storage accounts** and related ARM metadata Iru should read. Open **Access control (IAM)** → **View my access**. Confirm **Reader** (or equivalent read) at subscription scope, per **Prerequisites**. Allow **pop-ups** for your **Iru** hostname so the Microsoft consent window can open. If you use multiple tenants, use a clean browser session so OAuth signs in to the tenant that owns the subscription. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Microsoft Azure**](#microsoft-azure) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Microsoft Azure Storage** (set **Category** to **Developer tools** or use **Search by name or description**). On that card, turn on the **toggle** to start the connector wizard. Select **Launch OAuth Authentication**. When the Microsoft window opens, sign in with the same account you verified in the Azure portal and click **Accept** on the consent screen. When the OAuth window closes and Iru finishes the exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Microsoft Azure Storage** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm **Reader** at **subscription** scope if you expect accounts across the whole subscription. **Reader** scoped only to a **resource group** omits accounts elsewhere. Sign **out** of the Microsoft pop-up and sign in with the account for the **correct** tenant. Turn **Microsoft Azure Storage** **off** and **on** in **Sources**, then complete OAuth again. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Notion Source: https://docs.iru.com/en/compliance/sources/notion-source Connect Notion to Iru Compliance with an internal integration token to collect workspace, page, database, and member-access evidence for control assessments. ### About Notion The **Notion** connector reads **page metadata**, **database schemas**, **workspace membership**, and integration configuration so you can map knowledge-base evidence to controls in Iru Compliance. Authentication uses a **Notion internal integration token** (sometimes called a connection secret) generated from **[My integrations](https://www.notion.com/my-integrations)**. ### How It Works Notion expects the token in the **`Authorization`** header: ```http theme={null} Authorization: Bearer YOUR_INTEGRATION_TOKEN ``` Internal integrations only reach content that you explicitly **share** with the integration. Plan sharing deliberately - typically by attaching the integration at a **parent page** so children inherit access. | Detail | Value | | ------------------ | ------------------------------------------------- | | **Category** | Productivity | | **Authentication** | Bearer token (internal integration) | | **Workspace role** | Only **workspace owners** can create integrations | Documentation: [Create integrations](https://www.notion.com/help/create-integrations-with-the-notion-api), [Authorization overview](https://developers.notion.com/docs/authorization), [API reference](https://developers.notion.com/reference). ### Prerequisites * **Workspace owner** rights (needed to create integrations). * A clear list of **pages or databases** compliance evidence should include. ### Connect Notion to Iru Complete this tab before you connect the source in Compliance. Sign in at [notion.so](https://www.notion.so) with a user who can create **internal integrations** for the workspace you want Iru to read. Visit **[notion.com/my-integrations](https://www.notion.com/my-integrations)**, or in the Notion app open **Settings** → **Connections** and follow the path to **Create** or manage integrations. Create a new integration. Name it (for example **Iru Compliance**), assign it to the **correct workspace**, and enable capabilities your controls need: at minimum **Read content**, and **Read user information including email addresses** when membership evidence matters. **Save** the integration, then copy the **internal integration secret**. Treat it like a password; it does not expire unless you rotate or delete the integration. Open each top-level page or database → **`⋯`** → **Connections** → pick **Iru Compliance**. Sharing a parent page reduces duplicate work for nested docs. Without explicit shares, the integration legitimately sees **nothing**, even if your humans can read the pages. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Notion**](#notion) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Notion** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the internal integration **secret** into the bearer-token step. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Notion** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Re-copy the secret, ensure the integration was not deleted or rotated. Re-open each parent page and confirm **Connections** lists your integration. Only workspace owners manage integrations - confirm you created it in the intended workspace. ### Considerations Rotate secrets on your schedule and update Iru immediately afterward. Iru reads metadata exposed to the token - it does not silently edit pages or invites. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Okta Source: https://docs.iru.com/en/compliance/sources/okta-source Connect Okta to Iru Compliance with an API token to collect directory users and groups, application assignments, MFA policies, and System Log audit evidence. ### About Okta The **Okta** connector reads directory data, group memberships, application assignments, policies, MFA posture, and audit-related signals from your Okta org and surfaces them as artifacts in Iru Compliance. Authentication uses an **Okta API token** over the **Okta Management API**. The integration is intended for **read-only** evidence collection. Iru does not provision users or change policies in Okta beyond what your token’s admin permissions allow during API reads. ### How It Works Okta accepts API tokens using the **SSWS** scheme: ```http theme={null} Authorization: SSWS YOUR_API_TOKEN ``` Tokens inherit the permissions of the admin who created them. **Unused tokens expire after 30 days**; successful API calls refresh that window. The Iru connector walks through server URLs for your tenant (production, EMEA, Gov, preview, or custom domain), then collects your **API token** on the final step. Earlier wizard steps align OAuth-related URLs where the product expects them; **SSWS token authentication** is what authorizes Management API calls for this source. | Detail | Value | | ------------------ | -------------------------------------------------------- | | **Category** | Security | | **Authentication** | Okta API token (`Authorization: SSWS YOUR_TOKEN`) | | **Okta plan** | Any plan that includes Management API access you rely on | Documentation: [Create an API token](https://developer.okta.com/docs/guides/create-an-api-token/main/), [API token management](https://help.okta.com/en-us/content/topics/security/api.htm), [Rate limits](https://developer.okta.com/docs/reference/rate-limits/). ### Prerequisites * An Okta administrator role that can **create API tokens** (**Super Admin**, **Org Admin**, or **Read-only Admin**, depending on what your org allows for automation accounts). * Your org’s **subdomain** or full **Okta domain** (for example `acme` if users sign in at `https://acme.okta.com`). ### Connect Okta to Iru Complete this tab before you connect the source in Compliance. Open your org’s admin URL (for example `https://YOUR_SUBDOMAIN.okta.com/admin`) and sign in with a role that can create **API tokens** (**Super Admin**, **Org Admin**, or **Read-only Admin**, per what your org allows for automation accounts). In the left navigation, expand **Security** (or search **API** in the admin search bar). Choose **API** → **Tokens** to open the list of existing tokens and **Create token**. Select **Create token**, enter a name you will recognize (for example **Iru Compliance**), then confirm creation so Okta can display the secret once. Copy the token value before you close the dialog. You cannot view it again after you leave the page. Store it in a vault until you paste it into Iru. Plan for **idle expiry**: if no successful API call uses the token for **30 days**, Okta invalidates it and you must create a new token. If your environment uses fixed egress IPs, optionally attach a **network zone** policy to the token per Okta’s documentation. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Okta**](#okta) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Okta** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A new tab opens the connector wizard. Select the row that matches where your org lives: | Environment | Base URL pattern | | ----------------- | ---------------------------------------- | | Production (US) | `https://YOUR_SUBDOMAIN.okta.com` | | EMEA | `https://YOUR_SUBDOMAIN.okta-emea.com` | | Preview / sandbox | `https://YOUR_SUBDOMAIN.oktapreview.com` | | US Gov | `https://YOUR_SUBDOMAIN.okta-gov.com` | | Custom domain | `https://YOUR_OKTA_DOMAIN` | Confirm your choice so the wizard can build the correct Management API base URL. Follow each wizard screen: enter your **subdomain** or domain values where prompted so OAuth-related URLs stay consistent with your tenant. Mid-wizard steps that mention OAuth URLs exist because the connector template configures endpoints completely. **SSWS token authentication** on the last step is what Iru uses for Management API reads for this source. On the credential step, paste your **API token** into the authorization field. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Okta** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Verify the token string, that the admin account is still active, and that the token was not revoked. Recreate the token under **Security** → **API** → **Tokens** if it has been idle for 30 days. The admin profile tied to the token may lack read access to some endpoints. Confirm at least **Read-only Admin** (or equivalent) for evidence you need. Disconnect and reconnect, double-checking subdomain and region (US vs EMEA vs Gov vs preview). ### Considerations Treat API tokens like credentials. Prefer a **service account** with the **minimum** admin role that still satisfies evidence requirements. Okta applies **rate limits** to Management API traffic; large orgs may see longer sync times during first collection. Iru reads data exposed by the APIs your token can access - it cannot override Okta entitlements you do not grant. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # OpenAI Source: https://docs.iru.com/en/compliance/sources/openai-source Connect OpenAI to Iru Compliance with a Platform API key to collect project settings, API key inventory, usage metrics, and organization metadata. ### About OpenAI Iru reads **project** configuration, **usage** metrics, **model access** settings, and **org membership** from **platform.openai.com**. Authentication uses **`Authorization: Bearer`** with an API key. Modern **`sk-proj-`** keys are **project-scoped**; broader **`sk-`** or org keys expose more surface area - choose the narrowest key that satisfies your controls. ### How It Works ```http theme={null} Authorization: Bearer sk-proj-xxxx ``` | Detail | Value | | ------------------ | ---------------- | | **Category** | Developer tools | | **Authentication** | Bearer (API key) | Official references: [Authentication](https://platform.openai.com/docs/api-reference/authentication), [API keys](https://platform.openai.com/api-keys), [Projects](https://help.openai.com/en/articles/9186755-managing-your-work-in-the-api-platform-with-projects). ### Prerequisites * Access to **platform.openai.com** and the **project** you want evidence for. ### Connect OpenAI to Iru Complete this tab before you connect the source in Compliance. Open **[platform.openai.com](https://platform.openai.com)** and sign in with a user who can manage **API keys** for the target **project**. Use the **project** picker (or **Default project**) to select the OpenAI **project** whose usage and configuration Iru should read for compliance evidence. In the left navigation, open **API keys** for that project. Select **Create new secret key** (or **+ Create key**). Enter a label such as **Iru Compliance** so you can revoke the correct key later. Confirm creation. OpenAI may ask you to re-authenticate or confirm org policy depending on your tenant settings. Copy the key value when OpenAI shows it. OpenAI does **not** show it again. Store it in a vault until you paste it into Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**OpenAI**](#openai) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **OpenAI** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the key into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **OpenAI** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Full key string; key not deleted in Platform UI. **`sk-proj-`** keys only see **their project** - add keys per project or use org-level guidance from your program. Billing / limits on the OpenAI side - not an auth fix. ### Considerations Iru does **not** run inference on your behalf. It reads administrative and usage metadata only. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # PagerDuty Source: https://docs.iru.com/en/compliance/sources/pagerduty-source Connect PagerDuty to Iru Compliance with a read-only REST API key to collect incidents, services, escalation policies, and on-call evidence. ### About PagerDuty Iru reads **incidents**, **services**, **escalation policies**, **schedules**, **teams**, and **audit** data through the PagerDuty REST API. Authentication uses PagerDuty’s header format (not plain Bearer): ```http theme={null} Authorization: Token token=YOUR_API_KEY ``` Prefer a **General Access** REST API key with **read-only** scope so Iru cannot change incidents or services. ### How It Works PagerDuty REST API keys are sent with PagerDuty’s custom header format **`Authorization: Token token=`** (this is **not** a generic **`Bearer`** token). | Detail | Value | | ------------------ | --------------------------------------------- | | **Category** | Developer tools | | **Authentication** | REST API key (`Authorization: Token token=…`) | **General Access** keys are created by admins and can cover the whole account. **User** tokens inherit that user’s visibility. Avoid them unless you intentionally restrict scope. Official references: [API access keys](https://support.pagerduty.com/main/docs/api-access-keys), [REST API reference](https://developer.pagerduty.com/api-reference/), and [Rate limiting](https://developer.pagerduty.com/docs/rest-api-v2/rate-limiting/). ### Prerequisites * **Admin** or **Account Owner** (or equivalent) to create **General Access** API keys. ### Connect PagerDuty to Iru Complete this tab before you connect the source in Compliance. Open [PagerDuty](https://www.pagerduty.com) and sign in with an **Admin** or **Account Owner** (or equivalent) who can create **API Access Keys**. From the product navigation, open **Integrations** (sometimes under **Automation** or **Developer**, depending on your PagerDuty edition). Select **Developer Tools** (or **API Access**), then locate **API Access Keys**. Choose **Create new API key** (wording may read **New key**). Prefer a **General Access** key when org policy allows so Iru reads are not tied to a single human user’s visibility. Enter a name such as **Iru Compliance**. Set the key type to **Read-only** (or the least-privilege read option PagerDuty offers for REST evidence collection). Finish creation and copy the key value **once** when PagerDuty shows it. It is not shown again after the dialog closes. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**PagerDuty**](#pagerduty) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **PagerDuty** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **raw API key** into the field the wizard provides. The product formats `Authorization: Token token=YOUR_API_KEY` for you. Do **not** prefix `Token token=` yourself. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **PagerDuty** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Full key, no spaces; key not disabled. Switch from a **User** token to a **General Access** key with sufficient scope. User-scoped tokens only see that user’s teams. Use **General Access**. ### Considerations API keys do not auto-expire - rotate on a schedule. Large backfills stay within PagerDuty **rate limits**; sync may spread over time. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Postman Source: https://docs.iru.com/en/compliance/sources/postman-source Connect Postman to Iru Compliance with an API key to collect workspace inventory, collection metadata, team membership, and audit-log evidence. ### About Postman Postman exposes team and workspace data over APIs authenticated with **`X-API-Key`**. Iru reads **workspaces**, **collections**, **API definitions**, **membership**, and **audit** logs where your plan allows. ### How It Works ```http theme={null} X-API-Key: YOUR_API_KEY ``` | Detail | Value | | ------------------ | --------------------- | | **Category** | Developer tools | | **Authentication** | API key (`X-API-Key`) | Keys inherit the creator’s workspace access - use a **dedicated** user when you want tighter blast radius. Official references: [Managing API keys](https://learning.postman.com/docs/administration/managing-your-team/managing-api-keys), Postman **public** workspace docs for API surface. ### Prerequisites * Permission to **generate API keys** (org policy may restrict this). ### Connect Postman to Iru Complete this tab before you connect the source in Compliance. Open [postman.com](https://www.postman.com) and sign in with a user who can manage **API keys** for your **team** or **personal** account, per where Iru should authenticate. Select your **Avatar** in the upper-right to open the account menu. Choose **Account Settings** (or **Settings** → **Account** on some layouts). Select **API Keys** to view existing keys and the control to generate a new one. Select **Generate API Key**. Name it (for example **Iru Compliance**) and set **expiration** if your org requires it. Copy the key value when Postman shows it. Postman may **auto-revoke** keys found in public repos, so store it in a secrets manager until you paste it in **Iru Compliance**. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Postman**](#postman) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Postman** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the key into the **`X-API-Key`** field. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Postman** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Full key; not expired or revoked. Org admin must allow API keys for your role. Issue a new key; store in a secrets manager. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Reach 360 Source: https://docs.iru.com/en/compliance/sources/reach-360-source Connect Articulate Reach 360 to Iru Compliance with a Manage API key used as a Bearer token to collect course, training, and learner completion evidence. ### About Reach 360 Iru reads **enrollments**, **completions**, **content**, and **group** data from Reach **360** using a **Bearer** token created under **Manage** → **Settings** → **Manage API Keys**. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_KEY ``` | Detail | Value | | ------------------ | ---------------- | | **Category** | Productivity | | **Authentication** | Bearer (API key) | Official references: [Manage API keys](https://community.articulate.com/kb/user-guides/reach-360-manage-api-keys/1136824), [Reach 360](https://articulate.com/360/reach). ### Prerequisites * **Admin** on the Reach 360 tenant. ### Connect Reach 360 to Iru Complete this tab before you connect the source in Compliance. Open your Reach 360 admin experience and sign in with an **Admin** on the tenant. Select **Manage** (or the gear **Settings** entry your tenant uses for administration). Choose **Settings** to reach tenant-wide configuration pages. Select **Manage API Keys** (or **API keys**) to list existing keys and creation controls. Choose **Generate New Key**, enter a name such as **Iru Compliance**, and confirm. Copy the key value **once** when Reach 360 displays it and store it in a vault until you paste it into Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Reach 360**](#reach-360) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Reach 360** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **Bearer** token when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Reach 360** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Key deleted - generate a new one. Confirm **Admin** role. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # RingCentral Source: https://docs.iru.com/en/compliance/sources/ringcentral-source Connect RingCentral to Iru Compliance with OAuth 2.0 and the platform host that matches your account to collect user, role, and platform configuration evidence. ### About RingCentral Iru uses **OAuth 2.0** (**authorization code**) against **RingCentral Platform** APIs. Typical read scopes include **ReadAccounts**, **ReadCallRecording** (metadata), and **ReadAuditTrail** - exact names follow the consent screen. Pick **`https://platform.ringcentral.com`** (or the **media** host if your integration requires it) before authorizing. ### How It Works Iru uses RingCentral’s **OAuth 2.0 authorization code** flow. After you **confirm the server** / region in the wizard, a **browser popup** opens RingCentral’s authorization server. You sign in, review the requested scopes, and grant access; RingCentral returns a code that Iru exchanges for **access** (and **refresh**) tokens. | Detail | Value | | ------------------ | -------------- | | **Category** | Communications | | **Authentication** | OAuth 2.0 | Official references: [Auth code flow](https://developers.ringcentral.com/guide/authentication/auth-code-flow), [Permissions](https://developers.ringcentral.com/guide/basics/permissions), [API reference](https://developers.ringcentral.com/api-reference). ### Prerequisites * **Admin** or **Super Admin** for the RingCentral account. * Browser **popups** allowed. ### Connect RingCentral to Iru Complete this tab before you enable **RingCentral** in **Iru Compliance**, so the right administrator completes OAuth. Open the [RingCentral service web](https://service.ringcentral.com) (or your branded login URL) and sign in with **Admin** or **Super Admin** rights. Confirm your RingCentral plan includes the **ReadAccounts**, **ReadCallRecording** (metadata), and **ReadAuditTrail** capabilities Iru’s consent screen requests. Some scopes are tier-dependent. Decide whether your tenant uses **`platform.ringcentral.com`** (typical production) or a **media** host, and match what RingCentral documents for your account region. In the browser profile you will use for Compliance, allow **pop-ups** for your **Iru** hostname so the RingCentral OAuth window is not blocked. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**RingCentral**](#ringcentral) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **RingCentral** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Confirm **server** / region in the wizard, then start **OAuth** so the consent window can open. Sign in to RingCentral if prompted. Review access and select **Authorize** (or the equivalent approval button). When the RingCentral popup closes and Iru finishes the token exchange, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **RingCentral** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Use an **Admin** account. Plan may not include **audit** API access. Re-run OAuth from Iru. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Sage HR Source: https://docs.iru.com/en/compliance/sources/sage-hr-source Connect Sage HR to Iru Compliance with an API key in the X-Auth-Token header and your account subdomain to collect employee, leave, and team directory evidence. ### About Sage HR Iru calls **`https://YOUR_SUBDOMAIN.sage.hr/api`** with: ```http theme={null} X-Auth-Token: YOUR_API_KEY ``` Keys are **per admin** and inherit that user’s permissions. Disabling and re-enabling API access **rotates** the key. ### How It Works Sage HR’s REST API accepts an **API key** in the **`X-Auth-Token`** header. The connector wizard collects your **subdomain** first (to build **`https://{subdomain}.sage.hr/api`**) and the **API key** in a follow-up step. | Detail | Value | | ------------------ | ------------------------ | | **Category** | HRIS | | **Authentication** | API key (`X-Auth-Token`) | Official references: [How the API works](https://support.sage.hr/en/articles/3246469-how-does-sage-hr-api-work), [Sage developer HR](https://developer.sage.com/hr/reference/). ### Prerequisites * **Admin** access. * **Subdomain** (`acme` from `https://acme.sage.hr`). ### Connect Sage HR to Iru Complete this tab before you connect the source in Compliance. Open your Sage HR site (`https://YOUR_SUBDOMAIN.sage.hr`) and sign in with an **Admin** who can change **Integrations** settings. Select **Name** (your profile) in the Sage HR header to open the account menu. Choose **Settings** (or **Company settings**, depending on Sage HR edition). Navigate to **Integrations**, then **API** (labels may read **Integrations** → **API access**). Toggle or select **Enable API Access** and confirm any prompts Sage HR shows about data access. Copy the **API key** Sage HR displays and store it securely. You will use it as the **`X-Auth-Token`** value in Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Sage HR**](#sage-hr) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Sage HR** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **subdomain** when the wizard asks for it. Paste the **`X-Auth-Token`** value when prompted. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Sage HR** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Key rotated - recopy after re-enable. Correct **subdomain**. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Segment Source: https://docs.iru.com/en/compliance/sources/segment-source Connect Segment to Iru Compliance with a Public API access token to collect workspace, source, destination, and tracking-plan evidence. ### About Segment The **Segment Public API** backs this connector. Iru reads **workspace settings**, **sources and destinations**, **tracking plans**, and **membership** metadata - enough to evidence how customer data flows through Segment. The integration is **read-only** on the Iru side; it does not send events or change workspace configuration. Only **Workspace Owners** can create Public API tokens in Segment. ### How It Works Iru authenticates with a **Bearer** token (Segment **Public API access token**): ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` | Detail | Value | | ------------------------ | -------------------------------------- | | **Category** | Analytics | | **Authentication** | Bearer token (Public API access token) | | **Role to create token** | Workspace Owner | Official references: [Segment Public API](https://segment.com/docs/api/public-api/), [API reference](https://docs.segmentapis.com/), and [Access Management](https://segment.com/docs/segment-app/iam/). ### Prerequisites * **Workspace Owner** on the Segment workspace you need for compliance. * A few minutes to create the token and paste it into Iru. ### Connect Segment to Iru Complete this tab before you connect the source in Compliance. Open [Segment](https://segment.com) and sign in with a user who can manage **workspace** tokens. Select **Settings** (gear) from the Segment app chrome. Choose **Workspace Settings** for the workspace Iru should read. Select **Access Management** (or **Members & access**), then open **Tokens**. Select **Create token** (or **New token**). Enter a name such as **Iru Compliance**. Pick a role aligned to least privilege: * **Workspace Owner**: Broad API access; use when you need full workspace visibility for audits. * **Workspace Member**: Narrower; may omit resources your program cares about. Create the token and **copy it immediately**. Segment shows it **once**. Treat it like a password until you paste it in **Iru Compliance**. Segment may **auto-revoke** tokens detected in public repositories; owners get notified. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Segment**](#segment) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Segment** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. When the wizard asks for the token, paste the **Public API access token** and submit. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Segment** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Copy the token exactly; confirm it was not deleted or auto-revoked. Prefer a **Workspace Owner** token over a limited Member token. Tokens are **workspace-scoped** - create the token in the workspace you connected in Iru. ### Considerations Tokens do not expire by default - rotate on a schedule and update Iru after rotation. Multiple workspaces need **separate** Iru connections and tokens. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Semgrep Source: https://docs.iru.com/en/compliance/sources/semgrep-source Connect Semgrep AppSec Platform to Iru Compliance with a Bearer API token that includes the Web API scope to collect findings, deployments, and policy evidence. ### About Semgrep Iru calls Semgrep’s **Web API** for **findings**, **projects**, and **policies**. Tokens must include the **Web API** scope - **Agent/CI**-only tokens return **404**s on web endpoints. **Team** or **Enterprise** tier is typically required for API access. ### How It Works ```http theme={null} Authorization: Bearer YOUR_API_TOKEN ``` | Detail | Value | | ------------------ | ---------------------- | | **Category** | Security | | **Authentication** | Bearer (Web API scope) | Official references: [Tokens](https://semgrep.dev/docs/deployment/tokens), [Web API scope](https://semgrep.dev/docs/kb/semgrep-appsec-platform/api-404-token-scope), [API reference](https://semgrep.dev/api/v1/docs/). ### Prerequisites * **Admin** or **Owner** on the Semgrep org. ### Connect Semgrep to Iru Complete this tab before you connect the source in Compliance. Open the **Semgrep AppSec Platform** and sign in with an **Admin** or **Owner** for the organization Iru should read. Select **Settings** (gear or profile menu, depending on Semgrep UI). Navigate to **Tokens**, then **API tokens** (wording may read **API Tokens** or **Personal access tokens**). Select **Create** (or **New token**). Enter a name such as **Iru Compliance**. Enable the **Web API** scope (required for this connector). Remove any write scopes your security team does not want for evidence-only use. **Save** the token, then copy the **secret** once. Semgrep shows it only at creation. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Semgrep**](#semgrep) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Semgrep** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the **Bearer** token when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Semgrep** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Recreate token with **Web API** scope. Upgrade to a tier that includes API access. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Sentry Source: https://docs.iru.com/en/compliance/sources/sentry-source Connect Sentry to Iru Compliance with an auth token and the correct regional API host to collect projects, issues, releases, and organization audit logs. ### About Sentry Iru reads **projects**, **issues/events**, **teams**, **releases**, and **audit** data from your **Sentry organization**. Choose the **API host** that matches your deployment (**sentry.io**, **US**, **EU**, or self-hosted). Authentication is a **Bearer** token - either a **personal** auth token or an **organization** token. ### How It Works ```http theme={null} Authorization: Bearer YOUR_AUTH_TOKEN ``` | Detail | Value | | ------------------ | ------------------------------------------------------------------------------------------- | | **Category** | Monitoring | | **Authentication** | Bearer token (personal or org auth token) | | **Audit logs** | Typically **Business** or **Team**; requires **Owner** or **Manager** for full audit access | **Org-level tokens** (Organization Settings → Auth Tokens) survive user churn; **personal** tokens stop working if the user leaves the org. Official references: [Auth tokens](https://docs.sentry.io/account/auth-tokens/), [Create a token](https://docs.sentry.io/api/guides/create-auth-token/), [API](https://docs.sentry.io/api/). ### Prerequisites * Access to the Sentry **organization** you need for compliance. * **Owner** or **Manager** when audit-log evidence is required. ### Connect Sentry to Iru Complete this tab before you connect the source in Compliance. Sign in to **sentry.io** (or your self-hosted Sentry URL) with a user who can create **auth tokens** for the target **organization**. Decide whether Iru should use a **personal** token (tied to your user) or an **organization** token (survives user churn). Organization tokens require **Owner** or **Manager** in many setups. If you chose a personal token: **Settings** → **Personal Tokens** (for example `https://sentry.io/settings/account/api/auth-tokens/`). If you chose an organization token: open your **Organization Settings** → **Auth Tokens** (labels may read **Developer settings** → **Auth tokens**). Create a token, name it (for example **Iru Compliance**), and enable read scopes your controls need, commonly **org:read**, **project:read**, **team:read**, and **event:read** (add audit-related scopes if your plan and role allow). Copy the token value when Sentry shows it. It is shown **once**. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Sentry**](#sentry) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Sentry** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Select the **server** that matches your account: * **`https://sentry.io`**: Default SaaS. * **`https://YOUR_REGION.sentry.io`**: Data residency (for example **`us`** or **`de`**). Confirm the server before entering credentials. Paste the **Bearer token** when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Sentry** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Token copied fully; not revoked. Confirm plan supports audit logs and your role is **Owner**/**Manager**. EU orgs must use the EU host - US endpoint calls fail. User left org - switch to an **org** token or recreate under an active user. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Shortcut Source: https://docs.iru.com/en/compliance/sources/shortcut-source Connect Shortcut to Iru Compliance with a workspace API token in the Shortcut-Token header to collect story, epic, iteration, and workflow membership evidence. ### About Shortcut Iru uses the **Shortcut REST API v3** with the **`Shortcut-Token`** header. Tokens are **workspace-wide** and highly sensitive - Shortcut may **auto-revoke** keys found in public repositories. ### How It Works ```http theme={null} Shortcut-Token: YOUR_TOKEN ``` | Detail | Value | | ------------------ | ------------------------- | | **Category** | Project management | | **Authentication** | API token (custom header) | Official references: [API tokens](https://help.shortcut.com/hc/en-us/articles/205701199-Shortcut-API-Tokens), [REST v3](https://developer.shortcut.com/api/rest/v3). ### Prerequisites * Shortcut user with access to the target **workspace**. ### Connect Shortcut to Iru Complete this tab before you connect the source in Compliance. Open [Shortcut](https://www.shortcut.com) and sign in with a user who can access the **workspace** Iru should read. Select your **Avatar** in the Shortcut header. Choose **Settings** from the menu. Select **Account**, then **API Tokens** (wording may read **Personal API tokens**). Enter a name for the token (for example **Iru Compliance**), then select **Generate Token**. **Copy** the token value once. **Regenerate** invalidates the old token, so update Iru if you rotate. Shortcut may **auto-revoke** keys found in public repositories. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Shortcut**](#shortcut) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Shortcut** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste into the **`Shortcut-Token`** field when prompted. Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Shortcut** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. New token; check auto-revocation. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Slack Source: https://docs.iru.com/en/compliance/sources/slack-source Connect Slack to Iru Compliance with a bot token to collect workspace metadata, channel inventory, user and group membership, and Enterprise Grid audit logs. ### About Slack The **Slack** connector reads workspace membership, channel configuration, and user groups. On **Enterprise Grid**, it also reads **audit log** events. It surfaces that information as artifacts in Iru Compliance. Iru authenticates with a **bot OAuth token** (`xoxb-`) obtained by installing a Slack app into your workspace. Access is **read-oriented** for compliance evidence; it does not send messages or change workspace settings through the scopes described here. ### How It Works Slack APIs expect the bot token in the **Authorization** header: ```http theme={null} Authorization: Bearer xoxb-XXXX-XXXX-XXXX ``` You create an app at **api.slack.com**, grant **Bot token scopes**, install the app to the workspace, then copy the **Bot User OAuth Token**. Expanding scopes requires **reinstalling** the app, which issues a **new** token. Update Iru whenever that happens. | Detail | Value | | ------------------ | -------------------------------------------------------------------------------------------------------------------------------- | | **Category** | Communications | | **Authentication** | Bearer token (bot OAuth token `xoxb-`) | | **Audit logs** | **`auditlogs:read`** is **Enterprise Grid only**. Without Grid, audit-log-style evidence is not available through this API path. | References: [OAuth tokens](https://docs.slack.dev/authentication/tokens/), [Scopes](https://docs.slack.dev/scopes/), [Audit Logs API](https://docs.slack.dev/apis/audit-logs-api/). ### Prerequisites * **Workspace Owner** or **Workspace Admin** rights so you can install apps. * Ability to sign in to **[api.slack.com/apps](https://api.slack.com/apps)** for your workspace. * Optional: Enterprise Grid if you need **`auditlogs:read`**. **Typical bot scopes for directory and channel evidence** | Scope | Purpose | | ------------------ | ------------------------------------------------ | | `users:read` | Read member profiles | | `users:read.email` | Read member email addresses | | `channels:read` | List and read public channels | | `groups:read` | List and read private channels (where permitted) | | `usergroups:read` | Read user group configuration | | `auditlogs:read` | Audit logs (**Enterprise Grid** only) | ### Connect Slack to Iru Complete this tab before you connect the source in Compliance. In a browser, go to **[api.slack.com/apps](https://api.slack.com/apps)** and sign in with a Slack account that can **create apps** for the target **workspace** (often a workspace admin). Select **Create New App**, then **From scratch** (unless your org standardizes on a manifest; this article assumes **From scratch**). Enter an app name such as **Iru Compliance** and select the **Slack workspace** where Iru should install. In the app’s left sidebar, open **OAuth & Permissions**. Under **Bot Token Scopes**, add each scope from **Prerequisites** that your controls require. Add **`auditlogs:read`** only if you are on **Enterprise Grid** and need audit evidence. From **OAuth & Permissions**, select **Install to Workspace** (or **Reinstall** after scope changes). Review permissions and approve. Copy the **Bot User OAuth Token** (starts with **`xoxb-`**). If you change scopes later, reinstall to get a **new** token. Paste the current token into the Iru connector wizard when **Iru Compliance** prompts you. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Slack**](#slack) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Slack** (set **Category** to **Communications** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. When the wizard asks for a bearer token, paste the **`xoxb-`** **Bot User OAuth Token** and submit. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Slack** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Confirm the token is current, begins with **`xoxb-`**, and the app is still installed. Add the scope under **OAuth & Permissions**, **reinstall** the app, copy the **new** token, and update Iru. Reinstall the app or rotate credentials; update Iru with the new bot token. **`auditlogs:read`** requires **Enterprise Grid**. Without it, audit-log API evidence is unavailable. ### Considerations Bot tokens generally **do not expire** unless your workspace enforces rotation. Follow Slack’s guidance if rotation is enabled. Uninstalling the app **revokes** the token immediately. Scope increases always require **reinstall** and a new token. Plan changes during a maintenance window. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Smartsheet Source: https://docs.iru.com/en/compliance/sources/smartsheet-source Connect Smartsheet to Iru Compliance with a read-only API access token to collect user and license inventory, sheet sharing permissions, and workspace membership. ### About Smartsheet Iru reads **users with their license types**, **sheets with their sharing permissions**, **workspaces with member access**, and **groups** from the Smartsheet API. Authentication uses an **API access token** generated under **Account** → **Personal Settings** → **API Access**. Requests target `https://api.smartsheet.com/2.0`; there is no subdomain to configure. Iru reads **sharing and access configuration**, not sheet contents. It collects who each sheet is shared with, not the cell data inside. ### How It Works ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` Smartsheet authenticates with a **Bearer** token. Tokens are generated per user and carry that user's **effective access**, with no separate per-endpoint scopes. Sheets and workspaces are shared individually, so a token from a user who is not a member of a workspace returns nothing for it. Iru cannot tell that apart from a workspace that has no sharing to report. Generate the token from a **System Admin** account for the most complete user and license inventory. | Detail | Value | | ------------------ | ------------------------- | | **Category** | Project management | | **Authentication** | Bearer (API access token) | Official references: [API overview](https://smartsheet.redoc.ly/), [Authentication and access tokens](https://smartsheet.redoc.ly/#section/Security/Authentication-and-Access-Tokens). ### Prerequisites * An account that can generate an API access token. Prefer **System Admin** so user and license inventory is complete. * Access to every workspace you expect evidence from. Smartsheet access is per object. * Decide which workspaces are in scope. Excluded workspaces produce no evidence. ### Connect Smartsheet to Iru Complete this tab before you connect the source in Compliance. Sign in to Smartsheet with the account whose access the integration should inherit, ideally a **System Admin**. Select **Account** (your avatar, lower left), then **Personal Settings**. Select **API Access**. Select **Generate new access token**. Enter a name such as **Iru Compliance** so you can identify this token later. Copy the token value **once** while Smartsheet displays it. It cannot be retrieved afterward. If you lose it, generate a replacement. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Smartsheet**](#smartsheet) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Smartsheet** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Paste the token into the **Bearer** field. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Smartsheet** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Regenerate the token and paste the full string. Smartsheet does not let you view an existing token, so a partial copy cannot be checked after the fact. The token's owner is not shared into it. Regenerate the token from a **System Admin** account, or share the in-scope workspaces with the account you used. A non-admin token returns only the users it can see. Use a System Admin token for complete user and license inventory. This is expected. Iru collects sharing and access configuration, not cell data. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Snowflake Source: https://docs.iru.com/en/compliance/sources/snowflake-source Connect Snowflake to Iru Compliance with key-pair JWT authentication and ACCOUNT_USAGE access to collect role grants, users, and data-governance evidence. ### About Snowflake Iru collects **warehouse and account usage**, **database/schema metadata**, **roles and grants**, and **login/query history** from Snowflake, primarily via **`SNOWFLAKE.ACCOUNT_USAGE`** views. Authentication uses **key-pair authentication**: short-lived **JWTs** signed with your **RSA private key**, verified against the **public key** registered on the Snowflake **user** Iru uses. ### How It Works ```http lines theme={null} Authorization: Bearer YOUR_SIGNED_JWT X-Snowflake-Authorization-Token-Type: KEYPAIR_JWT ``` JWTs are **short-lived** (about **60 seconds**); Iru regenerates them using the configured key and account details. | Detail | Value | | ------------------ | ------------ | | **Category** | Databases | | **Authentication** | Key-pair JWT | Official references: [Key-pair authentication](https://docs.snowflake.com/en/user-guide/key-pair-auth), [Account identifiers](https://docs.snowflake.com/en/user-guide/admin-account-identifier), [REST API](https://docs.snowflake.com/en/developer-guide/snowflake-rest-api/snowflake-rest-api), [ACCOUNT\_USAGE](https://docs.snowflake.com/en/sql-reference/account-usage). ### Prerequisites * **`SECURITYADMIN`** (or equivalent) to assign **`RSA_PUBLIC_KEY`** on a dedicated service user. * **OpenSSL** (or another tool) to generate a **2048-bit** (or larger) RSA key pair. * Your **account identifier** (`orgname-accountname` preferred, or legacy locator with region/cloud if required). ### Connect Snowflake to Iru Complete this tab before you connect the source in Compliance. Sign in to Snowsight or the classic console with **`SECURITYADMIN`** (or equivalent) so you can run **`ALTER USER`** and **`GRANT`** statements for the integration user. Use a trusted machine with **OpenSSL** (or another RSA tool your security team approves). You will keep **`snowflake_private_key.pem`** only in your vault. Never commit it to git or send it to Snowflake support. Example with OpenSSL: ```bash lines theme={null} openssl genrsa -out snowflake_private_key.pem 2048 openssl rsa -in snowflake_private_key.pem -pubout -out snowflake_public_key.pem ``` Protect **`snowflake_private_key.pem`**. Never commit it or share it with Snowflake. As an administrator, strip the PEM headers and newlines from **`snowflake_public_key.pem`** so only the base64 body remains, then run: ```sql theme={null} ALTER USER YOUR_USERNAME SET RSA_PUBLIC_KEY='YOUR_PUBLIC_KEY'; ``` Snowflake allows **two** keys per user (`RSA_PUBLIC_KEY` / `RSA_PUBLIC_KEY_2`) for rotation. Assign the new key to **`RSA_PUBLIC_KEY_2`**, update Iru, then drop the old key. Use **Snowflake CLI** or a library. For example: ```bash lines theme={null} snow connection generate-jwt \ --account YOUR_ACCOUNT_IDENTIFIER \ --user YOUR_USERNAME \ --private-key-path snowflake_private_key.pem ``` Copy the JWT string for the initial Iru handshake; ongoing regeneration is handled in product. The integration user needs a role that can read **`SNOWFLAKE`** shared metadata, for example: ```sql lines theme={null} GRANT IMPORTED PRIVILEGES ON DATABASE SNOWFLAKE TO ROLE YOUR_ROLE; GRANT ROLE YOUR_ROLE TO USER YOUR_USERNAME; ``` Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Snowflake**](#snowflake) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Snowflake** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Choose the host pattern that matches your account: * Standard: `https://YOUR_ACCOUNT_IDENTIFIER.snowflakecomputing.com` * **PrivateLink**: `https://YOUR_ACCOUNT_IDENTIFIER.privatelink.snowflakecomputing.com` Enter **`account_identifier`** and confirm server variables before continuing. When prompted, paste the **JWT**. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Snowflake** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Wizard session expired. Toggle the source off and on, then retry. Run **`DESCRIBE USER`** to confirm the fingerprint matches and the private key pairs with the registered public key. Prefer **`org-account`** form; legacy locators may need **region/cloud** suffix. Ensure Iru egress can reach your endpoint; allowlist if required. **`IMPORTED PRIVILEGES`** on **`SNOWFLAKE`** for the Iru role. ### Considerations Iru does **not** run arbitrary queries against your tables. It reads governance-oriented metadata and usage views. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Trello Source: https://docs.iru.com/en/compliance/sources/trello-source Connect Trello to Iru Compliance with a Power-Up API key and user token to collect read-only access to boards, lists, cards, and workspace membership evidence. ### About Trello Trello’s REST API expects **`key`** (application id from **Power-Ups admin**) and **`token`** (user-authorized) on requests (for example **`GET /1/members/me/boards?key=…&token=…`**). The **key** is shareable; the **token** is secret and scopes access to what the authorizing user can see. ### How It Works Iru authenticates to Trello’s REST API with your **Power-Up API key** and a **user token**, passed as **`key`** and **`token`** query parameters on each request (for example **`GET https://api.trello.com/1/members/me/boards?key=…&token=…`**). | Detail | Value | | ------------------ | ---------------------------------- | | **Category** | Project management | | **Authentication** | API key + token (query parameters) | Create or open a **Power-Up** at **`https://trello.com/power-ups/admin`**, open the **API key** tab, **generate** a key, then visit Trello’s **authorize** URL with **`scope=read`** and your key to mint a **token**. Official references: [Authorization](https://developer.atlassian.com/cloud/trello/guides/rest-api/authorization/), [API introduction](https://developer.atlassian.com/cloud/trello/guides/rest-api/api-introduction/), [Power-Up admin](https://trello.com/power-ups/admin). ### Prerequisites * Trello user who can access the **boards** and **workspaces** you need for audits. ### Connect Trello to Iru Complete this tab before you connect the source in Compliance. Open [Trello](https://trello.com) and sign in with a user who can access the **boards** and **workspaces** Iru should read. Go to **`https://trello.com/power-ups/admin`** (Trello Power-Up administration) for your account. Create a new Power-Up (or open an existing one) that you will use only to mint API credentials for Iru. Name it clearly (for example **Iru Compliance**). Open the **API key** tab for that Power-Up and **generate** an API **key** (`key`). Copy the key value; you will enter it in Iru as the **`key`** parameter. Open Trello’s **authorize** URL documented for Power-Ups, including **`expiration`**, **`scope=read`**, **`response_type=token`**, and **`key=YOUR_API_KEY`**. Approve access when Trello prompts you. After you click **Allow**, Trello returns a **token** string. Copy it immediately; you will pair it with **`key`** in Iru. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Trello**](#trello) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Trello** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Provide **`key`** and **`token`** as the wizard shows (one screen or separate fields). Click **Submit API Key**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Trello** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Regenerate token; confirm key still valid. Rate limits - retries may spread sync. Token user must **join** those boards/workspaces. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # WordPress Source: https://docs.iru.com/en/compliance/sources/wordpress-source Connect WordPress to Iru Compliance over the REST API using HTTP Basic Auth with an Application Password to collect site, user, role, and plugin evidence. ### About WordPress **WordPress 5.6+** supports **Application Passwords** for REST clients. Iru calls **`https://YOUR_HOST/wp-json/...`** with **HTTP Basic** (**username** + **application password**). **HTTPS** is required - Application Passwords are rejected over plain HTTP. ### How It Works ```http theme={null} Authorization: Basic base64(username:application_password) ``` | Detail | Value | | ------------------ | ---------------------------- | | **Category** | CRM | | **Authentication** | Basic (Application Password) | Self-hosted **5.6+** or **WordPress.com** **Personal+** (Free tier does not expose Application Passwords per product limits). Official references: [Application Passwords](https://developer.wordpress.org/advanced-administration/security/application-passwords/), [REST API](https://developer.wordpress.org/rest-api/reference/). ### Prerequisites * **Administrator** (or role that may issue Application Passwords). * **`/wp-json`** reachable and not blocked by security plugins. ### Connect WordPress to Iru Complete this tab before you connect the source in Compliance. Open **`https://YOUR_HOST/wp-admin`** and sign in with a user who can edit **Users** and create **Application Passwords** (often an **Administrator**). In the left admin menu, select **Users** → **All Users**, then click the user Iru will authenticate as (often a dedicated service account). Select **Edit** (or **Profile**) for that user to open the profile screen. Scroll to the **Application Passwords** section (WordPress **5.6+**). If it is missing, confirm the site allows Application Passwords and is served over **HTTPS**. Enter a name such as **Iru Compliance**, then select **Add New Application Password** (or **Add**). WordPress generates a spaced token. Copy the full application password string once. You may paste it into Iru **with or without spaces**; WordPress accepts both forms. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**WordPress**](#wordpress) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **WordPress** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **hostname** only (for example `blog.example.com`). Confirm server variables if prompted. Enter **username** and **application password** for the integration account. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **WordPress** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Correct password; plugin not blocking REST. Security plugins - allow **`wp-json`**. Enable **TLS**. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Workable Source: https://docs.iru.com/en/compliance/sources/workable-source Connect Workable to Iru Compliance with a scoped Bearer token and your account subdomain to collect job, candidate pipeline, and recruiter access evidence. ### About Workable Iru calls **`https://YOUR_SUBDOMAIN.workable.com/spi/v3`** with **`Authorization: Bearer`**. Access tokens are **scoped** and carry a **mandatory expiration** (between **30 days** and **2 years**). Use **read** scopes only, e.g. **`r_jobs`**, **`r_candidates`** - and omit **write** scopes for least privilege. ### How It Works ```http theme={null} Authorization: Bearer YOUR_ACCESS_TOKEN ``` | Detail | Value | | ------------------ | ---------------------------- | | **Category** | HRIS | | **Authentication** | Bearer (scoped access token) | Official references: [Access tokens](https://help.workable.com/hc/en-us/articles/115015785428), [API](https://help.workable.com/hc/en-us/articles/115013356548), [REST reference](https://workable.readme.io/reference). ### Prerequisites * **Admin** role - only Admins create tokens. * **Subdomain** from `https://YOUR_SUBDOMAIN.workable.com`. ### Connect Workable to Iru Complete this tab before you connect the source in Compliance. Open `https://YOUR_SUBDOMAIN.workable.com` and sign in with an **Admin** (only Admins can create access tokens). Select **Profile** (or your avatar) in the Workable header. Choose **Settings** from the menu. Select **Integrations** (or **Developer** / **API**, depending on your Workable edition) until you see **Access Tokens**. Open **Access Tokens**, then **Generate new token**. Enter a name such as **Iru Compliance**. Set **expiry** per your rotation policy. Enable only **read** scopes your controls need (for example **`r_jobs`**, **`r_candidates`**). Generate the token and copy the value **once** when Workable displays it. Store it securely until you paste it into Iru as the **Bearer** token. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Workable**](#workable) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Workable** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **subdomain** only (for example `mycompany`), not the full URL. Confirm server variables if the wizard shows a preview. Paste the **Bearer** token when prompted. Click **Submit Bearer Token**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Workable** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. Token expired; rotate. Add missing **read** scopes - new token required. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Workday Report Source: https://docs.iru.com/en/compliance/sources/workday-report-source Connect Workday Reports as a Service to Iru Compliance using an Integration System User and HTTP Basic Auth to collect employee, role, and report evidence. ### About Workday Report Iru consumes **Advanced Custom Reports** exposed as **REST** (**Reports as a Service**, **RaaS**). Authenticate with an **Integration System User (ISU)** via **HTTP Basic** (`isu_username`/`isu_password`). URLs follow **`https://YOUR_HOST/ccx/service/customreport2/YOUR_TENANT/YOUR_OWNER/YOUR_REPORT`** - **production** vs **implementation** hosts and **data-center** suffixes (`wd5`, `wd12`, …) must match your tenant. ### How It Works ```http theme={null} Authorization: Basic base64(isu_username:isu_password) ``` | Detail | Value | | ------------------ | ----------- | | **Category** | HRIS | | **Authentication** | Basic (ISU) | Official references: [RaaS community article](https://community.workday.com/articles/6445), Workday docs on **ISU** and **security** (see your Workday release documentation). ### Prerequisites * **Tenant admin** to create an **ISU**, **security group**, and **enable** target reports as **web services**. ### Connect Workday Report to Iru Complete this tab before you connect the source in Compliance. Sign in to the correct **Workday tenant** (production vs implementation) with security rights to create **Integration System Users** and **security groups**. Use the **Create Integration System User** task. Create a **dedicated** service account for Iru, not a human interactive user. Set **Session Timeout** to **0** only where policy allows, and choose a password policy compatible with automation. Add the ISU to an **Integration System Security Group** that grants **Get** access to the **domains** your reports need (commonly **HR** and **Security Configuration**; adjust to your report definitions). In the security group (or related authentication policy), ensure **User Name Password** (or **WS-Security Username Token**) authentication is allowed for the ISU, per Workday’s integration authentication model. Run **Activate Pending Security Policy Changes** (or your tenant’s equivalent) so Workday applies the new user and group memberships. Locate the **Advanced Custom Report** (or report definition) you want Iru to consume via **Reports as a Service**. Set the report type to **Advanced** where required, enable **Enable As Web Service**, and **save** the definition. Use **Actions** → **Web Service** → **View URLs** (wording may vary) and copy the **REST** endpoint URL, tenant path, and credentials details Iru’s wizard asks for. Continue on the [**Iru Compliance**](#iru-compliance) tab. Finish the [**Workday Report**](#workday-report) tab first. In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**. Left navigation: Compliance expanded, Sources selected Find **Workday Report** (use **Category** or **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard. Enter **tenant** and host values as the wizard shows. Match **implementation** vs **production** and **region** to your Workday tenant. Enter the **ISU** **username** and **password**. Click **Submit Credentials**. When the connection succeeds, the wizard shows **Connection Configured**. Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Workday Report** card is **Active**. ### Troubleshooting Check **pop-up blocker** settings for the Iru site and try again. ISU credentials; auth policy allows password auth. ISSG **domain** permissions; activate security changes. Report not **web service**-enabled; ISU cannot see data domain. Do not mix **impl** and **prod** credentials. ### Related Articles Browse and manage every Compliance source. Frameworks, actions, and **Artifacts**. How Endpoint, Compliance, and Identity fit together. Upload, review, and organize evidence from sources and actions. # Trust Center Accounts Source: https://docs.iru.com/en/compliance/trust-center/trust-center-accounts Create and manage Trust Center user accounts and viewer access. Control who can view your compliance posture and security documentation. ### About Trust Center Accounts Management The **Accounts** tab is where you manage who has access to your Trust Center. It provides visibility into all pending access requests and approved accounts. Each request or account record shows details such as the requester's organization, email, status, and NDA attachments when applicable. From this tab, you can approve or reject access requests, verify NDA submissions, review existing accounts, and revoke access at any time. ### How It Works Trust Center accounts management provides a structured approach to controlling access to your compliance materials. The system tracks all access requests, manages the approval workflow, and maintains a record of all approved users with their access history and download activity. ### Accounts Management Capabilities #### Access Request Workflow When someone requests access from your public Trust Center page, the request appears under **Access Requests** Each entry includes requester information and an NDA file if NDA protection is enabled Click **Preview** to open a request and review its details If NDA protection is enabled, download and verify the signed NDA before approving Click **Approve** to grant access or **Reject** to deny the request #### Account Management Approved users appear in the **Approved Accounts** section From here, you can view user details, track document access, or remove accounts when no longer needed Review download activity and access patterns for each account Modify account details or contact information as needed #### Access Revocation Select any account from the Approved Accounts list Click **Delete** to remove access Once deleted, the user will no longer be able to log in or download documents from your Trust Center Consider notifying the user about access revocation if appropriate Ensure all access decisions are documented and comply with your organization's security policies and applicable regulations. The accounts management system maintains a complete audit trail of all access decisions and user activity for compliance purposes. Trust Center access events also appear on the [Unified Activity](/en/iru/platform-overview/unified-activity). # Trust Center Answers Questionnaires Source: https://docs.iru.com/en/compliance/trust-center/trust-center-answers-questionnaires Complete security questionnaires in Trust Center for auditors and customers. Use saved answers, collaborate with team members, and track progress. ### About Answers & Questionnaires The **Answers** tab stores reusable question-and-answer pairs (with categories, owners, and optional public publishing). The **Questionnaires** tab accepts uploaded assessments (CSV, XLSX, DOCX, PDF); Iru fills answers where possible using **Answers** and artifacts marked **Show in Trust Center**, then your team reviews and approves before delivery. ### How It Works Maintain **Answers** over time so auto-complete stays accurate. When you upload a questionnaire, match confidence depends on how closely customer questions align with your library and which artifacts you attach as context. ### Answers Management #### Answers Library Overview The **Answers** tab is a centralized knowledge base for frequently asked security/compliance questions. Create answers once, reuse them internally, and optionally **publish** selected answers to the public Trust Center. * Stores **Question, Answer, Comments, Categories, Owner, Date Added, Visibility** * Add entries one-by-one or upload in bulk via **CSV template** * Edit via the **⋮ (three-dot) menu**; toggle **Show in Trust Center** to publish * Add **support links** (e.g., Privacy Policy URL) to any answer #### Adding Answers Click **New Entry** to add a single answer Fill in **Question**, **Answer**, optional **Comments**, **Categories**, **Owner**, **Support Links**, and toggle **Show in Trust Center** (optional) Click **Save** to add the answer to your library #### Bulk Upload Click **Bulk Entries → Download Template** Populate required columns exactly as in the template: `question,answer,comments,categories,owner,support_links` Click **Bulk Entries → Upload CSV** and submit #### Managing Answers In the **Answers** list, use the **⋮** menu → **Edit Answer** Update **Question, Answer, Comments, Categories, Owner, Support Links** Toggle **Show in Trust Center** to make it public **Delete** answers if no longer needed ### Questionnaires Management #### Questionnaires Overview The **Questionnaires** tab lists uploaded customer or vendor assessments. After upload, Iru proposes answers from your **Answers** library and artifacts you allow as context; your team reviews, edits, approves, then downloads or emails the result. Typical list statuses include **Imported** (processing), **Draft**, **In Review**, **Approved**, and **Delivered** - exact labels follow what your tenant shows. #### Uploading Questionnaires From the **Questionnaires** tab, click **Upload Questionnaire** Enter a display name that will appear in the list view Select an account. If the questionnaire is from an internal request, choose your internal company account. If it is from a customer, select the customer account so the completed questionnaire can later be delivered back to them Optionally, set a due date if a delivery commitment has been made Attach the questionnaire file by dragging and dropping or browsing your system. Accepted file types are CSV, XLSX, DOCX, and PDF The upload screen will display any available artifacts already marked as **Show in Trust Center** so you can select them as supporting sources Click **Submit** to upload and begin AI processing #### AI Processing and Review Once submitted, **Iru AI** automatically scans the uploaded questionnaire It searches your **Answers** library and selected **Artifacts** to match and populate relevant answers After processing is complete, click the questionnaire name in the list to open it You can edit any answer manually by clicking the question and opening the edit details screen For any non-applicable items, select **Mark Not a Question** to exclude them #### Approval and Delivery Before a questionnaire can be finalized, every question must either have an answer or be marked as not a question You can approve answers individually or click **Approve All** once you have reviewed the entire questionnaire At any time, click **View Original** at the top of the page to download the questionnaire file that was originally uploaded Once all questions are approved, the questionnaire can be marked as complete Click **Download** to export the final document or **Email** to send the approved version directly to the associated account contact ### Support Tips * **CSV upload fails**: Verify headers, data types (`TRUE/FALSE`), and required columns * **Not visible publicly**: Ensure **Show in Trust Center** is on; give the portal a moment to refresh * **Broken links**: Use full `https://` URLs * **Findability**: Use specific, consistent **Categories** * **Auto-answers missing**: Verify that questions align with existing entries in the **Answers** library or that relevant **Artifacts** are marked **Show in Trust Center** * **Cannot approve questionnaire**: Confirm that every question has either an answer or is marked not a question * **Customer doesn't receive email**: Check that the correct **Account** is assigned and includes a valid contact email Always review AI-generated answers for accuracy and completeness before approving questionnaires. AI responses should be validated against your organization's actual practices and policies. Revisit **Answers** when policies change so questionnaire drafts stay aligned with current practices. Update policies in [Policies Management](/en/compliance/policies-management). # Trust Center Management Source: https://docs.iru.com/en/compliance/trust-center/trust-center-management Manage the Iru Trust Center for sharing your security posture. Publish compliance documents, answer questionnaires, and manage viewer access. ### About Iru Trust Center Iru Trust Center is a branded portal where you publish certifications, policies, and answers to common security questions. Visitors can request access to restricted documents; you approve accounts, enforce NDAs when needed, and revoke access from one place. On the left navigation bar, expand **Compliance** and select **Trust Center**. The page uses tabs for **Accounts**, **Editor**, **Answers**, and **Questionnaires**. Left navigation: Compliance expanded, Trust Center selected ### How It Works You can run Trust Center alongside the full Compliance suite or on its own. Either way, you control branding, domains, which artifacts and answers are public, and who can sign in after approval. Visitors open your portal, request access to restricted content when needed, sign an NDA if you require it, then read or download only what you published. Your admins use the **Editor**, **Accounts**, **Answers**, and **Questionnaires** tabs (see [Compliance Permissions](/en/compliance/compliance-permissions) for who can change each area). Default hosting uses an Iru subdomain; you can add a **custom domain** with DNS verification. See [Trust Center Setup](/en/compliance/trust-center/trust-center-setup). ### Trust Center Capabilities #### Accounts Management Manage who can view and download your published compliance documents (**Accounts** tab). * Review **Access requests** and approve or reject them * View and manage approved accounts with granted access * Click **Access rules** to open **Access request rules**. Turn **Access auto-approval** on or off depending on whether visitors with a signed NDA should be approved automatically. * Review and verify signed NDAs before approval when your process requires it * Revoke or delete access instantly #### Editor Customize and brand your public Trust Center to reflect your organization's identity (**Editor** tab). * Use **Get started** in the section header when you are setting up the profile for the first time * Complete **Your profile** (logo, company name, brand colors, tagline, description, domain, email, privacy policy URL) * Set a **custom domain** (for example `trust.yourdomain.com`) with CNAME verification where supported * Under **Certifications**, choose standard entries and add **custom certifications** as needed * Use **Manage artifacts** to choose which evidence appears on the public page * Under **NDA - Access requests**, upload a manual NDA PDF, or use the **DocuSign** card: turn the **toggle** on, then **Select template** once **DocuSign** shows as connected (until then the card shows **Not connected**). * Enable **NDA protection** so users must sign before viewing restricted materials #### Artifacts Integration Publish approved compliance documents, reports, or policies directly to your Trust Center. * Create and publish policies in [Policies Management](/en/compliance/policies-management), then share them through Trust Center * Upload or select existing artifacts from the **Artifacts** module * From the artifact's detail drawer, toggle **"Show in Trust Center"** * Manage all published documents through the **Editor** tab for visibility and NDA settings #### Answers Create and manage a repository of pre-approved responses for security and compliance questionnaires (**Answers** tab). * Add entries with **+ Add entry** or **+ Bulk entries**; use **Manage categories** to organize the library * Include questions, answers, comments, categories, owners, and support links * Toggle **Show in Trust Center** to make answers publicly visible * Feed responses into Iru AI for automatic questionnaire completion #### Questionnaires Upload questionnaires from customers or vendors and let **Iru AI** automatically generate answers using your **Answers** library and **Trust Center artifacts** (**Questionnaires** tab). * Start with **+ Upload questionnaire**. The flow accepts **CSV, XLSX, DOCX, and PDF** (shown in the modal). * Optionally link **sources for generated answers** by selecting artifacts from the list * Displays each questionnaire's progress and status * Review, edit, approve, or mark questions as non-applicable * Download or email the completed questionnaire to customers once approved #### Public Trust Center Portal A fully branded, secure webpage where approved users can view and download published compliance information. * Public visitors can request access to restricted materials * Approved users see certifications, artifacts, and published answers * Access is gated behind NDA enforcement when enabled * Supports a dual-domain experience: default Iru subdomain and optional custom URL ### Core Concepts #### Trust Center A branded portal for publishing and sharing compliance information securely with external stakeholders. #### Accounts The list of users or organizations that have requested or been granted access to the Trust Center. #### Access Requests Pending access requests that must be reviewed before approval. #### Editor The configuration section used for branding, domain setup, and publication of documents and certifications. #### Artifacts Compliance evidence, reports, or policies published from [Policies Management](/en/compliance/policies-management), **Artifacts**, or uploaded directly. #### Answers Pre-approved responses for recurring compliance or security questions. #### Questionnaires Uploaded security or compliance assessments that Iru AI can automatically populate with answers and evidence. #### NDA Protection A feature that enforces signing an NDA before access to sensitive materials is granted. ### Quick Start Guide #### Set Up Your Trust Center On the left navigation bar, expand **Compliance** and select **Trust Center** Set up your company information, logo, and contact details Set up your custom domain or use the default Iru subdomain Upload your NDA document and enable protection if needed #### Publish Your First Artifacts Upload compliance documents, reports, or policies Toggle **"Show in Trust Center"** for artifacts you want to publish Check how artifacts appear on your public Trust Center #### Set Up Answers Library Add frequently asked security and compliance questions Toggle **"Show in Trust Center"** for public answers Upload a test questionnaire to verify AI auto-answering ### Related Articles Once you've completed the quick start guide, explore these detailed guides: Trust Center in context with Endpoint, Compliance, and Identity on one platform. Create and publish security policies before sharing them on Trust Center. Configure branding, domains, and NDA protection. Access request management and account approval. AI-powered questionnaire processing. The external user experience. Ensure all published content is accurate and up-to-date. Outdated compliance information can create legal and business risks. # Trust Center Public Portal Source: https://docs.iru.com/en/compliance/trust-center/trust-center-public-portal Share compliance documentation through the Trust Center public portal. Customize branding, publish certifications, and control public visibility. ### About the Trust Center Public Portal The **Public Trust Center Portal** is a fully branded, secure webpage where approved users can view and download published compliance information. It provides a professional, self-service experience that builds confidence, supports sales, and protects sensitive materials. The portal replaces one-off email requests with a controlled, branded experience that gives external stakeholders easy access to your compliance information while maintaining security and control. ### How It Works The public portal provides a secure, branded interface where external stakeholders can request access, view published compliance materials, and download approved documents. The system enforces access controls, NDA requirements, and provides a professional presentation of your organization's security posture. ### Public Portal Features #### Public Access * **Public visitors** can request access to restricted materials * **Approved users** see certifications, artifacts, and published answers * **Access is gated** behind NDA enforcement when enabled * **Supports dual-domain** experience: default Iru subdomain and optional custom URL #### Branding and Customization * **Professional appearance** with your organization's logo and branding * **Custom domain** support (e.g., `trust.yourdomain.com`) * **Company information** display including description and contact details * **Consistent branding** across all portal pages #### Access Control * **Request-based access** with approval workflow * **NDA protection** when enabled for sensitive materials * **Account management** with individual user access * **Download tracking** and activity monitoring #### Content Display * **Certifications** prominently displayed with download options * **Artifacts** organized by category and type * **Answers** section for frequently asked questions * **Search functionality** for finding specific information ### User Experience #### Initial Visit Users visit your Trust Center URL (custom domain or Iru subdomain) Public visitors can see basic company information and available certifications To access restricted materials, users click **Request Access** Users enter their name, email, organization, and purpose for access #### NDA Process (if enabled) If NDA protection is enabled, users are prompted to download the NDA document Users sign the NDA and upload the signed document Users submit their access request with the signed NDA Users receive confirmation that their request is under review #### Approved Access Once approved, users receive an email with login instructions Users log in using their email and the provided access credentials Approved users can browse all published certifications, artifacts, and answers Users can download approved documents and materials ### Portal Configuration #### Public Information Display * **Company logo** and branding elements * **Company description** and contact information * **Published certifications** with download links * **Available artifacts** organized by category * **Frequently asked questions** from your answers library #### Access Request Form * **Requester information** fields (name, email, organization) * **Purpose of access** description * **NDA download** and upload (if enabled) * **Terms and conditions** acceptance #### Approved User Experience * **Dashboard view** of all available materials * **Search functionality** for finding specific documents * **Download tracking** and history * **Account management** options Ensure all published content is accurate and up-to-date. Outdated compliance information can create legal and business risks. Smoke-test the visitor path after you change branding, NDAs, or published documents so visitors see what you expect. # Trust Center Setup Source: https://docs.iru.com/en/compliance/trust-center/trust-center-setup Set up and customize your Iru Trust Center. Configure branding, add compliance documents, enable the public portal, and invite viewers. ### About Trust Center Setup The **Editor** tab is where you customize, configure, and publish your Trust Center: branding, company details, domain, certifications, and NDA enforcement. Everything you publish or change here affects how your public Trust Center portal looks and behaves. ### How It Works Setup walks through branding, domain, published content, and access rules so the public portal matches how you want to share compliance information. ### Setup Capabilities #### Initial Configuration Navigate to **Trust Center** → **Editor** in the sidebar If this is your first time configuring the Trust Center, click **Get Started** Enter your company name, description, contact email, and privacy policy URL Upload your company logo to display on your public page #### Domain Configuration By default, your Trust Center is hosted at `yourcompany.trust-center.iru.com` To use a custom domain, click the **Edit** icon next to the domain field Enter your preferred subdomain (e.g., `trust.yourdomain.com`) Follow the DNS instructions to add a CNAME record Once verified, your Trust Center will be accessible from both your Iru subdomain and your custom domain #### Certification Management From the Editor, upload or link your compliance certifications such as SOC 2, ISO 27001, and GDPR You can also add custom certifications or policies that you wish to display on your public page Arrange certifications in the order you want them to appear on your public Trust Center #### NDA Protection Setup To enable NDA protection, attach your NDA document under the NDA section of the Editor When NDA is active, anyone requesting access will be prompted to download, sign, and upload the NDA before approval Administrators can then review the NDA file in the Accounts tab before granting access #### Artifacts Management From the Editor, click **Manage Artifacts** to open the list of available artifacts Click **Upload Artifact** to add new materials Provide a clear name, description, and upload the file or let Iru AI automatically process the document and generate a title and description Accepted file types include PDF, DOCX, XLSX, and CSV Open any artifact to view its details and select **Show in Trust Center** to publish it on your public page You can update artifact details, replace files, or unselect **Show in Trust Center** to remove them from public view without deleting them from your internal system Ensure all published content is accurate and up-to-date. Outdated compliance information can create legal and business risks. You can work through setup in stages and return later; progress is saved as you go. # How to Submit Iru Agent Diagnostics Source: https://docs.iru.com/en/endpoint/agent/how-to-submit-iru-agent-diagnostics Submit Iru Agent diagnostic data for troubleshooting macOS and Windows issues. Collect logs, generate reports, and share them with support. This guide applies to Mac computers ### About Iru Agent Diagnostics The Iru Agent has a built-in tool for gathering and submitting detailed diagnostic data from your Mac to Iru Endpoint for troubleshooting. This data includes logs, operating system information, and other relevant details about your device, which helps the Iru Endpoint support team investigate behaviors and provide guidance to troubleshoot issues. For information on submitting macOS-specific diagnostics, please see our [How to Generate a Sysdiagnose in macOS](/en/endpoint/devices/device-configurations/apple/how-to-generate-a-sysdiagnose-in-macos) support article. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. Submit Diagnostics has been updated to Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How to Submit Iru Agent Diagnostics There are three ways to submit diagnostics from an Iru Endpoint-enrolled Mac: using the Iru menu bar, using Self Service, or using the command-line interface (CLI). #### Submitting Diagnostics using the Iru menu bar If the Iru menu bar icon is hidden, it can be revealed again from the Iru Self Service application. Select the **Iru jellyfish** from the menu bar. Click the settings **gear**. Iru Endpoint menu bar showing the jellyfish icon and settings gear Choose **Submit Diagnostics...** from the dropdown menu. Iru Endpoint settings menu open with Submit Diagnostics visible Optionally, add comments describing the issue you're experiencing. Click **Submit**. Iru Endpoint menu bar flow: Submit Diagnostics and submitting diagnostic data #### Submitting Diagnostics using Iru Self Service Open the **Self Service** app. Click **Device Info**. Click the **ellipsis** next to Sync. Select **Submit Diagnostics**. Iru Self Service Device Info page showing the ellipsis menu with Submit Diagnostics option Optionally, add comments describing the issue you're experiencing. Click **Submit**. Submit diagnostics dialog with optional comments field and Cancel and Submit buttons for sending diagnostic data to Iru Endpoint #### Submitting Diagnostics using the Command-Line Interface This method requires administrator privileges. Open **Terminal.app**. Run the following Terminal command, using `--comment` to add optional comments describing the issue you're experiencing: ```bash theme={null} sudo iru submit-diagnostics [--comment text] ``` ### Data and Privacy Considerations When a user submits diagnostics, the Iru Agent collects the following information from an enrolled Mac: * System logs * OS version * Application inventory * Device configuration details * Network information * Error messages and alerts Iru Endpoint ensures that the diagnostic data collected is used solely for troubleshooting and improving device management and support, respecting user privacy. For more information on privacy with Iru Endpoint, see our [Privacy Policy](https://www.iru.com/legal/privacy/). # Iru Agent and MDM Source: https://docs.iru.com/en/endpoint/agent/iru-agent-and-mdm Learn how the Iru Agent works alongside MDM on macOS and Windows. Understand agent capabilities, communication protocols, and management features. This guide applies to Mac computers and Windows devices As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Agent** app name changed from **Kandji Agent** to **Iru Agent**. Please update **scripts, automations, and utilities** that still reference the old app names. ### About the macOS Agent Iru Endpoint's proprietary macOS agent extends the functionality of our platform beyond what the MDM framework can achieve by itself. The Iru Agent for macOS is custom-built in Swift for **Apple devices**. The agent also installs a system extension that uses Apple's Endpoint Security framework for extra device management, plus EDR and Vulnerability Management. #### Actions performed by the Iru Agent Blocks applications specified in the App Blocking Library Item and presents the Iru Endpoint dialog window to end users. Handled by the Iru system extension to ensure blocks happen as quickly and effectively as possible. Installs and enforces updates for Auto Apps. On limited networks, background update downloads may be deferred until enforcement is due soon. See [Downloads on limited networks](#downloads-on-limited-networks) below. Collects the full application list and other system details the MDM framework cannot always pull. Application inventory data in Prism is gathered by the Iru system extension, allowing it to be made available in near real-time. Installs DMG, PKG, and ZIP files and runs audit, pre-install, and post-install scripts. Can force restarts when that option is enabled. See also [Configure the Mac Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-custom-apps-library-item). Installs Custom Printers with downloadable files. On limited networks, background downloads may be deferred until enforcement is due soon. See [Downloads on limited networks](#downloads-on-limited-networks) below. EDR and its associated scans are completed using the Iru Agent. Built-in Blueprint options that control system-level settings on Mac computers. The Iru Agent enforces them at check-in. All scripts are run as root by the Iru Agent. Vulnerability Management and its associated scans are completed using the Iru Agent. #### Downloads on limited networks When macOS reports that the current connection is constrained (for example Low Data Mode), expensive (for example a mobile hotspot), or both, the Iru Agent adjusts when it downloads managed software. During background processing at [check-in](/en/endpoint/devices/device-check-in/device-check-in), the agent defers Auto App update downloads and Custom Printer file downloads on limited networks unless the install is due within 8 hours. When enforcement is approaching, the agent proceeds with the download and records the reason in the agent log. For installs, updates, and reinstalls that a user starts in [Iru Self Service](/en/endpoint/settings/self-service/self-service-for-macos) or the Iru menu bar app, the agent warns before downloading on a limited connection. The message reflects the network type macOS detected. Iru Self Service Updates view with Network considerations dialog warning that macOS identified a constrained network or mobile hotspot before updating apps The agent still downloads managed software without deferral in these cases: * First-time installs, including Library Items selected for install during [Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) * Forced installs from [Vulnerability Response](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) Agent logs record deferrals, proceed decisions, and user cancellations so you can see why an install or update ran or did not run. See [Troubleshooting Agent Check-Ins](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins) for log locations and related steps. ```text agent.log theme={null} AutoApp Discord: deferring download because network is constrained AutoApp Firefox: network is constrained, proceeding with download due to impending enforcement at 2025-11-12 23:00:00 +0000 AutoApp Asana: network is expensive and constrained, proceeding with download due to impending enforcement at 2023-09-29 16:00:00 +0000 Install/update of 1Password 8 cancelled by user on limited network. ``` ### About the MDM Framework Using Apple's MDM framework in macOS, iOS, iPadOS, and tvOS, you can deploy and configure apps and settings, collect device information, and remotely lock or wipe devices. This can be done with corporate-owned as well as Bring Your Own Device (BYOD) devices. One advantage of using Apple's MDM framework is how quickly it can communicate with devices. That means commands (such as to lock or erase devices) are implemented almost instantly. This is made possible by the [Apple Push Notification service (APNs)](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service). Apple devices are constantly polling APNs for notifications requesting that managed devices check in with their MDM servers. Because of this constant polling, management of online devices can happen almost instantly. #### Actions performed by MDM Installs apps acquired via Apple Business or Apple School Manager using the MDM protocol (formerly VPP). See also [Add Apps from Apps and Books](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint). Enrolls devices during Setup Assistant using the MDM protocol (formerly DEP). When a macOS device enrolls into Iru Endpoint, one of the first commands is `InstallEnterpriseApplication` to install the Iru Agent. Automatically sends `InstallEnterpriseApplication` when the device checked in via MDM in the last 7 days but not via the Iru Agent in the last 7 days. See [Troubleshooting Agent Check-Ins](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins) if the agent is not checking in. Delivers commands such as those in the device Action menu through the MDM protocol. When users download the enrollment profile from the enrollment portal, device enrollment is handled through the MDM protocol. Delivers MDM configuration profiles to the device. See [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) for how profiles and Library Items are managed. ### About the Windows Agent Windows devices in Iru Endpoint are managed through a combination of Windows MDM (mobile device management) and the Iru Agent. MDM delivers device policies and configuration. The Iru Agent handles app inventory, app deployment, and PowerShell scripts on a 15-minute check-in cycle. Devices are enrolled via the [Enrollment Portal](/en/endpoint/enrollment/windows/configuring-windows-enrollment); the agent is installed automatically as part of MDM enrollment. For check-in timing and how MDM enforcement differs from agent work, see [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in). #### Actions performed by the Iru Agent Installation and updates for assigned Auto Apps are handled via the Iru Agent. Installs MSI and EXE installers delivered in a zip archive. See also [Configure the Windows Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-windows-custom-app-library-item). Collects and submits application inventory to Iru Endpoint on each agent check-in. Runs custom PowerShell scripts assigned through Library Items on the agent check-in cycle. The agent updates itself to a newer version when available. ### About the MDM Framework Windows includes a built-in management component that communicates with the management server using the [MDM protocol](https://learn.microsoft.com/en-us/windows/client-management/mdm-overview). Using Windows MDM, you can enroll Windows devices, deploy configuration profiles and system policies, and send commands such as wipe or retire. New policies and settings changes from an admin are event-driven via [Windows Push Notification Services (WNS)](https://learn.microsoft.com/en-us/windows/client-management/push-notification-windows-mdm). On online devices, they generally apply within a couple of minutes. If a user manually changes something on the device (for example, local firewall settings), MDM remediates that drift on the daily check-in (every 24 hours). **Perform Recurring Check-In** pushes down MDM policies that were waiting to deploy; it does not remediate existing policies. #### Actions performed by MDM Establishes the MDM connection during enrollment and installs the Iru Agent as part of the process. See [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment) and [User Experience with Windows Enrollment](/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment). Delivers Wi-Fi, Windows Firewall, BitLocker, and other system policies through the MDM channel. These align with Microsoft's [MDM security baseline](https://learn.microsoft.com/en-us/windows/client-management/mdm-overview#mdm-security-baseline). Configure via Library Items such as [Wi-Fi](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item), [Windows Firewall](/en/endpoint/library/library-items-profiles/configure-the-windows-firewall-library-item), and [BitLocker](/en/endpoint/library/library-items-profiles/configure-the-bitlocker-library-item). New admin policy and settings changes (and commands such as wipe or retire) are sent via WNS and generally apply within a couple of minutes when the device is online. Every 24 hours, MDM validates configuration against admin intent and remediates local drift (for example, if a user manually changed firewall settings) and collects daily device information. Delivers configuration profiles through the MDM protocol. See [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) for how Library Items and profiles are managed. For Windows agent troubleshooting (force check-in, reinstall), see [Troubleshooting Agent Check-Ins](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins). Windows agent logs are located at `%ProgramData%\kandji\agent\logs`. # Iru Agent Command Line Interface Source: https://docs.iru.com/en/endpoint/agent/iru-agent-command-line-interface Use the Iru Agent CLI to check status, trigger actions, and troubleshoot devices from the terminal on macOS and Windows managed endpoints. This guide applies to Mac computers ### About the Iru Agent CLI The Iru Agent offers a suite of powerful Terminal commands that give admins additional control and information for their fleet of devices. While some commands can only be executed locally on a device using Terminal, others can be deployed through a Custom Script Library Item for greater flexibility. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Agent** app name changed from **Kandji Agent** to **Iru Agent**. Please update **scripts, automations, and utilities** that still reference the old app names. ### Local-Only Commands The following commands must be executed directly on a device in Terminal. They cannot be deployed via a Custom Script or a Custom App Library Item. #### Interactive Mode (TUI) Run **`sudo iru`** with **no subcommand and no options** to open a **terminal user interface** (TUI): a full-screen, menu-driven flow in Terminal so you can browse and trigger common agent actions without typing full commands and flags. ```bash Terminal icon="terminal" theme={null} sudo iru ``` #### Run The agent will run and check in immediately. Normally, the agent checks in every 15 minutes. Without an internet connection, the agent will run in offline mode. ```bash Terminal icon="terminal" theme={null} sudo iru run ``` Add `--reset-daily` to force daily agent work to run even if it already ran in the last 24 hours: * **Blueprint Parameters:** Daily Parameters run even if they already ran in the last 24 hours. * **Custom Scripts:** Custom Scripts whose frequency is daily also run, not only scripts that run at every check-in or are continuously enforced. * **App inventory:** Collects application inventory (including MDM commands) and ignores the once-per-day inventory schedule. ```bash Terminal icon="terminal" theme={null} sudo iru run --reset-daily ``` ### Run Daily MDM Inventory Update The agent will request the MDM server to initiate its daily MDM commands, such as validating Apps & Books from Apple Business or Apple School Manager, as well as querying certain device information. ```bash Terminal icon="terminal" theme={null} sudo iru update-mdm ``` ### Collect Apps Collects full application inventory from the Mac. ```bash Terminal icon="terminal" theme={null} sudo iru collect-apps ``` ### Run Library Items Checks for library items to execute. ```bash Terminal icon="terminal" theme={null} sudo iru library ``` To force a single library item to execute even if it is not scheduled, use `--item` with `--reset-daily` (same as `-F`): ```bash Terminal icon="terminal" theme={null} sudo iru library --item --reset-daily ``` Available *library* command options: | **Option** | **Description** | | ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | | `--list` | List all of the library items assigned to the computer. | | `--state` | Get the current state of the Iru Agent library manager. | | `--item` | Run a specific library item by name or library item ID. Use `-F` or `--reset-daily` to force execution even if the item is not scheduled. | | `--reset-daily` | With `--item`, force-execute the item even if it is not scheduled. Same as `-F`. | | `--cancel` | Cancel the currently running library item and clears the current queue. | ### Print Iru Agent Logs Prints log entries for the Iru Agent subsystem from the unified logging system. The `--last` option is **required** and specifies the number of previous seconds to print logs from. Replace \ with a number, like 300. (Actual results displayed are limited based on available unified log storage.) Redirect the output of the command using > to save to an external log file. ```bash Terminal icon="terminal" theme={null} sudo iru logs --last ``` Available *logs* command options: | **Option** | **Description** | | ------------------------------- | --------------------------------------------------------------- | | `--no-format` | Print log entries without ANSI color formatting. | | `--debug` | Includes debug level logs, debug logging must be enabled prior. | **Unified Logging** is separate from product branding: subsystem identifiers on the Mac still use the **`io.kandji`** prefix in `log show` predicates and in `log config --subsystem`, as in the examples below. Use those strings so commands match what the system records. Enable debug logging for a subsystem, which are listed in the **Logging Subsystems** section. ```bash Terminal icon="terminal" theme={null} sudo log config --mode "level:debug" --subsystem io.kandji.installer ``` Example debug logging command usage. ```bash Terminal icon="terminal" theme={null} sudo iru logs --no-format --debug --last 10000 > ~/Desktop/iru.log ``` **Logging Subsystems** The logging subsystems available in the Iru Agent offer granular and targeted logging. Subsystem predicate log command. ```bash Terminal icon="terminal" theme={null} sudo log show --predicate 'subsystem beginsWith "io.kandji"' ``` Available predicate log command options: | **Option** | **Description** | | ------------------------------- | --------------------------------------------------------------- | | `--info` | Includes info level logs when available. | | `--debug` | Includes debug level logs, debug logging must be enabled prior. | | `--help` | Displays a complete list of available options. | Subsystem predicate log command with options. ```bash Terminal icon="terminal" theme={null} sudo log show --predicate 'subsystem beginsWith "io.kandji.daemon"' --info --debug ``` Available logging subsystems: * io.kandji.beekeeper * io.kandji.cli * io.kandji.daemon * io.kandji.installer * io.kandji.library-manager * io.kandji.menu * io.kandji.passport * io.kandji.parameter-agent * io.kandji.self-service * io.kandji.liftoff ### EDR List quarantined files. ```bash Terminal icon="terminal" theme={null} sudo iru avert --list-quarantine ``` Delete quarantined files. ```bash Terminal icon="terminal" theme={null} sudo iru avert --delete-quarantine ``` ### Scriptable Commands These commands can be executed through a Custom Script or a Custom App Library Item. They can also be run locally on a Mac in Terminal. When using the scriptable options below, such as within a Custom Script Library Item, you must replace **sudo iru** with the full path to the binary: /usr/local/bin/iru ### Reboot This option can be used in scripted workflows to force a reboot leveraging the Iru Agent and menu bar application. It's visually similar to the reboot forced during FileVault enablement or a Managed OS upgrade. This initiates a restart by prompting the logged-in user with a countdown timer. If no delay is specified, the default 1800 (30 minutes) will be used. If no user is logged in, the delay will be ignored, and the Mac will restart immediately. Replace `` with the countdown length in seconds (for example `300` for five minutes). ```bash Terminal icon="terminal" theme={null} sudo iru reboot --delaySeconds ``` Forces a restart without giving users the option to delay. ```bash Terminal icon="terminal" theme={null} sudo iru reboot --no-deferral ``` ### Dock This option can be used in scripted workflows to add items to the end of the macOS Dock or remove items from the macOS Dock of the currently logged-in user. The application referred to by the bundle identifier must be in the /Applications folder. Optionally specifying the *--all* option adds the icon to the end of the Dock for all user accounts. ```bash Terminal icon="terminal" theme={null} sudo iru dock [--add ] [--remove ] [--all] ``` If using multiple options at a time, use a single command, and separate options using quotes and separating spaces, as shown in the example below. ```bash Terminal icon="terminal" theme={null} /usr/local/bin/iru dock --add "com.google.Chrome us.zoom.xos com.tinyspeck.slackmacgap" ``` ### Alert This command can be used in scripted workflows to present an alert to users. ```bash Terminal icon="terminal" theme={null} sudo iru display-alert [--title ] [--message ] [--icon ] [--suppression-key ] [--help-url ] [--no-wait] ``` It has several options, outlined below. | **Option** | **Description** | **Default if not provided** | | ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------- | | `--title` | Specifies a custom title for the alert window | "Alert" | | `--message` | Specifies a custom message for the alert window | No default value | | `--icon` | Specifies a custom icon for the alert window. It is recommended to use .jpg, .png, or .icns files | Iru Agent icon | | `--suppression-key` | If provided, it will show an option to the user: "Do not show this message again." If this suppression key is provided in a future alert, and the user opts not to see it again, the alert will not be shown. | No default value. If no suppression key is specified, the "Do not show this message again" option is not displayed. | | `--help-url` | Allows for specifying a custom URL for the alert Help button. Must be an HTTPS URL. | No default value. If no URL is specified, the Help button is not displayed. | | `--no-wait` | Allows the alert to show but keeps the remainder of the script running without waiting for user interaction on the alert | Alert will show and wait for interaction from the user before the script proceeds. | Below is an example of the underlying command for an alert and the resulting experience in macOS Tahoe: ```bash Terminal icon="terminal" wrap lines theme={null} sudo /usr/local/bin/iru display-alert --title "Low Disk Space" --message "Your Mac computer's Hard Drive is running critically low on space, please contact Accuhive IT as soon as possible." --suppression-key accuhive --help-url https://iru.com --no-wait ``` Alert dialog on macOS Tahoe showing Low Disk Space title, warning message, Help button, and OK after running the display-alert command ### Submit Diagnostics [Submit Diagnostics](/en/endpoint/agent/how-to-submit-iru-agent-diagnostics) to Iru Endpoint. Equivalent to the action menu (gear) item available in the Iru menu. ```bash Terminal icon="terminal" theme={null} sudo iru submit-diagnostics [--comment ] ``` Available submit-diagnostics command option: | **Option** | **Description** | **Default if not provided** | | ------------------------------- | ------------------------------------------------------ | ------------------------------------------------ | | `--comment` | Specifies a comment to be presented in the diagnostics | No default value | ### Version Display the installed Iru Agent version. ```bash Terminal icon="terminal" theme={null} sudo iru version ``` ### Help Display help text. ```bash Terminal icon="terminal" theme={null} sudo iru help ``` # Iru Agent Settings and Database Files Source: https://docs.iru.com/en/endpoint/agent/iru-agent-settings-and-database-files Reference guide for Iru Agent settings profiles and local database files. Locate configuration data and logs for troubleshooting on managed devices. This guide applies to Mac computers ### About Iru Agent Settings and Database Files When a Mac is enrolled in Iru Endpoint, the Iru Agent is installed to extend the device management capabilities beyond what Apple's Mobile Device Management (MDM) framework can achieve. The agent ensures that various configurations, security policies, and applications are enforced and maintained on the device. To support its functionality, the Iru Agent installs a few key components, including the Iru Agent Settings Profile and encrypted database (.dbee) files. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Agent** app name changed from **Kandji Agent** to **Iru Agent**. Please update **scripts, automations, and utilities** that still reference the old app names. ### Iru Agent Settings Profile The Iru Agent Settings Profile is an MDM configuration profile automatically installed on all enrolled Mac computers. It installs Login and Background Items, Notification Settings, Privacy Preferences Policy Control, and System Extensions payloads so the Iru Agent, Self Service, Liftoff, Passport, and Iru Library Manager can run. It includes several important payloads: * **Login and Background Items Management (Service Management)** - For macOS Ventura and later, this payload ensures users can't prevent the Iru Agent from loading at startup using System Settings. * **Notification Settings** - This payload ensures the various Iru applications can send notifications to the user. * **Privacy Preferences Policy Control** - This payload ensures the Iru Agent has Full Disk Access to the Mac so it can run custom scripts and install and update both custom and Auto Apps. * **System Extensions** - This payload ensures the Iru ESF Extension installed with Iru Library Manager can activate and deactivate itself without user approval. The Iru ESF Extension is used for the [**App Blocking** Library Item](/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item) and replaces the older mechanism used for App Blocking. The Iru ESF Extension is more efficient and prevents a blocked application from launching before the process is even able to execute any code as it's denied by the macOS kernel. The Iru ESF Extension also collects application data for Prism. These payloads ensure that the Iru Agent can perform critical tasks without user interference, such as enforcing security policies, running scripts, and managing app installations. ### Encrypted Database Files (.dbee) The Iru Agent also installs encrypted database files on each device to store essential information locally. These files enable offline functionality and ensure that data is preserved even if network connectivity is lost. The primary database files include: * **agent.dbee** - Contains parameter settings and history for offline usage. * **kandjidata.dbee** - Stores currently enabled features, first-time run information, Self Service deferrals, and scheduled installs. * **library.dbee** - Holds information about Library Items and their statuses for reporting during an agent run. * **rtcdata.dbee** - Stores Real-Time Communication (RTC) messages in case of network failure or power loss. * **tcdata.dbee** - Stores hashes of application data, quarantine data, Endpoint Detection & Response (EDR) offline rules, EDR settings, and other EDR-related events. * **VBData.dbee** - Logs Prism report history. These database files allow the Iru Agent to function independently of network connectivity by storing critical configuration data locally. # How to Set Up the Iru Endpoint API in Postman Source: https://docs.iru.com/en/endpoint/api/how-to-set-up-the-iru-endpoint-api-in-postman Set up the Iru Endpoint API in Postman for testing and automation. Import the collection, configure authentication, and send your first request. ### About Postman API Setup This setup configures Postman with the collections, environment variables, and authentication you need to call the Iru Endpoint API. ### How It Works The Iru Endpoint API uses standard REST principles with token-based authentication. Postman collections provide pre-configured requests for all available API endpoints, while environment variables securely store your authentication credentials and API URLs. ### Prerequisites * Access to Iru Endpoint with API permissions * Postman application (free or paid version) * API token from Iru Endpoint ### Set Up Postman for Iru Endpoint API To make any API requests, you'll create an API Key that you'll use whenever you interact with the API. 1. Visit the [Iru Endpoint API Overview](/en/endpoint/api/iru-api-overview) article for instructions on creating your API Token 2. Store the new API token in a secure location for use later It's possible to use other third-party API tools, but we have a Postman Collection available to import all of the current API commands for a quick setup. If you already have Postman installed on your device, skip this step. 1. Visit the [Postman website](https://www.postman.com/downloads/) to download the Postman app 2. Copy the Postman.app to your Applications folder 3. Launch the application If this is your first time launching Postman, you can Create a Free account, Sign in, or Skip and avoid signing into the app. * Check the Postman Preferences to adjust settings such as the Theme Follow these steps to easily import all available Iru Endpoint API requests into Postman. When new Iru Endpoint API commands are added, you'll need to import the Iru Endpoint API again to have these new commands available in the Collection. 1. Visit [api-docs.kandji.io](https://api-docs.kandji.io) and click the **Run in Postman** button at the top right of the page 2. Select **Postman for Mac** 3. Select **Allow** in the Do you want to allow this website to open "Postman.app"? prompt This prompt may vary depending on which internet browser you're using. 4. Select the Workspace where the Collection should be added 5. Select **Import** Creating environment variables allows you to store values such as your API token more securely and use the same variables across different Collections in Postman. You can read more about this in [Postman's Collections](https://www.postman.com/collection/) article. 1. Click **File** 2. Click **New** 3. Select **Environment** 4. Add the following variables to the Environment and set the type to Secret: * api\_token, device\_id, ade\_token\_id * At this time, define the value for **api\_token**, and only define the others now if you have that information available 5. Click **Save** 1. Select the new Postman Environment [following their guide](https://learning.postman.com/docs/sending-requests/managing-environments/#selecting-an-active-environment) 1. In the Collections Panel, click on **Iru Endpoint API** 2. In the middle panel, click on the **Variables** tab 3. Define the value for the API URL variable. To find your API URL: a. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. Screenshot of the account menu with Access option highlighted b. Click the **API tokens** tab ### Best Practices * **Store credentials securely** - Use Postman's environment variables for sensitive information * **Keep collections updated** - Re-import the collection when new API endpoints are added * **Test your setup** - Run a simple API call to verify everything is configured correctly * **Use descriptive names** - Name your environments and collections clearly for easy identification ### Considerations * **Token security** - Never share your API tokens or commit them to version control * **Collection updates** - You'll need to re-import the collection when new API commands are added * **Browser compatibility** - The import process may vary slightly depending on your browser ### Next Steps You should now be ready to perform API commands. For more information about specific API commands, please review our [API documentation](https://api-docs.kandji.io/). # Iru API Overview Source: https://docs.iru.com/en/endpoint/api/iru-api-overview Create API tokens in Access, scope permissions, and use the Iru Endpoint REST API to read fleet data, run device actions, and automate Library workflows. An **API** (Application Programming Interface) is how other **systems** talk to Iru Endpoint with structured **requests and responses** instead of only the Web App. The **[Iru Endpoint Management API reference](https://api-docs.kandji.io/)** documents each call: what to send, what you get back, parameters, and examples for scripts and integrations. This article focuses on **API tokens** in **Access**: creating credentials, choosing permissions, reviewing activity, and revoking access when you are done. After you [create a token](#generate-an-api-token), you use it with the reference to work with devices, apps, Library items, Blueprints, tenant activity, device actions, Library uploads, and Automated Device Enrollment (ADE) tokens for your organization. For guides that show how the API is used in practice, see [Related articles](#related-articles). ### Generate an API Token Iru Endpoint uses tenant-level bearer tokens to control access to the API. To generate one: In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. Screenshot of the account menu with Access option highlighted In **Access**, click the **API tokens** tab. On the **API tokens** page, look for **Your organization's API URL**. The line shows your tenant hostname in this form (your value will differ): **Your organization's API URL is:** `accuhive.api.kandji.io` Make a note of this hostname. You use it with the Iru Endpoint API and your bearer token. Click **Add Token** to create a new API token. Access API tokens with organization API URL and Add Token Provide a **Name** and a **Description** for your API token. If you want this token to work with Model Context Protocol (MCP) clients (for example Cursor, Claude Desktop, or OpenAI Codex), turn on **Enable MCP**. See [Iru MCP](/en/endpoint/integrations/ai-assistants/iru-mcp) for MCP configuration, permissions, and supported clients. Click **Create.** Create API token prompt with Name, Description, and Create Iru Endpoint will display a modal with the API token. Click the visibility symbol to expose it or use the **Copy Token** button to copy the API token to your clipboard, storing it in a safe place. If you turned on **Enable MCP**, the same one-time success screen also shows an **MCP configuration** block next to the token. Use **Copy MCP configuration** to copy the JSON snippet (your MCP URL and the values an MCP client uses to authenticate) and store it alongside the token. See [Iru MCP](/en/endpoint/integrations/ai-assistants/iru-mcp#copy-your-token-and-mcp-configuration) for how to use that snippet in Cursor, Claude Desktop, or other supported clients. You will not be able to see the token or the MCP configuration again. Click **Next.** Copy your API token dialog with visibility toggle and Copy Token Click **Configure** to manage the API permissions for this specific token or **Skip** to change them later. Copy API token dialog with Next and option to manage permissions Check or uncheck the box next to each permission you want to change. If you check or uncheck the box at the top of a section (for example **Blueprints Management**), every permission in that section is checked or unchecked together. After making your modifications, click **Save**. ### Edit Token On the **API tokens** page, click a **token name**, or click the vertical **ellipsis** and then **View**, to open that token and its permissions. API token detail view after opening a token from the list Click **Edit** to change the token's API permissions. If none are assigned yet, you can use **Configure Permissions** instead. **Edit** works whether the token already has permissions or not. Edit API token permissions in Access Check or uncheck the box next to each permission you want to change. If you check or uncheck the box at the top of a section (for example **Blueprints Management**), every permission in that section is checked or unchecked together. Click **Save**. ### View Activity The [Unified Activity](/en/iru/platform-overview/unified-activity) timeline lists tenant-wide API token activity: **API token created**, **API token updated**, and **API token deleted**. Filter by **Activity type** to narrow the timeline. The steps below show token-specific activity on the token detail page. On the **API tokens** page, click a **token name**, or click the vertical **ellipsis** and then **View**, to open that token and its permissions. API token detail view after opening a token from the list Click the **Activity** tab. The timeline lists lifecycle events and API usage. In the timeline, click a row to expand it and read its fields. **Collapsed row** * Chevron, event icon, title, actor (admin **display name** or a dash when there is no administrator), short date (`M/D/YY`). **Expanded detail** * Expanded rows show full timestamps (`M/D/YY, h:mm:ss AM` or `PM`) for time fields, plus the event-specific fields in each accordion below. **Summary:** Key icon, **Token created**, creator display name, short date (`M/D/YY`). **Expanded** * **Created by:** same display name as the summary row. * **Created at:** when the token was created. **Summary:** Icon, **Token name changed**, editor display name, short date (`M/D/YY`). **Expanded** * Same administrator **by** / **at** layout as **Token created** and **Token permissions edited**: who renamed the token and when. **Summary:** Padlock icon, **Token permissions edited**, editor display name, short date (`M/D/YY`). **Expanded** * **Edited by** and **Edited at** (who saved the change and when). * **Permissions enabled:** one `METHOD /path` per line for permissions turned on in that save (for example `GET /blueprint-routing`, `PATCH /blueprint-routing`). * **Permissions disabled:** same format for permissions turned off (for example `GET /devices-list`). * One save can list routes under **both** sections. If nothing was turned on or off in that save, the matching section has no lines. **Summary:** Eye icon, **Token accessed**, dash in the actor column (no admin; the client used the token), short date (`M/D/YY`). **Expanded** * **Accessed by:** the caller's **public IPv4** address. * **Accessed at:** when the token was used. * **Endpoints accessed:** one or more lines, each `METHOD /path` (for example `GET /devices-list`). ### Revoke a Token Revoking stops the token from working with the Management API. If **Enable MCP** was on for that token, this access is also disabled when the token is revoked. See [Iru MCP](/en/endpoint/integrations/ai-assistants/iru-mcp) for MCP client configuration. Revoking a token removes all **Activity** recorded for that token. That history cannot be recovered. To keep **Activity** history but stop using the token, [edit the token](#edit-token) instead: open it, click **Edit**, remove all API permissions, then **Save**. On the **API tokens** page, click the vertical **ellipsis** next to the token you want to revoke, then click **Revoke**. Or open the token, click **Edit**, then **Revoke** at the bottom left. API tokens list with Revoke option for a token Enter the **token name** exactly as it appears in the prompt. Click **Revoke** to confirm. After revocation, the token disappears from the list and you can't review its **Activity** anymore. ### Best Practices Create a **unique API token** for each integration or use case so you can rotate or revoke one connection without affecting others. Use clear, descriptive **Name** and **Description** values in the **Iru Endpoint** Web App so tokens are easy to recognize on the **API tokens** page in **Access**. ### Considerations If you remove an administrator from the Iru Endpoint Web App, **API tokens they created stay in place and keep working** until they are revoked. Deleting the user does **not** automatically revoke those tokens. Open **Access**, go to **API tokens**, and **Revoke** (or rotate by creating a new token and revoking the old one) if you need to stop access. Anyone with permission to use the **Access** page can **manage every API token** in the tenant: edit **Permissions**, **rename** the token, review **Activity**, and **revoke** it. You do not need to be the user who originally created the token. The **secret** (the string you use as a **bearer token**) is shown **only once**, when the token is first created. After that, other administrators can still administer the token in **Access**, but they **cannot see that secret again** unless the creator **shared** it with them at creation time (for example in a password manager or secure message). Anyone with **Access** can still revoke the token or narrow its permissions if the secret might have been exposed. The Iru Endpoint Management API currently has an API rate limit of **10,000 requests per hour per customer**, documented in the introduction of the [Iru Endpoint Management API documentation](https://api-docs.kandji.io/). When **Iru Compliance** collects evidence through the [**Iru Endpoint** Compliance source](/en/compliance/sources/iru-endpoint-source), it calls the Management API with your API token. **Those requests count toward the same hourly limit** for your tenant. ### Troubleshooting The Iru Endpoint Management API enforces **10,000 requests per hour per customer** (see [Considerations](#considerations) and the [Iru Endpoint Management API documentation](https://api-docs.kandji.io/)). **All API tokens in your tenant share that same limit.** There is no separate rate limit per token. When a request is blocked for exceeding the limit, the response body includes: ```json lines theme={null} { "message": "API rate limit exceeded" } ``` To see whether a specific integration or script is driving volume, open **Access**, select each token, and review **Activity** for that token ([View Activity](#view-activity)). Expanding **Token accessed** entries shows which endpoints were called so you can throttle or fix the client, rotate credentials, or adjust automation as needed. If the token does not have the API permissions required for the endpoint you are calling, you may receive a response like: ```json lines theme={null} { "detail": "You do not have permission to perform this action." } ``` In **Access**, open the token, select **Edit**, and enable the permissions that match the routes your integration uses ([Edit token](#edit-token)). ### Related Articles Browse endpoints, parameters, and request and response examples. Connect third-party products and map the API permissions each one needs. Import the published collection and send authenticated requests. How **Iru Compliance** uses your token on the Management API for evidence. Publish and update in-house apps using the API and the Web App. Query and export fleet data with Prism's API-first analytics workflows. Renew, update, or delete ADE tokens using an API token from Access. Connect multiple Apple Business or Apple School Manager accounts or organizational units to Iru Endpoint. Connect Okta Workflows to Iru Endpoint with an API token and device permissions. Deliver tenant activity logs to Amazon S3 and review logged event types in the API documentation. # Creating a Blueprint Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/creating-a-blueprint Create a new Blueprint with Assignment Maps in Iru Endpoint. Define device groups, assign Library Items, and configure management policies. This guide applies to all device platforms ### About Blueprint Management **New to Blueprints?** Start with our [Getting Started with Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) guide for basic setup, then return here for advanced management features. A Blueprint is how you organize and deploy configurations across your devices. It's a collection of settings, apps, and security policies that you can apply to groups of devices. Think of it as your master plan for how a group of devices should be set up and managed. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### How It Works Blueprints allow you to assign Library Items to devices through Assignment Maps. Simple views assign Library Items to all devices within the Blueprint, while advanced views use conditional logic for more detailed scoping based on device attributes, user information, or other criteria. ### Creating a Blueprint Navigate to the **Blueprints** page in the Iru Endpoint Web App. Click the **+ Add Blueprint** button. Choose to start from scratch or use one of Iru Endpoint's pre-built templates. Name your Blueprint, and give it an optional description. You can also set the **icon** and **icon color** when the creation flow shows those options, or change them later with **Edit Blueprint** as described in [Modifying a Blueprint](/en/endpoint/blueprints/assignment-maps/modifying-a-blueprint). Click **Create Blueprint**. ### Blueprint Views #### Simple View By default, new Blueprints allow assignment of Library Items to all devices within the Blueprint. #### Advanced View Advanced views in Assignment Maps can be used for more detailed scoping of Library Items based on [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). Once at least one conditional block has been added, the interface will reveal additional tools and options. ### Using an Assignment Map within a Blueprint Once your Blueprint has been created, you can add Library Items and Parameters to build out your configuration. Changes made to Assignment Maps are visible in the Assignment Maps Activity tab. Blueprint and assignment changes also appear on the [Activity Page](/en/endpoint/devices/activity-page). #### Adding Library Items from the Assignment Map View Once your Assignment Map is open within your Blueprint, select **Edit assignments**. From the Library Item Bank, locate the Library Items you want to add to install on all devices in your Assignment Map. From this list, you can: * Use the Search bar to locate Library Items * **Shift+click** to select multiple Library Items in a row * **Command+click** to select multiple Library Items not in a row * Filter Library Items by the currently assigned Blueprint, making it easy to select all and drop them into your preferred Assignment Node * Use a second browser tab to switch between a live editing session in your Assignment Map and your Library view. The Library Item Bank will automatically refresh as you create new Library Items Drag your selections to the Assignment Map. Once you've added your desired Library Items, you can begin configuring conditional blocks and assignment nodes. See our [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) support article for more information. #### Adding Library Items to an Assignment Map from the Library Item Open the Library Item you want to assign to an Assignment Map. In the Assignment section, next to Blueprint, click on **Assign**. In the modal that opens, search for and select your desired Assignment Maps. ### Self-Conflicting Library Item icon When two **Auto App**, **App Store App**, or **Managed OS** Library Items for the same app or managed OS configuration are assigned on the same Blueprint, they are **self-conflicting** with each other. Each affected Library Item tile shows the **Self-Conflicting Library Item icon** in the Blueprint **Assignment Map** view (stacked cards with a slash). Hover the icon to read how assignment is resolved for that item. Blueprint Assignment Map with Library Item tiles showing the Self-Conflicting Library Item icon and tooltip The hover text follows this pattern. In the product, *type name* is replaced with the name of that Library Item type (for example, **Auto App**, **App Store App**, or **Managed OS**). For how those types are organized in the Library UI, see [Library Sections](/en/endpoint/library/library-items-profiles/library-overview#library-sections). **App Store App** tooltips also include that app's display name. > Only one *type name* Library Item may be assigned per device for the same app or managed OS configuration. Devices which qualify for more than one will receive whichever is scoped to them last (farthest right) on the map. For duplicating **Auto App**, **App Store App**, or **Managed OS** Library Items, labels, and assigning both copies on one Blueprint, see [Assigning Duplicated Self-Conflicting Library Items to One Blueprint](/en/endpoint/library/library-items-profiles/library-overview#assigning-duplicated-self-conflicting-library-items-to-one-blueprint) in Library Overview. ### Adding Parameters to a Blueprint Parameters apply to all Mac computers in every Blueprint where they are enabled. Once your Blueprint is open, select **Parameters** at the top of the Assignment Map. Select whether you'd like to Add Parameters individually, or Import Parameters from an Existing Blueprint. * If you choose to add Parameters individually, toggle each Parameter on or off in the list as described in [Modifying a Blueprint](/en/endpoint/blueprints/assignment-maps/modifying-a-blueprint#modify-parameters-mac-only) * If you choose to import Parameters from an existing Blueprint, locate the Blueprint in the list, select it, and then click **Import Parameters** ### Deleting Items from an Assignment Map * Deleting an **Assignment Node** will delete all its rules and Library Item assignments. You will be asked to confirm deletion. * Deleting a **Library Item** will remove it from the Assignment Map, but will not delete the Library Item. You will not be asked to confirm removal. * Deleting a **Conditional Block** will delete its children, including all Library Item assignments contained within it. You will be asked to confirm deletion. ### Customizing a Blueprint Navigate to the Blueprint you'd like to customize. Click the ellipsis at the top right of the Assignment Map. Click **Edit Blueprint**. Click the icon button to change the graphic and color associated with the Blueprint. Update the name. Click **Confirm** to apply the changes. ### Creating and Deleting Notes Navigate to the Blueprint where you'd like to add a note. Click the **Notes** tab. Click **+ Create Note**. Use the formatting bar to adjust the look of the note. Enter the note text. Click **Save**. To modify the note, you can click the ellipsis beside the note. * If you want to make changes to the note, click **Edit** * If you want to delete the note, click **Delete note** ### Using Assignment Maps with the Enterprise API Assignment Maps come with several useful features when using the Iru Endpoint Enterprise API: * **Creation** - You can create a new Assignment Map from scratch, use a template, or duplicate an existing map. * **Deletion** - Remove Assignment Maps you no longer need. * **Modification** - Change Blueprint attributes like name, description, and Enrollment code for Manual Enrollment. ### Related Articles Create and configure device Blueprints for policy management Copy an existing Blueprint and Assignment Map Edit Blueprint details, assignments, and Parameters Remove an unused Blueprint safely Use conditional logic in Blueprints Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Organize and group devices using tags # Deleting a Blueprint Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/deleting-a-blueprint Safely delete a Blueprint in Iru Endpoint. Reassign or remove devices before deletion and understand the impact on assigned configurations. This guide applies to all device platforms ### About Deleting a Blueprint Deleting a Blueprint permanently removes it from Iru Endpoint. This action cannot be undone. Before deletion, move devices to a different Blueprint to avoid unintended policy or software changes. Blueprint changes, including deletion, are recorded on the [Activity Page](/en/endpoint/devices/activity-page). As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### Before You Delete * Confirm no active devices still depend on this Blueprint * Move assigned devices to a destination Blueprint first * Validate required Library Items and Parameters exist in the destination Blueprint ### Delete a Blueprint #### From a Blueprint Tile on the Blueprints Page Open **Blueprints** in the left navigation. On the **tile** for the Blueprint you want to delete, click the **ellipsis** (**…**). Click **Delete Blueprint**. Blueprints page with a Blueprint tile ellipsis menu open and Delete Blueprint in red Review the prompt and confirm. #### From the Blueprint Page Open **Blueprints** in the left navigation. On the Blueprints page, click the **tile** for the Blueprint you want to delete. Click the **ellipsis** (**…**) in the Blueprint header. Click **Delete Blueprint**. Blueprint page opened from a tile, with header ellipsis open and Delete Blueprint in red Review the prompt and confirm. ### If Deletion Is Not Available yet A Blueprint cannot be deleted while it is still in use. Typical blockers are **Blueprint Routing** that references the Blueprint and devices that remain assigned to it. Iru Endpoint disables **Delete Blueprint** in that situation and surfaces **This Blueprint cannot be deleted yet** with the specific reasons. #### From a Blueprint Tile Open **Blueprints** in the left navigation. On the **tile** for the Blueprint, click the **ellipsis** (**…**). **Delete Blueprint** is disabled when deletion is not allowed. Hover over **Delete Blueprint** to see the warning (for example references to **Blueprint Routing** and assigned devices). Blueprints page with ellipsis menu open, hovering over disabled Delete Blueprint and cannot-delete warning for Blueprint Routing and assigned devices #### From the Blueprint Page Open **Blueprints**, then click the **tile** for the Blueprint. Click the **ellipsis** (**…**) in the Blueprint header. **Delete Blueprint** is disabled when deletion is blocked. Hover over it to see the **cannot be deleted yet** message and the reasons. Blueprint page with header ellipsis open, hovering over disabled Delete Blueprint and cannot-delete warning for Blueprint Routing and assigned devices #### How to Unblock Deletion When the warning cites **Blueprint Routing**, open [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing) and update or remove any rules that still point at this Blueprint. Routing is evaluated during enrollment; until no rule references the Blueprint, Iru Endpoint keeps **Delete Blueprint** disabled so you do not strand new or existing enrollments. When the warning cites assigned devices, every device on the Blueprint must be moved to a different Blueprint before you can delete it. Use a device record for a single device or bulk actions on the Devices list, pick a destination Blueprint that already has the Library Items and Parameters those devices need, then confirm the move. Step-by-step instructions are in [Moving Devices Between Blueprints](/en/endpoint/blueprints/assignment-maps/moving-devices-between-blueprints). After routing no longer references the Blueprint and no devices remain assigned to it, **Delete Blueprint** becomes available. Use the **Delete a Blueprint** steps earlier in this article. ### Move Devices Before Deletion If devices are still assigned, move them first: Open a device record (single move) or select devices in the Devices list (bulk move). Use **Edit Blueprint** (single) or **Change Blueprint** (bulk). Choose the destination Blueprint and confirm. For detailed movement steps, see [Moving Devices Between Blueprints](/en/endpoint/blueprints/assignment-maps/moving-devices-between-blueprints). ### Related Articles Reassign devices before removing a Blueprint Create destination Blueprints before migration Update destination Blueprint settings and assignments Scope assignments in destination Blueprints # Duplicating a Blueprint Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/duplicating-a-blueprint Duplicate an existing Blueprint and its Assignment Map in Iru Endpoint. Copy configurations to quickly create variations for different device groups. This guide applies to all device platforms ### About duplicating a Blueprint Duplicating a Blueprint creates a **new** Blueprint with a copy of another Blueprint's Assignment Map layout, Library Item placements, and Parameter configuration. Devices stay on the original Blueprint until you move them. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### How It Works Use duplication when you need a similar Assignment Map without rebuilding nodes, rules, and Library Item assignments from scratch. After duplication, the two Blueprints are independent: edits to one do not change the other. Library Items in the Library are **not** duplicated. The new Blueprint references the same Library Items you place on the map. Updates to a Library Item still apply everywhere that item is assigned. ### How to duplicate a Blueprint #### From a Blueprint tile on the Blueprints page Sign in to Iru Endpoint and open **Blueprints** in the left navigation. On the **tile** for the Blueprint you want to copy, click the **ellipsis** (**…**). Click **Duplicate Blueprint**. Blueprints page with a Blueprint tile ellipsis open and Duplicate Blueprint highlighted Enter a new **name** and optional **description** for the duplicate. Click **Duplicate**. #### From the Blueprint page Open **Blueprints** in the left navigation. On the Blueprints page, click the **tile** for the Blueprint you want to copy. Click the **ellipsis** (**…**) in the Blueprint header. Click **Duplicate Blueprint**. Blueprint page opened from a tile, with header ellipsis open and Duplicate Blueprint highlighted Enter a new **name** and optional **description** for the duplicate. Click **Duplicate**. ### Related Articles Create and manage Assignment Maps, Library Items, and Parameters Getting started with Blueprints and Assignment Maps Edit Blueprint details, assignments, and Parameters Remove an unused Blueprint safely Reassign devices after you create or duplicate a Blueprint # Modifying a Blueprint Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/modifying-a-blueprint Edit Blueprint settings and Assignment Maps in Iru Endpoint. Update Library Item assignments, change parameters, and adjust device configurations. This guide applies to all device platforms ### About modifying a Blueprint Modifying a Blueprint lets you update Blueprint details (name, description, and appearance), adjust Assignment Map logic, and manage Parameters for Mac devices. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### How It Works Blueprint changes apply to devices based on check-in behavior and the specific items assigned in the Assignment Map. Changing metadata (name, description, icon) affects organization only; changing assignments or rules affects what devices receive. Blueprint updates are recorded on the [Activity Page](/en/endpoint/devices/activity-page). ### Modify Blueprint details **Edit Blueprint** is where you change how the Blueprint is labeled in the product: its **name**, optional **description**, and the **icon** and **color** shown on the Blueprint tile and elsewhere. Those updates are organizational only; they do not change Assignment Map content, Library Item assignments, or what devices receive. #### From a Blueprint tile on the Blueprints page Open **Blueprints** in the left navigation. On the **tile** for the Blueprint you want to edit, click the **ellipsis** (**…**). Click **Edit Blueprint**. Blueprints page with a Blueprint tile ellipsis menu open Update the Blueprint **name**, optional **description**, and icon/color as needed. Click **Confirm**. #### From the Blueprint page Open **Blueprints** in the left navigation. On the Blueprints page, click the **tile** for the Blueprint you want to edit. Click the **ellipsis** (**…**) in the Blueprint header. Click **Edit Blueprint**. Blueprint page opened from a tile, with header ellipsis menu open Update the Blueprint **name**, optional **description**, and icon/color as needed. Click **Confirm**. ### Modify Assignment Map content From the Assignment Map view, click **Edit assignments**. Add or remove Library Items, adjust Assignment Nodes, and edit conditional blocks. Click **Save** when finished. ### Modify Parameters (Mac only) In the Blueprint, open the **Parameters** tab. Click **Edit Parameters**, then enable, disable, or adjust needed Parameters. Click **Save**. ### Related Articles Create and manage Assignment Maps, Library Items, and Parameters Copy an existing Blueprint and Assignment Map Remove an unused Blueprint safely Use conditional logic to scope assignments # Moving Devices Between Blueprints Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/moving-devices-between-blueprints Move one or more devices between Blueprints in Iru Endpoint. Reassign devices individually or in bulk to apply different management policies. This guide applies to all device platforms ## About moving devices between Blueprints Moving devices between Blueprints reassigns them from one Blueprint to another in Iru Endpoint. The destination Blueprint controls which Library Items and Parameters apply going forward. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ## When to move devices Common reasons to move devices include: * **Role changes:** the device should follow a different user role or department configuration. * **Location changes:** the device moved to an office or network that uses another Blueprint. * **Compliance:** the device needs different security or compliance settings. * **Testing:** you want to validate a Blueprint on a device before wider rollout. * **Temporary assignments:** short-term configuration for a project or pilot. ## How it works After a move, the device is assigned to the new Blueprint’s policies and Library Items. Some changes apply right away in Iru Endpoint; full enforcement on the device often depends on the next **Iru Agent** or **MDM** check-in (see [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in)). Device history is retained across Blueprints. Blueprint reassignments also appear on the [Activity Page](/en/endpoint/devices/activity-page). Moving devices changes configuration and can affect the user experience. When possible, plan moves during a maintenance window and tell people what to expect. ## Before you move * Confirm the **destination Blueprint** has the right Library Items, Parameters, and policies for that device and user. * Check for **conflicts** between the old and new Blueprint (for example overlapping policies or app assignments) so you are not surprised by remediation behavior. * For large or sensitive changes, **test** on a small set of devices first and **document** moves for audits and support. ## Move one device from its device record Sign in to Iru Endpoint and open the **device record** for the device you want to move. Click **Edit device details**, then select **Edit Blueprint**. Choose the destination Blueprint, then click **Change**. ## Move one or more devices from the Devices page Open **Devices** in the left navigation. Click the checkmark next to one or more devices you want to move. Click **Change Blueprint** near the bottom of the page. Select the new Blueprint from the dropdown, then click **Change**. Bulk moves can be processed in the background. Completion time depends on how many devices you selected and whether they are online and checking in. ## What happens after moving a device Mac computers will enforce **Parameters** and other agent-driven **Library Items** (for example **Passport**) the next time the Mac checks in via the Iru Agent. Parameters that were enforced on the previous Blueprint will change from their current state unless a new parameter enforces a different behavior. **Auto Apps** and **Custom Apps** that were enforced in the previous Blueprint will **not** be removed, but **Profiles** and **Apps and Books** apps will be added or removed as soon as possible during the next MDM check-in. More information about the differences in MDM and Agent check-in types can be found in our [Device Check-In support article](/en/endpoint/devices/device-check-in/device-check-in). Apps already on the device **remain** installed. Settings **stay as they are** unless the destination Blueprint’s policies **change** them. **New** apps and policies you target on the new Blueprint are **enforced**. Apps that were only **available in Self Service** on the previous Blueprint and are **no longer** targeted **do not appear** in Self Service anymore. For how quickly the Agent and MDM apply changes, see [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in). All Library Items, including apps and profiles, will be added or removed during the next MDM check-in as soon as possible. More information about device check-in can be found in our [Device Check-In support article](/en/endpoint/devices/device-check-in/device-check-in). **Library Items** on the destination Blueprint (including **Managed Google Play** apps and work-profile **policies**) apply when assignments change, and items that were only on the previous Blueprint are updated or removed when they are no longer assigned. Iru Endpoint sends policy updates to the **Android Management API**, and the device applies them through Google’s management channel; changes usually take effect **quickly** because Android management is event-driven. See [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in). ## After you move On the admin side, it helps to: * **Verify** the device record shows the new Blueprint and that assignments look correct. * **Monitor compliance** and key apps or services on a sample of moved devices. * **Confirm with users** that anything business-critical still works after check-ins complete. * **Update** internal inventory or CMDB records if your team tracks Blueprint per device. ## Troubleshooting **Possible causes:** Device is offline or not checking in, network issues, or the Blueprint assignment did not apply as expected. **What to try:** Confirm the device is online, [force a check-in](/en/endpoint/devices/device-check-in/device-check-in) if your workflow supports it, and verify the assignment on the device record. **Possible causes:** Overlapping or conflicting policies between the previous and new Blueprint, or app installation order. **What to try:** Compare Library Items and policies on both Blueprints, resolve duplicates or contradictions, and communicate setting changes to users if their experience shifts. **Possible causes:** The app is not assigned on the new Blueprint, deployment scope, storage or compatibility limits, or the device has not checked in yet. **What to try:** Confirm the app is targeted on the destination Blueprint, review device storage and OS compatibility, and allow time for the next Agent or MDM check-in. ## Best practices Schedule larger moves for maintenance windows when you can. Try Blueprint changes on a small group before a wide rollout. Record who moved which devices and when, for support and audits. Follow moved devices afterward for compliance and user-reported issues. For more detailed information about taking action on devices, see the [Devices](/en/endpoint/devices/) section of our Knowledge Base. # Using Conditional Logic in Blueprints Source: https://docs.iru.com/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints Use conditional logic in Iru Endpoint Blueprints to dynamically assign Library Items based on device attributes like OS version or model type. This guide applies to all device platforms ### About Conditional Logic in Blueprints Conditional logic lets you create deployment strategies using if/else statements and conditional blocks. You can deploy different configurations, apps, and settings based on device attributes, user information, or other criteria. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### How It Works Conditional logic works on a simple premise: **if a condition is true, apply these settings; otherwise (else), apply different settings.** The system evaluates conditions in order; the first match wins, and no further conditions in that block are checked. You build this using a visual interface on an infinite canvas. ### Conditional Blocks: Structure and Function **What Are Conditional Blocks?** Conditional blocks are the building blocks of decision-making in Assignment Maps. Each block contains a set of if/else conditions that determine which configurations to apply based on device or user attributes. **Evaluation flow:** When a device checks in, the system evaluates conditions in the order they appear. Once one evaluates to true, that configuration is applied and the system moves to the next conditional block. Remaining conditions in the current block are skipped. **Components of Conditional Blocks** * **If/Else conditions:** Group similar criteria and are evaluated in order; the first matching condition is applied. If you need another condition to be evaluated separately, move it into its own conditional block. For examples (including department-based logic), see [Examples of Common Assignment Map Conditions](#examples-of-common-assignment-map-conditions). * **Assignment nodes:** The logical conditions (Assignment Rules) inside each block. They define the criteria that must be met and can reference device attributes (model, OS version, serial number) or user attributes (department, location, role). Combine multiple conditions with AND/OR operators. * **Root line:** Connects all conditional blocks back to the main flow so there are no dead ends in your Assignment Map. **Supported Inputs, Operators, and Values** Assignment Map conditional logic supports the following inputs, platforms, operators, and values: | Input | Platforms | Operators | Example Values | | ---------------------------------------- | ----------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | | **Device criteria** | | | | | Device family | | `is one of` `is not one of` | Mac, iPhone, iPad, Apple TV, Vision, Windows, Android | | Enrollment type | | `is` `is not` | Automated Device Enrollment, Manual Device Enrollment | | Chip type | | `is` | Apple Silicon, Intel | | FileVault | | `is` | On, Off | | Supervision status | | `is` | Supervised, Not Supervised | | Mac family | | `is one of` `is not one of` | iMac, iMac Pro, Mac Pro, MacBook, MacBook Pro, MacBook Air, Mac mini, Mac Studio | | Asset tag | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | Honolulu, 123987, DEN-123845-MBP | | Serial number | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | QCM2XXXXXX | | OS version | | `is` `is not` `is greater than` `is less than` `is greater than or equal to` `is less than or equal to` `is between` | 14, 14.1, 16.2.2 | | Tags | | `are exactly` `are not exactly` `contain one of` `does not contain one of` | Test, Pilot, Production | | Apple Beta Enrollment | | `is` `is not` `is one of` `is not one of` `is any` `is not any` | OS versions that have a beta configured (for example, a macOS or iOS version with a Seed Token) | | **User directory criteria** | | | | | User department | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | Product | | User email | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | [admin@accuhive.io](mailto:admin@accuhive.io) | | User username | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | jsmith | | User job title | | `is` `is not` `is one of` `is not one of` `contains` `does not contain` `contains one of` `does not contain one of` | Product Engineer | | User group | | `is one of` `is not one of` | database-admins | **Platform-Specific and Universal Attributes** Some attributes in the table above are specific to Apple devices (Chip type, FileVault, Supervision status, Mac family, Apple Beta Enrollment). Device family applies to all platforms and lets you target Mac, iPhone, iPad, Apple TV, Vision, Windows, or Android. Assignment Maps work across all device platforms (Apple, Windows, and Android). Universal attributes that work on all platforms include: Enrollment Type, Device family, [Tags](/en/endpoint/devices/device-record-management/tags-for-devices), Asset Tag, Serial Number, OS version, User email, User Group, User Job Title, and User Department. You can use these universal attributes to create conditional logic for Windows and Android devices in Assignment Maps. ### Creating and Configuring Conditional Logic Editing an Assignment Map in a Blueprint triggers an immediate reevaluation of all rules. **Adding Conditional Logic to Assignment Maps** For new or simple Assignment Maps without existing conditional logic, click the **+ Add conditional logic** button when editing your Assignment Map. For Assignment Maps with existing conditional logic, click the **+** button to add a new Conditional Block within your canvas. Once you've added a conditional block, you'll need to configure the Assignment Rules that should apply to each condition. Click the **pencil icon** within the conditional block to configure the Assignment Rules that should apply to the **If** condition. Continue adding Library Items that you want to apply to the conditions defined in your If, Else, and Elseif statements in your conditional blocks. You can continue adding and configuring any number of conditional blocks using the + buttons on each Assignment Node. **Configuring Assignment Rules** Assignment Rules define the specific criteria that must be met for a condition to be evaluated as true. These rules can be based on various attributes: * Device attributes (model, OS version, serial number) * User attributes (department, location, role) When configuring Assignment Rules, you can combine multiple criteria using AND/OR operators. For instance, you might create a rule that targets "MacBook Pro devices AND running macOS Sonoma AND in the Marketing department" for Apple devices, "OS version greater than or equal to 11.0 AND User Department contains Engineering" for Windows devices, or "User Group is one of Sales AND Tags contain Production" for Android devices. To add additional pathways within a conditional block, click the **+** button to add an **else if** condition and configure Assignment Rules for that pathway. This allows you to create multiple branches within a single conditional block, each with its own set of configurations. ### Examples of Common Assignment Map Conditions **Department-Based Software Deployment** ```javascript Software Deployment lines theme={null} Conditional Block: Software Deployment if (Department equals "Marketing") - Install Adobe Creative Cloud - Install Figma - Install Slack else if (Department equals "Engineering") - Install Visual Studio Code - Install GitHub Desktop - Install Docker else if (Department equals "Finance") - Install QuickBooks - Install Excel Add-ins - Install Financial Reporting Tools else - Install Basic Office Suite ``` Devices are evaluated against the user's department. The first matching condition wins, and the appropriate software is installed. **Location and Role-Based Security Configurations** ```javascript Security Configurations lines theme={null} Conditional Block: Security Configurations if (User Group equals "Remote" AND Role contains "Executive") - Apply Strict VPN Configuration - Enable Enhanced Security Monitoring - Require Biometric Authentication else if (Location equals "Remote") - Apply Standard VPN Configuration - Enable Basic Security Monitoring else if (Location equals "Office" AND Role contains "Executive") - Enable Enhanced Security Monitoring - Require Biometric Authentication else - Apply Standard Security Configuration ``` This configuration applies different security settings based on whether a user is remote or in-office, with stricter requirements layered on for executive roles. **OS Version-Based Configurations** ```javascript OS-Specific Configurations lines theme={null} Conditional Block: OS-Specific Configurations if (OS Version is greater than or equal to "15.0") - Apply macOS Sequoia Optimizations - Install Sequoia-Compatible Apps else if (OS Version is greater than or equal to "14.0") - Apply macOS Sonoma Optimizations - Install Sonoma-Compatible Apps else - Apply Legacy OS Configurations - Schedule OS Update Notification ``` Devices receive only configurations and apps compatible with their current OS version. ### Manual Device Exclusion In cases where you'd like to exclude a device from a Library Item in an Assignment Map, you can use manual device exclusion. While editing your Assignment Map, select the Library Item you would like to exclude for a device. Expand the **Manual device exclusions** section. Click **+ Add device**. Search by device name, serial number, asset tag, user name, or email. Select the device to exclude for the Library Item. Click **+ Add device button** if you'd like to exclude additional devices. Click the **X** beside a specific device to remove it from the exclusion list. Click **Clear all** to remove all devices from the device exclusion list. Once all changes are complete, click **Save**. ### Using Search and Device Lookup The search field near the top left of the Assignment Map allows you to search by Library Items, rules, or look up a device or user. **Search** Entering a specific Library Item, or a rule, will locate and highlight the item on the Assignment Map. This can be useful when there are many items on the map, making it difficult to locate. Enter the name of the Library Item in the search field, and click **Jump to**. The selected Library Item will be highlighted in the Assignment Map. Clicking the **x** in the search field will clear the highlighted Library Item. **Device and User Lookup** Looking up a device will allow you to see the device's path through the map's logic. This is a useful way to troubleshoot the logic and ensure that the device has all of the expected Library Items in its path. When searching by user, you can select any of the devices assigned to that user. When viewing a Device Record, you can click the magnifying glass next to the Blueprint name to look up the device on the Assignment Map. When viewing an Assignment Map, you can enter any device detail, such as serial number, device name, or the user that is assigned to the device. Once the device has been selected, the Library Items that will be assigned to the device will be highlighted. It is expected behavior that the Automated Device Enrollment Library Item will always be greyed out, as it is not evaluated for conditional logic, and always applies for eligible devices. You can view the status of Automated Device Enrollment assignments in the **Enrollment** section from the left-hand navigation. Liftoff does not support Assignment Rules. Place it in the **All Devices** node at the beginning of the Assignment Map to use it in that Blueprint. You can still only assign a single Liftoff Library Item per Blueprint. For more information, see [Configure the Liftoff Library Item](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item). Clicking **Exit device lookup** will return you to the default Assignment Map view. ### Best Practices for Using Conditional Logic **Keep Your Logic Organized** * Group conditional blocks by purpose (e.g., department-based conditions together, location-based together). * Use meaningful names for blocks and position them logically on the canvas so the flow is easy to follow. **Test Your Conditional Logic** * Before deploying to production, use the device or user lookup feature to see the path a device takes through the map. This helps you catch issues before they affect users. * Editing an Assignment Map triggers an immediate reevaluation of all rules. That's good for testing, but be careful when changing production maps. **Use the Simplest Logic That Works** * Prefer the simplest solution that meets your needs; complex logic is harder to maintain and troubleshoot. * For very complex logic, consider splitting into multiple Assignment Maps to keep each one clearer. **Document your Assignment Maps** * Document the purpose and logic of your maps, especially when they have many conditional blocks. This helps your whole IT team understand the deployment strategy. ### Considerations In **Advanced View**, how you enter criteria on Assignment Rules affects whether a device or user matches. Keep the following in mind when you configure **User group**, **Mac family**, **User job title**, and **User department**. For **User group**, **Mac family**, **User job title**, and **User department**, each extra value you add to a criterion is combined with **OR** logic. The device or user needs to match only one of those values for that criterion to evaluate as true. For example, if **User group** is **is one of** with **Finance users** and **Engineer users**, a user in either group satisfies the rule. **User group** offers autocomplete for groups Iru already knows. Select a suggested group as you type to keep names aligned with your directory and avoid typos. **User job title** and **User department** do not offer autocomplete. Type each value in full so it matches how the attribute appears in your directory or HR records. To add several **user job titles**, **user departments**, **serial numbers**, or **asset tags**, press **Enter** after each value. The current entry becomes a chip so you can add more. You can also paste a newline-separated list into the field. Each line becomes its own chip. ### Related Articles Organize and group devices using tags Create a Blueprint with Assignment Maps Create and configure device Blueprints for policy management Configure dynamic Blueprint assignment during device enrollment using Assignment Rules # Check Applications, Library, and System folders for world writable files Source: https://docs.iru.com/en/endpoint/blueprints/parameters/checking-library-and-system-folders-for-world-writable-files Audit Applications, Library, and System folders on Mac for world writable files. This guide applies to Mac computers ### About the Applications, Library, and System world writable Parameters These Blueprint Parameters audit Mac computers for files with overly permissive permissions in the Applications, Library, and System folders. They identify security vulnerabilities caused by world writable files. ### How It Works These Parameters scan the Applications, Library, and System folders for world writable files. The Applications Parameter changes out-of-compliance applications to be world executable. The Library Parameter can attempt to remediate world writable directories if found. The System Parameter alerts you to their presence. ### What are World Writable Files? World writable files in macOS are files or directories that any user on the system can modify. While this might seem convenient, it poses significant security risks. Any user, including those with malicious intent, can alter these files, potentially leading to unauthorized changes, data corruption, or even system compromise. Being aware of these files is crucial because they can be exploited to inject malicious code or disrupt services. Regularly auditing and managing file permissions helps maintain system integrity and security. Minimizing or eliminating world writable permissions protects Mac computers from those vulnerabilities. ### Check Applications folder for appropriate permissions This Parameter verifies applications located anywhere within the `/Applications` directory are not world writable. Applications found to be out of compliance will have their permissions changed to be world executable. A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable applications in the Applications folder and remediate them if found. To configure the Parameter: Open your Blueprint, then click **Parameters**. Select **Edit Parameters**. If this is the first Parameter you're adding, select **Add Parameters**. In the search field, enter "Applications folder". Locate the **Check Applications folder for appropriate permissions** Parameter, and enable it by toggling the switch. Optionally, click the bell icon to mute notifications for this Parameter. Click **Save**. ### Check Library folder for world writable files This Parameter verifies directories in `/Library` aren't set to be world writable. Directory exclusions can be created for Iru to skip over specified folders. This is useful for applications that don't function properly if their directories are modified to comply with this Parameter. Adobe is an example of this. Test thoroughly before mass deployment. Certain applications do not function properly if their associated directories in `/Library` aren't world writable. A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable files located in the Library folder and attempt to remediate them if found. To configure the Parameter: Open your Blueprint, then click **Parameters**. Select **Edit Parameters**. If this is the first Parameter you're adding, select **Add Parameters**. In the search field, enter "world writable". Locate the **Check Library folder for world writable files** Parameter, and enable it by toggling the switch. Optionally, click **Add Directory Exclusion** and enter the full path of each directory Iru Endpoint should skip under **Full paths of excluded directories**. Optionally, click the bell icon to mute notifications for this Parameter. Click **Save**. ### Check System folder for world writable files This Parameter verifies directories in `/System` aren't set to be world writable. Because of Apple's [System Integrity Protection (SIP)](https://support.apple.com/en-us/102149), world writable files found in the System folder cannot be remediated automatically. Manual intervention is required to resolve alerts for world writable files found in this location. A Parameter can be configured on a Blueprint (Assignment Map) to audit for world writable files located in the System folder and alert admins to their presence. To configure the Parameter: Open your Blueprint, then click **Parameters**. Select **Edit Parameters**. If this is the first Parameter you're adding, select **Add Parameters**. In the search field, enter "world writable". Locate the **Check System folder for world writable files** Parameter, and enable it by toggling the switch. Optionally, click the bell icon to mute notifications for this Parameter. Click **Save**. For more detailed information on Parameters, see the [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) section of our Knowledge Base. # Create User Accounts Source: https://docs.iru.com/en/endpoint/blueprints/parameters/create-user-accounts Use the create user accounts parameter in Iru Endpoint Blueprints to automatically provision local user accounts on Mac computers during enrollment. This guide applies to Mac computers ### About the Create User Accounts Parameter The Create User Accounts parameter is a Blueprint parameter in Iru Endpoint that can be used to create both Standard and Administrator user accounts on Mac computers. This parameter is especially useful as the user accounts can be created in this state from device setup without the need to change the account ID, location, or modify any permissions after the fact. ### How It Works This parameter creates user accounts during device setup, allowing you to establish both Standard and Administrator accounts without needing to modify permissions or account settings after the fact. This Parameter will not duplicate or modify any existing accounts. Iru Endpoint will only create the user account if that user account does not currently exist. After completing the required fields of **Full name**, **Short Name**, and **Password**, you will have the option to select the path to the home folder and the account type. There is also a toggle to create a sub-500 user account. Updating a user password in this parameter will not update a password for an existing local user. ### What is a sub-500 hidden user account? A **sub-500 Hidden Account** is an account that is created with a UID (User ID) with a value of less than 500. Accounts with a UID lower than 500 are hidden in multiple parts of macOS. Accounts with a UID lower than 500: * Are not shown at the macOS **List of Users** login window by default. * Are hidden from the fast user switching menu. * Are not shown in System Preferences > Users and Groups ### Why should I place a hidden account in `/private/var`? When you place a User Account's home folder in `/private/var`, you ensure that the home folder is not in a place that another user might see, such as the `/Users` folder. ### How can I log in with a Hidden Account at the macOS Login Window? If your macOS devices use the **List of Users** Login Window style, then you may be unsure how to log in with a hidden user account. This can be done at the login window by pressing the following keys. Press the down arrow key. Press Option + Return (Enter). A username and password field will appear where you can log in with your hidden user account. For more detailed information on Parameters, see the [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) section of our Knowledge Base. ### How do I unlock a FileVault 2 encrypted Mac with a user created by the Parameter? When the Iru Agent creates a user based on the "Create user accounts" parameter, it does not automatically grant that user a [secure token](https://support.apple.com/guide/deployment/use-secure-and-bootstrap-tokens-dep24dbdcf9e/web). This means that you cannot use these user credentials to unlock FileVault after a Mac restarts. You can enable a user for FileVault with the following steps: In System Settings, navigate to Privacy & Security Settings > FileVault Click the Enable Users button Click the Enable User button for the user Enter the password, then click OK. # Demote User Accounts to Standard Source: https://docs.iru.com/en/endpoint/blueprints/parameters/demote-user-accounts-to-standard Use the demote user accounts parameter in Iru Endpoint to automatically convert admin users to standard accounts on managed Mac computers. This guide applies to Mac computers ### About the Demote User Accounts Parameter The "Demote user accounts to Standard" parameter changes all local accounts to standard users. This is particularly useful when you want to limit access to Administrator-level controls, such as for NIST compliance. This Parameter is not compatible with [SAP Privileges and the Privileges Checker](/en/endpoint/library/deployment-guides/apple/deploy-sap-privileges-auto-app-with-privileges-checker) script. ### How It Works During each agent check-in, the parameter will activate on Mac computers to verify the access level of all local accounts. If any local account, aside from the designated excluded admin, has admin privileges, it will be changed to a standard account. The user will then see a 30-minute countdown before the Mac restarts. After the countdown, the Mac will restart, and all non-excluded local user accounts will be set to standard users. ### Requirements * The "Create User Accounts" Parameter must be enabled * At least one user account must be excluded from demotion ### Enabling The Parameter Once you are in the [Blueprint](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint) you wish to edit and have enabled the "Demote user accounts to Standard" Parameter, follow these steps to complete the configuration: Input the desired **Administrator account shortname** for the account you wish to exclude from demotion. Click **Add Exclusion** to add additional accounts you would like to remain as Administrators. Click **Save Parameters**. For more information on Parameters, see the [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) section of our Knowledge Base. # Don't allow the Guest user to log in Source: https://docs.iru.com/en/endpoint/blueprints/parameters/dont-allow-the-guest-user-to-log-in Disable the macOS Guest user account using the Blueprint parameter in Iru Endpoint. Prevent unauthorized access by blocking guest login sessions. This guide applies to Mac computers ### About the Don't Allow Guest User to Log In Parameter This parameter disables the Guest user account on Mac computers, which is considered a security vulnerability because it grants access without login credentials. ### How It Works When enabled, Iru Endpoint will ensure the Guest user feature is disabled. During each check-in, Iru Endpoint will verify and adjust settings to the disabled state should they change. By default, macOS allows a Guest user account that grants access to the general macOS system and apps without login credentials. The Guest user is considered a security vulnerability because it does not have a password. It's recommended that the Guest user account be disabled on all macOS systems unless there is a demonstrated need. ### Enabling this Parameter When enabled, Iru Endpoint will ensure the Guest user feature is disabled. During each check-in, Iru Endpoint will verify and adjust settings to the disabled state should they change. ### Disabling this Parameter Disabling this parameter stops Iru Endpoint from managing the Guest user feature during each check-in. The feature will remain in its current state until a user manually changes it. For more detailed information on Parameters, see the [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) section of our Knowledge Base. # Monitor encryption status of Time Machine volumes Source: https://docs.iru.com/en/endpoint/blueprints/parameters/monitor-encryption-status-of-time-machine-volumes Monitor Time Machine backup encryption status using the Blueprint parameter in Iru Endpoint. Get alerts when backup volumes are not encrypted. This guide applies to Mac computers ### About the Monitor Time Machine Encryption Parameter The "Monitor encryption status of Time Machine volumes" parameter triggers an alert if devices are using Time Machine to back up to an unencrypted local disk. ### How It Works This parameter monitors Time Machine backup volumes and alerts you when backups are being made to unencrypted disks, helping ensure proper backup security. As with all parameters, it's ideal to test changes before deploying them to Mac computers in your production environment. ### Configuring the Parameter To **enable** this Parameter, toggle the switch on the right-hand side. To mute this Parameter, click the bell icon. You can also toggle the alert if Time Machine backups are not enabled. For more detailed information on Parameters, see the [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) section of our Knowledge Base. # Report FileVault keys escrowed to iCloud Source: https://docs.iru.com/en/endpoint/blueprints/parameters/report-user-accounts-with-filevault-recovery-keys-escrowed-to-icloud Detect Mac user accounts with FileVault recovery keys stored in iCloud using the Blueprint parameter. Get alerts for unescrowed recovery keys. This guide applies to Mac computers ### About the Report FileVault iCloud Recovery Keys Parameter This parameter monitors and reports when user accounts have FileVault Recovery Keys escrowed to iCloud, which is not recommended for enterprise-owned Mac devices. ### How It Works The parameter raises an alert if a Recovery Key is stored in iCloud, providing a reminder to work with the user to remove the recovery key from their iCloud account for better security. macOS allows users to store Recovery Keys with their iCloud account. This is not recommended for enterprise-owned Mac devices, as it's possible that an unknown party can retrieve keys. This parameter raises an alert if a Recovery Key is stored in iCloud, providing a reminder to work with the user and follow the steps below to remove the recovery key from their iCloud account. ### Remove the FileVault library item Remove the FileVault library item assignment from the Mac with the following steps: Use a rule in your [Assignment Map](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) to exclude the Mac from getting the FileVault Library Item installed. Once the FileVault profile has been removed from the Mac, launch System Settings and [turn off FileVault encryption](https://support.apple.com/guide/mac-help/turn-off-filevault-encryption-on-mac-mchlp2560/mac). If present, remove the following file locally within the home directory of the associated iCloud user: ```bash theme={null} ~/Library/Preferences/com.apple.preference.security.plist ``` ### Reassign the FileVault library item Depending on your [FileVault enforcement settings](/en/endpoint/library/deployment-guides/apple/configure-filevault), a forced restart of the Mac or reminder that the end user must restart to enforce FileVault encryption may be triggered when the FileVault library item is reassigned. Change the rule in your Assignment Map to include the Mac again, which will trigger a reinstall of the FileVault profile. As enforced by your library item, FileVault should now be turned on, and the iCloud account may no longer be used to unlock the disk. # Restart After X Number of Days of Continuous Uptime Source: https://docs.iru.com/en/endpoint/blueprints/parameters/restart-after-x-number-of-days-of-continuous-uptime Automatically restart Mac computers after a set number of days of continuous uptime using this Blueprint parameter. Improve performance and stability. This guide applies to Mac computers ### About the Restart after X Number of Days Parameter The "Restart after x number of days of continuous uptime" parameter will force a device to restart once the set number of days of uptime has been reached. ### How It Works When this Parameter is enabled, Iru Endpoint monitors continuous uptime. When the device reaches the number of days you set, it starts the restart notification and countdown described below. ### Enabling the Parameter Once you are in the Parameters tab of the Blueprint you wish to edit and have enabled the "Restart after x number of days of continuous uptime" Parameter, follow these steps to complete the configuration: Input the desired number of days until forced restart. Optionally, click the bell icon to mute notifications for this Parameter. Click **Save**. ### Restart Notifications Users will receive a banner notification starting 5 days before the enforcement deadline. Clicking on the notification will open the Iru Endpoint Menu Bar App. ### Enforcement Deadline Reached Once the enforcement deadline has been reached, the Iru Endpoint menu bar app will open, displaying a 30-minute countdown, giving the user time to close all programs and save their work. Users can defer the forced restart for an hour at a time, up to a maximum additional 24 hours past the deadline. # Set umask for all users Source: https://docs.iru.com/en/endpoint/blueprints/parameters/setting-umask-for-all-users Configure the default umask value for all users on managed Mac computers using this Blueprint parameter. Control default file and directory permissions. This guide applies to Mac computers ### What is umask? The **umask** (user file-creation mode mask) is a command in Unix that sets default permissions for new files and directories. It essentially dictates which permission bits will not be set when a file or directory is created, thus controlling the default permissions. For more information about setting custom umask values in macOS, see this [Apple guide](https://support.apple.com/en-gb/101914). ### How It Works When you create a file or directory, it starts with a default set of permissions. The umask value is subtracted from this default to determine the final permissions. For instance, the default permissions are typically 666 for files (read and write for everyone) and 777 for directories (read, write, and execute for everyone). The umask value is subtracted from these defaults to get the actual permissions. Setting the umask to 027 is a common practice for enhancing security. Here’s a breakdown of what this means: **0:** This digit is often ignored in the context of umask. **2:** This digit affects group permissions, removing write permissions. **7:** This digit affects "others" permissions, removing read, write, and execute permissions. After the umask is applied the following numeric values for permissions will be set: Files will have permissions 640 (666 - 027): | **Owner** | **Group** | **Others** | | -------------- | --------- | -------------- | | read and write | read-only | no permissions | Directories will have permissions 750 (777 - 027): | **Owner** | **Group** | **Others** | | ------------------------ | ---------------- | -------------- | | read, write, and execute | read and execute | no permissions | ### How to Set the umask to 027 A Parameter can be configured on a Blueprint (Assignment Map) to set the umask to 027 across all users on the Mac computers in your fleet. Enabling this Parameter will require a restart for each Mac it runs on if the umask value does not already match the value set. It may also cause unintended consequences for software installs, or in collaborative environments. Please test umask adjustments thoroughly before deploying to production computers. ### Configuring the Parameter Open your Blueprint, then click **Parameters**. Select **Edit Parameters**. If this is the first Parameter you're adding, select **Add Parameters**. In the search field, enter "**umask**". Locate the **Set umask for all users** Parameter, and enable it by toggling the switch. Click **Save**. # Activity Page Source: https://docs.iru.com/en/endpoint/devices/activity-page View and filter tenant-wide Endpoint activity in Iru Endpoint. Review blueprint, device, library, and enrollment events from the Activity page. ### About the Activity Page The **Activity** page shows a tenant-wide audit log of actions in **Iru Endpoint**. Review blueprint updates, device changes, library assignments, enrollment events, tag changes, and other Endpoint activity in one timeline. This page shows **Endpoint** activity only. **[Unified Activity](/en/iru/platform-overview/unified-activity)** is in [Preview](/en/iru/platform-overview/iru-release-stages) and adds **Detections**, **Vulnerabilities**, **Compliance**, and **Tenant** events in one timeline. ### How It Works Activity events from across Iru Endpoint appear in one feed, sorted with the most recent events first. Each entry records what happened, who performed the action, and when it occurred. Device records, Blueprints, Library Items, Assignment Maps, and other objects may also have their own **Activity** tabs scoped to that object. Those events appear in this tenant-wide Activity feed as well. ### Access the Activity Page Click the **Activity** icon (pulse icon) in the top right navigation bar. Activity icon in the top right navigation bar ### Considerations * **Alerts vs Activity**: **Alerts** (bell icon) and **Activity** (pulse icon) both live in the top navigation bar. Alerts surface device and Parameter issues; Activity records administrative and configuration changes. ### Related Articles Preview cross-product activity timeline across Endpoint, Detections, Vulnerabilities, Compliance, and Tenant. Monitor Parameter and Library Item alerts from the bell icon in the top navigation bar. Export tenant activity events to Amazon S3 for SIEM ingestion, compliance retention, or offline analysis. # Cellular Commands Source: https://docs.iru.com/en/endpoint/devices/device-actions/cellular-commands Send cellular commands to managed iOS and iPadOS devices from Iru Endpoint. Enable or disable personal hotspot, data roaming, and voice roaming. This guide applies to iOS devices and cellular-enabled iPadOS devices ### About Cellular Commands Iru Endpoint supports three device management commands for iPhone and iPad devices with cellular connectivity. These commands let you refresh a device's eSIM, set personal hotspot settings, and set data roaming settings remotely. These commands can be sent from the Devices page in the Iru web app and the Iru enterprise API. ### How It Works Cellular commands are sent via MDM to devices with cellular connectivity. The commands execute when the device is online and allow you to manage cellular settings without requiring physical access to the device. Users can override some settings unless explicitly restricted by the Restrictions Library Item. ## Using Cellular Commands Navigate to the **Devices** page in the Iru web app and select an iPhone or cellular-enabled iPad. Select the three dots action menu in the upper right corner of the device record. Select **Cellular commands** from the action menu. Choose between **Refresh eSIM**, **Set data roaming**, or **Set personal hotspot**. ## Available Commands ### Refresh eSIM The **Refresh eSIM** command instructs the device to contact a carrier eSIM server, also known as an SM-DP+ server, and download an available eSIM profile. This effectively provisions the device with a new eSIM. Contact your carrier to obtain the SM-DP+ server address before using this command. ### Set Data Roaming The **Set data roaming** command enables or disables data roaming on the device. This setting can be overridden by the user unless explicitly restricted by the Restrictions Library Item. ### Set Personal Hotspot The **Set personal hotspot** command enables or disables personal hotspot on the device. This setting can be overridden by the user unless explicitly restricted by the Restrictions Library Item. ## Considerations ### Command Execution * **Single device only**: These commands can only be triggered for a single device at a time, either via the Devices page or Iru enterprise API * **Online requirement**: Devices must be online to receive and execute cellular commands * **User override**: Data roaming and personal hotspot settings can be overridden by users unless restricted by the Restrictions Library Item ### Restrictions Library Item To prevent users from overriding data roaming or personal hotspot settings, configure the [Apple Restrictions Library Item](/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item) with the appropriate restrictions. This ensures your cellular settings remain enforced. ## References For more information about Apple's cellular management commands, see: * [Refresh eSIM command](https://github.com/apple/device-management/blob/release/mdm/commands/device.esim.yaml) - Apple developer documentation * [Data roaming command](https://github.com/apple/device-management/blob/f878dea98fb88293a3686e44bcfb891f8e78f98f/mdm/commands/settings.yaml#L101) - Apple developer documentation * [Personal hotspot command](https://github.com/apple/device-management/blob/f878dea98fb88293a3686e44bcfb891f8e78f98f/mdm/commands/settings.yaml#L171) - Apple developer documentation # Delete a User Account Source: https://docs.iru.com/en/endpoint/devices/device-actions/delete-a-user-account Remotely delete a local user account from a managed Mac computer using Iru Endpoint. Remove user data and free up disk space on macOS devices. This guide applies to Mac computers ### About Deleting User Accounts Iru Endpoint provides administrators the ability to delete macOS user accounts using Apple's MDM framework. This allows you to remove user accounts from enrolled Mac computers remotely and securely. ### How It Works When you delete a user account through Iru Endpoint, the command is sent to the device using the MDM protocol. As long as the device is online, the account gets deleted near-instantly. You can monitor the progress of this command through the device's activity section. ## Deleting a User Account Click **Devices** from the left-hand navigation bar Select a **macOS device** from your list of devices Click the **Device Actions** button at the top right-hand side of the window Click the **Delete User Account** option from the menu Input the full **Account Name** of the user you want to delete Click **Delete User** You can check the progress of this command by going to the activity section of the device record. You can also view a list of all local users on an enrolled Mac by going to the **Details** tab of a device record. See [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details). # Enable Lost Mode Source: https://docs.iru.com/en/endpoint/devices/device-actions/enable-lost-mode Activate Lost Mode on managed iOS and iPadOS devices from Iru Endpoint. Display a custom message, lock the device, and track its location remotely. This guide applies to iOS devices and iPadOS devices ### About Lost Mode Lost Mode in Iru Endpoint gives you a centralized way to locate and secure lost or misplaced devices, even if they have Location Services disabled. ### How It Works The requirements for Lost Mode in Iru Endpoint are: * Supervised iPhone or iPad running a [supported version](/en/iru/requirements/device-requirements) of iOS or iPadOS * Device enrolled to Iru Endpoint * Device accessible over the Internet The simplest way to achieve device supervision is Automated Device Enrollment with Apple Business or Apple School Manager. If that path is not available in your location, supervision can be enabled manually with Apple Configurator (but without the benefit of mandatory, non-removable MDM profiles). Mac computers don't support Apple's Managed Lost Mode, which is the underlying technology for Lost Mode in Iru Endpoint. ## Enable Lost Mode Enabling Lost Mode in Iru Endpoint is simple. The Device Action menu for compatible devices will show the **Enable Lost Mode** option. Selecting this option will open the Enable Lost Mode window, where you can enter messaging and contact information to display on the Lost Mode Lock Screen: You must enter at least a message or phone number. If you don't provide a message or footnote, the device will display a generic one. Here's what the lock screen looks like on a device in Lost Mode: Once you select **Enable Lost Mode**, Iru Endpoint will send an MDM command to the device to start the Lost Mode session. Once the device receives it, it's immediately secured with the Lost Mode lock screen. The device isn't usable by anyone, and its content is secured until the Lost Mode session is terminated in Iru Endpoint. Even if the device doesn't have a passcode, it's secured by the Lost Mode lock screen. Once the device acknowledges the MDM command, two things happen: * Iru Endpoint sends an MDM command to the device to obtain its location (and will do so automatically every 15 minutes until Lost Mode is disabled) * The Device Details view adds an orange icon and "LOST" label to the device image at the top. A Lost Mode tab appears in the Device details view: Once Lost Mode is enabled, you can see the following information: * The name of the Iru Endpoint user who enabled Lost Mode, with date and time of the event * A note about location update behavior with a link to this support document * An interactive map displaying the device's location based on longitude and latitude received by Iru Endpoint * A street address obtained from those coordinates, with a "copy-to-clipboard" link for easy sharing * A link to Apple Maps (which opens the Apple Maps website on non-Apple devices) * A copy of the information you entered when enabling Lost Mode This view also contains two actions you can take on a device while it's in Lost Mode. First, you can force a location update with the **Update Location** button, which will automatically refresh the map, address, and coordinates once the device responds with new location data. In addition to initially querying location information after Lost Mode is enabled, and subsequently every 15 minutes, Iru Endpoint automatically monitors for significant location changes of 50 or more meters (about 160 feet) since the last position update and will alert you if it detects one. Second, if the situation calls for it (someone is close to the device), you can trigger the Lost Mode sound with the **Play Sound** button. The Lost Mode sound will play for 2 minutes, even if the device is in silent mode. Anyone finding the device can silence it by pressing any of its side buttons. ## Device Activity The device activity stream will display the commands in use during the Lost Mode session: ## Alerts As always, we display full timestamps and Iru Endpoint usernames next to the commands. For privacy, we don't display any location data next to the location update command alerts. The contents of alerts will be the same and won't contain any location information. Location data will only be visible in the Device Details Lost Mode tab. ## Disable Lost Mode Once the device is located, you can disable Lost Mode in the device's Action menu or in the Lost Mode tab. Once the device receives this command, it will return to its previous state and display a notification that Iru Endpoint gathered its location and at what time. The Lost Mode tab is also removed from the Device Details view, and all location information is deleted from Iru Endpoint. Don't attempt to restart a passcode-protected, Wi-Fi only device while it's in Lost Mode. The device needs a local passcode entry after a restart to access the Wi-Fi credentials, and the Lost Mode Lock Screen prevents the passcode from being entered. If the device is restarted, you'll need to erase the device to get it back online. ## Device View Status The Lost Mode Status information can be enabled for a Device View. From the lefthand navigation, select **Devices**. Ensure the **Views** tab is selected. In the upper righthand corner, click **Edit columns**. When the Edit Columns drawer opens, search for **Lost Mode Status**. Check the **Lost Mode Status** checkbox. Click **Save View** near the top left of the drawer. ## Iru Endpoint API The Iru Endpoint API will display Lost Mode information on the Get Device Details and Get Lost Mode Details query endpoints, and supports these device actions: * Enable Lost Mode * Disable Lost Mode * Play Lost Mode Sound * Update Lost Mode Location * Cancel Lost Mode As in the admin interface, updated location information will be available on the aforementioned query endpoints. # Erase an Apple Device Source: https://docs.iru.com/en/endpoint/devices/device-actions/erase-a-device Remotely erase a managed Apple device from Iru Endpoint. Wipe all data and settings on Mac, iPhone, iPad, Apple TV, and visionOS devices. This guide applies to Mac computers, iOS devices, iPadOS devices, tvOS devices, and visionOS devices ### About Device Erase You can use the **Erase Device** command on macOS, iOS, iPadOS, tvOS, and visionOS devices. This command doesn't require supervision. For Windows devices, see [Erase a Windows Device](/en/endpoint/devices/device-actions/erase-a-windows-device). For Android devices, see [Erase an Android Device](/en/endpoint/devices/device-actions/erase-an-android-device). ### How It Works The Erase Device command permanently removes all data and settings from a device, returning it to factory defaults. The command is delivered through the MDM framework and executes when the device is online or queued for offline devices. A locked Apple device cannot receive an Erase Device MDM command. For more information on locking a device, see our [Lock a Device](/en/endpoint/devices/device-actions/lock-a-device) support article. ### Erase Apple Devices Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Erase Device**. After you select **Erase Device**, the confirmation dialog and erase behavior depend on the device. Type `ERASE` in the confirmation field and click **Erase Device** to send the command. #### macOS Erase Behavior Erase behavior depends on the Mac's hardware and macOS version. The command either performs Erase All Content and Settings (EACS) or obliteration. If EACS fails, the Mac falls back to obliteration. | Hardware | macOS version | Behavior | | --------------------------------- | --------------------- | ------------------------------- | | Apple silicon | macOS 12 or later | EACS | | Intel with T2 Security Chip | macOS 12 or later | EACS | | Apple silicon | macOS 11 and earlier | Obliteration without a PIN | | Intel with T1 or no security chip | Any supported version | Obliteration with a 6-digit PIN | When obliteration uses a PIN, Iru generates a 6-digit PIN and shows it on the device record after the Mac receives the command. Erase device PINs are not supported on Mac computers with Apple silicon. #### EACS Requirements * **Bootstrap token**: EACS fails if no bootstrap token is escrowed. * **Iru Web App**: Use the Iru Web App rather than the local Erase Assistant. * **Auto Advance**: Using the Iru Web App prepares the Mac for re-enrollment with Auto Advance. #### Legacy Firmware Passwords On Intel-based Mac computers with the T2 Security Chip running macOS Monterey, Iru sends Erase All Content and Settings. If a legacy firmware password is still on the Mac, the device completely erases and requires a macOS reinstall instead of EACS. To keep EACS, move the Mac to a Blueprint that does not include a Recovery Password Library Item, then send the Erase Device command. In the confirmation dialog, optionally select the **Use Return to Service** checkbox. This option is available on iPhone and iPad devices running iOS 17 or iPadOS 17 or later. If you selected **Use Return to Service**, optionally choose a Wi-Fi profile from the dropdown. Select a profile from your Library unless the device is connected to Ethernet. The **Retry enrollment** checkbox is visible only on iPhone and iPad devices running iOS 27 or iPadOS 27 or later, after you select **Use Return to Service**. It is selected by default. If enrollment fails after erase, the device retries automatically, with an increasing delay of up to 5 minutes between attempts. Type `ERASE` in the confirmation field and click **Erase Device** to send the command. #### iOS and iPadOS Erase Behavior * **Erase All Content and Settings**: The device restarts and presents Setup Assistant. * **Not a full system restore**: The device is not updated to the latest version. * **eSIM preservation**: Cellular plans are automatically preserved when you erase from the Iru Web App. #### Return to Service (iOS/iPadOS 17+) When erasing iOS or iPadOS 17+ devices, you can select **Use Return to Service** which: * **Automatic setup**: Device proceeds through Setup Assistant to home screen without user intervention * **Auto re-enrollment**: Device automatically re-enrolls into Iru after erasure * **Wi-Fi configuration**: Automatically joins Wi-Fi network from selected Library Item * **Ethernet support**: Works with tethered Ethernet connections (kiosks) without Wi-Fi profile On iPhone and iPad devices running iOS 27 or iPadOS 27 or later, selecting **Use Return to Service** shows **Retry enrollment**. The option is selected by default. Deselect it if you do not want the device to retry. If enrollment fails after the device is erased, the device retries automatically, with an increasing delay of up to 5 minutes between attempts. **Retry enrollment** does not appear on other devices or on iOS or iPadOS versions earlier than 27. ##### Considerations Activation Lock must be removed before issuing a Return to Service command. Do not select Library Items with EAP-TLS 802.1X networks with SCEP client identity. Return to Service will not work with Automated Device Enrollment that requires authentication. Self Service apps will not automatically reinstall when erased from Iru (unlike user-initiated erases). **Retry enrollment** requires iOS 27 or iPadOS 27 or later on iPhone and iPad. Type `ERASE` in the confirmation field and click **Erase Device** to send the command. #### tvOS and visionOS Erase Behavior * **tvOS**: Initiates a Reset. The device reboots and presents Setup Assistant. * **visionOS**: Initiates Erase All Contents and Settings. ### Apple Device Considerations Erase commands work on both supervised and unsupervised devices. Commands are sent through MDM and execute when the device is online. All data is permanently deleted and cannot be recovered. eSIM-based cellular plans are automatically preserved when you erase from the Iru Web App. ### Erase Command Execution Erase commands are delivered through the MDM framework. * **Online devices**: The command runs within minutes of being sent. * **Offline devices**: The command is queued until the device next connects to the internet. Erasing a device permanently deletes all data and cannot be undone. Back up anything you need to keep before you proceed. ### Related Articles Remotely wipe a Windows device with Local, Cloud, or Protected erase Factory reset a managed Android device, including optional external storage and eSIM erase Remotely lock a managed device and optionally display a message on the lock screen Activate Lost Mode on managed iOS and iPadOS devices to lock the device and track its location Delete device records and uninstall Iru Endpoint when preparing devices for reassignment or removal Configure Return to Service and other Self Service options for iOS, iPadOS, and visionOS # Erase a Windows Device Source: https://docs.iru.com/en/endpoint/devices/device-actions/erase-a-windows-device Remotely wipe a managed Windows device from Iru Endpoint. Choose Local, Cloud, or Protected erase to remove all data and apps. This guide applies to Windows devices ### About Device Erase When you erase a Windows device, Iru Endpoint sends a remote wipe command over MDM. You choose one of three erase types. The type you select controls how Windows is reinstalled and how the device handles an interrupted wipe. None of the three erase types retain user data. All three remove all data and apps from the device, equivalent to a factory reset. Back up anything you need to keep before you erase. For Apple devices, see [Erase an Apple Device](/en/endpoint/devices/device-actions/erase-a-device). For Android devices, see [Erase an Android Device](/en/endpoint/devices/device-actions/erase-an-android-device). ### Erase Windows Devices Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Erase Device**. In the confirmation dialog, choose an **Erase type**: * **Local**: Rebuilds Windows using the recovery image already stored on the device * **Cloud**: Downloads a fresh copy of the Windows installation files from Microsoft's servers * **Protected**: Fully cleans the internal drive and continues retrying until the wipe completes. Recommended for lost or stolen devices Type `ERASE` in the confirmation field and click **Erase Device** to send the command. The erase command is queued and will execute the next time the device is connected to the internet. ### Choose an Erase Type | Erase type | How Windows is reinstalled | If the wipe is interrupted | | ---------- | --------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- | | Local | Uses the recovery image already stored on the device | Windows attempts to roll back to its pre-wipe state. If rollback fails, the device can become unusable and may require a manual Windows reinstall | | Cloud | Downloads a fresh copy of the Windows installation files from Microsoft's servers | The device must remain connected to the internet for the duration of the wipe | | Protected | Fully cleans the internal drive | Continues retrying until the wipe completes, even if the device is power cycled. Can leave the device unable to boot | #### Local * Fastest option, and does not require an internet connection to reinstall Windows. * Equivalent to **Reset this PC > Remove everything** in Windows Settings with **Keep my files** turned off. #### Cloud * Returns the device to a current, unmodified Windows build. * Useful when the local recovery image is missing, outdated, or otherwise untrusted. #### Protected * Performs the most thorough wipe available. * Designed by Microsoft for lost or stolen devices. * Unlike Local, Protected does not prioritize rolling back to a working state if interrupted. It prioritizes leaving the drive clean. * In some device configurations, a Protected erase can leave the device unable to boot. This is expected behavior. The goal is to ensure data is removed, not to preserve a bootable device. ### Considerations Local is the fastest option and does not depend on network connectivity. Use it for routine device retirement or reimaging when you have the device on hand and do not need the latest Windows build. Use Cloud when you want a current, unmodified Windows build, or when you cannot trust the local recovery image. That includes a missing or outdated image, a history of failed resets, or a corrupted recovery partition. Use Protected when the device is lost, stolen, or otherwise outside your physical control. Queue it as soon as the device is reported lost or stolen so it runs the next time the device connects. Local and Protected erases both carry a risk that an interrupted wipe leaves the device unable to boot, requiring a manual Windows reinstall to recover. This is how Windows handles interrupted resets, and it is not controlled by Iru Endpoint. Protected accepts this risk intentionally: it prioritizes completing the wipe over preserving a bootable device, which is appropriate when data protection is more important than recovering the hardware. Erasing a device permanently deletes all data and cannot be undone. Back up anything you need to keep before you proceed. ### Related Articles Remotely erase a Mac, iPhone, iPad, Apple TV, or visionOS device Factory reset a managed Android device, including optional external storage and eSIM erase Remotely lock a managed device and optionally display a message on the lock screen Delete device records and uninstall Iru Endpoint when preparing devices for reassignment or removal # Erase an Android Device Source: https://docs.iru.com/en/endpoint/devices/device-actions/erase-an-android-device Remotely factory reset a managed Android device from Iru Endpoint. Optionally erase external storage and eSIMs. This guide applies to Android devices ### About Device Erase You can use the **Erase Device** command on Android devices enrolled in Iru Endpoint. The command factory resets the device through the Android Management API. For Apple devices, see [Erase an Apple Device](/en/endpoint/devices/device-actions/erase-a-device). For Windows devices, see [Erase a Windows Device](/en/endpoint/devices/device-actions/erase-a-windows-device). ### How It Works The Erase Device command permanently removes all data and settings from a device, returning it to factory defaults. The command is delivered through the Android Management API. * **Online devices**: The command runs when the device is online. * **Offline devices**: The command is queued until the device next connects to the internet. ### Erase Android Devices Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Erase Device**. In the confirmation dialog, review the erase details and optionally configure: * **Erase external storage**: Erase any connected SD cards or external storage drives * **Erase eSIMs**: Erase any installed eSIMs Type `ERASE` in the confirmation field and click **Erase Device** to send the command. ### Android Erase Behavior * **Factory reset**: All data, applications, and settings are removed. * **Setup**: The device returns to initial setup state. * **Erase external storage**: Optionally erase any connected SD cards or external storage drives. * **Erase eSIMs**: Optionally erase any installed eSIMs. ### Considerations Android erase commands work through the Android Management API and factory reset the device. All data is permanently deleted and cannot be recovered. You can optionally erase connected SD cards or external storage drives as part of the command. You can optionally erase any installed eSIMs as part of the command. Erasing a device permanently deletes all data and cannot be undone. Back up anything you need to keep before you proceed. ### Related Articles Remotely erase a Mac, iPhone, iPad, Apple TV, or visionOS device Remotely wipe a Windows device with Local, Cloud, or Protected erase Remotely lock a managed device and optionally display a message on the lock screen Reset or set a work profile passcode on a managed Android device Delete device records and uninstall Iru Endpoint when preparing devices for reassignment or removal # Lock a Device Source: https://docs.iru.com/en/endpoint/devices/device-actions/lock-a-device Remotely lock a managed device from Iru Endpoint. Set a PIN or password and display a message on the lock screen across Mac, iOS, and Windows. This guide applies to Mac computers, iOS devices, iPadOS devices, visionOS devices, and Android devices ### About Device Lock The Lock Device command is available on macOS, iOS, iPadOS, visionOS, and Android. It doesn't require supervision. A locked device can't receive an Erase Device MDM command. For more information on erasing a device, see [Erase an Apple Device](/en/endpoint/devices/device-actions/erase-a-device) or [Erase an Android Device](/en/endpoint/devices/device-actions/erase-an-android-device). ### How It Works When you lock a device, Iru Endpoint sends an MDM command to the device to immediately secure it. The device will require a passcode to unlock, and you can optionally display a custom message on the lock screen. #### How to Lock a Mac Navigate to the Device Record. Open the **Device Action Menu**. Select **Lock Device**. Optionally, configure a **Lock message** (macOS 14 or higher). Click **Lock device**. #### How to Lock an iPhone or iPad Navigate to the Device Record. Open the **Device Action Menu**. Select **Lock Device**. Optionally, configure a **Lock message** and **Phone number** to display on the locked device. Click **Lock device**. #### How to Lock a Vision device Navigate to the Device Record. Open the **Device Action Menu**. Select **Lock Device**. Click **Lock device**. #### How to Lock an Android Device Navigate to the **Devices** page. In the upper right corner, select the three dot ellipsis icon. Select **Lock device**. Select **Lock device** again to send the lock command. ## Command Behavior #### Command Behavior for macOS For macOS devices, the device will be locked with an EFI/Find My PIN code. Some conditionals, whose behavior is unique to the hardware and macOS version, are outlined below. Once the device receives the command, a 6-digit pin will automatically be generated and available on the device record. **Mac computers** with **Apple silicon** running **macOS 11.5 or earlier**. * Lock device PINs aren't supported on Mac computers with Apple silicon before macOS 11.5 * The device will restart to recoveryOS, where an admin must authenticate, and activation will be required **Mac computers** with **Apple silicon** running **macOS 11.5 or later**. * The device will restart and be locked with a randomly generated PIN once the device receives the command **Mac computers** with **Intel** running **any supported macOS version**. * The device will restart and be locked with a randomly generated PIN once the device receives the command #### Command Behavior for iOS, iPadOS, and visionOS For iOS, iPadOS, and visionOS devices, once the command is received, the screen will automatically be locked, and you can optionally specify a lock message. The device will be locked with the existing passcode. #### Command Behavior for Android For Android company-owned work profile devices, the lock command will immediately lock the device. The device will be locked with the existing device passcode or work profile passcode, depending on the device configuration. # Reset a macOS User Password Source: https://docs.iru.com/en/endpoint/devices/device-actions/reset-a-macos-user-password Reset a local macOS user password remotely from the Iru Endpoint web app. Generate a temporary password and require a change at next login. This guide applies to Mac computers ### About Password Reset Resetting a macOS user password requires different approaches depending on whether FileVault disk encryption is enabled. When FileVault is enabled, you'll need the FileVault recovery key to reset passwords. When FileVault is disabled, you can use macOS Recovery to reset passwords directly. ### How It Works Password reset works differently based on FileVault status. With FileVault enabled, the startup disk is encrypted and macOS isn't running at the login screen, so remote password reset isn't possible. You must use the FileVault recovery key at the login window or in macOS Recovery. Without FileVault, you can use Terminal in macOS Recovery to reset passwords directly. When using Passport, there are specific steps to follow when resetting passwords. For more information, see the [Managing Passwords with Passport](/en/endpoint/library/passport/managing-passwords-with-passport) article. ## If FileVault 2 is Enabled If FileVault is turned on and you have a FileVault recovery key, you can use that key to reset the password at the FileVault login window or in macOS Recovery. #### FileVault Login Window At the FileVault login window, use the following steps to reset the password with your FileVault recovery key. Click the question mark next to the password field. You may see a password hint (if you set one) or one of the following messages: * **Restart and show password reset options** * **Reset it using your Apple ID** * **Reset it using your recovery key** If you do not see a reset message or question mark, enter an incorrect password up to three times and look again for the question mark or arrow next to the message. When the option to reset using your recovery key appears, click it (or the arrow next to the message). Enter the FileVault recovery key in uppercase, including the hyphens. Follow the on-screen instructions to set a new password. Log in with the new password. You may need to reset the keychain after logging in. #### macOS Recovery If you are unable to reset the password at the FileVault login window, boot the Mac into macOS Recovery. * **Apple silicon:** Turn on your Mac and continue to press and hold the power button until you see the startup options window. Select the gear icon labeled Options, then click Continue. * **Intel processor:** Turn on your Mac and immediately press and hold Command (⌘)-R until you see an Apple logo or other image. If you're asked to select an admin user you know the password for, click **Forgot all passwords?** and proceed as described below. Enter your FileVault recovery key. When prompted to reset your password, click **Reset Password**. Select a user to reset the password for. After successfully authenticating, click **Exit**. Choose Apple menu > **Restart**. Password reset is now complete, so you don't need to take additional steps. ### Why can't Iru Endpoint just reset the password remotely? FileVault works by encrypting the full startup disk of the Mac. When you are at the FileVault login window, the macOS startup disk is not yet unlocked. Therefore macOS is not yet running or connected to the internet to receive any MDM or agent communication. To find the FileVault recovery key: On the device record for the Mac, click the **Device Action Menu**. From the drop-down, select **View FileVault2 recovery key**. ### If FileVault 2 is not Enabled If FileVault is not turned on, you can use Terminal in the recovery partition to reset an account password. Boot your device into macOS Recovery. * **Apple silicon:** Turn on your Mac and continue to press and hold the power button until you see the startup options window. Select the gear icon labeled Options, then click Continue. * **Intel processor:** Turn on your Mac and immediately press and hold Command (⌘)-R until you see an Apple logo or other image. Once you see the macOS Utilities window, choose **Utilities** from the menu bar, then choose **Terminal**. In Terminal, type *resetpassword* and press Return. At the Reset Password window, click **Deactivate Mac**, then click **Deactivate** to confirm. If you see an Activation Lock window, enter your Apple ID email and password, then click **Next**. ### If You Can't Log In After a Password Reset If you can authenticate at the FileVault login window but are then asked to log in again at the standard login window, the local account may be locked due to incorrect password attempts. It can be unlocked via MDM. #### Select the Unlock User Account Command On the device record for the Mac, click the **Device Action Menu**. From the drop-down, select **Unlock user account**. #### Unlock User Account Enter the short name of the account to unlock. (Check the **Details** page for a list of usernames.) Click **Unlock User** to send the command. # Reset Android Work Profile Passcode Source: https://docs.iru.com/en/endpoint/devices/device-actions/reset-android-work-profile-passcode Reset or set a new work profile passcode on managed Android devices from Iru Endpoint. Clear forgotten passcodes and restore access to work apps. This guide applies to Android devices ### About Reset Android Work Profile Passcode The **Reset work profile passcode** command resets the work profile passcode on an Android device and optionally lets you set a new one. Run it from a device record in the Iru web app or via the Iru enterprise API. ### Requirements * Enrolled Android device with a work profile ### How It Works Iru Endpoint sends the command to the device through the Android Management API. When the device receives it, the existing work profile passcode is reset. If you set a new passcode, it is validated against any assigned *Android Work Profile Passcode* Library Item and must meet Android’s minimum length (4 characters, or 6 on Android 14). #### When No Work Profile Passcode Policy Is Assigned When no *Android Work Profile Passcode* Library Item is assigned to the device, you can reset the passcode and optionally set a new one. To enforce stricter requirements, assign the [Android Work Profile Passcode](/en/endpoint/library/library-items-profiles/configure-the-passcode-library-item#creating-android-work-profile-passcode-policies) Library Item. Go to the **Devices** page and select an Android device. Open the **Device Action Menu** (ellipsis) in the upper right corner and select **Reset work profile passcode**. Device Action Menu with Reset work profile passcode option To reset the work profile passcode only, leave **Set new passcode** off and click **Reset passcode** to send the command. Confirm reset passcode To set a new passcode, turn on **Set new passcode**, enter a passcode that meets the minimum length, then click **Reset passcode**. Reset work profile passcode modal with New passcode field Optionally turn on **Lock work profile immediately after passcode reset** before clicking **Reset passcode**. With this option, the new passcode is required immediately to access any work profile content. Without it, the new passcode is only required the next time the user would normally enter their PIN. Lock work profile option (base flow) #### When a Work Profile Passcode Policy Is Assigned When the device has the *Android Work Profile Passcode* Library Item assigned, a new passcode is required and the policy requirements are enforced. For details on configuring the Library Item, see [Android Work Profile Passcode](/en/endpoint/library/library-items-profiles/configure-the-passcode-library-item#creating-android-work-profile-passcode-policies). Go to the **Devices** page and select an Android device. Open the **Device Action Menu** (ellipsis) in the upper right corner and select **Reset work profile passcode**. Device Action Menu with Reset work profile passcode option The modal displays the requirements from the assigned Library Item (for example, minimum length, numbers, letters). Each requirement appears in the list until it is met. Passcode requirements from Library Item displayed in modal As you enter a passcode, validation runs and each requirement shows a green checkmark when met. When all requirements are met, **Reset passcode** is enabled. Passcode validation met, ready to send command Optionally turn on **Lock work profile immediately after passcode reset**. With this option, the new passcode is required immediately to access any work profile content. Without it, the new passcode is only required the next time the user would normally enter their PIN. Lock work profile option when Library Item is assigned Click **Reset passcode** to send the command. ### When to Use This Command The **Reset work profile passcode** command gives admins a way to restore access to work apps when an end user forgets their passcode, so users can avoid unenrolling and re-enrolling the Android device. To learn more about the underlying command and behavior, see the [Android Management API](https://developers.google.com/android/management/reference/rest/v1/enterprises.devices/issueCommand#resetpasswordflag) in Google's documentation. ### Related Articles Remotely lock devices across all platforms Remotely factory reset a managed Android device View and manage the application list on devices # Set the Auto Admin Account Password Source: https://docs.iru.com/en/endpoint/devices/device-actions/set-the-auto-admin-account-password Set or change the auto admin account password on managed Mac computers from Iru Endpoint. Rotate the hidden administrator credentials remotely. This guide applies to Mac computers This MDM command requires supervision. ### About Auto Admin Account Password You can change the Auto Admin account password remotely on supervised Mac computers as long as the device is powered on and connected to the network. The Auto Admin account is the MDM-configured administrator that can be optionally created during the Automated Device Enrollment process. ### How It Works When you set the Auto Admin account password through Iru Endpoint, the command is sent to the device using the MDM protocol. The password gets updated on the device, allowing you to maintain access to the administrative account. This account can be configured in Iru Endpoint inside an Automated Device Enrollment Library item. If the device is at the FileVault authentication window, the command will not be received. Additionally, the Set Auto Admin Password MDM command will not update the Auto Admin User's SecureToken (FileVault) password. ## Setting the Auto Admin Account Password You can issue this command through the **Device Action Menu** while viewing a device record. You'll only see the command if it's applicable for the device based on its enrollment status. Select a supervised macOS device from the devices page Select the device action menu in the upper right-hand corner Click the **more (...)** button Select **Set Auto Admin Password** Enter the new password twice in the modal Select **Set Auto Admin Password** You can check the status of the command in the device activity section. # Setting Device Names Source: https://docs.iru.com/en/endpoint/devices/device-actions/setting-device-names Set or change device names remotely from the Iru Endpoint web app. Rename Mac, iPhone, iPad, Apple TV, and Windows devices for easier identification. This guide applies to Apple devices ### About Device Naming The Device Name Library Item helps IT administrators apply consistent naming conventions across Apple devices. It provides flexibility and control over device naming, making device management easier. ### How It Works You can create standardized naming patterns using customizable formulas that include variables like asset tags, user names, blueprint names, company names, serial numbers, and custom text. The Device Name Library Item also manages device hostnames by replacing spaces with hyphens, ensuring compatibility with systems that rely on hostnames, like network security appliances. This Library Item requires supervision. The Device Name Library Item cannot be duplicated. ### Add a Device Name Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Device Name Library Item a **name**. **Assign** to your desired Blueprints. ### Configure the Device Name Library Item #### Device Name Drag variables in the Device name pattern field to define your desired pattern. Be mindful of platform-specific differences; for example, "Primary local user name" is only available for macOS. Review the resulting pattern preview. #### Hostname By default, the Device Name Library Item will use the same pattern for the device name and hostname. Optionally, you can configure the Device Name Library Item to have separate device name and hostname patterns on Mac computers (allowing the device name to be more user-friendly). Select **Customize hostname**. Drag variables into the hostname pattern field to define your desired pattern. Review the resulting pattern preview. #### Hostname Considerations * If you deselected Mac in the device families, the Hostname section will be disabled as MDM can only manage hostname on Mac. iOS, iPadOS, tvOS, and visionOS devices set their hostname automatically based on the Device Name. * iOS, iPadOS, and visionOS devices connect to Wi-Fi networks with Private Wi-Fi Address turned on by default. With this setting turned on, the device does not share the hostname with the network. Instead, it shares the device's Model Name, e.g., iPad Pro 11 (4th Gen). You can turn this setting off using the Disable MAC address randomization configuration option in the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item). ### Device Name Modification Optionally, to prevent users from modifying the device name or hostname, select the **Prevent users from modifying device name and hostname** checkbox. Click the **Save** button to save the Device Name Library Item to your Library. * On iOS, iPadOS, tvOS, visionOS and macOS 14 Sonoma and later, this will set the Supervised restriction preventing users from modifying their device's name. On macOS versions prior to macOS 14 Sonoma, the Iru Agent will remediate device name and hostname changes after the next Agent check-in. ### Manually Rename a Device macOS, iOS, iPadOS, tvOS, visionOS device names can be set directly on the associated device record page. This action will be unavailable if you have a Device Name Library Item set to configure the device's name. Manually renaming a device does not change the device hostname. This Device Action requires supervision. Navigate to a device record. Click the **Device Action** menu in the upper right corner. Click **Set device name** from the action menu. Enter a device name into the **Set Device Name** window. Click **Set Device Name**. # Turn on Remote Desktop Source: https://docs.iru.com/en/endpoint/devices/device-actions/turn-on-remote-desktop Enable Apple Remote Desktop on managed Mac computers from Iru Endpoint. Allow remote screen sharing, observation, and management for IT support. This guide applies to Mac computers ### About Remote Desktop Remote Desktop on macOS gives you the flexibility to access and manage your Mac computers from a different location using Apple or other third-party tools to initiate screen sharing. ### How It Works Remote Desktop uses the virtual network computing (VNC) protocol for screen-sharing sessions between admin and client Mac computers. Iru Endpoint uses the EnableRemoteDesktop MDM command to allow all local users on the Mac to observe and control the device, which is the standard configuration set by macOS. Once Remote Desktop is activated, you can use the following Apple tools to start a screen-sharing session, depending on your needs: * **Apple Remote Desktop** - This tool is designed for managing multiple Mac computers remotely. It allows IT administrators to control screens, send files, and execute commands on client Macs. * **Screen Sharing** - This built-in feature of macOS allows users to view and control another Mac's screen over the network. It is simple to set up and doesn't require additional software. However, it is typically limited to local network connections and offers basic functionality compared to Apple Remote Desktop ### Enabling Remote Desktop in the Iru Endpoint Web App Navigate to the Device Record for the Mac you'd like to enable Remote Desktop on. Open the Device Action Menu, and select **Turn on Remote Desktop**. ### Disabling Remote Desktop in the Iru Endpoint Web App Navigate to the Device Record for the Mac you'd like to disable Remote Desktop on. Open the Device Action Menu, and select **Turn off Remote Desktop**. ### Enabling or Disabling Remote Desktop in Bulk To enable or disable Remote Desktop on multiple devices at once, you can use the Device Actions API script ([GitHub Link](https://github.com/kandji-inc/support/tree/main/api-tools/device-actions)) ### Customizing Permissions when Enabling Remote Desktop Using the Turn on Remote Desktop device action enables **all** local users on the Mac to observe and control the device, which is the [default configuration applied by macOS](https://support.apple.com/en-us/HT209161). To customize permissions more specifically, you can use the kickstart command-line utility included in macOS and deploy it as a [Custom Script](/en/endpoint/library/library-items-profiles/custom-scripts-overview). Please be aware that while the kickstart command can still be used to apply more detailed settings for Remote Desktop, it is no longer capable of enabling or disabling Remote Management starting from macOS 12.1 or later. For instance, you can use the [Audit Script](https://github.com/kandji-inc/support/blob/main/Scripts/remote-desktop/remote_desktop_audit.zsh) from the Iru Endpoint support GitHub repository to ensure that Remote Desktop is configured with more detailed settings. If it is not configured as desired, you can use the [Remediation Script](https://github.com/kandji-inc/support/blob/main/Scripts/remote-desktop/remote_desktop_remediation.sh) from the same repository to grant full privileges only to a user with the username "ladmin." Refer to the comments in the script for further customization options, along with: ``` sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -h ``` # Using the Blank Push Command Source: https://docs.iru.com/en/endpoint/devices/device-actions/using-the-blank-push-command Send a blank push command from Iru Endpoint to verify APNs connectivity and help complete stuck MDM commands on managed Apple and Windows devices. This guide applies to Apple devices ### About the Blank Push Command A Blank Push uses the same service that sends MDM profiles and commands. It's meant for verifying a connection to Apple Push Notification Service (APNs), but it sometimes helps to complete pending commands that may be stuck in the queue. ### How It Works Each MDM command sent to a device consists of the command itself as well as a separate APNs notification that, once received, tells the device it needs to connect with Iru Endpoint to retrieve that pending command. The Blank Push sends just this APNs notification without adding a new action for the device to complete. ## Sending a Blank Push On the Device page, click the **Device Action Menu** in the upper right-hand corner of the page. Within the Device Action Menu, click **Send blank push**. In the Activity tab of the device, you'll see a pending BlankPush command. Once the command has been sent, it will show **MDM Command Completed: BlankPush** in the device's Activity Stream. # Device Check In Source: https://docs.iru.com/en/endpoint/devices/device-check-in/device-check-in Learn how device check-in works for MDM and the Iru Agent. Understand check-in intervals, triggers, and how devices communicate with Iru Endpoint. This guide applies to all device platforms ### About Device Check-In Iru Endpoint uses different check-in mechanisms depending on the device platform. Each platform has specific check-in types that serve different purposes and occur at various frequencies. Understanding these check-ins helps you track device state, enforce policies, and ensure applications are deployed reliably. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works Device check-ins are the communication mechanism between managed devices and Iru Endpoint servers. They enable: * Policy enforcement and compliance monitoring * Application deployment and updates * Device inventory collection * Configuration profile management * Real-time device management commands The check-in frequency and mechanism vary by platform, with some using agent-based check-ins and others relying on MDM push notifications. ### Platform-Specific Check-In Details ### Recurring Check-In **Frequency:** Every 15 minutes\ **Mechanism:** Iru Agent This check-in ensures that the Iru Agent is up-to-date, executes and enforces Blueprint parameters, and installs any pending Library Items such as custom scripts, printers, apps, and auto apps. Each item has a specific timeout period for installation. #### Order of Operations and Timeouts Library Items are processed in a specific sequence. Each type of Library Item is handled in an alphanumeric order, with uppercase letters taking precedence over lowercase ones. The timeout values define the maximum time allowed for each Library Item to complete its installation or execution before it is stopped. Additionally, each run is governed by a global timeout limit of 12 hours, which also applies to installations of Custom Apps and Apps and Books initiated through Self-Service. | **Priority** | **Operation** | **Timeout** | | ------------ | --------------- | ----------------------- | | 1 | Custom Scripts | 1 hour per item | | 2 | Custom Printers | 3 hours per item | | 3 | Custom Apps | 12 hours (global limit) | | 4 | Auto Apps | 6 hours per item | | 5 | Managed OS | 12 hours (global limit) | #### Forcing a Recurring Check-In To force a recurring check-in, run the following command in Terminal: ```bash theme={null} sudo iru run ``` ### Daily Check-In **Frequency:** Every 24 hours\ **Mechanism:** Iru Agent This check-in includes all recurring check-in items and additional daily items like custom scripts, compliance scripts, and Blueprint parameters. It also involves securing home folders, checking application and system folders for appropriate permissions, and collecting daily computer information for submission to the Iru Endpoint tenant. The daily check-in follows the same sequence as the recurring one, starting after executing Blueprint Parameters. Once all Library Items are completed, the application inventory is sent back to Iru Endpoint. #### Forcing a Daily Check-In To force daily check-in, run the following command in Terminal: ```bash theme={null} sudo iru run --reset-daily ``` This also reruns daily Blueprint Parameters, daily Custom Scripts, and application inventory (including MDM commands), even if they already ran in the last 24 hours. To force a single Library Item, use `sudo iru library --item --reset-daily`. See [Iru Agent Command Line Interface](/en/endpoint/agent/iru-agent-command-line-interface). A daily check-in can also be forced using the sync button in Self Service: Open the **Iru Self Service** app. Navigate to the **Device Info** section on the left. Click **SYNC**. ### MDM Daily Check-In **Frequency:** Every 24 hours\ **Mechanism:** Apple Push Notification Service (APNs) / MDM Framework This check-in involves executing the following MDM commands to update device information: * ProfileList * InstalledApplicationsList * SecurityInfo * CertificateList * AvailableOSUpdates * DeviceInformation #### Forcing an MDM Daily Check-In From the Iru Web App, select **Perform daily check-in** in the **Device Action Menu**. On Mac computers, this runs the MDM items listed above. It does not run the Iru Agent daily check-in. Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Perform daily check-in**. You can also force the daily MDM commands in Terminal: ```bash theme={null} sudo iru update-mdm ``` ### MDM Commands & Profiles **Frequency:** Instant\ **Mechanism:** APNs / MDM Framework This check-in allows for instant execution of any MDM command, such as wiping a device, setting a device name, or installing applications. It also includes any profile deployed via a Library Item. #### How Instant is MDM Communication? MDM servers send a unique notification to the Apple Push Notification service, prompting managed devices to check in with their MDM server. Apple devices regularly poll APNs for these notifications, enabling almost immediate management of devices that are online. Consequently, there isn't a set check-in time for MDM commands, nor is there a way to enforce a check-in. ### Recurring Agent Check-In **Frequency:** Every 15 minutes\ **Mechanism:** Iru Agent The Iru Agent checks in every 15 minutes for app inventory, app deployment, and PowerShell scripts. The agent also keeps itself up to date. During a recurring check-in, the Iru Agent: * Installs or updates assigned apps * Runs assigned PowerShell scripts * Submits application inventory to Iru Endpoint * Updates the agent to a newer version if available MDM-delivered policies, including Windows Firewall and BitLocker, are not driven by this interval. See [Event-Driven MDM Commands](#event-driven-mdm-commands) and [MDM Daily Check-In](#mdm-daily-check-in) below. ### Event-Driven MDM Commands **Frequency:** Generally within a couple of minutes\ **Mechanism:** Windows Push Notification Services (WNS) / MDM Framework New policies and settings changes from an admin are event-driven. When you save a change in the Iru Endpoint Web App, the request is sent via WNS. On online devices, enforcement generally happens within a couple of minutes. This includes MDM system policies (including Windows Firewall and BitLocker) and commands such as wipe or retire. There's no fixed check-in interval for event-driven delivery; timing depends on device connectivity and WNS availability. ### MDM Daily Check-In **Frequency:** Every 24 hours\ **Mechanism:** MDM If a user manually changes something on the device (for example, local firewall settings), that drift is remediated on the daily MDM check-in. The daily check-in evaluates targeted policies against admin intent, remediates as needed, and collects daily device information (system info, hardware inventory, policy status). #### Forcing an MDM Daily Check-In The Device Action menu uses the same **Perform daily check-in** command on Windows. This sends an MDM check-in. It pushes down MDM policies that were waiting to deploy. It does not remediate policies that have already been applied, and it does not force an Iru Agent sync. Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Perform daily check-in**. ### Logs * **Iru Agent Logs**: `%ProgramData%\kandji\agent\logs` * **Windows MDM Logs**: Event Viewer → **Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider (Admin)** Use these logs to validate whether check-ins occurred and to identify failures in MDM or Agent processing. ### How is MDM Communication Instant? MDM servers send a particular type of notification to request managed devices to "Check in" with their MDM server. As part of Apple Push Notification service (APNs), Apple devices constantly poll Apple Push Notification service for **Notifications**. This results in near-instant management of online devices; as such, there is no defined "Check-in" time for MDM commands. ### MDM Daily Check-In **Frequency:** Every 24 hours\ **Mechanism:** Apple Push Notification service/MDM framework\ **Description:** A combination of the following MDM commands automatically initiated by Iru Endpoint: * ProfileList * InstalledApplicationsList * CertificateList * AvailableOSUpdates * DeviceInformation #### Forcing the MDM Daily Check-In From the Iru Web App, select **Perform daily check-in** in the **Device Action Menu**. On Apple devices, this runs the MDM items listed above. Navigate to the **Device Record** in the Iru Web App. Open the **Device Action Menu** (ellipsis). Select **Perform daily check-in**. You can also request a Device Information refresh from the device record: Navigate to the device record in your Iru Endpoint tenant. Select the **Details** tab. For more on the fields shown there, see [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details). Click **Update Now** under Device Information. ### MDM Commands & Profiles **Frequency:** Instant\ **Mechanism:** Apple Push Notification service/MDM framework\ **Description:** Any MDM command, including: * EraseDevice * BlankPush * DeleteUser * SetDeviceName * UnlockUserAccount * InstallApplication * InstallProfile **Able to be Forced?** No ### Installed Application List **Frequency:** Every 24 hours\ **Mechanism:** Apple Push Notification service/MDM framework\ **Description:** An MDM command: * InstalledApplicationList #### Forcing the Installed Application List Daily Check-In Navigate to the device record in your Iru Endpoint tenant. Select the **Apps** tab. Click **Update Now** under the Last updated section. ### Event-Driven Status Reports **Frequency:** Near real-time (within seconds)\ **Mechanism:** Google Pub/Sub notifications via Android Management API Android devices use an event-driven check-in system that's completely reliant on device status reports. When changes occur on the device, the device automatically reports these state changes to Google, who then relays the information to Iru Endpoint via [Pub/Sub notifications](https://developers.google.com/android/management/notifications). This mechanism works similarly to Apple's Declarative Device Management status reports, providing near real-time updates as changes happen. #### Pub/Sub Notification System The Android Management API uses Google Cloud Pub/Sub to deliver device notifications to Iru Endpoint. When something changes on an Android device, Google receives that information and immediately sends it to Iru Endpoint through Pub/Sub. This approach works well because Pub/Sub is designed to handle large volumes of messages reliably. If there's a temporary network issue, Pub/Sub will keep trying to deliver the notification until it reaches Iru Endpoint. Google also batches multiple device events together when they happen close together, which makes the system more efficient. The result is that you get near real-time updates about what's happening on your Android devices - app installations, policy changes, security updates, and other important events all show up in Iru Endpoint within seconds of occurring on the device. #### What Gets Reported Android devices automatically report various state changes including: * Application installations and updates * Device configuration changes * Security posture updates #### Event-Driven Benefits The Android event-driven approach offers several advantages: * **Immediate Response**: Device changes are reported as they happen, providing near real-time visibility * **Efficient Resource Usage**: Only reports actual changes rather than periodic status queries * **Reliable Delivery**: Pub/Sub ensures notifications reach Iru Endpoint even during network interruptions * **State change capture**: Captures all significant device state changes automatically Android check-ins are event-driven and provide near real-time updates through Google's Pub/Sub notification system. This approach ensures immediate visibility into device changes without requiring manual check-in commands. ### Troubleshooting Check-In Issues If devices aren't checking in as expected, see our [Troubleshooting Agent Check-In](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins) guide for platform-specific troubleshooting steps. ### Best Practices Regularly monitor device check-in status to identify issues early and ensure policy compliance. Be aware that different platforms use different check-in mechanisms and frequencies. Force check-ins only when necessary, as they can impact device performance and battery life. Check agent and MDM logs to identify patterns in check-in failures or delays. # Troubleshooting Agent Check Ins Source: https://docs.iru.com/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins Diagnose and resolve Iru Agent check-in failures on macOS and Windows. Troubleshoot network issues, certificate errors, and connectivity problems. This guide applies to Mac computers and Windows devices ### About Agent Check-In Issues macOS and Windows devices enrolled in Iru Endpoint use the Iru Agent for various management tasks. The agent attempts to check in every 15 minutes. If a device is not checking in as expected, the following steps can help restore communication. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works The Iru Agent communicates with Iru Endpoint servers to receive configuration updates, policy changes, and application deployments. When check-ins fail, devices may not receive important updates, leading to compliance issues or outdated configurations. ### Check Internet Connectivity Ensure the device has an active internet connection with access to the domains and ports outlined in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). As a quick troubleshooting step: * Try connecting the device to a different network, such as a mobile hotspot * If check-ins resume, the issue may be with the original network's filtering or firewall configuration ### Platform-Specific Troubleshooting ### Force a Check-In (macOS) #### Self Service * End users can open **Iru Self Service**, go to **Device Info**, and click **Sync** #### Command Line * Run the following command in **Terminal** to force a check-in: ```bash theme={null} sudo iru run -F ``` The output may provide additional details. ### Reinstall the Iru Agent On macOS, you can reinstall the Iru Agent from the Iru web app: In the Iru web app, go to the device record From the Device Action Menu, select **Reinstall Agent** Monitor status from the **Activity** tab. Look for the `InstallEnterpriseApplication` MDM command If the command returns **NotNow** (device is busy): * Ensure the Mac has a user logged in and is plugged into power, then retry. See [Apple's developer documentation](https://developer.apple.com/documentation/devicemanagement/implementing_device_management/handling_notnow_status_responses) ### Restart Considerations * After restart, Iru may wait up to 30 minutes to check in, allowing macOS to finish updates and background tasks ### Agent Status Verification Check agent status: ```bash theme={null} sudo iru library --state ``` ### Force a Check-In (Windows) #### Restart Iru Agent Service * Right-click the **Windows** icon and select **Run** * Type `services.msc` and press **Enter** * Find **Iru Agent** in the services list * Right-click **Iru Agent** and select **Restart** This will force an immediate check-in. #### Command Line * Run the following command in **PowerShell** as Administrator: ```powershell theme={null} dsregcmd /status ``` ### Reinstall the Iru Agent On Windows, you can either push any new app or policy to the device, or re-enroll so the agent can install. ### Restart Considerations * Check-ins generally resume within the 15-minute Agent cycle ### Check Agent Logs Agent logs are located at: ``` %ProgramData%\kandji\agent\logs ``` ### Agent Status Verification Check agent status in: * **Settings** > **Accounts** > **Access work or school** * **Event Viewer** > **Applications and Services Logs** > **Microsoft** > **Windows** > **DeviceManagement-Enterprise-Diagnostics-Provider** ### Restart Restarting the device can resolve a stalled process and allow the Iru Agent to resume normal check-in. ### Re-Enroll If the above steps do not resolve the issue, manually re-enroll the device. Remove the existing MDM enrollment Re-enroll using the correct **Enrollment code** Ensure the correct Blueprint is selected when enrolling a device. If a different Blueprint is selected, the device will enforce that Blueprint's assigned Library items and parameters. The device record will not be duplicated after re-enrollment. Iru Endpoint links the new enrollment with the existing device record. ### Advanced Troubleshooting Review logs for: * Installation errors * Policy failures * Communication issues * Network connectivity problems ### Network Diagnostics Use network diagnostic tools to test connectivity to Iru services Verify firewall rules allow communication with Iru domains Ensure DNS resolution works for Iru domains Verify proxy settings if applicable ### Common Issues and Solutions **Symptoms:** * Device shows as offline in Iru * No recent check-ins in device record * Policies not applying **Solutions:** * Check internet connectivity * Restart the device * Force a manual check-in * Reinstall the agent if necessary **Symptoms:** * Error messages in agent logs * Network connectivity issues * Firewall blocking communication **Solutions:** * Verify network connectivity * Check firewall rules * Test with different network * Review agent logs for specific errors **Symptoms:** * Agent not installed after enrollment * Installation errors in logs * Device not appearing in Iru **Solutions:** * Verify device meets requirements * Check network connectivity during enrollment * Review installation logs * Try manual agent installation ### Best Practices Regularly monitor device check-in status to identify issues early Test network connectivity to Iru services from managed devices Regularly review agent logs for potential issues Document recurring issues and their solutions for future reference # Delay and Enforce OS Updates Source: https://docs.iru.com/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates Configure OS update delays and enforcement deadlines for managed Apple devices in Iru Endpoint. Defer updates and set mandatory installation windows. This guide applies to Apple devices ### About OS Update Delay and Enforcement To maintain a consistent software update schema across your organization, you can defer software updates and choose when they'll automatically be installed. There are two places you'll want to configure this: Software Update profile and Apple Restrictions profile from within your Library. ### How It Works Iru Endpoint provides flexible options for managing OS updates: * **Delay periods** - Configure how long to wait before enforcing updates * **Enforcement policies** - Set automatic or manual enforcement rules * **User notifications** - Keep users informed about pending updates * **Compliance tracking** - Monitor which devices have successfully updated ### Software Update Library Item You can use the Software Update Library Item to manage downloading, installing, and deferring updates. This is a great way to make sure that, at minimum, security updates are being automatically installed on all of your devices. The Software Update Library Item is supported on macOS, iOS 18.0+, iPadOS 18.0+, tvOS 18.4+, and visionOS 26+. ### Create a Software Update Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Configure the Software Update Library Item Give your software update profile a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select your desired settings for **Automatic Updates**. Under **Software Update Deferrals**, in the **iPhone, iPad, Apple TV, Vision only settings** section, check **Defer updates**. Set **Defer for** to the number of days (1–90). Set **Recommended cadence** to **All**, **Oldest**, or **Newest** to specify how software updates are shown to the user. Under **Mac only settings**, select **Defer macOS updates by type** from the dropdown. For each option you enable, set **Defer for** to the number of days (1–90): * **Defer major macOS upgrades**: Delays software upgrades on the device; upgrades appear only after the specified delay following release. * **Defer minor macOS upgrades**: Delays software updates only (not upgrades or Rapid Security Response); updates appear only after the specified delay following release. * **Defer other system updates**: Delays non-operating system updates; they appear only after the specified delay following release. Under **Other**, in **iPhone, iPad, Mac only settings**, set **Beta program enrollment**: * **Not configured**: Do not manage beta enrollment from this Library Item. Use this when [Managed OS](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#enforce-a-specific-version) or [ADE](/en/endpoint/enrollment/apple/configuring-apple-enrollment#require-minimum-os-version) handles beta enrollment and version enforcement. * **Disallow**: Prevent users from enrolling in beta programs from Software Update settings. See [Restrict Access to Beta OS Releases](/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases). * **Offer**: Present one or more beta programs so users can opt in on the device. * **Enforce**: Enroll the device in a selected beta program without requiring a specific beta OS version. To enforce a specific beta *version*, keep this setting as **Not configured** and use Managed OS. **Offer** and **Enforce** are supported on **macOS 15.4+** and **iOS/iPadOS 18.0+**. When you choose **Offer** or **Enforce**, select the **Beta programs** to apply. See [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment) for which option to use. Click **Save** in the bottom right corner. ### Apple Restrictions Library Item The **Defer software updates** section in the **Apple Restrictions Library Item** is deprecated as of iOS 27, iPadOS 27, tvOS 27, and macOS 27. Use the Software Update Library Item instead. Under **OS Updates** in the Apple Restrictions Library Item, the **Defer software updates** option delays user visibility of software updates for a specified number of days (up to 90). iPhone and iPad devices require Supervision. For Mac computers, Iru Endpoint recommends using a Software Update Library Item and deferring updates by specific types. For step-by-step configuration, see the [Configure the Software Update Library Item](#configure-the-software-update-library-item) section above. ### Block Beta & Standard Upgrades The native options for blocking beta updates are also enabled using the **Software Update** Library Item in your Blueprints. Set **Beta program enrollment** to **Disallow**, or see [Restrict Access to Beta OS Releases](/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases). Due to this change, the [App Blocking Library Item](/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item) can't block these upgrades. The only circumstance when the App Blocking Library Item will block the update is when it's downloaded from the Mac App Store. Learn more about [Restricting Access to Beta OS Releases](/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases). The following examples are specific to macOS Sonoma, macOS Sequoia, and macOS Tahoe. For each release, you'll need to update each setting with the relevant info specific to that release. This will only block the installer if it's downloaded from the App Store and won't block the update in Software Update. **Tahoe - Public Release** * **Process name**: Install macOS Tahoe * **Match Type**: Contains * **Path**: /Applications/Install macOS Tahoe.app * **Match Type**: Contains * **Bundle ID**: com.apple.InstallAssistant.macOSTahoe * **Match Type**: Exact **Sequoia - Public Release** * **Process name**: Install macOS Sequoia * **Match Type**: Contains * **Path**: /Applications/Install macOS Sequoia.app * **Match Type**: Contains * **Bundle ID**: com.apple.InstallAssistant.macOSSequoia * **Match Type**: Exact **Sonoma - Public Release** * **Process name**: Install macOS Sonoma * **Match Type**: Contains * **Path**: /Applications/Install macOS Sonoma.app * **Match Type**: Contains * **Bundle ID**: com.apple.InstallAssistant.macOSSonoma * **Match Type**: Exact ### Related Articles Choose ADE, Managed OS, or Software Update for Apple beta enrollment Compare different OS update management strategies Prevent users from installing beta OS releases Configure managed OS updates for Mac computers Configure managed OS updates for iOS, iPadOS, and tvOS devices # How to Generate a Sysdiagnose in macOS Source: https://docs.iru.com/en/endpoint/devices/device-configurations/apple/how-to-generate-a-sysdiagnose-in-macos Generate a sysdiagnose report on Mac computers for Apple Support troubleshooting. Collect system logs, crash reports, and diagnostic data from macOS. This guide applies to Mac computers ### About Sysdiagnose A sysdiagnose in macOS collects diagnostic data for troubleshooting system issues. It gathers logs, crash reports, and system state from the Mac. You can generate a sysdiagnose in a few ways, depending on the user's access level. ### How It Works Sysdiagnose collects system information used to diagnose issues: performance data, logs, hardware information, and system state. * [Generating a Sysdiagnose Using a Keyboard Shortcut](#generating-a-sysdiagnose-using-a-keyboard-shortcut) * [Generating a Sysdiagnose Using the Command Line](#generating-a-sysdiagnose-using-the-command-line) * [Generating a Sysdiagnose Using Activity Monitor](#generating-a-sysdiagnose-using-activity-monitor) ### What Sysdiagnose Collects When you run sysdiagnose, it gathers an extensive array of information, including: * **System-wide performance profiles** - Captures the state of running processes * **Filesystem activity logs** - Reports on system calls and page faults related to filesystem usage * **Process information** - Provides detailed data on running processes and memory usage * **Kernel memory usage** - Includes data on kernel zones and loaded kernel extensions * **System and crash logs** - Collects all relevant logs to help diagnose issues * **Hardware and software configuration** - Similar to the System Information app, but more detailed * **Network and power management data** - Details on current network status and power settings ### Generating a Sysdiagnose Using a Keyboard Shortcut Click the **Finder icon** in the Dock to ensure that Finder is in the foreground. All at once, press **Command + Option + Shift + Control + Period (.)** on the keyboard. After a few moments, a Finder window should appear with a tar.gz file shown. If the sysdiagnose was requested by Iru Endpoint Support, please zip it and provide the entire bundle. ### Generating a Sysdiagnose Using the Command Line This method requires administrator privileges. Launch Terminal.app and enter the following command: ``` sudo sysdiagnose -f ~/Desktop/ ``` Wait a few moments for a file ending in .tar.gz to appear on the logged-in user's Desktop. If you logged into Terminal with a different user than is logged into the Mac, the file will be on the Terminal user's Desktop. If the sysdiagnose was requested by Iru Endpoint Support, please zip it and provide the entire bundle. ### Generating a Sysdiagnose Using Activity Monitor This method requires administrator privileges. Open the Activity Monitor app on your Mac. Click the **ellipsis** at the top of the Activity Monitor window. Select **System Diagnostics...** Activity Monitor interface showing the ellipsis menu with System Diagnostics option for generating sysdiagnose reports Read through and accept the privacy agreement. Wait for the progress bar to complete. Once done, a Finder window should appear with a tar.gz file shown. If the sysdiagnose was requested by Iru Endpoint Support, please zip it and provide the entire bundle. # OS Update Strategies: OS Deferral Restriction and Managed OS Source: https://docs.iru.com/en/endpoint/devices/device-configurations/apple/os-update-strategies-os-deferral-restriction-and-managed-os Compare OS update strategies in Iru Endpoint including deferral restrictions and Managed OS. Choose the right approach for your Apple device fleet. This guide applies to Apple devices ### About OS Update Strategies Iru Endpoint manages operating system (OS) updates on supervised Apple devices with software update deferral and Managed OS. You can keep devices secure and compliant while minimizing disruptions. ### How It Works Iru Endpoint provides three main strategies for managing OS updates: * **OS Deferral** - Delay updates for a specified period * **OS Restriction** - Block certain updates entirely * **Managed OS** - Automatically manage and enforce updates Think of these features as working together: * **Managed OS** - Sets the minimum OS version your devices should be running. * **Software Update Deferral** - Sets the maximum OS version offered to users. ### Understanding Software Update Deferral Software update deferral gives you control over which OS updates are offered to users when they update their devices manually or through automatic updates. Configure deferral using the **Software Update Library Item** (see [Delay and Enforce OS Updates](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates) for step-by-step configuration). By setting a deferral period (between 1 and 90 days), you prevent users from immediately installing the latest OS releases. This "ceiling" allows you to test new OS versions in your environment before they're widely deployed, ensuring compatibility and stability. Users will only see updates that fall within your defined deferral policy. The **Defer software updates** option in the Apple Restrictions Library Item is deprecated as of iOS 27, iPadOS 27, tvOS 27, and macOS 27. Use the Software Update Library Item instead. **Example:** If you set a 30-day deferral, users won't see an update until 30 days after its release. Learn about the importance of testing OS releases in our blog post: [How and Why You Should Be Testing Apple's Next Operating Systems Now](https://www.kandji.io/blog/testing-prerelease-operating-systems-apple) ### The Role of Managed OS While software update deferral relies on users to update their devices, Managed OS ensures compliance by enforcing a minimum OS version. Managed OS proactively monitors your fleet, identifies devices running outdated software, caches updates locally, prompts users to update, and can even automatically execute the update process. This acts as a "floor," guaranteeing that all devices meet your specified OS requirements. ### Combining Software Update Deferral and Managed OS Let's say you implement the following strategy: * **Software Update Deferral:** Set to 30 days. This gives you a one-month window to test new Apple releases. * **Managed OS:** Configured to automatically apply new updates three months (90 days) after Apple releases them. In this scenario, your OS update "ceiling" is 30 days, and your "floor" is 90 days. * Users can update their devices independently, knowing they're getting vetted releases. * You have a month to validate and approve OS updates for production. * If users neglect updates for more than 90 days, Managed OS automatically brings them into compliance. This strategy balances user autonomy with organizational security, providing a secure and productive environment. Users benefit from compliant devices without impacting their workflow, while administrators gain peace of mind knowing the organization's needs are met. ### Understanding Software Update Declarations and MDM Software update declarations can coexist with traditional MDM commands and profiles. Updates enforced by declarations always take precedence. Account for that when you design your OS update strategy. ### Important Considerations When Using Managed OS When using Managed OS for macOS, iOS, iPadOS, or tvOS, be aware that Software Update Library Item deferrals do not block updates once Managed OS has sent its target-version declaration. Managed OS overrides those deferrals for the update it is enforcing. If you use **Rolling enforcement** with optional **Delay enforcement by**, you can delay when that declaration is sent (up to 90 days) without changing the enforcement date. Pair **Delay enforcement by** with a matching Software Update Library Item deferral if you also want to hide the new OS version from users for that period. If **Delay enforcement by** is shorter than the Software Update deferral, Managed OS still overrides the deferral once its declaration is sent. For details, see [Rolling enforcement](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#rolling-enforcement) in **Understanding Managed OS for Apple Platforms**. ### Related Articles Configure OS update delays and enforcement policies Prevent users from installing beta OS releases Configure managed OS updates for iOS, iPadOS, and tvOS devices Configure managed OS updates for Mac computers # Restrict Access to Beta OS Releases Source: https://docs.iru.com/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases Block users from installing beta OS releases on managed Apple devices using Iru Endpoint. Restrict access to macOS, iOS, and iPadOS beta programs. This guide applies to Apple devices ### About Beta OS Release Restriction Apple offers beta software programs such as [AppleSeed for IT](https://beta.apple.com/for-it) and the Apple Beta Software Program. Users with an eligible Apple ID can enroll devices running macOS, iOS, iPadOS, or visionOS. Once enrolled, the Software Update section in Settings (or Software Update in System Settings on Mac) shows the option to download and install beta OS versions. Restricting access to beta releases helps keep devices on stable, supported versions. To **Offer** or **Enforce** beta program enrollment instead of blocking it, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment). ### Disallow Beta Installation **Beta program enrollment** in the Software Update Library Item applies to iPhone and iPad on **iOS/iPadOS 18.0+**, and to Mac. Set it to **Disallow** to block users from enrolling in beta programs from Software Update settings. **Offer** and **Enforce** require **macOS 15.4+** and **iOS/iPadOS 18.0+**. You can use the Software Update Library Item to disallow beta program enrollment. The steps below are limited to the beta-related settings. For the full Software Update flow (deferrals, automatic updates, and more), see [Delay and Enforce OS Updates](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates). ### Add a Software Update Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your software update profile a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Under **Other**, in **iPhone, iPad, Mac only settings**, set **Beta program enrollment** to **Disallow**. This prevents users from enrolling in beta programs from Software Update settings. Click **Save** in the bottom right corner. ### Add an Apple Restrictions Library Item The Apple Restrictions Library Item applies to iPhone and iPad running iOS or iPadOS below 18.0, and to Vision (visionOS). All devices must be supervised. Use the Apple Restrictions Library Item when you need to prevent beta enrollment on devices where the Software Update option is not available. The Apple Restrictions Library Item disables manual installation of configuration profiles and certificates, so users cannot install the profile required for beta enrollment. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Apple Restrictions Library Item a **Name**. In the **Install on** field, select iPhone, iPad, and Vision as needed for your environment. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Filter the restrictions options by using the search term **Profiles**. Check the box for **Disallow manual installation of configuration profiles and certificates**. Click **Save**. ### Block Beta & Standard Upgrades For more information about blocking the beta installer app and standard upgrades (e.g. with the App Blocking Library Item), see the Block Beta & Standard Upgrades section of [Delay and Enforce OS Updates](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates). ### Related Articles Test Apple betas with Iru Endpoint and request AppleCare enhanced log collection Configure OS update delays and enforcement policies Compare different OS update management strategies Configure device restrictions, privacy, and content settings Configure managed OS updates for Mac computers Configure managed OS updates for iOS, iPadOS, and tvOS devices # Testing Apple Beta Releases Source: https://docs.iru.com/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases Enroll Apple devices in beta OS programs with Iru Endpoint using ADE, Managed OS, or the Software Update Library Item, and request AppleCare log collection. This guide applies to Apple devices We encourage you to try Apple beta OS releases and share what you find. Beta operating systems aren’t supported through our normal support channels (such as live chat), so please send any beta‑related feedback to [apple-beta-feedback@iru.com](mailto:apple-beta-feedback@iru.com) for direct review by our R\&D team. ### About Testing Apple Beta Releases Apple beta programs such as [AppleSeed for IT](https://beta.apple.com/for-it) and the Apple Beta Software Program let you evaluate upcoming OS releases before they are publicly available. Organizations often enroll a limited set of devices so IT can validate apps, configurations, and workflows against pre-release builds. Iru Endpoint supports three ways to manage Apple beta program enrollments and version enforcement. Use the option that fits your goal: enrollment during Setup Assistant, a required beta build after enrollment, or an opt-in experience for users. For Managed OS enforcement details, see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms). To keep devices on stable releases and block beta enrollment, see [Restrict Access to Beta OS Releases](/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases). When you are actively testing betas, use [apple-beta-feedback@iru.com](mailto:apple-beta-feedback@iru.com) for product feedback related to Iru Endpoint on beta OS releases. ### Ways to Manage Apple Beta Program Enrollment #### At enrollment, using the ADE Library Item Use **Require minimum OS version** in the Automated Device Enrollment Library Item to enforce a beta enrollment and an OS upgrade or beta update *before* the device enrolls into Iru Endpoint. This is helpful for testing enrollment-time configurations on new OS releases. For beta targets, set **Custom**, select **This is a beta version**, and choose a **Seed Token**. Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) during Setup Assistant. For steps, see [Require Minimum OS Version](/en/endpoint/enrollment/apple/configuring-apple-enrollment#require-minimum-os-version) in **Configuring Apple Enrollment**. #### Managed OS Use Managed OS to enforce a beta program enrollment and a specific beta release together after enrollment. Enrollment and version enforcement stay in one Library Item. Managed OS applies **Software Update Settings**, then **Software Update Enforcement**, for the Seed Token and build you configure. For behavior and configuration, see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#enforce-a-specific-version), [Configure Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos#enforce-a-specific-version), and [Configure Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos). #### Software Update Library Item Use the Software Update Library Item to test the end user experience of updating or upgrading manually, or to offer one or more beta program enrollments for user opt-in, without requiring a specific beta version at the same time. Under **Other**, in **iPhone, iPad, Mac only settings**, set **Beta program enrollment** to one of the following: * **Not configured**: Do not manage beta enrollment from this Library Item. Use this when Managed OS or ADE handles beta enrollment and version enforcement. * **Disallow**: Prevent users from enrolling in beta programs from Software Update settings. See [Restrict Access to Beta OS Releases](/en/endpoint/devices/device-configurations/apple/restrict-access-to-beta-os-releases). * **Offer**: Present one or more selected beta programs so users can opt in on the device. * **Enforce**: Enroll the device in a selected beta program without requiring a specific beta OS version. To enforce a specific beta *version*, keep **Beta program enrollment** as **Not configured** and use [Managed OS](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#enforce-a-specific-version) instead. **Offer** and **Enforce** are supported on **macOS 15.4+** and **iOS/iPadOS 18.0+**. When you choose **Offer** or **Enforce**, select the **Beta programs** to apply (for example, Seed Tokens synced from Apple). For full Software Update configuration, including deferrals and automatic updates, see [Delay and Enforce OS Updates](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item). Beta seed builds are exempt from Software Update deferral on devices already enrolled in an Apple beta software program. Deferral periods also do not apply to updates deployed by MDM. ### Request AppleCare Enhanced Log Collection (iOS and iPadOS) AppleCare may ask you to run enhanced log collection on a device that is testing an Apple beta. On supervised iPhone and iPad devices running **iOS 27+** or **iPadOS 27+** beta releases, you can trigger that collection from the device record in Iru Endpoint after AppleCare provides a token. #### Requirements * Supervised iPhone or iPad enrolled in Iru Endpoint * Device currently running an **iOS 27+** or **iPadOS 27+** beta release * AppleCare token provided for the enhanced log collection request #### Trigger Enhanced Log Collection Go to the **Devices** page and select the iPhone or iPad that is testing an Apple beta. Open the **Device Action Menu** (ellipsis) in the upper right corner of the device record, then select **Trigger enhanced log collection**. In the **Trigger enhanced log collection** dialog, enter the **AppleCare token** provided by AppleCare, then click **Trigger enhanced log collection**. After you submit the request, the device record shows an **Enhanced log collection status** banner (for example **Requested**) while collection proceeds. ### Related Articles Configure the Software Update Library Item, including beta program enrollment Prevent users from enrolling devices in Apple beta programs Enforce OS versions, including Apple beta builds with a Seed Token Enforce a beta OS at ADE before enrollment completes When and how to work with AppleCare Enterprise Support # Configure Auto Advance for Apple TV and Mac Source: https://docs.iru.com/en/endpoint/devices/device-features/apple/configure-auto-advance-for-apple-tv-and-mac Configure Auto Advance for Apple TV and Mac in Iru Endpoint. Automatically skip Setup Assistant screens during enrollment for hands-free deployment. This guide applies to Mac computers and Apple TV ### About Auto Advance for Apple TV and Mac The Auto Advance option in the Automated Device Enrollment Library Item lets an Apple TV or Mac skip all Setup Assistant steps when it is connected to Ethernet during Setup Assistant. ### How It Works When Auto Advance is selected in the Automated Device Enrollment Library Item and the device is connected to Ethernet during Setup Assistant, the device advances through every Setup Assistant screen with no user input. ### Prerequisites * **Automated Device Enrollment**: Ensure you have an Automated Device Enrollment Library Item configured * **Ethernet Connection**: Devices must be connected to Ethernet during Setup Assistant * **Apple TV or Mac**: This feature is specifically designed for Apple TV and Mac devices * **Network Connectivity**: Ensure devices have proper network connectivity for enrollment ### Configuring Auto Advance Follow the instructions in the [Automated Device Enrollment support article](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) to create or modify an Automated Device Enrollment Library Item. For Mac devices, for the "Skip screens during setup..." option, choose to "**Automatically advance through all Setup Assistant screens**". For Apple TV devices, for the "Skip screens during setup..." option, choose to "**Automatically advance through all Setup Assistant screens**". # Configure Shared iPad Source: https://docs.iru.com/en/endpoint/devices/device-features/apple/configure-shared-ipad Set up Shared iPad in Iru Endpoint for multi-user environments. Configure Managed Apple ID login, guest sessions, and storage quotas for each user. This guide applies to iPadOS devices **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Shared iPad Shared iPad allows for a multi-user experience for iPad. This feature allows you to easily share and continue your work on multiple devices (such as in a healthcare setting where a device may be shared from one shift to the next). ### How It Works Each user signs in with their own Managed Apple ID from Apple Business or Apple School Manager, allowing them a personalized session with all of their data at their fingertips. Shared iPad creates individual user spaces that are securely isolated, enabling multiple users to access the same device while maintaining their personal data and settings. [Click here](https://support.apple.com/guide/deployment/prepare-shared-ipad-dep6fa9dd532/web) to learn more about preparing your devices for Shared iPad. ### Prerequisites * **iPad Devices**: Ensure you have compatible iPad devices for Shared iPad configuration * **Managed Apple IDs**: Users must have Managed Apple IDs from Apple Business or Apple School Manager * **Device Erasure**: iPad devices must be erased and re-enrolled to be configured for Shared iPad * **Apple Business or Apple School Manager**: Ensure your organization has access to the correct portal * **Network Connectivity**: Devices must have internet connectivity for user authentication and data synchronization ### Shared iPad Considerations * **Self Service Compatibility**: The Self Service app is not compatible with Shared iPad * **Device Requirements**: iPad devices must be erased and re-enrolled to be configured for Shared iPad * **User Management**: Plan for user account management and data storage requirements * **Session Management**: Understand guest session limitations and timeout configurations * **Storage Planning**: Consider storage allocation for multiple user profiles ### Configuring Shared iPad Options These settings appear on the **iPad** tab of the **Automated Device Enrollment** Library Item in the **Library** after you enable **Shared iPad**. The screenshot below shows the Shared iPad block in context; use it alongside the steps that follow. Automated Device Enrollment iPad Shared iPad options Specify the **User configuration** for Shared iPad. Shared iPad has multiple user configuration options available, each with its own advantages. [Click here for additional details](https://support.apple.com/guide/deployment/prepare-shared-ipad-dep6fa9dd532/web#depc6982766b) on user space considerations when deploying Shared iPad. **Maximum resident users** allow you to specify the maximum number of users stored locally on a Shared iPad. **User quota size** can be used to specify the maximum storage allocation for each user on Shared iPad. Apple recommends setting the storage allocation as low as possible to enable the maximum number of users to be stored locally. **Only allow guest user sessions** on Shared iPad. Users will not be able to sign in with a Managed Apple ID. When this user configuration option is selected, **Guest session timeout** will be the only additional option available. ### Additional Configuration Options **Guest session timeout**: Specify the number of minutes of inactivity at which a guest user session will be automatically logged out. **Passcode lock grace period**: Specify the number of minutes after locking the screen before users are required to re-enter their Shared iPad passcode. Shared iPad does not support the passcode profile, which is why the Passcode lock grace period exists within the Shared iPad configuration options. Not available when the **Only allow guest user sessions** user configuration is selected. **Automatic user logout**: Specify the number of minutes of inactivity after which a signed-in user is automatically logged out. Not available when the **Only allow guest user sessions** user configuration is selected. ### Additional Questions About Shared iPad If you have questions regarding your particular use case and how your Shared iPad deployment should be configured for use with Iru Endpoint, please reach out to [Iru Endpoint Support](/en/iru/iru-support/access-to-iru-support). ### Considerations * **User Experience**: Plan for user onboarding and training on Shared iPad functionality * **Data Management**: Understand how user data is stored and managed across sessions * **Security**: Configure appropriate security settings for multi-user environments * **Storage Planning**: Allocate sufficient storage for multiple user profiles * **Session Management**: Configure appropriate timeout settings for your use case * **Guest Access**: Plan for guest user access and session limitations * **Device Lifecycle**: Consider device management and user profile cleanup * **Network Requirements**: Ensure reliable network connectivity for user authentication * **Apple Business or Apple School Manager**: Keep portal configuration (Managed Apple IDs, assignments, and related settings) up to date * **User Training**: Provide training on Shared iPad features and limitations * **Backup Strategy**: Plan for data backup and recovery procedures * **Support**: Contact Iru Endpoint Support for assistance with complex Shared iPad scenarios * **Testing**: Test Shared iPad configuration in a controlled environment * **Documentation**: Keep records of Shared iPad configuration and user management procedures * **Monitoring**: Regularly monitor Shared iPad usage and performance # Assigning and Unassigning Users to Devices Source: https://docs.iru.com/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices Assign and unassign users to devices in Iru Endpoint for user-based management. Link directory identities to device records for targeted policies. This guide applies to all device platforms ### About User Assignment Once you set up a Google Workspace, Entra ID or SCIM integration, users will automatically be imported into Iru Endpoint every 4 hours. Once imported, users can be assigned to devices, allowing you to view all devices assigned to a specific user. You can find more information about syncing users from Google Workspace or Entra ID [here](/en/endpoint/integrations/directory-services/user-directory-integration). ### How It Works User assignment allows you to associate specific users with devices, enabling better device management and tracking. When users are assigned to devices, you can view all devices for a specific user and apply user-based policies and configurations. ### Prerequisites * Before you can assign users, you must [configure a directory integration](/en/endpoint/integrations/scim/scim-directory-integration) to import users for assignment. ### Assigning a User to a Device Click **Devices** in the navigation menu. Click the device you wish to assign to a user. Click on **Edit device details**. Click on **Edit user**. **Type the name** you wish to assign to this device and click the **Assign** button. The device will now display the user's name inside the user field. ### Viewing Devices Assigned to a User Click **Users** in the navigation menu. Click on the **User** in the list to view devices assigned to them. For more detailed information about taking action on devices, see the [Using Iru AI](/en/iru/iru-ai/using-iru-ai) section of our Knowledge Base. ### Remove an Assigned User from a Device Log in to Iru Endpoint and click **Devices** in the navigation menu. **Click the device** for which you wish to remove the user assignment. Click on **Edit device details**. Click on **Edit user**. Click on the **Unassign Device**. ### Considerations * Assigning or unassigning users to devices may result in Library Item assignment changes if you're leveraging user group-based [conditional logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). * Assigning users to devices may result in changes to profiles on the device if you're leveraging [Global Variables](/en/endpoint/library/library-items-profiles/global-variables) in any profile fields. # Deleting a Device Record and Uninstalling Iru Endpoint Source: https://docs.iru.com/en/endpoint/devices/device-record-management/deleting-a-device-record-and-uninstalling-iru-endpoint Delete device records and uninstall Iru Endpoint from managed devices. Remove MDM profiles, the Iru Agent, and all management configurations. This guide applies to all device platforms ### About Device Record Deletion Deleting a device record from Iru Endpoint lets admins remove unwanted or unused devices from the Iru Endpoint Web App. If the device is online, the Iru Agent and MDM Profile will be removed as applicable. The device must be powered on and have internet access for the uninstall to complete. Deleting the device record will remove all history of that device stored in Iru Endpoint and can't be recovered. This will not erase the device. ### How It Works When you delete a device record, Iru Endpoint removes all management components from the device and permanently deletes all associated data from the platform. This process is irreversible and requires re-enrollment to restore management. Device deletion is recorded on the [Activity Page](/en/endpoint/devices/activity-page). For Android devices, deleting the device record causes complete device unenrollment. The work profile is removed along with any corporate resources provisioned by Iru Endpoint. At that point, the device is considered completely unmanaged and "personally owned." ### Device Record Removal Considerations * All related device record information is destroyed when a device record is deleted. * The following device secrets will be **permanently removed** from Iru Endpoint: * Device lock PIN code * Recovery password * FileVault Recovery Key * Activation Lock Bypass Code * All Parameter history will be lost. * The device will need to be re-enrolled into Iru Endpoint to regain management. * If the device is Automated Device Enrollment-eligible, it will automatically re-enroll with Iru Endpoint during Setup Assistant. * If the device is not Automated Device Enrollment-eligible, it must be manually re-enrolled using your Add Devices link. ### Removing a Device from Your Iru Endpoint Tenant **This action cannot be undone.** If you no longer wish to manage a device, you can uninstall Iru Endpoint from the device and remove its record from your Iru Endpoint account with one step. Here's how: Log in to your Iru Endpoint account and open **Devices**. Click on the device you wish to remove. Click the **Device Action Menu** at the top right of the device record. Click **Delete Device Record**. In the confirmation pop-up window, type **DELETE** in the text field. Click **Delete Device Record**. When the device record is deleted, the device will be notified during its next check-in that it's no longer enrolled and will automatically remove management components. The specific timing and process varies by platform: The [Iru Agent](/en/endpoint/agent/iru-agent-and-mdm) will be notified on the next check-in (every 15 minutes) that the computer is no longer enrolled and uninstall itself automatically after removing installed profiles. **Items removed:** * Iru Agent * Profiles installed via MDM * Apps deployed using Apps and Books The Iru Agent will be notified during its next check-in (every 15 minutes) and will automatically remove management components. **Items removed:** * Iru Agent * Self Service app * Profiles installed via MDM * All policies delivered through the Windows MDM channel (Wi-Fi, Windows Firewall, BitLocker) The device will be notified via MDM push notification and will automatically remove management components. **Items removed:** * Profiles installed via MDM * Apps deployed using Apps and Books The device will be notified via Google's notification system and will automatically remove the work profile and all corporate resources. **Items removed:** * Work profile and all corporate resources * Apps deployed using Apps and Books * All policies and configurations ### Removing Multiple Devices from Your Iru Endpoint Tenant Log into your Iru Endpoint account and open **Devices**. Use the radio buttons on the left to select the devices you wish to remove. Use the **Bulk Action Menu** at the top right of the devices list. Click **Delete devices**. ### Platform-Specific Considerations **Best Practices for Reassigning Mac Computers** In many organizations, there are instances where a computer is returned by one user and needs to be prepared for a new user. In such cases, it's recommended to erase the computer and reinstall macOS completely. This process guarantees a fresh and clean setup for the new user, eliminating any concerns about residual data on the computer. If the computer is enrolled in Iru Endpoint, you can [follow these steps to erase the device](/en/endpoint/devices/device-actions/erase-a-device). **What Happens When I Erase a Mac Remotely?** macOS's behavior varies based on the version and hardware support. Specifically, one of two actions will be triggered: Erase All Content and Settings or Obliteration. The remote wipe behavior experienced is unique to each combination of hardware and macOS version, is subject to multiple conditions. These conditions are detailed in our [Lock Device and Erase Device](/en/endpoint/devices/device-actions/lock-a-device) support article. **Can I Erase a Mac Locally?** There are a few options if you need to erase the computer locally. Apple has a support article on how to [Erase your Mac and reset it to factory settings](https://support.apple.com/en-us/HT212749). That article shows how to Erase all Content and Settings on Apple Silicon computers and Intel devices with the Apple T2 Security Chip so that macOS doesn't have to be reinstalled once the device is erased. It also has additional article links that cover how to erase the device when that option isn't available. If macOS needs to be reinstalled, you can use Apple's support article on [How to reinstall macOS from macOS Recovery](https://support.apple.com/en-us/HT204904). **Windows Device Reassignment** For Windows devices, you can use [Erase a Windows Device](/en/endpoint/devices/device-actions/erase-a-windows-device) to prepare devices for new users. This will remove all user data and reset the device to a clean state. **Apple Device Reassignment** For iOS, iPadOS, tvOS, and visionOS devices, you can use the [erase device](/en/endpoint/devices/device-actions/erase-a-device) functionality to prepare devices for new users. This will remove all user data and reset the device to a clean state. **Android Device Reassignment** For Android devices, you can use [Erase an Android Device](/en/endpoint/devices/device-actions/erase-an-android-device) to prepare devices for new users. This will remove all user data and reset the device to a clean state. # Device Record Details Source: https://docs.iru.com/en/endpoint/devices/device-record-management/device-record-details Review inventory and status fields on the Details tab of a device record in Iru Endpoint for macOS, iOS, iPadOS, visionOS, Windows, and Android. This guide applies to all device platforms ### About Device Record Details The **Details** tab on a device record shows inventory and status information collected from the device. Use it to confirm hardware and OS identity, network addresses, management state, and platform-specific security settings without leaving the device record. Many of the same attributes are also available as filters and columns in [Device Views](/en/endpoint/devices/device-views-overview). The Details tab is the place to review the full set of fields for a single device. ### How It Works After you open a device from **Devices**, the device record includes tabs such as **Status**, **Activity**, and **Details**. The **Details** tab organizes fields into sections that vary by platform. Values refresh when the device checks in. On Apple devices, some Device Information sections also include **Update Now** so you can request a fresh MDM inventory sync. For more on check-in behavior, see [Device Check-in](/en/endpoint/devices/device-check-in/device-check-in). Not every field appears on every device. Availability depends on the platform, hardware capabilities (for example, cellular), enrollment type, and whether the Iru Agent or MDM profile is present. ### View the Details Tab Navigate to **Devices** in the Iru Endpoint web app. Select a device to open its device record. You can use [Device Views](/en/endpoint/devices/device-views-overview) filters to find the device first. Select the **Details** tab. ### What's on the Details Tab Mac Details include general identity and enrollment information, MDM and agent status, hardware and network inventory, storage volumes, local users, profiles, and security settings such as Activation Lock, Recovery Lock, and FileVault. * **Device Name** - Name of the Mac * **Device ID** - Unique identifier for the device in Iru Endpoint * **Last Enrollment** - Most recent enrollment date * **First Enrollment** - First enrollment date * **Model** - Device model * **OS Version** - macOS version * **System Version** - Full system version string * **Boot Volume** - Boot volume name * **Time Since Boot** - Time since the last restart * **Last User** - Most recently logged-in user * **Beta enrollment** - Beta enrollment status * **MDM Enabled** - Whether MDM is enabled * **Install Date** - When the MDM profile was installed * **Last Check-In** - Most recent MDM check-in * **MDM-enabled users** - Users with MDM enabled * **Supervised** - Whether the Mac is supervised * **Remote Desktop Status** - Remote Desktop status * **Bootstrap Token Escrowed** - Whether a bootstrap token is escrowed * **Automated Device Enrollment Eligible** - Whether the device is eligible for Automated Device Enrollment * **Automated Device Enrolled** - Whether the device enrolled through Automated Device Enrollment * **Agent Installed** - Whether the Iru Agent is installed * **Install Date** - When the agent was installed * **Last Check-in** - Most recent agent check-in * **Agent Version** - Installed agent version * **Model Name** - Human-readable model name * **Model Identifier** - Specific model identifier * **Processor Name** - Processor name * **Processor Speed** - Processor speed * **Number of Processors** - Number of processors * **Total Number of Cores** - Total number of CPU cores * **Memory** - Installed memory * **Serial Number** - Hardware serial number * **Hardware UUID** - Hardware UUID * **Battery Health** - Current battery health status * **Local Hostname** - Local network hostname * **MAC Address** - Network interface MAC address * **Local IP address** - Local IP address of the device * **Public IP Address** - Public IP address of the device For each volume: * **Format** - Volume format * **Percent Used** - Percentage of storage used * **Identifier** - Volume identifier * **Capacity** - Total volume capacity * **Available** - Free space on the volume * **Encrypted** - Whether the volume is encrypted Local user accounts, including regular and system users. For each user: * **Account name** - Local account name * **UID** - User ID * **Path** - Home directory path * **Admin** - Whether the account has administrator privileges For related actions, see [Delete a User Account](/en/endpoint/devices/device-actions/delete-a-user-account). * Installed configuration profiles, including the MDM profile * **Bypass Code Expired** - Whether the bypass code has expired * **User-based Activation Lock Status** - User-based Activation Lock status * **Device-based Activation Lock Status** - Device-based Activation Lock status * **User-based Activation Lock Allowed** - Whether user-based Activation Lock is allowed * **Activation Lock Supported** - Whether Activation Lock is supported * **Recovery Lock** - Recovery Lock status * **Firmware Password** - Firmware password status, including pending restart or rotation when applicable * **FileVault Enabled** - Whether FileVault is enabled * **Recovery key type** - Type of recovery key in use * **Personal recovery key escrowed** - Whether the personal recovery key is escrowed * **Key rotation or regeneration** - Scheduled rotation or regeneration when configured iPhone, iPad, and Apple Vision Pro Details center on **Device Information**, plus enrollment, profiles, certificates, security, and Activation Lock. Cellular fields appear when the device supports cellular service. Some Device Information sections include an updated timestamp and an **Update Now** control. See [Device Check-in](/en/endpoint/devices/device-check-in/device-check-in). * **Device Name** - Name of the device * **OS Version** - Operating system version * **OS Build** - Operating system build * **Model Name** - Human-readable model name * **Model Identifier** - Specific model identifier * **Model Number** - Model number * **Serial Number** - Hardware serial number * **UDID** - Unique device identifier * **EAS Device Identifier** - Exchange ActiveSync device identifier * **TimeZone** - Device time zone * **Beta enrollment** - Beta enrollment status * **Battery Level** - Current battery level * **Battery Health** - Current battery health status * **Available Device Capacity** - Free storage capacity * **Device Capacity** - Total storage capacity * **Wi-Fi Address** - Wi-Fi MAC address * **Bluetooth Address** - Bluetooth MAC address * **Cellular Technology** - Cellular connectivity technology * **Modem Firmware** - Modem firmware version when available * **Supervised** - Whether the device is supervised * **Awaiting Configuration** - Whether the device is awaiting configuration. When a device is held in Setup Assistant, see [Manually release devices held in Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#manually-release-devices-held-in-setup-assistant). * **MDM Lost Mode Enabled** - Whether MDM Lost Mode is enabled * **PIN Required For Device Lock** - Whether a PIN is required to lock the device * **PIN Required For Erase Device** - Whether a PIN is required to erase the device Available on cellular-capable devices: * **Phone Number** - Phone number * **IMEI** - International Mobile Equipment Identity * **ICCID** - Integrated Circuit Card Identifier * **MEID** - Mobile Equipment Identifier * **Personal Hotspot Enabled** - Whether personal hotspot is enabled * **Roaming Enabled** - Whether roaming is enabled * **Data Roaming Enabled** - Whether data roaming is enabled * **Voice Roaming Enabled** - Whether voice roaming is enabled * **Current Carrier Network** - Current carrier network * **Carrier Settings Version** - Carrier settings version * **Current MCC** / **Current MNC** - Mobile country and network codes * **Subscriber** and **SIM** carrier network details * **Service Subscriptions** - Per-SIM or eSIM slot subscription details * **Network Tethered** - Whether the device is network tethered * **App Analytics Enabled** - Whether app analytics are enabled * **Diagnostic Submission Enabled** - Whether diagnostic submission is enabled * **iCloud Backup Enabled** - Whether iCloud Backup is enabled * **Last iCloud Backup Date** - Date of the last iCloud backup * **Location Services Enabled** - Whether Location Services are enabled * **Do Not Disturb In Effect** - Whether Do Not Disturb is in effect * **iTunes Store Account Active** - Whether an iTunes Store account is active * **Public IP Address** - Public IP address of the device * **Automated Device Enrollment Eligible** - Whether the device is eligible for Automated Device Enrollment * **Automated Device Enrolled** - Whether the device enrolled through Automated Device Enrollment * Installed configuration profiles, including the MDM profile * **Common Name** - Certificate common name * **Identity** - Whether the certificate is an identity certificate * **Hardware Encryption Capabilities** - Hardware encryption capabilities * **Passcode Present** - Whether a passcode is set * **Passcode Compliant** - Whether the passcode is compliant * **Passcode Compliant With Installed Profiles** - Whether the passcode complies with installed profiles * **Passcode Lock Grace Period (Enforced)** - Enforced passcode lock grace period * **Passcode Lock Grace Period (User-Defined)** - User-defined passcode lock grace period * **Bypass Code Expired** - Whether the bypass code has expired * **User-based Activation Lock Status** - User-based Activation Lock status * **Device-based Activation Lock Status** - Device-based Activation Lock status * **User-based Activation Lock Allowed** - Whether user-based Activation Lock is allowed * **Activation Lock Supported** - Whether Activation Lock is supported Windows Details include general OS and device identity, MDM and agent status, hardware overview, and network information reported for the device. * **Device type** - Device type * **Model number or name** - Model number or name * **Original Equipment Manufacturer (OEM) name** - Device manufacturer * **Device name** - Name of the device * **Device ID** - Unique identifier for the device in Iru Endpoint * **Current language** - Current language setting * **Firmware version** - Firmware version * **Hardware version** - Hardware version * **Full software version** - Full software version string * **OS name** - Operating system name * **OS version** - Operating system version * **OS edition** - Operating system edition * **OS build** - Operating system build * **Update Build Revision (UBR)** - Update Build Revision * **Device identifier (Windows)** - Windows device identifier * **Current management client revision of the device** - Management client revision * **Agent installed** - Whether the Iru Agent is installed * **Agent installed at** - When the agent was installed * **Agent version** - Installed agent version * **Last check-in** - Most recent agent check-in * **Commercialization operator** - Commercialization operator * **Free storage space** - Free storage space * **Processor architecture** - Processor architecture * **Radio software version** - Radio software version * **SMBIOS serial number** - SMBIOS serial number * **BIOS version** - BIOS version * **Total RAM** - Total installed memory * **Total storage capacity** - Total storage capacity * **DNS computer name** - DNS computer name * **Integrated Circuit Card Identifier (ICCID) of the first adapter** - ICCID of the first adapter when present * **VoLTE service setting** - VoLTE service setting * **Wi-Fi DNS suffix** - Wi-Fi DNS suffix * **Wi-Fi IPv4 address** - Wi-Fi IPv4 address * **Wi-Fi IPv6 address** - Wi-Fi IPv6 address * **Wi-Fi subnet mask** - Wi-Fi subnet mask Android Details include general OS and device identity, hardware and cellular information, management mode and ownership, and security posture. Attributes are sourced through the Android Management API. For related Android inventory on the device record, see [View Device Application List](/en/endpoint/devices/view-device-application-list). * **OS Version** - Android version * **OS Build** - Operating system build * **API Level** - Android API level * **Security Patch Level** - Security patch level date * **Manufacturer** - Device manufacturer * **Model Name** - Device model name * **Serial Number** - Hardware serial number * **Enterprise ID** - Enterprise ID * **Enterprise Device ID** - Enterprise device ID * **Available Device Capacity** - Free storage capacity * **Device Capacity** - Total storage capacity * **Total RAM** - Total installed memory * **Wi-Fi Address** - Wi-Fi MAC address * **Cellular Technology** - Cellular connectivity technology * **Management Mode** - Management mode * **Ownership** - Device ownership * **IMEI** - International Mobile Equipment Identity when available * **Storage Encryption** - Storage encryption status * **Encryption Status** - Encryption status detail * **Device Posture** - Device posture status * **Passcode** - Whether a passcode is set * **Google Play Protect** - Google Play Protect status * **Unknown App Sources** - Whether unknown app sources are allowed * **Developer Mode** - Whether developer mode is enabled * **Android Debug Bridge** - Whether ADB is enabled ### Related Articles Filter, sort, and organize your device fleet with device views and attributes Understand agent and MDM check-ins and how device information stays current Create and apply tags to organize devices and support Assignment Rules Link directory users to device records for user-based management View and manage the application list on devices Remove local user accounts on Mac computers from the device record # Tags for Devices Source: https://docs.iru.com/en/endpoint/devices/device-record-management/tags-for-devices Create and apply tags to devices in Iru Endpoint for filtering and organization. Group devices by location, department, or custom criteria using tags. This guide applies to all device platforms ### About Device Tags Tags let you group devices locally in Iru Endpoint and can be used with Assignment Rules in [Assignment Maps](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Tags differ from an Asset Tag, which can also be set for a device but only supports one value and is usually used specifically for inventory purposes. ### How It Works Device tags allow you to organize and categorize devices for easier management and policy assignment. Tags can be used with Assignment Rules to automatically apply Library Items to devices based on their tag assignments. ### Tagging a Device To add one or more tags in Iru Endpoint, follow these steps. Visit the device record you want to tag. Click **Edit device details.** Select **Edit tags**. From the dialog that appears, you can select one or more existing tags or type to create your first one. Any tags you create become available for any and all devices in your Iru Endpoint tenant. ### Managing Tags Using the Manage tags menu, you can manage tags for your tenant from the Devices page. From here, you can: * Add new tags without assigning them to any devices * Rename tags * Delete tags if they're not used in scoping rules To access the Manage tags menu: Click on **Devices** in the navigation menu on the left-hand side. Click the **ellipsis** in the upper right corner of the Devices page. Select **Manage tags**. In the **Manage tags** modal, you can search for, add, edit, or delete tags. To edit or delete tags, click the ellipsis to the right of the tag and select **Edit tag** or **Delete tag**. Tags that are used in rules cannot be deleted. To see where tags are being used in rules, select the ⓘ next to the ellipsis. ### Adding or Removing Tags in Bulk You can add or remove tags from devices in bulk using the Bulk Actions menu on the Devices Page. Select the radio buttons next to the devices for which you want to edit tags. Click the **Bulk Actions menu**. Select **Edit Tags**. In the modal that appears, choose the tags you want to add and remove. Click **Save**. ### Tags for Automated Device Enrollment Tags can be applied to Automated Device Enrollment (ADE) devices before they enroll. The tags carry over to the enrolled device record and stay in sync both ways: updating an enrolled device's tags updates the ADE record as well. Click **Enrollment** in the left-hand navigation. Ensure the **Automated Device Enrollment** tab is selected. Select the device(s) you would like to tag. Click **Assign tags**. Select which tags to add or remove. Click **Assign**. You can manage tags (add, rename, or delete them) by following the steps in the [Managing Tags](#managing-tags) section. Tags assigned to ADE devices can be used in [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing) rules to route devices to Blueprints during enrollment. ### Activity Logging Updates to Tags are logged in the Device Record Activity, as well as on the [Activity Page](/en/endpoint/devices/activity-page). ### Using Tags with Conditional Logic To learn more about conditional logic, see [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). Tags support the following operators, which are case-sensitive: | **Operator** | **Definition** | | ------------------------- | -------------------------------------------------------------------------- | | `are exactly` | matches against the entire tag set | | `are not exactly` | matches against the entire tag set | | `contain one of` | looks for one or more of the specified tags in the device's entire tag set | | `does not contain one of` | looks for one or more of the specified tags in the device's entire tag set | ### Related Articles Create a Blueprint with Assignment Maps Create and configure device Blueprints for policy management Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Use conditional logic in Assignment Maps # Understanding When Devices Go "Offline" Source: https://docs.iru.com/en/endpoint/devices/device-record-management/understanding-when-devices-go-offline Understand why managed devices show as offline in Iru Endpoint. Troubleshoot connectivity issues, check-in failures, and network problems. This guide applies to all device platforms ### About Device Offline Status After 30 days of MDM inactivity, an Iru Endpoint-enrolled device will be marked as "Offline". The device will remain offline until it can check in again or one of the following actions is taken. ### How It Works Devices go offline when they haven't communicated with Iru Endpoint for 30 days. This can happen when devices are powered off, have no internet connection, or are experiencing connectivity issues. The offline status helps administrators identify devices that may need attention or troubleshooting. When a device goes offline, it's automatically moved to the "Offline" section in the Iru Endpoint web app. This status change doesn't affect the device's enrollment or configuration - it simply indicates that the device hasn't been able to communicate with Iru Endpoint recently. For detailed information about how devices check in with Iru Endpoint, see [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in). ### Reactivate Offline Devices To bring a device out of "Offline" status, it must be turned on with an active Internet connection. Once it completes a check-in with Iru Endpoint, the device will be removed from the "Offline" section. Devices will automatically return to online status once they successfully check in with Iru Endpoint. No manual intervention is required from administrators. If you need to troubleshoot check-in issues, see [Troubleshooting Agent Check-In](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins) for detailed troubleshooting steps. ### Remove from Account If Iru Endpoint should no longer look for this device, follow [these steps](/en/endpoint/devices/device-record-management/deleting-a-device-record-and-uninstalling-iru-endpoint) to remove it from your account. Carefully review the ramifications of removing a device from Iru Endpoint before proceeding. Removing a device from your account will permanently delete the device record and all associated data. This action cannot be undone. ### Reinstall Iru Endpoint If a device was erased, Iru Endpoint must be re-installed manually or via MDM with Automated Device Enrollment to operate properly. Iru Endpoint will automatically link the old and new records using the UUID and serial number. Choose between manual reinstallation or Automated Device Enrollment based on your device management strategy. Follow the appropriate enrollment process for your chosen method. Confirm the device appears in Iru Endpoint and is properly enrolled. ### Troubleshooting Offline Devices If devices remain offline after being powered on and connected to the internet, the issue is likely related to check-in problems rather than the offline status itself. For troubleshooting check-in issues, see [Troubleshooting Agent Check-In](/en/endpoint/devices/device-check-in/troubleshooting-agent-check-ins). See the [Using Iru AI](/en/iru/iru-ai/using-iru-ai) section of our Knowledge Base for more detailed information about taking action on devices. # Device Views Overview Source: https://docs.iru.com/en/endpoint/devices/device-views-overview Use device views in Iru Endpoint to filter, sort, and organize your managed device fleet. Create saved views and custom filters for quick access. This guide applies to all device platforms ### About Device Views Device Views let you filter and sort your fleet across Apple, Windows, and Android. You can use various attributes to organize, search, and analyze your devices. To review the full inventory for a single device, open the device record and select the **Details** tab. See [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details). ### How It Works Device Views collect and display information from multiple sources including the Iru Agent, MDM profiles, and platform-specific APIs. This data is continuously updated through device check-ins and provides real-time insights into your device fleet status, compliance, and configuration. Not all attributes are applicable to every platform. The availability of each attribute depends on the device type (Apple, Windows, or Android) and the data source (Agent or MDM). ### Available Attributes The following attributes can be used to sort and filter your device fleet: * **Device ID** - Unique identifier for the device * **Device Name** - User-assigned or system-generated device name * **Device Serial Number** - Hardware serial number * **Device Family** - Device family. Values include **Mac**, **iPhone**, **iPad**, **Apple TV**, **Vision**, **Android**, and **Windows** * **Model** - Device model information * **Model Identifier** - Specific model identifier * **Model Name** - Human-readable model name * **Manufacturer** - Device manufacturer * **Hardware UUID** - Hardware UUID of the device * **Host Name** - Network hostname * **Local Hostname** - Local network hostname * **Asset Tag** - Organization-assigned asset tag * **Bluetooth MAC Address** - Bluetooth MAC address of the device * **Ethernet MAC Address** - Ethernet MAC address of the device * **Wi-Fi MAC Address** - Wi-Fi MAC address of the device * **Local IP address** - Local IP address of the device * **Public IP Address** - Public IP address of the device * **OS Name** - Operating system name (macOS, Windows, Android) * **OS Version** - Operating system version * **OS Build** - Operating system build number * **OS Edition** - Operating system edition * **Display OS Version** - User-visible OS version * **Full Software Version** - Full software version string * **Supplemental Build Version** - Additional build information * **Supplemental OS Version Extra** - Extra OS version details * **Update Build Revision** - Update build revision * **API Level** - Android API level * **Beta Enrollment** - Beta enrollment information for the device * **Security Patch Level** - Security patch level date * **Agent Installed** - Whether the Iru Agent is installed * **Agent Version** - Version of the installed Iru Agent * **MDM Enabled** - Whether MDM is enabled on the device * **Status** - Device status. Values include **All Clear**, **No History**, **Warning**, and **Offline**. Library Item failures are usually reflected as **Error** status on the Library Item and generate an alert; see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details * **Lost Mode Status** - Lost Mode status. Values include **Pending**, **Enabled**, and **Errored** * **Last Check-In** - Most recent device check-in * **Last Check-In Agent** - Most recent agent check-in * **Last Check-In MDM** - Most recent MDM check-in * **Device User** - Primary user of the device * **Device User Email** - Email address of the device user * **Device User ID** - Unique identifier of the device user * **First Enrollment Date** - When the device was first enrolled * **Last Enrollment Date** - Most recent enrollment date * **First Seen** - When the device was first detected * **Last Updated** - When device information was last updated * **Last Changed** - When device configuration last changed * **Last Collected** - When device data was last collected * **Device Capacity** - Total storage capacity of the device * **Available Device Capacity** - Free storage capacity on the device * **Available Device Capacity Percent** - Free storage capacity as a percentage * **Memory** - Device memory * **Number of Processors** - Number of processors * **Total Number of Cores** - Total number of CPU cores * **Processor Name** - Processor name * **Processor Speed** - Processor speed * **Battery Health** - Current battery health status. Values include **Non-genuine**, **Normal**, **Service recommended**, **Unknown**, and **Unsupported** * **Apple Silicon** - Whether the device uses Apple Silicon (Apple devices only) * **Cellular Technology** - Cellular connectivity technology. Values include **None**, **GSM**, **CDMA**, and **Both GSM and CDMA** * **Data Roaming** - Data roaming status * **Personal Hotspot** - Personal hotspot capability * **Blueprint Name** - Assigned Blueprint name * **Blueprint ID** - Unique identifier of the assigned Blueprint * **Tags** - Custom tags assigned to the device * **Shared iPad** - Whether the device is a shared iPad (iOS only) ### Using Device Views #### Filtering Devices Navigate to the **Devices** section in the Iru web app to view your device fleet. Use the filter options to narrow down your device list based on specific attributes like OS version, Blueprint, or user information. Click on column headers to sort devices by different attributes in ascending or descending order. Save frequently used filter combinations as custom views for quick access. #### Platform-Specific Attributes Apple devices report the largest attribute set, including: * **Apple Silicon** - Identifies devices with Apple's custom processors * **Shared iPad** - Identifies shared iPad configurations * **Supplemental Build Version** - Additional macOS/iOS build information * **Battery Health** - Battery health status, including values such as **Normal**, **Service recommended**, and **Unsupported** * **Beta Enrollment** - Beta enrollment information for the device * **Bluetooth MAC Address**, **Ethernet MAC Address**, and **Wi-Fi MAC Address** - Network interface addresses * **Local IP address** and **Public IP Address** - Network address information * **Lost Mode Status** - Lost Mode status, including **Pending**, **Enabled**, and **Errored** Windows devices include platform-specific attributes: * **OS Build** - Windows build number * **OS Edition** - Windows edition * **Model Identifier** - Windows device model information * **Agent Version** - Iru Agent version information * **Processor Name**, **Processor Speed**, **Number of Processors**, and **Total Number of Cores** - Processor details Android devices provide: * **OS Version** - Android version information * **API Level** - Android API level * **Security Patch Level** - Security patch level date * **Model** - Android device model * **Device Capacity** - Total storage capacity * **Available Device Capacity** - Free storage capacity * **Available Device Capacity Percent** - Free storage capacity as a percentage ### Best Practices Set up regular monitoring of device attributes to track fleet health and compliance status. Create custom views for different teams or use cases to improve efficiency. Configure alerts based on device attributes to stay informed about important changes. Use device attributes in reports to provide insights to stakeholders. ### Troubleshooting **Possible causes:** * Device not enrolled * Agent not installed or not running * Device offline or not checking in **Solutions:** * Verify device enrollment status * Check agent installation and connectivity * Ensure device is online and checking in regularly **Possible causes:** * Stale data from previous check-in * Agent reporting issues * Platform-specific limitations **Solutions:** * Force a device check-in to refresh data * Check agent logs for reporting issues * Review platform-specific documentation for limitations ### Related Articles Review inventory and status fields on the Details tab of a device record Understand agent and MDM check-ins and how device information stays current # Global Alerts Source: https://docs.iru.com/en/endpoint/devices/global-alerts Monitor and manage alerts in Iru Endpoint including parameter alerts and Library Item alerts. View alert details, status, and remediation steps. This guide applies to Apple devices ### About Alerts Alerts are notifications within the Iru Endpoint Web App that keep admins informed about the status of their managed Apple devices. All active, muted, and cleared alerts can be viewed from **Alerts** (bell icon) in the top right navigation bar. ### How It Works Alerts can be triggered in two ways: * **Parameter Alerts** - Parameters can trigger alerts, informing admins about things like available OS updates or iCloud sign-ins. These alerts are initiated as part of the Iru Agent check-in that occurs every 15 minutes and only apply to Mac computers. Parameter alerts can be muted if desired. * **Library Item Alerts** - When a Library Item does not succeed for a device, the Library Item shows **Error** status for that device and Iru generates an alert. Library Item alerts can be initiated by either an MDM check-in or an Iru Agent check-in, and apply to all applicable device types. The following Library Item types commonly surface **Error** status and trigger an alert when something goes wrong: * Profiles * Custom Scripts * Custom Printers * Custom Apps * App Store Apps ### Parameter Alerts Alerts are available for a number of Parameters. Those Parameters have a **bell icon** next to their on/off toggles. When a Parameter and its Alert are both enabled, alert events display in the Alerts section of Iru Endpoint. For example, when **Report available macOS updates** is enabled, Iru Endpoint generates an alert if a software update becomes available for any Mac enrolled in the associated [Blueprint](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). #### Mute Parameter Alerts Parameter alerts can be muted so that their alerts are still logged for viewing and tracking, but there won't be an indicator for them in the top right navigation bar. Navigate to the Parameter you want to mute in your Blueprint configuration. Click the **bell icon** next to the on/off toggle of the Parameter you'd like to mute. ### Library Item Alerts When certain Library Items fail, the Library Item shows **Error** status for that device and Iru generates an alert. For example, if a Custom App or configuration profile doesn't install, you'll see **Error** status on the Library Item's device list and a corresponding entry under **Alerts** in the top navigation. ### Viewing Alerts Click the **Alerts** icon in the top right navigation bar to view new alerts. Within **Alerts**, you can view details of all current alerts. Current alerts generate an indicator in the top right navigation bar. Muted Parameter alerts will not generate an indicator in the top right navigation bar. Click on the **Muted Alerts** tab to view details of all current muted alerts. If a device has resolved its alert, it will be marked as cleared. For instance, if an alert for FileVault enforcement is visible, the alert will be cleared once FileVault has been enabled on the device. Resolved alerts will be accessible in the **Cleared Alerts** tab. ### Receiving Alerts Outside of Iru Endpoint Configure the [Slack](/en/endpoint/integrations/communication/slack-integration) or [Teams](/en/endpoint/integrations/communication/microsoft-teams-integration) integration to receive alerts outside of Iru Endpoint. # macOS Login Screens User Experience Source: https://docs.iru.com/en/endpoint/devices/macos-login-screens-user-experience See what macOS login and unlock screens look like on managed Mac computers. Understand login window customizations, FileVault prompts, and messages. This guide applies to Mac computers While they all look similar, macOS has three separate screens that let you log in and start a new user session, unlock your encrypted disk at startup, or unlock an existing user session. The screen to sign in to your Mac will be familiar to any Mac user. But on closer inspection, you might have noticed three similar, yet slightly different, screens that can ask for your password. Those three screens are the login window, the FileVault unlock screen and the lock screen. * The **login window** starts a new user session or lets you re-enter an existing user session running in the background. This is the screen you see when your Mac starts up. It can have user icons or a name and password form. * When your disk is encrypted with FileVault, the **FileVault unlock screen** appears at startup or after waking up from sleep. It will always have icons for the users who can unlock the disk. * The **lock screen** shows up when your Mac has locked after waking up from sleep, when the screen saver has locked the screen, or if some other event has triggered a lock. This screen will prompt for the active user's password. ### Login Window The login window is the screen that greets you after your Mac has finished starting up. This window shows a list of user icons. You can configure login options in System Settings > Lock Screen preferences to show only your name and password instead of icons. This option removes the icons from the login window, and you'll instead see a form with fields for your account name and password. If you later return to the login window and there are user sessions already open in the background, those users will have a check mark next to their account name. If you've set the login options to show only a name and password field, there will be no visual indication that already open user sessions are running in the background. ### FileVault Unlock Screen If you have enabled disk encryption on your Mac with FileVault, your Mac won't be able to read the encrypted disk until a FileVault-enabled user unlocks it. Your Mac will start up to a special screen that shows a FileVault unlock window that looks just like the login window with icons for the enabled users (even if you selected name and password to be shown at the login window). One way to tell you're at the FileVault unlock screen is a progress bar that appears after you enter your password. This progress bar shows the status of unlocking your disk. When you successfully enter your password to unlock the disk, your Mac will use those credentials to log you in instead of showing you the login window again. Generally, all users on your Mac will be enabled to unlock FileVault. But it's possible that accounts were created before FileVault was turned on, or users created through your organization's management tools, may not be enabled to do so. In that case, you'll only see the enabled users at the FileVault unlock screen. ### FileVault Login Screen Differences Between Intel and Apple Silicon Mac Computers #### Intel Mac Computers * Enables the use of account icons and password fields on the FileVault login screen. * Does not support username and password fields at the FileVault login screen. * Does not support smart cards for login at the FileVault login screen #### Apple Silicon Mac Computers * Enables the use of account icons and password fields on the FileVault login screen. * Supports username and password fields at the FileVault login screen * Supports smart cards for login at the FileVault login screen After you log in with the enabled account and your Mac is unlocked, you can then switch to another user account by selecting **Login Window** from the Fast User Switching menu. After logging in with an enabled account, you may also choose to log out from the Apple menu. In System Settings > Security & Privacy > Security > FileVault, you'll see a warning that some users are not enabled for FileVault. Clicking the Enable Users button will allow the remaining users to unlock FileVault. ### Lock Screen The lock screen appears when your Mac has locked after a period of inactivity, the screen saver is set to lock your Mac, or some other event has triggered your Mac to lock. When you return to your Mac, you'll be prompted to unlock the screen with your account password. You can tell you're at the lock screen because your user account is already selected and the password prompt is ready for input. If a screen saver is enabled, you may see the screen saver image behind the account icon and password field. # macOS Managed OS User Experience Source: https://docs.iru.com/en/endpoint/devices/macos-managed-os-user-experience See what happens on Mac computers when Managed OS triggers an update. Understand notifications, countdown timers, restart behavior, and deferral options. This guide applies to Mac computers Managed OS is a feature that simplifies how you handle operating system updates for Mac computers in your organization. It automates the update process so that devices stay on required macOS versions without needing constant manual oversight. For iPhone, iPad, and Apple TV, see [User Experience with Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos). #### Notifications Notifications for software updates are handled by macOS. A **Managed Update** notification shows the scheduled date and time for the update. You can install now, schedule for that night, or dismiss and install later. macOS notifies you once per day until the deadline. Within 24 hours of the deadline, notifications appear hourly and are not suppressed by Do Not Disturb. In the final hour, you’re notified at 30 minutes and then every 10 minutes. If the Mac is off when the enforcement deadline passes, the update is scheduled for 60 minutes after it’s powered on and detects it’s past the deadline. The contents and timing of these notifications are determined by the operating system. **System Settings** > **Software Update** shows the pending update and your organization’s required date and time. You can start the update from there or wait for it to run automatically at the scheduled time. ### Related Articles What to expect when Managed OS updates run on your device # User Experience with Managed OS for iOS, iPadOS and tvOS Source: https://docs.iru.com/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos See what happens on iPhone, iPad, and Apple TV when Managed OS triggers an update. Understand notifications, installation prompts, and enforcement. This guide applies to iOS devices, iPadOS devices, and Apple TV Iru Endpoint's Managed OS uses the built-in OS update notifications on the device. To avoid interruptions to your work, it's essential to understand what you'll experience with Managed OS. For Mac, see [macOS Managed OS User Experience](/en/endpoint/devices/macos-managed-os-user-experience). ### Upcoming Update Notifications Once Iru Endpoint has cached an update on your device, you'll see a red notification badge on the Settings app indicating that an update is available. You'll also see a message at the top of the Settings app: If you tap on that message (or navigate to **Settings > General > Software Update**), you'll be able to proceed with the update before the enforcement deadline: ### Update Experience Once the enforcement deadline is reached, your experience will vary depending on whether a passcode exists on the device: * Since tvOS does not support passcodes, the update will be installed immediately, and the Apple TV will reboot. * iOS and iPadOS devices that do not have a passcode will behave the same way as tvOS. Once devices without a passcode reach their enforcement deadline, the device will restart without warning and begin the update process. ### Unique Update Prompts for Passcode-Protected Devices iOS and iPadOS devices that are protected with a passcode require that you enter your passcode to authorize any operating system update. At the Lock Screen, you'll see a notification: Once at the Home Screen, you'll first see a Software Update prompt giving you the ability to start the update immediately or later: If you choose to proceed with the update, you'll be prompted for your passcode and the update will be installed right away. If you instead tap **Later**, you'll be asked to enter your passcode to authorize the update to happen overnight. At the bottom of that screen is a **Remind Me Later** option to further defer the update: You're allowed to defer the update just three times. After a third deferral, you'll be forced to update your device before continuing to use it: This three-deferral limit for MDM-initiated updates is new in iOS 15 and iPadOS 15 and later and is enforced across a device restart. Previous versions did not limit the number of deferrals. Once you enter your passcode to allow the update, your device will apply the update overnight. ### Related Articles What to expect when Managed OS updates run on your device # View Device Application List Source: https://docs.iru.com/en/endpoint/devices/view-device-application-list View the list of installed applications on a managed device in Iru Endpoint. Check app versions, bundle IDs, and installation status for compliance. This guide applies to all device platforms ### About Device Application Lists Iru Endpoint lets you view a list of applications installed on any enrolled device. This is especially useful for comparing version numbers, checking for unauthorized applications, or verifying that required software is present. If you'd like to view all applications installed across your entire fleet, see the [App Install Report script](https://github.com/kandji-inc/support/tree/main/api-tools/installed-apps) in our Support GitHub Repo. Application inventory is updated at different intervals: Apple platforms once per day, Windows every 15 minutes, and Android when something changes on the device. ### How It Works Device application inventory is collected automatically from enrolled devices and displayed in the Iru Endpoint Web App. This data helps administrators monitor software compliance, track application versions, and identify unauthorized or outdated software across their device fleet. ### Platform-Specific Application Viewing #### Apple Devices To view a list of apps on an Apple device: Navigate to **Devices** in the left-hand navigation bar. Select the Apple device you want to view. Select the **Apps** tab. The Apps tab displays details for each installed application, including: * **Name**: The application name * **Version**: The installed version number * **Bundle ID**: The unique identifier for the application * **Size**: The application size on disk * **Install Date**: When the application was installed * **Source**: How the application was installed (App Store, Auto App, Custom App, etc.) Application inventory on Apple platforms is updated once per day during the device's daily check-in. #### Windows Devices Iru Endpoint also provides application inventory for enrolled Windows devices. To view a list of apps on a Windows device: Navigate to **Devices** in the left-hand navigation bar. Select the Windows device you want to view. Select the **Apps** tab. The Apps tab displays details for each installed application, including: * **Display Name**: The name of the app as shown in Windows * **Version**: The installed version number * **Architecture**: Indicates `x64`, `x86`, or `arm64` * **Publisher**: The publisher or developer of the app * **Product Code**: The Windows Installer product code (if available) * **Installed Path**: The file system path where the app is installed App inventory may include system tools, plugins, and background agents in addition to user-facing applications. Windows application inventory is updated every 15 minutes. #### Android Devices View device information for **company-owned work profile** Android devices. Note that there are some caveats with what Google allows and Iru Endpoint currently supports. #### View Android Device Information Navigate to **Devices** in the left-hand navigation bar. Select an Android device from the **All Devices** list view. This will take you to the device's **Status** tab. Select the **Activity** tab to view device activity. Select the **Details** tab to view device details. For a full list of fields by platform, see [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details). All **Details** attributes are sourced via the Android Management API. [Learn more](https://developers.google.com/android/management/reference/rest/v1/enterprises.devices). Select the **Notes** tab to view device notes. Select the **Apps** tab to view applications installed within the device's work profile. #### Android Device Information Caveats *If a particular attribute is missing, it is likely it is not supported by the Android Management API. We'd love to hear your feedback on what device attributes are important to log and display.* * *Device name: The Android Management API does not allow collecting device name. Because of this, the Iru Endpoint Web App displays the device name as `{Model}+{Last 4 Serial Number}`. We'd love to hear your feedback on this approach.* * *Enterprise ID & Enterprise Device ID: these are unique identifiers specific to Android Enterprise and the Android Management API that identify a particular device within an organization.* * *Attributes with missing values: Available device capacity, unknown app sources, developer mode, and Android Debug Bridge seem to only report intermittently. We are currently working with Google to troubleshoot these.* **Android Caveats**: For company-owned work profile devices, the Android Management API allows collecting installed app info only for apps within the **work profile**, i.e. managed applications. Personal profile apps are not visible to maintain user privacy. ### Application Inventory Details #### Application Sources Applications can be installed through various methods: * **Auto Apps**: Pre-packaged applications managed by Iru * **Custom Apps**: Applications uploaded and managed by administrators. See [Custom Apps Overview](/en/endpoint/library/library-items-profiles/custom-apps-overview) for Mac (PKG, DMG, ZIP) and Windows (MSI, EXE). * **App Store**: Applications installed from platform app stores * **System Apps**: Built-in system applications * **User Installed**: Applications installed by end users (where permitted) #### Filtering and Searching You can filter and search the application list by: * **Application Name**: Search for specific applications * **Version**: Filter by version numbers * **Source**: Filter by installation method * **Install Date**: Filter by when applications were installed * **Size**: Filter by application size ### Best Practices Regularly review application inventories to ensure compliance with software policies. Monitor application versions to ensure devices are running current, secure versions. Check for unauthorized applications that may pose security risks. Use application inventories to ensure software license compliance. ### Troubleshooting **Possible causes:** * Device not enrolled or agent not running * Application installed after last inventory collection * Application installed in personal profile (Android) **Solutions:** * Verify device enrollment status * Wait for next inventory collection cycle * Check if application is in work profile (Android) **Possible causes:** * Application metadata not properly extracted * Application installed through non-standard methods * System application with limited metadata **Solutions:** * Check application installation method * Verify application is properly installed * Contact support for system applications **Possible causes:** * Device offline or not checking in * Agent not running properly * Network connectivity issues **Solutions:** * Check device online status * Verify agent is running * Test network connectivity # Behavioral Detection Rule Groups Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/behavioral-detection-rule-groups Create and manage behavioral detection rule groups in Iru EDR. Fine-tune which process behaviors trigger alerts and customize detection sensitivity. This guide applies to Mac computers The Endpoint Detection and Response add-on is required to use Behavioral Detection Rule Groups. ### About Behavioral Detection Rule Groups Behavioral Detection Rule Groups provide fine-tuned control over your EDR behavioral detections. This feature allows you to customize which security rules monitor your environment, enabling you to increase protection levels when needed or reduce alert noise by adjusting sensitivity settings. ### How It Works Behavioral Detection Rule Groups operate through configurable detection levels that determine the sensitivity of threat monitoring. By default, behavioral detections run on **Cautious** mode, focusing on the most serious threats while minimizing false positives. You can adjust security levels based on your organization's risk tolerance and operational requirements. ### Understanding Detection Levels Out of the box, behavioral detections run on **Cautious** mode, which means only the most serious threats trigger alerts. This keeps false alarms to a minimum while catching the worst actors. You can raise sensitivity by choosing **Moderate** or **Aggressive**: * **Cautious**: Focuses on clear-cut malicious activity with very few false positives * **Moderate**: Casts a wider net to catch more potential threats while staying manageable * **Aggressive**: Highest sensitivity; expect more alerts ### Understanding Rule Groups Behavioral detections are split into eight focused categories, each watching for different types of suspicious behavior. You can set each group to Cautious, Moderate, or Aggressive independently. * **Discovery and Information Gathering**: Detects suspiciously probing commands, such as those identifying security software installations or virtual machines * **Exploit Detection**: Detects exploitation attempts against publicly known or privately disclosed vulnerabilities * **Obfuscation and Encryption Detection**: Detects the use of encryption and obfuscation to conceal data or commands * **Persistence Mechanisms**: Monitors the creation or modification of launch agents and daemons intended to establish persistence on a macOS host * **Privilege Escalation Detection**: Monitors for signs that someone's trying to gain higher-level access, like messing with file permissions or accessing sensitive configuration files * **Script and Command Usage Monitoring**: Identifies the execution of suspicious commands and scripts * **Security Tool and System Configuration Alterations**: Detects altering or disabling of security configurations and tools designed to protect macOS, such as Gatekeeper, Transparency Consent and Control (TCC), and endpoint security products * **User Account Alterations**: Detects the creation or manipulation of user accounts intended to remain hidden from normal user interactions or system administration ### Configuring Rule Groups Open the **Detections** page in the left-hand navigation (under **Endpoint**). Select the **Rules** tab. Rules tab on the Detections page To set rules globally, select the **Rule detection level**. To set rules based on rule group, select **Set detection level per rule group**. Under each rule group type, select your desired **detection level**. When finished, **Save detection settings**. ### Handling Rule Exceptions Rule exceptions are only available for rules that do not target highly malicious behavior. Critical security rules cannot be individually disabled. You may occasionally need to disable a specific rule that generates excessive alerts without affecting the entire rule group's settings. To do this: On the Detections page, select the **Detections** tab. Select the **detection(s)** generating unwanted alerts using the checkbox to the left of the threat. Select the ellipsis in the lower-left corner. Choose **Disable suspicious rules**. ### Managing Your Exceptions Any rules you disable automatically show up in the **Rule Exceptions** list under the **Rules** tab in your EDR configuration. From there, you can: * See all the rules you've turned off * Turn rules back on if circumstances change * Keep track of what's not being monitored ### Considerations * **Detection Level Balance**: Choose detection levels that balance security coverage with manageable alert volumes to avoid alert fatigue * **Rule Group Customization**: Configure each rule group independently based on your organization's specific security requirements and risk profile * **Exception Management**: Regularly review disabled rules to ensure they remain appropriate and don't create security gaps * **Critical Rule Protection**: Understand that critical security rules cannot be disabled to maintain essential security coverage * **Alert Tuning**: Use rule exceptions strategically to reduce false positives while maintaining security effectiveness * **Regular Review**: Periodically assess rule group settings and exceptions to ensure they align with current threat landscape and business needs * **Documentation**: Keep records of rule exceptions and their rationale for compliance and audit purposes * **Testing and Validation**: Test rule group changes in a controlled environment before deploying to production * **Performance Impact**: Monitor system performance when adjusting detection levels, as more aggressive settings may impact device performance * **Team Training**: Ensure security teams understand the implications of different detection levels and rule exceptions * **Incident Response**: Consider how rule group settings affect incident response workflows and threat investigation processes, including [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) actions for compromised devices. * **Compliance Requirements**: Align rule group configurations with regulatory and compliance requirements for your industry # Configure the Accessory & Storage Access Library Item Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/configure-the-accessory-and-storage-access-library-item Configure the Accessory and Storage Access Library Item to control external storage, server volumes, and DMG access on managed Mac computers. This guide applies to Mac computers ### About Accessory & Storage Access Library Item Iru Endpoint's Accessory & Storage Access Library Item allows you, as the device or security administrator, to define access privileges and controls for external storage volumes, server volumes, and DMG file types on Mac computers. To use this Library Item, the [Endpoint Detection & Response](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) add-on is necessary. However, you do not need to assign the EDR Library Item to the device Blueprint to deploy this Library Item. ### How It Works The Accessory & Storage Access Library Item provides granular control over storage device access on managed Mac computers. It allows administrators to configure access privileges for external storage devices, disk images, and server volumes, with options for encryption requirements, password protection, and user-specific access controls. ### Adding an Accessory & Storage Access Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Accessory & Storage Access Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). ### Configuring External Volumes The External volumes section allows you to manage access privileges for external storage devices such as USB, CD, and DVD drives connected to the accessory port and memory cards (SD, SDXC) inserted in the SD card slot. To manage access for external volumes, follow the steps below. The **Require encryption** and **Require admin password to access** settings are only available for Read & Write and Read only access privileges. Turn on management for external volumes. From the Access privileges menu, select the desired access privileges for external volumes. The available options are: **Read & Write**, **Read only**, or **No access**. a. **Set Encryption Requirements:** Optionally, select **Require encryption** to ensure only encrypted volumes are mounted. For information about using Disk Utility to encrypt storage devices, see [this Apple support article](https://support.apple.com/guide/disk-utility/encrypt-protect-a-storage-device-password-dskutl35612/mac#:~:text=In%20the%20Disk%20Utility%20app,Erase%20button%20in%20the%20toolbar.). b. **Configure Password Protection:** Optionally, select **Require admin password to access** to prompt users for an admin password to access content. Select **All users** to apply the access privileges to all users, including admin, or select **Standard users** to apply the access privileges only to standard users. Optionally, select **Display alert messages** to alert users when the mounting of external volumes is blocked. Note, this setting is forced on when **Require admin password to access** is selected. External volumes access privileges and alert messages configuration ### Configuring Disk Images The Disk images section allows you to manage access privileges for DMG file types. To manage access for disk images, follow the steps below. Disk image settings specified here will apply to all DMG mounts on the device, including those in scripted automated workflows and in-app DMG mounts such as Google Chrome's Auto Update Agent. The **Require admin password to access** setting is only available for Read & Write and Read only access privileges. Turn on management for disk images. The Access privileges menu allows you to select the desired access privileges for disk images. The available options are: **Read & Write**, **Read only**, or **No access**. a. Optionally, select **Require admin password to access** to prompt users for an admin password to access content. Select **All users** to apply the access privileges to all users, including admin, or select **Standard users** to apply the access privileges only to standard users. Optionally, select **Display alert messages** to alert users when the mounting of disk images is blocked. Note, this setting is forced on when **Require admin password to access** is selected. Disk images access privileges and alert messages configuration ### Configuring Server Volumes The Server volumes section allows you to manage access privileges for server volume mounts such as SMB shares. To manage access for server volumes, follow the steps below. Any external, server and DMG volumes previously mounted on the device prior to the deployment of this Library Item will not be managed by Iru Endpoint until these items are unmounted and a re-mount is attempted. Turn on management for server volumes. Choose the desired access privileges for disk images from the Access privileges menu. The available options are: **Read & Write** or **No access**. Select **All users** to apply the access privileges to all users, including admin, or select **Standard users** to apply the access privileges only to standard users. Optionally, select **Display alert messages** to display alert messages to users when the mounting of external volumes is blocked. Click the **Save** button to save the Accessory & Storage Library Item to your Library. Accessory and Storage Library Item server volumes and Save button ### Understanding Restricted Mode on Apple Silicon On a Mac with Apple silicon running macOS 13+ and depending on the device's Privacy & Security settings, when new or unknown USB accessories are used, the user may get an alert asking whether or not the USB accessory should be allowed to connect. This is known as [Restricted Mode](https://support.apple.com/guide/deployment/manage-accessory-access-depf8a4cb051/web) on macOS and is independent of Device alert settings in this Library Item. Restricted Mode can be managed with the **Allow USB accessories while device is locked** setting in the Restrictions Library item. See [this Apple support article](https://support.apple.com/en-us/102282) for more details. ### Considerations The Endpoint Detection & Response add-on is required to use this Library Item. You do not need to assign the EDR Library Item to device Blueprints. Choose **Read & Write**, **Read only**, or **No access** based on your security requirements. Server volumes support **Read & Write** or **No access** only. For external volumes, use **Require encryption** and **Require admin password to access** when you need stronger controls. Those options are available only for **Read & Write** and **Read only**. Apply privileges to **All users** or **Standard users** only, depending on your access control policies. Use **Display alert messages** so users know when mounting is blocked. This setting is forced on when **Require admin password to access** is selected. Volumes mounted before this Library Item is deployed are not managed until they are unmounted and remounted. Restricted Mode on Apple silicon is separate from this Library Item’s alert settings. Manage it with **Allow USB accessories while device is locked** in the Apple Restrictions Library Item. Disk image settings apply to all DMG mounts, including scripted workflows and in-app mounts such as Google Chrome’s Auto Update Agent. Test configuration changes in a controlled Blueprint before deploying widely, and review access settings as security policies change. # Configure the EDR Library Item Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item Configure the EDR Library Item in Iru Endpoint. Set posture modes, user alerts, behavioral detections, and custom allow and block lists. This guide applies to Mac computers and Windows devices The [Endpoint Detection and Response](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) add-on is required to use this Library Item. ### About EDR Library Item Configuration The EDR Library Item is the core component of Iru Endpoint EDR. Configure detection settings, posture modes, end-user notifications, and custom allow and block lists to meet your organization's security requirements. ### Adding an EDR Library Item To add this Library Item to your Iru Endpoint Library, follow the steps in [Library Overview](/en/endpoint/library/library-items-profiles/library-overview). Open the Iru Endpoint Web App and navigate to your **Library**. Add a new **EDR** Library Item and give it a **Name**. Assign the Library Item to the [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint) containing the devices you want to protect. EDR Library Item configuration interface showing settings or Blueprint assignment Configuration differs by platform. Select **macOS** or **Windows** below. ### Configuring File Detection Settings Configure individual posture mode preferences for Malware and PUPs. **Detect** mode scans and reports known malicious items. **Protect** mode scans, reports, and automatically quarantines known malicious items. Select **Detect** or **Protect** for **Malware Posture**. Select **Detect** or **Protect** for **PUP Posture**. If either Malware or PUP posture is set to **Protect**, a **Send user alerts** toggle becomes available to enable or disable end-user notifications. You can click **Expand preview** to see a sample of the user notifications. File detection settings for Malware and PUP posture modes ### Configuring Behavioral Detections Behavioral detections are turned on by default when creating a new EDR Library Item, but can be turned off to suit certain workflows. Suspicious behavioral detections are automatically listed in the Detections table with an informational status to highlight unusual activities that may warrant attention. These detections are designed to provide visibility and cannot have their posture mode configured. Toggle the switch to enable Behavioral detections. Under **Malicious behavior posture**, select either Detect or Protect. * **Detect** mode identifies and reports malicious behavioral detections * **Protect** mode identifies, reports, and blocks malicious behavioral detections If Malicious behavior posture is set to Protect, a **Send user alerts** toggle becomes available to enable or disable user notifications. You can click **Expand preview** to see a sample of the user notifications. Behavioral detection settings with Malicious behavior posture options ### Security Events in Self Service End users can view a list of quarantined files and blocked processes on their Mac computers by opening **Self Service** and clicking **Security events** from the left-hand navigation menu. Configure the EDR Library Item step or screen ### Configuring Allow and Block Lists Allow and Block lists ensure that specific files or applications are always allowed or blocked in your environment, regardless of whether they appear in Iru Endpoint EDR's threat feeds. Block items are considered Malware and require the Malware posture to be in **Protect** mode to be blocked on the device. Click the **+ Add item** button. Allow and Block list configuration interface Give the item a **Name**. Select **Allow** to permit a file or application. Select **Block** to block it. Specify the item type **Hash** or **Path** for the file or application. If **Path** was selected, enter the application or file path. If **Hash** was selected, enter the file hash. For **Path** entries, wildcard matching is supported: * `*` matches characters within a single path segment. * `**` matches one or more directory levels (recursive matching). Examples: `/usr/*/file.*`, `**/file.bin`. Click **Add** to add the item to the Allow and Block list. Optionally, toggle **Add another item** in the lower-left corner to continue adding items. Add item dialog for Allow or Block list Click **Save** in the lower-right corner. Settings deploy and activate automatically on enrolled devices in the assigned Blueprints. #### Determine Hash Value The **Hash** item type is only supported for files. The **Path** item type is supported for both files and applications. Use Terminal to determine the SHA256 hash value of a file: ``` shasum -a 256 /path/to/file ``` ### Considerations * **Posture mode selection**: Choose **Detect** for visibility without blocking, or **Protect** to actively quarantine known threats * **Behavioral detection**: Enable behavioral detections to monitor threats; consider impact on performance and false positive rates * **User alert management**: Configure user alerts to balance security awareness with user experience when files are quarantined * **Device isolation**: EDR provides [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) for quarantining compromised devices from the network * **Allow and block list management**: Maintain accurate lists to prevent legitimate applications from being blocked while ensuring malicious software is identified * **Hash vs. path configuration**: Use hash-based entries for specific file versions and path-based entries for applications that may update frequently * **Testing and validation**: Test configuration changes on a pilot device before broad deployment ### Next Steps See [Testing EDR Malware Detection](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection) to validate your deployment. After you add the EDR Library Item and assign it to Blueprints, click **Save** to deploy it to enrolled Windows devices. See [Endpoint Detection & Response (EDR) Overview](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) for Windows capabilities and [Testing EDR Malware Detection](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection) to validate your deployment. ### Viewing Edit History in the EDR Library Item You can audit changes to the EDR Library Item in the Activity tab of the Library Item or on the [Activity Page](/en/endpoint/devices/activity-page). This shows what configurations changed, the previous state, and who made the change. Click **Activity** in your EDR Library Item or the **Activity** icon in the top-right navigation bar to open the [Activity Page](/en/endpoint/devices/activity-page). Select the disclosure triangle next to **Library Item Edited** for the entry you want to review. Activity tab showing Library Item edit history # Device Isolation Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/device-isolation Isolate compromised devices from the network using Iru EDR. Choose partial or complete isolation to contain threats during active security incidents. This guide applies to Mac computers The Endpoint Detection and Response add-on is required to use Device Isolation. ### About Device Isolation Device Isolation allows administrators to immediately sever a device's network connection, effectively quarantining it from the rest of the fleet. This is a critical response capability when a device is suspected of being compromised or is under active threat. Device Isolation can be performed on individual devices or in bulk across all devices associated with a specific threat detection. ### How It Works Device Isolation provides immediate network quarantine capabilities accessible directly from the Detections page. When a device is isolated, its network connectivity is restricted based on the isolation type selected. Administrators can monitor isolated devices through visual indicators in the Iru Endpoint Web App and restore network access once the threat has been neutralized. The isolation status is reflected in real-time across the Detections page and device records. ### Isolation Types There are two levels of isolation available, depending on the severity of the threat and the level of access you need to maintain: * **Partial Isolation**: The device is disconnected from the network, but the MDM agent maintains a connection. This allows administrators to perform specific remediation actions, such as erasing the device remotely. * **Complete Isolation**: The device is completely cut off from all network communication. No remote actions can be performed on the device while it is in this state, other than releasing it from isolation. ### Prerequisites * **Licensing**: This feature is available to customers with an active Endpoint Detection and Response (EDR) plan. * **Permissions**: Ensure your account has the necessary permissions to manage threats and device actions (see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions)). * **Devices**: This feature is only available for devices that have threats (open or closed) and can be accessed through the detections side panel. ### Isolating a Single Device You can isolate devices directly from the **Detections** page by accessing the side panel for a specific detection. Navigate to the **Detections** page (select **Detections** under **Endpoint** in the left-hand navigation). Click on a specific detection to open the **Side Panel**. In the side panel, locate the specific device you wish to quarantine. Hover over the **Isolate Globe Icon** next to the device name; it will display a tooltip that says **Isolate device from network.** Click the icon. Isolate globe icon next to a device in the Detections side panel to isolate the device In the pop-up window, choose between **Partial Isolation** and **Complete Isolation**. Optionally, enter a reason for the isolation for audit purposes. Click **Isolate Device** to confirm. Isolate device confirmation dialog with Partial or Complete isolation type and optional comment A progress indicator appears while the device is being isolated. Isolation in progress indicator ### Isolating Multiple Devices (Bulk Action) Bulk isolation actions require typing "ISOLATE" as a confirmation step to prevent accidental quarantine of multiple devices. When a threat affects multiple devices, you can isolate all affected devices simultaneously. Navigate to the **Detections** page (select **Detections** under **Endpoint** in the left-hand navigation). Click on a specific detection to open the **Side Panel**. Hover over the **Isolate Globe Icon** associated with the detection itself (at the top right of the panel, above the device list); it will display a tooltip that says **Isolate all devices (macOS only).** Click the icon. Isolate globe icon at detection level in the side panel to isolate all devices for the threat Click the icon to initiate isolation for all devices involved in this detection. In the pop-up window, choose between **Partial Isolation** and **Complete Isolation**. Optionally, enter a reason for the isolation for audit purposes. To prevent accidental bulk actions, type **"ISOLATE"** in the confirmation field. Click **Yes, isolate these devices** to confirm. Bulk isolate confirmation dialog requiring ISOLATE typed to confirm A progress indicator appears while devices are being isolated. Isolation in progress indicator ### Identifying Isolated Devices Once a device is isolated, its status is visually indicated in the Iru Endpoint Web App: * **Visual Indicator**: In the side panel for a threat, the device icon will display a **Red Locked Globe Symbol**. * **Device Record**: The device record will display the **Isolation status** near the top of the record. * **Filtering**: To view all currently quarantined machines, go to the Detections list and filter for detections containing **Isolated Devices**. ### Releasing a Device from Isolation When a threat has been neutralized or a device is deemed safe, you can restore network access. Locate the isolated device in the Detections side panel. Hover over the **Release Globe Icon** to the right of the device you would like to release from isolation; it will display a tooltip that says **Release device from network isolation.** Click the icon. Release globe icon next to an isolated device to restore network access A pop-up will appear asking for confirmation. Restore access confirmation dialog with optional comment Optionally, enter a reason for the release for audit purposes. Click **Restore Access** to restore network connectivity. A progress indicator appears while the device is being released from isolation. Restore access in progress indicator ### Releasing All Devices from Isolation When a threat has been neutralized or devices are deemed safe, you can restore network access for all isolated devices at once. Locate the isolated device in the Detections side panel. Hover over the **Release Globe Icon** associated with the detection itself (at the top right of the panel, above the device list); it will display a tooltip that says **Release all applicable devices.** Click the icon. Release globe icon at detection level to restore access for all isolated devices A pop-up will appear asking for confirmation. Optionally, enter a reason for the release for audit purposes. Click **Restore Access** to restore network connectivity. A progress indicator appears while the devices are being released from isolation. Restore access in progress indicator ### What the User Sees When a device is isolated or released from isolation, the user sees a message on their screen explaining the status of their device. #### When the Device Is Offline The user sees the following message when the device has been isolated. Message says You're Offline: Your administrator has disconnected this device from the network. Contact your IT or Security team for more information. #### When the Device Is Online The user sees the following message when the device has been released from isolation. Message says You're Online: Your administrator has reconnected this device to the network. ### Common Errors Isolation or Release actions can sometimes fail due to device state or network conditions. When that happens, the side panel for a specific threat shows an error status for each device so you can retry or investigate. #### Isolation Failed If isolating a device fails, the device's **Isolate Globe Icon** will have a red indicator. Hover over the icon and it will display a tooltip that says **Device failed isolating. Try again.** Click it to retry the isolation. Isolation failed error message #### Release Failed If releasing a device from isolation fails, the device's **Release Globe Icon** will have a red indicator. Hover over the icon and it will display a tooltip that says **Device failed releasing. Try again.** Click it to retry releasing it from isolation. Release from isolation failed error message #### Troubleshooting If isolating or releasing a device fails after multiple attempts, you can restart the computer and try again. You can also check the device's network connections to ensure it is connected to Wi-Fi or Ethernet. For isolated devices, it is normal for the network connection to have the "No Internet Connection..." status, but it should still be connected to the network. For network requirements and firewall configuration, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). ### Considerations * **Documentation**: Use the optional comment field for isolation and release actions to support audit and compliance. * **Activity logging**: Isolation and release actions appear on the [Unified Activity](/en/iru/platform-overview/unified-activity) under **Detections**. * **Incident response**: Integrate isolation into your broader workflows; see [security operations actions](/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection) for status, tags, and related controls. * **Investigation**: Use Device Isolation together with [threat event analysis](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events) to contain threats while investigating. * **Release timing**: Restore network access only after the threat is neutralized and you are ready to allow the device back on the network. * **Coordination**: Align with security or IT before isolating devices so incident response procedures are clear. # Endpoint Detection & Response (EDR) Overview Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview Learn how Iru Endpoint Detection and Response (EDR) works on macOS and Windows, including platform capabilities, detection coverage, and posture modes. This guide applies to Mac computers and Windows devices The Endpoint Detection and Response add-on is required to use the EDR Library Item. ### About Iru Endpoint EDR Iru Endpoint EDR is a security tool that monitors enrolled devices for malware and potentially unwanted programs (PUPs). It is integrated into the Iru Endpoint platform and managed through the same web app you use for device management. EDR is deployed as a Library Item called **EDR** in Iru Endpoint Blueprints. Once you enable it in a Blueprint, it deploys and activates automatically on enrolled devices. On macOS, EDR can terminate processes and quarantine files when Protect posture is enabled, supports response actions such as device isolation from the Detections page, and supports custom allow and block lists based on file hashes or paths. Admins can view detected threats, quarantine actions, and security events on the **Detections** page in the Iru Endpoint Web App. See [Understanding the Detections Page](/en/endpoint/endpoint-detection-response-edr/understanding-the-detections-page) for dashboard widgets, filters, and device record views. ### Platform Capabilities Iru Endpoint EDR monitors Mac computers using **file-based and behavioral detection**. It runs on enrolled Macs through Apple's Endpoint Security framework and analyzes files and processes against threat intelligence and detection models. EDR uses Apple's native frameworks for monitoring without significant performance impact. **Core capabilities:** * **File-based detection:** Categorizes files as malware, PUPs, benign, or unknown * **Behavioral detection:** Identifies malicious or suspicious process activity * **Automated threat response:** Terminates processes and quarantines files in Protect mode * **Custom allow and block lists:** Override default threat intelligence using file hashes or paths * **Posture modes:** Configure independent Detect or Protect modes for malware, PUPs, and malicious behavior * **Device isolation:** Quarantine compromised devices from the network during active incidents For behavioral detection tuning, see [Behavioral Detection Rule Groups](/en/endpoint/endpoint-detection-response-edr/behavioral-detection-rule-groups). The Endpoint Detection and Response add-on is also required for the [Accessory & Storage Access Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-accessory-and-storage-access-library-item). You do not need to assign the EDR Library Item to the Blueprint to deploy the Accessory & Storage Access Library Item. Iru Endpoint EDR for Windows monitors Windows computers using **file-based detection**. It analyzes files against threat intelligence and detection models and categorizes them as malware, PUPs, benign, or unknown. Iru Endpoint supports **Windows 11 24H2 or 25H2** on Pro, Pro Education, Enterprise, or Education editions. See [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup) for platform prerequisites. **Core capabilities:** * **File-based detection:** Analyzes files against threat intelligence and detection models * **Detect mode:** Scans and reports malware and PUPs without automatic quarantine ### Posture Modes The EDR agent supports **Detect** and **Protect** posture modes, configured independently for **Malware**, **PUPs**, and **Malicious behavior**. | Mode | Behavior | | ----------- | ------------------------------------------------------------------------ | | **Detect** | Scans and reports known malicious items. No automatic quarantine. | | **Protect** | Scans, reports, **and automatically quarantines** known malicious items. | The EDR agent uses **Detect** mode for **Malware** and **PUPs**. Detections are reported in the Iru Endpoint Web App without automatic quarantine. For configuration steps, see [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item). ### Considerations * **Platform scope**: File-based and behavioral detection with malicious behavior posture * **Posture configuration**: Configure Malware, PUP, and malicious behavior posture modes independently * **Response actions**: Configure process termination, file quarantine, custom allow and block lists, and [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) from the threat detail view * **EDR deployment**: EDR is deployed as the **EDR** Library Item in Blueprints and activates automatically on enrolled devices * **Testing**: Validate your deployment using the EICAR test file; see [Testing EDR Malware Detection](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection) * **Platform scope**: File-based malware and PUP detection in Detect mode * **Posture configuration**: Malware and PUP detections are reported without automatic quarantine * **EDR deployment**: EDR is deployed as the **EDR** Library Item in Blueprints and activates automatically on enrolled devices * **Testing**: Validate your deployment using the EICAR test file; see [Testing EDR Malware Detection](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection) ### Next Steps * [Understanding the Detections Page](/en/endpoint/endpoint-detection-response-edr/understanding-the-detections-page) * [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item) * [Testing EDR Malware Detection](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection) * [Understanding Threat Events](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events) # Testing EDR behavioral detections Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-behavioral-detections Test and validate behavioral detection rules in Iru EDR. Run sample scenarios to confirm that endpoint detection alerts trigger correctly on devices. This guide applies to Mac computers ### About Behavioral Detection Testing Behavioral detection testing validates that Iru Endpoint EDR can identify and respond to suspicious or malicious activities in real-time. This testing approach simulates actual attack behaviors to ensure your EDR system is properly configured and functioning as expected. ### How It Works Behavioral detection testing uses controlled simulation techniques to trigger EDR responses without posing actual security risks. The testing process involves executing specific commands or scripts that mimic malicious behaviors, allowing you to verify that your EDR system correctly identifies and responds to these activities based on your configured posture modes. ### Prerequisites * **EDR Library Item Configuration**: Ensure that the EDR Library Item has behavioral detections enabled and has been successfully applied to the device by confirming that a green dot is visible next to the EDR Library Item located within the Status tab of a Device Record. ### Single Detection Testing via Terminal Open Terminal. Run the following command to trigger a behavioral event: ``` cp 'X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' ``` #### Expected Results in Detect Mode When the Malicious behavior response posture in the EDR Library Item is set to Detect mode: * Iru Endpoint EDR will identify the test as malicious behavioral activity. This will be reported with a status of Detected in both the Detections module (select **Detections** under **Endpoint** in the left-hand navigation) and the **Detections** tab within a Device Record. Detections page with behavioral detection status Detected in Detect mode #### Expected Results in Protect Mode When the Malicious behavior response posture in the EDR Library Item is set to Protect mode: * Iru Endpoint EDR will recognize the test as malicious activity and block it. This will be reflected with a status of Blocked in both the Detections module (select **Detections** under **Endpoint** in the left-hand navigation) and the **Detections** tab within a Device Record. Endpoint Detection Response behavioral detection testing interface or results ### Multiple Detection Testing via Attack Simulation Script #### Prerequisites Apple's [Xcode Developer Tools](https://developer.apple.com/xcode/resources/) are required to run this script. When you run the script, it will prompt to install Xcode Developer Tools if missing. #### Download and Execute Script The following method requires downloading and executing our [EDR Test script](https://raw.githubusercontent.com/kandji-inc/security-toolkit/main/attack-simulation/edr_test.zsh) from GitHub. The script will simulate suspicious behaviors on the device, and the resulting detections will approximate an attack scenario. While there is no danger to executing the script, the Malicious behavior response posture and the PUP response posture in the EDR Library Item should be set to Protect. This will block behaviors simulated by this script and ensures an optimal experience. Open Terminal. You can either run the following command to download the script, or you can [download it](https://raw.githubusercontent.com/kandji-inc/security-toolkit/main/attack-simulation/edr_test.zsh) from our GitHub repository: ```bash theme={null} curl -O https://raw.githubusercontent.com/kandji-inc/security-toolkit/main/attack-simulation/edr_test.zsh ``` Run the following command to make the script executable: ``` chmod +x edr_test.zsh ``` Run the following command to execute the script: ``` sudo ./edr_test.zsh ``` #### Expected Results in Protect Mode When the Malicious behavior response posture in the Library Item is set to Protect mode: * Iru Endpoint EDR will recognize the executing behaviors as malicious or suspicious, and either flag or block them * This will be reflected as seven behavioral detections. These can be found on the **Detections** page (left-hand navigation) and on the **Detections** tab of a Device Record when **Detection type** is set to **Behavioral detections** * One file detection will be listed on the **Detections** page (left-hand navigation) and on the **Detections** tab of a Device Record when **Detection type** is set to **File detections** ### Considerations * **Safe Testing Environment**: Both testing methods use controlled, non-malicious techniques that simulate attack behaviors without posing actual security risks * **Posture Mode Validation**: Test both Detect and Protect modes to ensure proper behavioral detection configuration and response capabilities * **Real-time Response**: Behavioral detections should trigger immediately when suspicious activities are detected, demonstrating real-time protection capabilities * **Both test methods**: Use both single detection and attack simulation to validate behavioral detection * **Script Safety**: The attack simulation script is designed to be safe and will not cause actual harm to your system, but always ensure you're testing in a controlled environment * **Detection Verification**: Always verify that behavioral detections appear in both the main Detections module and individual device records to confirm proper detection and reporting * **Regular Testing**: Incorporate behavioral detection testing into your regular security validation procedures to ensure ongoing EDR functionality * **Team Training**: Use behavioral detection testing as a training tool to help security teams understand threat detection and response workflows * **Performance Impact**: Monitor system performance during testing to ensure EDR doesn't significantly impact device performance during normal operations * **Documentation**: Keep records of your behavioral detection testing results as part of your security compliance and audit documentation # Testing EDR malware detection Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/endpoint-detection-response-testing-malware-detection Test and validate malware detection in Iru EDR on macOS and Windows using the EICAR test file and confirm Detect and Protect posture behavior. This guide applies to Mac computers and Windows devices ### About Malware Detection Testing The EICAR (European Institute for Computer Anti-Virus Research) test file provides a safe, standardized way to validate that Iru Endpoint EDR is deployed correctly. The EICAR test file is non-malicious and designed to trigger anti-malware systems without posing a security risk. For more information, visit [EICAR's Anti-Malware Test File](https://www.eicar.org/download-anti-malware-testfile/) page. ### How It Works Malware detection testing using the EICAR test file validates that Iru Endpoint EDR is functioning correctly on enrolled devices. The test file triggers file-based detection in both **Detect** and **Protect** posture modes, allowing you to confirm reporting and quarantine behavior. ### Prerequisites * **EDR Library Item deployment**: Confirm the EDR Library Item has been applied to the device. A green dot should appear next to the EDR Library Item in the **Status** tab of the Device Record. ### Create the EICAR Test File #### Option 1: Download Using Terminal Open Terminal. Run the following command to download the EICAR test file directly from EICAR onto your Desktop: ```bash theme={null} curl "https://secure.eicar.org/eicar.com" -s -o ~/Desktop/eicar_test ``` #### Option 2: Manually Build the EICAR Test File Create a new empty text file using a text editor such as VS Code or Sublime Text. You can also use TextEdit, but you will need to set it to use plain text format. Choose **Format > Make Plain Text**, or press **Shift-Command-T**, so the file stays plain text before you add the EICAR string. Copy and paste the following string into the text file: ```text theme={null} X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* ``` Save the text file to the Desktop on your Mac and name the file **eicar\_test**. #### Expected Results In **Detect** mode, Iru Endpoint EDR detects the EICAR test file and reports it with a status of **Not quarantined** on the **Detections** page (under **Endpoint** in the left-hand navigation) and in the **Detections** tab of the Device Record. Detections page with EICAR test file detected and status Not quarantined In **Protect** mode, Iru Endpoint EDR detects and automatically quarantines the EICAR test file within seconds of making the file executable (for example, run `chmod +x ~/Desktop/eicar_test`), reporting it with a status of **Quarantined** on the **Detections** page and in the **Detections** tab of the Device Record. EDR threat detail with status Quarantined after EICAR executable bit added If Windows Defender is installed and active on the test device, it may detect and capture the EICAR file before Iru EDR does. Consider adjusting Defender settings for controlled testing, or interpret results in that context. The device must run **Windows 11 24H2 or 25H2**. ### Create the EICAR Test File On an enrolled Windows device, open a plain text editor such as Notepad. Copy and paste the following exact string into the file: ```text theme={null} X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* ``` Save the file to your Desktop as **`eicar_test.txt`** or **`eicar_test.com`**. #### Expected Results Windows EDR uses **Detect** mode only. It detects the EICAR test file and reports it as **Not quarantined** on the **Detections** page and in the **Detections** tab of the Device Record. Detections page with EICAR test file detected and status Not quarantined The 68-character EICAR string is the standard Anti-Malware Test File contents. Admins can view detected threats, quarantine actions, and security events on the **Detections** page in the Iru Endpoint Web App. ### Considerations * **Safe testing**: The EICAR test file is completely safe and designed specifically for anti-malware validation * **Posture mode testing**: Test both Detect and Protect modes to confirm your EDR Library Item settings * **Status verification**: Verify threat status in both the Detections module and individual device records * **macOS Protect mode**: Quarantine occurs after the EICAR file is made executable * **Windows Defender**: Account for Microsoft Defender behavior when interpreting test results on Windows * **Regular testing**: Include EICAR testing in periodic security validation procedures * **Documentation**: Record test results as part of compliance and audit documentation # Security Operations Actions in Endpoint Detection Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection Manage threat detection status, apply tags, and take response actions in Iru EDR. This guide applies to Mac computers and Windows devices ### About Security Operations Actions Security Operations (SecOps) actions are the controls available in an endpoint security or EDR workflow that let administrators review detections and take follow-up steps such as updating status, investigating details, isolating compromised devices, or performing other response tasks in the Iru Endpoint Web App. In Iru Endpoint Detection & Response, these actions are surfaced on the Detections page and include updating the detection's Status to track progress through review and remediation. ### How It Works Security Operations actions provide a structured approach to threat management through status tracking and tagging systems. The **Status** action on the Detections page in Endpoint Detection lets you track and update detection events as you work through them. As an admin, you can manually mark detections as **Open** or **Closed**, while Iru Endpoint automatically assigns other statuses based on timing, such as when the detection first occurred or how long it's been resolved. This creates a consistent workflow that helps you see what's new, what needs attention, and what's been handled, making it easier to triage threats and track progress across your fleet. The **Status** column is available in the detections table for file detections on all platforms. On Mac computers, it is also available for behavioral detections. ### Understanding Detection Status Types Detection events can have one of four statuses: * **New**: Occurred within the last 24 hours * **Open**: Not yet marked as closed * **Closed**: Resolved by manually marking as Closed * **Archived**: Closed for more than 30 days **Automatic management**: The **New** and **Archived** statuses are set automatically by Iru Endpoint. You can manually change a detection between **Open** and **Closed**. ### Filtering Detection Events by Status You can filter detection events by status on the **Detections** page: * **Event filter**: By default, shows **New**, **Open**, and **Closed** events. **Archived** events are hidden unless selected. * **Device filter**: Located in the side panel, allows filtering devices by **Open** or **Closed** detections. ### Changing Detection Status Updating statuses regularly helps keep detection lists accurate and improves filtering for active threats. Select the detection(s) using the checkbox. Click **Change Status** in the action bar. Choose the new status from the dropdown menu. Click **Change** to apply. You can update detections individually or in bulk. ### Platform-Specific Response Actions ### Device Isolation Device Isolation is a critical security operations capability that allows administrators to immediately quarantine a device from the network when it's suspected of being compromised or under active threat. The detections side panel provides access to [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) for Mac computers. Device Isolation provides two isolation levels: * **Partial Isolation**: Disconnects the device from the network while maintaining MDM agent connectivity for remote remediation actions * **Complete Isolation**: Completely cuts off all network communication, with release from isolation being the only available remote action Device Isolation can be performed on individual devices or in bulk across all devices affected by a specific threat detection. Isolation and release actions are recorded on the [Unified Activity](/en/iru/platform-overview/unified-activity). For detailed instructions on isolating and releasing devices, see the [Device Isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) article. Status updates and tag management above apply to Windows file detections. Use **Change Status** and **Assign tags** to track and organize malware and PUP detections on enrolled Windows devices. ### About Detection Organization Tags Tags provide a flexible way to organize, filter, and manage threats based on your team's specific operational needs. These admin-defined tags let you categorize detections with custom labels that match your workflow. The Detections page includes a Tags column, giving you visibility into which tags are associated with each threat. If a threat has multiple tags, you can hover over the column to see the full list. ### Managing Tags #### Creating Tags You have full control over your tags. To create, modify, or delete tags, click the **Manage Tags** button. This allows you to customize and maintain a tagging system that aligns with your team's operational needs. Select the **Manage Tags** icon in the upper right-hand corner of the Detections page. Click **Add Tag**. Enter your desired **tag text**. Select the **checkmark** to save, and repeat as desired for the number of tags you want to add. **Close** the modal. Manage tags modal for creating and managing threat and device tags #### Updating Tags Select the **Manage Tags** icon in the upper right-hand corner of the Detections page. Click the **pencil icon** next to the tag you want to edit. Update the **tag text**, then click the **check**. **Close** the modal. #### Deleting Tags Select the **Manage Tags** icon in the upper right-hand corner of the Detections page. Select the **Trash** icon to the right of the threat. **Close** the modal. #### Assigning Tags to Detections Select one or more **detections** from the list. Click on the **ellipsis** in the lower left corner. Select **Assign tags**, and select your tags from the list. Assign tags option and tag list for threat detection ### Filtering Detections by Tags You can filter the detections table by selecting one or more tags from the top filter. This helps you focus on specific types of threats or tasks. ### Considerations * **Status Management**: Regularly update detection statuses to maintain accurate threat tracking and improve filtering effectiveness * **Tag Strategy**: Develop a consistent tagging strategy that aligns with your team's operational workflows and threat classification needs * **Bulk Operations**: Use bulk status changes and tag assignments to efficiently manage multiple detections simultaneously * **Filter Combinations**: Combine status and tag filters to create focused views for specific threat types or operational priorities * **Team Collaboration**: Establish clear guidelines for status updates and tag usage to ensure consistent threat management across your security team * **Automated Statuses**: Understand that **New** and **Archived** statuses are automatically managed by Iru Endpoint based on timing, while **Open** and **Closed** require manual intervention * **Threat Prioritization**: Use status and tag combinations to prioritize threats that require immediate attention versus those that can be addressed later # Understanding the Detections Page Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/understanding-the-detections-page Navigate the Iru Endpoint Detections page. Review dashboard widgets, filters, the detections table, threat detail views, and device record detections. This guide applies to Mac computers and Windows devices ### About the Detections Page The **Detections** page in the Iru Endpoint Web App is where admins review threat events, monitor trends, and take response actions for devices with the EDR Library Item assigned. Access it by clicking **Detections** in the left-hand navigation bar (under **Endpoint**). For an overview of EDR capabilities and posture modes, see [Endpoint Detection & Response (EDR) Overview](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview). ### Dashboard Widgets #### Detections Over Time The **Detections Over Time** graph displays a chronological overview of security threats detected within a specified timeframe. By default, the graph shows data for the past 30 days. At the top of the **Detections** tab, click the date range beside **Viewing** (default **Last 30 days**) to change the period, such as **Last 24 hours** through **Last 90 days**, **All time**, or **Custom date range**. If you choose a date range exceeding 90 days, the system automatically limits the display to 90 days. The graph offers three visualization options: * **Granular:** Shows every individual threat detection * **Smooth:** Displays general trends and patterns * **Balanced:** Default setting between detailed data and trend visualization Detections Over Time graph on the Detections page #### Detections By Severity The **Detections By Severity** view provides a visual breakdown of detections by severity level. Each detection is assigned one of five severity levels: Critical, High, Medium, Low, and Informational. Iru Endpoint Detections page dashboard with Detections over time graph, Detections by severity donut chart and severity legend, and Devices under threat count #### Devices Under Threat The **Devices Under Threat** metric shows how many devices currently have active security threats. Adjust the timeframe using the date range at the top of the page. This data refreshes each time the page is loaded. Devices Under Threat metric on the Detections page #### Filter by Date Range On the **Detections** tab, click the date range at the top of the page to choose how far back threat events appear. The current range is shown to the right of **Viewing** and defaults to **Last 30 days**. Select a preset (**Last 24 hours**, **Last 7 days**, **Last 30 days**, **Last 60 days**, **Last 90 days**, or **All time**) or **Custom date range** for specific start and end dates. Your selection applies to the dashboard widgets and the detections table. Iru Endpoint Detections page with Last 30 days date range menu open next to Viewing, showing Last 24 hours through Custom date range ### Search, Filters, and the Detections Table Above the detections table, use **Search** and the filter dropdowns to narrow the list by detection type, classification, status, severity, and other criteria. Iru Endpoint Detections page showing Search field and filter dropdowns above the detections table The **Detections List** (detections table) shows each threat event with columns such as threat name, classification, severity, detection date, number of affected devices, and status. Click a row to open the side panel with full details and response actions. Detections List (detections table) on the Detections page ### Threat Detail View Click any threat event to open a side panel with detection and quarantine dates, file path, file hash, user information, and available response actions. Endpoint Detection and Response EDR threat detail view For investigation workflows, status changes, and response actions, see [Understanding Threat Events](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events) and [Security Operations Actions in Endpoint Detection](/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection). ### Device Record Detections Tab The device record page shows the total number of threat events found on a specific device. To see the actual threat events, select the **Detections** tab. Endpoint Detection and Response EDR device record view Select any threat entry to display the detection timestamp, quarantine date, file location, cryptographic hash, and related user account. Endpoint Detection Response overview showing EDR interface or configuration For more details about how device views work, see [Device Views Overview](/en/endpoint/devices/device-views-overview). ### Platform-Specific Detections Features Iru Endpoint EDR categorizes file detections as malware, PUPs, benign, or unknown, and behavioral detections as malicious or suspicious. Use the **Detection type** filter on the detections table to show **File detections**, **Behavioral detections**, or both. The threat detail side panel provides [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) for quarantining affected devices from the network. #### Rules Tab The **Rules** tab on the Detections page lets you configure behavioral detection rule groups and detection levels. From here you can set a global rule detection level or set detection levels per rule group (Cautious, Moderate, or Aggressive), and manage rule exceptions. For full details, see [Behavioral Detection Rule Groups](/en/endpoint/endpoint-detection-response-edr/behavioral-detection-rule-groups). Rules tab on the Detections page Windows EDR categorizes file detections as malware, PUPs, benign, or unknown. Use the **Classification**, **Severity**, and **Status** filters to investigate malware and PUP detections on enrolled Windows devices. ### Next Steps * [Understanding Threat Events](/en/endpoint/endpoint-detection-response-edr/understanding-threat-events) * [Security Operations Actions in Endpoint Detection](/en/endpoint/endpoint-detection-response-edr/security-operations-actions-in-endpoint-detection) * [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item) # Understanding Threat Events Source: https://docs.iru.com/en/endpoint/endpoint-detection-response-edr/understanding-threat-events Understand threat events in Iru EDR including detection types, severity levels, and classification categories. Investigate and respond to security alerts. This guide applies to Mac computers and Windows devices ### About Threat Events Endpoint Detection and Response (EDR) creates a threat event when it identifies malware or potentially unwanted programs (PUPs) on a device. Each threat event includes details such as the threat name, classification, process involved, detection date, and current status. You can find all threat events on the Detections page for devices linked to Blueprints with EDR. Additionally, these events are viewable on individual device records. Threat events are created in both Detect and Protect posture. In Protect posture, the threat is also quarantined. Threat events are created in Detect posture and reported without automatic quarantine. ### How It Works The threat events are automatically created when Iru Endpoint EDR identifies potential security risks on managed devices. The system organizes threat events in a threat-centric table view, grouping events by file hash for file detections and by detection rule for behavioral detections. This structure simplifies assessing a threat's impact across your Mac fleet. Each grouped event includes a side panel that provides detailed insights into the threat, enabling security teams to quickly understand the scope and severity of detected threats. ### Understanding Event Information Each threat event in the threat-centric table view provides essential information to assist InfoSec teams in investigating threats. * **Threat ID**: Displays the SHA-256 hash value of the detected threat * **Process**: Shows the most recently detected process responsible for the threat * **Classification**: Indicates the classification category of the threat event * **Detection Date**: Records the date when EDR identified the threat * **Devices**: Lists the total number of Mac devices affected by the threat event * **Threat Status**: Detected, Remediated, and Released counts across all devices for the grouped threat event ### Understanding Detection Severity Levels Iru Endpoint EDR includes severity scoring to help InfoSec teams quickly assess the criticality of detected threats. Each detection event is assigned one of five severity levels: Critical, High, Medium, Low, and Informational. The detections table includes a **Severity** column that displays the corresponding severity level for each detection. You can sort and filter detections based on severity for both file detections and behavioral detections. The Detections page also features a **Detections By Severity** pie chart that provides a visual breakdown of detections organized by their severity levels. ### Understanding Threat Classifications Iru Endpoint EDR classifies threats into four categories for file detections (malware, potentially unwanted program (PUP), benign, and unknown) and two categories for behavioral detections: malicious and suspicious. #### File Detection Classifications * **Malware**: This term refers to malicious software designed to harm devices, individuals, or organizations * **Potentially Unwanted Program (PUP)**: These are applications that might be unwanted on a device. PUPs often use high system resources, affecting performance, displaying unwanted ads, and collecting personal information. Unlike malware, PUPs are not intended to cause harm and are usually installed inadvertently with other software, often found in bundled packages * **Benign**: This classification is for files initially flagged as malicious but later determined to be non-malicious after further analysis. If you encounter benign threat events, it might be because the item was in your EDR Library Item block list at the time of detection or quarantine * **Unknown**: This category is for files that Iru Endpoint EDR cannot definitively classify as either malicious or benign based on the available data. Classification may change if more information becomes available or if the file is re-analyzed. #### Behavioral Detection Classifications * **Malicious**: A classification that refers to a behavioral activity that intends to cause harm * **Suspicious**: A classification that refers to behavioral activity that does not immediately indicate harm but warrants attention for further investigation ### Understanding Threat Statuses All threat events will have a status associated with them. The various statuses that a threat event may have are: #### File Detection Statuses * **Quarantined**: A detected threat that was automatically quarantined in Protect posture (macOS) * **Not Quarantined**: A detected threat that was not quarantined in Detect posture * **Released**: A threat that was initially quarantined but later released and restored to its original location (macOS) * **Resolved**: A detected threat that is no longer at the last detected file path and was not quarantined by the agent #### Behavioral Detection Statuses * **Detected**: Malicious behavioral activity was identified but not blocked (Detect posture) * **Blocked**: Malicious behavioral activity was identified and blocked (Protect posture) * **Informational**: Suspicious behavioral activity was detected and flagged for visibility On macOS, quarantining of Malware and PUP is determined by the posture mode configured in the EDR Library Item. Please see [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item) for more information on how to configure posture modes in your environment. ### Viewing Detections In the left-hand navigation bar, select **Detections** (under **Endpoint**). Use the **Detection type** filter to show **File detections**, **Behavioral detections**, or both in the same table. ### Filtering Threat Events You can filter threat events for both file and behavioral detections based on their status for easier visualization and remediation. At the top of the Detections page, click the date range beside **Viewing** (default **Last 30 days**) to limit threat events to a period, such as **Last 7 days** or **Custom date range**. Filter by **Classification** to show only certain threat types. For file detections, choose malware, PUP, benign, or unknown; for behavioral detections, choose malicious or suspicious. Choose **Threat status** to filter by remediation state (Quarantined, Not quarantined, Released, Resolved for file detections; Detected, Blocked, or Informational for behavioral). You can select one or multiple. Filter by **Status** to focus on workflow state: **New** (last 24 hours), **Open**, **Closed**, or **Archived**, so you can triage what needs attention versus what’s been handled. Filter by **Severity** (Critical, High, Medium, Low, or Informational) to prioritize which threats to investigate or remediate first. Filter by **Tags** to show only threats that have a specific admin-defined tag, or leave as All to include every tag. Use the **MITRE** filter to narrow the list by MITRE ATT\&CK technique. Search or select specific techniques to show only behavioral events that match the selected techniques. Click **Clear all** to remove all filters and return to the default view for the selected date range. Detections page showing Search and filter dropdowns for Detection type, Classification, MITRE, Status, Severity, Tags, and Device Isolation above the detections table ### Side Panel The threat-centric table view features a side panel for each grouped event, which can be opened by clicking on a threat event row to access detailed information about that specific threat. For file detections, the side panel includes: * Latest file name associated with the threat * A global view of all threat statuses (Detected, Remediated, and Released) for the grouped threat event across all devices * First and last detection dates across all devices * Insights on all unique file paths found related to the threat For behavioral detections, the side panel includes: * The latest process name associated with the grouped event * A global view of all threat statuses (Detected, Remediated, and Released) across all devices * A description of the malicious or suspicious activity * The malware family associated with the behavioral activity * Informational tags providing additional context * The first and last detection dates across all devices #### Device Cards Device cards in the side panel represent devices where the malicious file was found. From the side panel, you can also perform response actions such as [isolating devices](/en/endpoint/endpoint-detection-response-edr/device-isolation) to quarantine them from the network during active security incidents. For file detections, these cards will display information such as: * **Device Name** * **Serial Number** * **Blueprint and Library Item** * **Malware and PUP Posture Mode** * **Actionable Events** * **Threat event details:** * **Threat Status** - The current status of the threat on the device. * **Path** - The file path where the threat was detected. * **User** - The user associated with the process when the threat was detected. * **Detection Date** - The date when EDR identified the threat. * **Quarantine Date** - The date when EDR quarantined the threat. * **Resolved Date** - The date when the threat was marked as resolved in the web app. * **Release Date** - The date when the threat was released from quarantine on the device. * **Application Bundle Path** - The path to the application bundle. For behavioral detections, these cards will display information such as: * **Device name** * **Serial number** * **Blueprint and Library Item** * **Malicious behavioral detection posture mode information** * **Threat event details:** * **Threat Status** - The current status of the threat on the device. * **Detection date** - The date when EDR identified the threat. * **Rule version** - Current rule version * **Parent and target process information:** * Parent and target process name * Parent and target process ID * Process owner * Image paths for parent and target processes * Command line arguments for parent and target processes * SHA-256 hash of the parent and target processes ### Viewing Threat Events in the Side Panel #### For File Detections On the left-hand navigation bar, select **Detections** (under **Endpoint**). In the **Detection type** filter, select **File detections** to focus on file-based threat events. Click on any **threat event** to open the side panel. In the **Devices** tab, view the device cards for all devices where the malicious hash was detected. Click any device card to expand it and view associated threat events. From this view, you can also [isolate devices](/en/endpoint/endpoint-detection-response-edr/device-isolation) from the network using the Globe icon. #### For Behavioral Detections In the left-hand navigation bar, select **Detections** (under **Endpoint**). In the **Detection type** filter, select **Behavioral detections** to focus on behavioral threat events. Click on any **threat event** to open the side panel. ### Rechecking the Status of a Threat When the Malware or PUP posture modes are set to Detect, you can manually check a threat's status in the side panel to see if it's still present at the file path. If the threat is no longer there, its status will update from 'Not quarantined' to 'Resolved.' If the threat is still present, its status will remain unchanged. On the left-hand navigation bar, select **Detections** (under **Endpoint**). Click on any **threat event** to open the side panel. Click the desired **device card** to expand it and view the device's threat events. From this expanded view, you can also access response actions including [device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation). Click **Recheck status**. Recheck status in threat event side panel On macOS, when threats are initially detected and removed from a device, their status will change from **Not quarantined** to **Resolved** once the Malware or PUP posture modes in the EDR Library Item are set to Protect mode. This update also occurs when a new Blueprint with these settings is applied to the device. ### Releasing a Threat Event There might be situations where InfoSec teams need to release a threat event for specific files or applications that were mistakenly quarantined, such as a security tool or application used by the organization. Releasing a threat event involves adding the item to the Allow list for the associated EDR Library Item. The threat event release action will only apply to the Blueprints assigned to the EDR Library Item. Releasing a threat will release it from all Mac computers where the threat has been detected. On the left-hand navigation bar, select **Detections** (under **Endpoint**). Click on any **threat event** to open the side panel. Click the desired **device card** to expand it and view the device's threat events. Click **Release threat**. Release threat flow in threat event side panel Enter an **Item Name**. Optionally, enter an internal note stating why the threat event is being released. Type **RELEASE** to release the threat. Click **Add and Release** to add the threat to your Allow list and release the threat. ### Performing a VirusTotal Search VirusTotal analyzes files and URLs. From a threat event, you can search the hash in VirusTotal without leaving the Iru Endpoint web app. On the left-hand navigation bar, select **Detections** (under **Endpoint**). Click on the desired threat event to open the side panel. Click **Search VirusTotal** at the top of the side panel. Search VirusTotal from the threat event side panel Iru Endpoint EDR may classify certain hashes as malware or PUP, even if VirusTotal has no detections on them or considers them non-malicious; this is expected due to Iru Endpoint EDR's utilization of multiple threat sources. ### Exporting Threat Events in CSV In addition to using the Iru Endpoint API, InfoSec and IT teams can export the list of threat events directly from the admin console. The export icon in the threat-centric view applies the current filter settings and generates a CSV file with detailed information about each threat event in separate columns. This feature is available in both the main Detections module view and the Detections tab under Device Record. On the left-hand navigation bar, select **Detections** (under **Endpoint**). Optionally use the **Detection type** filter to select **File detections** or **Behavioral detections** before exporting. Click the **Export** icon on the far right of the threat events list view. A CSV export file will download automatically. ### Considerations * **Threat Classification**: Understand the difference between file detection classifications (malware, PUP, benign, unknown) and behavioral detection classifications (malicious, suspicious) for proper threat assessment * **Status Management**: Regularly review and update threat statuses to maintain accurate security posture and ensure proper remediation tracking * **Severity Prioritization**: Use severity levels (Critical, High, Medium, Low, Informational) to prioritize threat response efforts and allocate resources effectively * **Posture Configuration**: On macOS, ensure EDR Library Items are configured with appropriate posture modes (Detect vs. Protect) based on your security requirements. Windows EDR uses Detect mode for file detections. * **Threat Investigation**: Use the side panel and device cards for file paths, user context, and detection timelines * **False Positive Management**: Be prepared to release legitimate applications that may be mistakenly quarantined, using the threat release process with proper documentation * **External Validation**: Use VirusTotal integration to cross-reference threat intelligence and validate threat classifications * **Data Export**: Use CSV export for threat analysis, reporting, and integration with other security tools * **Bulk Operations**: Consider using bulk actions for efficient threat management when dealing with widespread threats across multiple devices, including [bulk device isolation](/en/endpoint/endpoint-detection-response-edr/device-isolation) capabilities * **Regular Monitoring**: Establish regular review processes for threat events to ensure timely response and proper classification of security incidents # Configuring Android Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/android/configuring-android-enrollment Configure Android device enrollment in Iru Endpoint. Set up Android Enterprise, connect Google Workspace, and enable work profile management. This guide applies to Android devices Android devices in Iru Endpoint use the Android Management API with work profile management for secure enterprise device management. This approach provides complete separation between work and personal data while giving organizations full control over work-related applications and policies. For enabling the Android platform and a quick enrollment overview, see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) and [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ## How Android Enrollment Works Android enrollment in Iru Endpoint uses Google's Android Management API to create and manage work profiles on Android devices. When users enroll their devices, a work profile is created that completely isolates work applications and data from personal content. Blueprints can use Assignment Maps to apply conditional logic based on device attributes, user information, or other organizational criteria. The enrollment process establishes a secure connection between the Android device and Iru Endpoint through Google's Android Management API, providing enterprise-grade security and management capabilities while maintaining user privacy for personal data. ## Prerequisites Before configuring Android enrollment, ensure you have: * **Android Enterprise** configured in Iru Endpoint (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup)) * **Super admin** access to your organization's Google Admin console ([learn more about super admin roles](https://support.google.com/a/answer/2405986?hl=en\&sjid=10473235341862195521-NA)) * **Third-party Android mobile Management** enabled in Google Workspace (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup)) * **Company-owned Android devices** in factory reset state (Android 13 and higher required) * **Blueprint** configured for Android devices * **(Recommended)** **Single sign-on (SSO)** configured for secure authentication ## Configure Android Enterprise Complete Android platform enablement and Android Enterprise integration before configuring enrollment. See [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) for enabling the Android platform in Organization settings. ## Configure Android Enrollment a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint. b. Ensure the **Enrollment Portal** is active. c. Under **Choose an enrollment method**, select **Android work profile** and locate the desired **Blueprint**. Copy the **Blueprint link** for that Blueprint. If **Require authentication** is enabled on the Blueprint, end users will need to authenticate to view the instructions. a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment. Optionally check the box to **Assign user to device record** to match the authenticated user to a user in your directory integration. b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps. a. Share the **Blueprint link** with end users to enroll company-owned Android devices with work profile. b. Provide clear instructions for the Android enrollment process, including the requirement for a secondary device to view the enrollment instructions and QR code. c. Consider creating a dedicated email or help article with the Blueprint link and these instructions for consistency. Each QR code can only be used once. If a user needs to enroll multiple devices, they must refresh the enrollment instructions page after each enrollment to generate a new QR code. ## Verify Enrollment In Iru Endpoint, open **Devices** Locate the newly enrolled Android device (search by user email, device name, or serial number) Confirm the device shows as enrolled with work profile management Verify that work applications are being deployed to the work profile ## Android-Specific Considerations ### Device Requirements Devices must be in a factory restored state to enroll and need to be compatible with most modern Android versions. The device must have Google Play Services installed and needs internet connectivity for enrollment. ## Best Practices Test Android enrollment with a small pilot group before full deployment Provide clear instructions to users about work profile setup and usage Monitor enrollment success rates and address any issues promptly Require authentication for enrollment and link Blueprints to your identity provider. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for configuration. Provide training on work profile features and benefits. See [User Experience with Android Enrollment](/en/endpoint/enrollment/android/user-experience-with-android-enrollment) for end-user guidance. Pre-stage Wi-Fi, certificates, SCEP, and password policies in the Blueprint so devices come online with required trust and connectivity. ## Troubleshooting **Possible causes:** * Device not in factory restored state * Network connectivity issues * Google Play Services not available **Solutions:** * Ensure device is factory reset before attempting enrollment * Check internet connectivity * Verify Google Play Services is installed and updated **Possible causes:** * Android Enterprise not properly configured * Device compatibility issues * User permissions problems **Solutions:** * Verify Android Enterprise integration is working * Check device compatibility with Android Enterprise * Ensure the user has proper permissions for work profile creation **Possible causes:** * Work profile not properly set up * App compatibility issues * Policy restrictions **Solutions:** * Verify work profile is active and properly configured * Check app compatibility with work profile * Review policy settings for app installation **Possible causes:** * Authentication required but user not authenticated * Incorrect Blueprint link * Network access issues **Solutions:** * Verify user authentication if required * Check Blueprint link is correct * Ensure user has network access to open the Blueprint link ## Android Management API Features ### Security Capabilities The Android Management API supports QR code enrollment, built-in security features, and work profile management. For company-owned work profile devices, Google provides some EMM reach into personal settings. ### Application Management You can deploy work applications to work profiles, manage application updates centrally, remove work applications when needed, and control which apps can be installed in both work and personal profiles. ### Policy Enforcement Iru Endpoint can enforce security settings on work profiles and some personal settings including: * Require passcodes * Block specific personal apps * Block camera and screenshot on personal side * Disable apps from unknown sources * Disallow developer mode * Deploy and configure work apps ### Device Management Iru Endpoint can also wipe the entire device when needed for security purposes. For more information about Android Management API capabilities, see [Google's Android Management API documentation](https://developers.google.com/android/management). ## Related Articles What to expect when enrolling your Android devices and setting up a work profile Set up work profile enrollment for Android devices Configure Apple device enrollment with Automated Device Enrollment (ADE) Complete guide to Windows device enrollment and management setup # User Experience with Android Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/android/user-experience-with-android-enrollment Walk through the Android enrollment experience step by step. See what users encounter when setting up a work profile and enrolling in Iru Endpoint. This guide applies to Android devices This guide walks you through enrolling your Android device with your organization's device management system. Android management uses Google's Android Management API with work profile technology to keep your work and personal data completely separate. You'll need the **Blueprint link** (which contains an embedded **Enrollment code**) provided by your IT team, and a second device (computer, tablet, or phone) to view the enrollment instructions and QR code. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding when you enroll your device, including in enrollment screens and links. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. If something still refers to Kandji, use the updated Blueprint link or guidance from your IT team. ## What to Expect When you enroll your Android device, a work profile will be created that isolates your work applications and data from your personal content. This allows your IT team to: * Deploy, upgrade, and uninstall company applications in the work profile * Apply security policies and settings to work data * Block specific personal apps and features (camera, screenshot, unknown sources) * Require passcodes and disable developer mode * Monitor work profile compliance and security Your personal data, applications, and settings remain mostly private, though your IT team has some control over personal settings for company-owned devices. ## Prerequisites Before starting, make sure you have: * **Blueprint link** - provided by your IT team * **Second device** - computer, tablet, or phone to load the Blueprint link and display enrollment instructions * **Work or school account** - your organization email and password (only required if authentication is enabled on the Blueprint) * **Android device** - in factory reset state Your device may need to be factory reset before enrollment. Check with your IT team about this requirement before starting the enrollment process. ## Android Enrollment Process On your second device (computer, tablet, or phone), open a web browser and go to the **Blueprint link** provided by your IT team. If you have trouble opening the link, see [Troubleshooting](#troubleshooting). If prompted, **sign in** with your **work or school account**. You may be redirected to your company's sign-in page. Use the same email and password you use for work. Review the enrollment instructions and locate the **QR code** displayed on the page. Follow the enrollment instructions provided in the Blueprint link. The process is mostly automated - you'll primarily need to press **Next** or **Continue** to proceed through the steps. If your organization requires a work profile PIN, you'll be prompted to create one. This only happens if your Blueprint contains the Android Work Passcode Library Item. ## After Enrollment Once enrollment is complete: * **Work profile** will be created and visible on your device * **Company applications** will begin installing automatically in the work profile * **Security policies** will be applied to work data * **Work profile sync** happens automatically to keep work settings current It may take several minutes for all company applications to appear in your work profile. If something doesn't appear immediately, wait a few more minutes and check again. ## Troubleshooting **Possible causes:** * Incorrect Blueprint link * Network connectivity issues * Firewall blocking access **Solutions:** * Double-check the Blueprint link provided by your IT team * Check your internet connection on the device opening the link * Contact your IT team if the problem persists **Possible causes:** * Incorrect email or password * Account not set up for enrollment * Issues with your company's sign-in page **Solutions:** * Make sure you're using your work or school email and password * Try signing out and signing back in * Contact your IT team if you still can't sign in **Possible causes:** * Device not in factory reset state * Network connectivity issues on the Android device * Google Play Services not updated **Solutions:** * Confirm with your IT team whether the device needs to be factory reset first * Check your Android device's internet connection * Make sure Google Play Services is up to date * Contact your IT team if the problem persists **Possible causes:** * Enrollment did not complete * Device compatibility issues * Network connectivity issues **Solutions:** * Wait a few minutes and check for the work profile again * Restart your device and try opening the Blueprint link again * Contact your IT team if the work profile still doesn't appear **Possible causes:** * Enrollment still in progress * Network connectivity issues * Work profile sync hasn't completed **Solutions:** * Wait 5–10 minutes for your device to finish setting up * Check your internet connection * Restart your device and wait a few more minutes * Contact your IT team if apps still don't appear after 30 minutes # Activation Lock Source: https://docs.iru.com/en/endpoint/enrollment/apple/activation-lock Manage Activation Lock on supervised Apple devices in Iru Endpoint. Bypass, enable, or disable Activation Lock for Mac, iPhone, iPad, and Apple TV. This guide applies to Apple devices **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### What is Activation Lock? Activation Lock is a security feature developed by Apple to help prevent unauthorized use of Apple devices if they are lost or stolen. This feature is part of the "Find My" service and is designed to deter theft by making it difficult for anyone other than the owner to use or sell the device. ### How Activation Lock Works Activation Lock is automatically enabled when a user sets up the "Find My" feature on their device. Here's how it functions: When "Find My" is turned on, the user's [Apple Account](/en/endpoint/enrollment/apple/apple-accounts-overview) is securely stored on Apple's activation servers and linked to their device. Each time the device is activated or recovered, it contacts Apple to check if Activation Lock is enabled. To turn off "Find My," erase the device, or reactivate it, the user must supply the Apple Account password. For corporate-owned devices, Iru Endpoint can be used to manage Activation Lock. Upon enrollment, a bypass code can be generated to unlock devices without the Apple Account and password, which is useful when reassigning devices to new users. In addition, for devices listed in **Apple Business** or **Apple School Manager**, Activation Lock can be disabled remotely by administrators with the Device Manager role in that portal. ### User-based Activation Lock User-based Activation Lock is activated when a device user signs in with their personal Apple Account and enables Find My Device. This feature is also known as iCloud Activation Lock. #### How to Prevent User-based Activation Lock By default, user-based Activation Lock is not allowed on supervised devices. When iOS, iPadOS, visionOS or macOS devices are enrolled into Iru Endpoint via Automated Device Enrollment, the Activation Lock Allowed While Supervised MDM option is set to false. However, you can modify the Automated Device Enrollment configuration before enrolling the device if you wish to allow user-based Activation Lock. Although Activation Lock is tied to "Find My", preventing Activation Lock will not prevent users from logging into "Find My". #### Special Considerations for Mac Computers For Mac computers that are already set up and enrolled in Iru Endpoint, there are a few things to consider: * **Pre-enrollment Activation Lock:** If a user enabled user-based Activation Lock before enrollment, it will remain enabled. * **Bypass Code Generation:** If the Mac was not previously supervised by an MDM, Iru Endpoint will generate and retrieve a bypass code. However, this code cannot retroactively disable an existing user-based Activation Lock. For the bypass code to be effective, the user must turn off Find My Mac and then turn it back on. * **Migration from Another MDM:** If a Mac is migrating from one MDM to Iru Endpoint, the existing Activation Lock bypass code may have expired, and Iru Endpoint will not be able to retrieve it. Bypass codes can only be retrieved within 30 days after the device is supervised. Therefore, it is recommended to retrieve these codes from the previous MDM before migration. #### User-based Activation Lock Bypass Code If you allow user-based Activation Lock and need to clear it (for example, when reassigning a device), first retrieve the bypass code from the device record in Iru Endpoint. Then enter that code on the device. The place you enter it depends on the platform: Setup Assistant on iPhone, iPad, and Apple Vision Pro; Finder on iPhone and iPad; or macOS Recovery on Mac. Bypass codes are available for supervised iOS, iPadOS, visionOS, and macOS devices (Mac computers with T2 or Apple silicon). Activation Lock status fields also appear on the device record **Details** tab. See [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details). Viewing bypass codes requires a role that can read Activation Lock secrets (for example, **Secrets Auditor**). See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). ##### Retrieve the bypass code Navigate to **Devices** in the Iru Endpoint web app and select the supervised device. Click the **Device Action Menu** at the top right of the device record. Select the option to view the Activation Lock bypass code, then copy the **user-based** bypass code. Keep this code available before you erase or restore the device. ##### Setup Assistant On iPhone, iPad, or Apple Vision Pro, when the Activation Lock screen appears during Setup Assistant (for example, after an erase), leave the Apple Account field blank and enter the user-based bypass code in the password field. ##### Finder On iPhone or iPad, connect the device to a Mac with a cable. In Finder, when you are prompted for Activation Lock credentials, leave the Apple Account field blank and enter the user-based bypass code in the password field. ##### macOS Recovery On a Mac at the Activation Lock screen, open **Recovery Assistant** in the menu bar and select **Activate with MDM Key...**. Enter the user-based bypass code when prompted. ### Device-based Activation Lock Device-based Activation Lock is enabled by an MDM solution submitting an API request to Apple's Device Assignment Service API. This feature is sometimes referred to as MDM or organization-based Activation Lock and is currently supported only on iOS, iPadOS, and visionOS devices. #### How to Enable Device-based Activation Lock To enable device-based Activation Lock, you need to modify the Automated Device Enrollment configuration before enrolling the device. Ensure you enable this setting separately for the iPhone, iPad and Vision sections within the Automated Device Enrollment configuration. Automated Device Enrollment configuration with Activation Lock setting for iPhone iPad and Vision #### Device-based Activation Lock Bypass Code If you enable device-based Activation Lock and need to clear it, retrieve the **device-based** bypass code from the device record using the same Device Action Menu path described in [Retrieve the bypass code](#retrieve-the-bypass-code), then enter that code on the device with the Setup Assistant or Finder methods above. You can also clear Activation Lock by signing in with the Managed Apple Account of the **Apple Business** or **Apple School Manager** user who created the Automated Device Enrollment token. To turn Activation Lock off from those portals instead, see [Removing Activation Lock using Apple Business or Apple School Manager](#removing-activation-lock-using-apple-business-or-apple-school-manager). ### Removing Activation Lock using Apple Business or Apple School Manager In **Apple Business** or **Apple School Manager**, you can disable Activation Lock for devices owned by your organization. The device must be listed in the same portal; it does not need to be associated with an MDM server. For step-by-step instructions, see the following Apple Support articles: * [Turn off Activation Lock in Apple Business](https://support.apple.com/guide/business/turn-off-activation-lock-axm812df1dd8/web) * [Turn off Activation Lock in Apple School Manager](https://support.apple.com/guide/apple-school-manager/turn-off-activation-lock-axm812df1dd8/web) If the Activation Lock bypass code is unavailable and Activation Lock cannot be removed using Apple Business or Apple School Manager, you can [contact AppleCare Enterprise Support](/en/endpoint/settings/apple-integrations/applecare-enterprise-support) for further assistance. ### Related Articles Understand Apple device supervision Configure Apple device enrollment with Automated Device Enrollment (ADE) Set up Automated Device Enrollment for zero-touch deployment and lifecycle management of corporate Apple devices # Apple Accounts Overview Source: https://docs.iru.com/en/endpoint/enrollment/apple/apple-accounts-overview Learn about Apple Account types and how they integrate with Iru Endpoint. Understand Managed Apple IDs, personal accounts, and enrollment requirements. As of macOS Sequoia and iOS/iPadOS 18, Apple IDs are known as Apple Accounts. ### About Apple Accounts An Apple Account, formerly known as an Apple ID, is the account users sign in with for Apple services such as iCloud, the App Store, iMessage, and Find My. ### Types of Apple Accounts There are two different kinds of Apple Accounts, each of which serves a different purpose in the Apple ecosystem. #### Personal Apple Accounts Personal Apple Accounts are created by individuals for personal use. They allow access to personal data and services on devices, and users manage their own account settings and security. Personal Apple Accounts are used for iCloud, iMessage, Photos, and Find My. #### Managed Apple Accounts Designed for organizations like businesses or schools, these accounts are managed through platforms such as Apple Business or Apple School Manager. They offer organizational control over accounts, including password resets and role-based access, along with options to federate using an Identity Provider (IdP). To learn more about creating and managing Managed Apple Accounts, see the [Apple Business on Apple Support](https://support.apple.com/guide/business/intro-to-managed-apple-accounts-axm78b477c81/web). For information about service access with Managed Apple Accounts, see [Apple's Service Access with Managed Apple Accounts](https://support.apple.com/en-gb/guide/deployment/depdc4ba8d82/web) guide. ### Using Apple Accounts with Iru There are various ways to use Apple Accounts with Iru. To learn more, see the following Support Articles: * [Getting Started - Apple Integrations](/en/endpoint/getting-started/platform-setup/apple-setup) * [Configure Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) * [Adding Devices to Apple Business or Apple School Manager](/en/endpoint/settings/apple-integrations/adding-devices-to-apple-business-manager) * [Activation Lock](/en/endpoint/enrollment/apple/activation-lock) * [Apple BYOD Management](/en/endpoint/enrollment/apple/apple-byod-management) # Apple BYOD Management Source: https://docs.iru.com/en/endpoint/enrollment/apple/apple-byod-management Set up Bring Your Own Device (BYOD) management for Apple devices in Iru Endpoint. Enroll personal iPhone, iPad, and Mac devices with user-initiated flow. This guide applies to Apple devices Iru Endpoint provides Bring Your Own Device (BYOD) management capabilities for Apple devices through manual enrollment, allowing organizations to securely manage employee-owned iPhones, iPads, and Mac computers. ### What is BYOD Management? BYOD management enables organizations to apply essential security policies and deploy corporate resources to employee-owned Apple devices through manual enrollment. This approach focuses on business-critical configurations for employee-owned devices. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How BYOD Management Works BYOD management in Iru Endpoint uses manual enrollment to establish a management relationship with employee-owned devices. When employees enroll their personal devices, Iru Endpoint installs a management profile that enables the organization to apply security policies and deploy corporate resources while respecting device ownership. The management profile provides a secure channel for policy enforcement and app distribution without requiring device supervision. This approach focuses on essential business configurations rather than full device control. ### BYOD Capabilities Iru Endpoint supports essential management capabilities for BYOD devices: #### Security and Compliance * **Passcode enforcement** - Require strong passcodes and biometric authentication * **Device encryption** - Ensure FileVault is enabled on Mac computers * **Certificate deployment** - Install device identity certificates for conditional access * **Network security** - Configure Wi-Fi and VPN profiles for secure connectivity #### Application Management * **Corporate app deployment** - Install and manage business applications * **App configuration** - Configure corporate apps with organization-specific settings * **App updates** - Ensure corporate applications stay current * **App distribution** - Deploy required business applications to managed devices #### System Management * **Operating system updates** - Enforce macOS and iOS updates for security * **System preferences** - Configure essential system settings * **Screen lock policies** - Enforce screen lock requirements on iOS devices * **Login window customization** - Apply organization branding on macOS devices ### Setting Up BYOD Management Create a dedicated Blueprint specifically for BYOD devices to ensure appropriate policy separation: Navigate to **Blueprints** in Iru Endpoint. Click **Create Blueprint**. Enter a descriptive name like "BYOD" or "Employee Devices". Add Library Items to your BYOD Blueprint. You can deploy any Library Items that are supported on unsupervised devices. Here are some common suggestions: * **Passcode Library Item** - Set appropriate passcode requirements * **FileVault Library Item** - Ensure Mac encryption is enabled * **Wi-Fi Library Item** - Configure corporate network access * **Certificate Library Item** - Deploy device identity certificates * **Custom Apps** - Install essential business applications Some Library Items require device supervision and won't work on BYOD devices. For details on which restrictions are available on supervised vs. unsupervised devices, see [Apple's supervision documentation](https://support.apple.com/guide/deployment/restrictions-for-supervised-devices-dep6b5ae23e9/1/web/1.0). Navigate to **Enrollment** → **Manual Enrollment**. Configure the **Enrollment Portal** settings. Select your BYOD Blueprint for enrollment. Copy the **Enrollment Portal link** and **Enrollment code**. ### User Enrollment Experience Once you've set up the enrollment portal, employees can enroll their devices by visiting the Enrollment Portal link you provide and entering the Enrollment code. If you've enabled authentication, they'll be prompted to sign in with their corporate credentials after entering the code. The device will then display the management profile details, showing employees exactly what permissions and policies will be applied. After they review and approve the management permissions, Iru Endpoint automatically applies your configured policies and installs any required apps. ### Best Practices for BYOD Apply only necessary security and productivity policies to avoid overly restrictive management of personal devices. Explain to employees what will and won't be managed on their personal devices. Periodically assess and update BYOD policies to ensure they remain appropriate and effective. Configure profiles to ensure corporate resources are accessible through managed connections. Plan for certificate renewal and distribution to maintain secure access to corporate resources. ### Enrollment Portal Configuration Share the enrollment information with your employees: ```text lines theme={null} Enrollment Portal link: https://your-tenant.iru.com/enroll Enrollment code: [Your BYOD Blueprint Enrollment code] ``` # Apple Device Supervision Source: https://docs.iru.com/en/endpoint/enrollment/apple/apple-device-supervision Learn which Apple enrollment methods create supervised devices and what additional controls supervision enables for Mac, iPhone, iPad, and Apple TV. This guide applies to Apple devices Device supervision is a critical concept in Apple device management that determines which restrictions and management capabilities are available through Iru Endpoint. Understanding supervision helps you choose the right enrollment method for your organization's security requirements. ## What is Device Supervision? Device supervision is an Apple security feature that provides enhanced management capabilities for iOS, iPadOS, and macOS devices. According to [Apple's documentation](https://support.apple.com/guide/deployment/restrictions-for-supervised-devices-dep6b5ae23e9/1/web/1.0), supervision enables additional restrictions and management features that are not available on non-supervised devices. ## How Device Supervision Works Device supervision works by establishing a trusted relationship between Apple devices and your organization through specific enrollment methods. When a device is supervised, Apple grants additional management permissions that allow Iru Endpoint to apply more restrictive policies and control more device functions. The supervision process happens during device enrollment and cannot be changed afterward without re-enrolling the device. This creates a permanent management relationship that provides enhanced security and control capabilities. ### How Devices Become Supervised Devices become supervised through specific enrollment methods: #### Automated Device Enrollment (ADE) Corporate-owned devices enrolled through Apple Business or Apple School Manager become supervised automatically during the initial setup process. This provides the highest level of management control available. For setup details, see [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment). #### Apple Configurator Devices can be manually supervised using Apple Configurator on Mac, which requires a physical device connection. This method is typically used for corporate-owned devices that need supervision but weren't enrolled through ADE. #### Manual Enrollment (Non-Supervised) Bring Your Own Device (BYOD) devices enrolled through the enrollment portal remain non-supervised. This user-initiated enrollment process provides essential management capabilities while respecting device ownership. For BYOD setup, see [Apple BYOD Management](/en/endpoint/enrollment/apple/apple-byod-management). ## Supervision Impact on Iru Endpoint Management ### Supervised Device Capabilities When devices are supervised, Iru Endpoint can apply additional restrictions and management features: #### Enhanced Security Restrictions * **App installation control** - Prevent users from installing apps from the App Store * **App removal prevention** - Users cannot remove installed applications * **Configuration profile protection** - Users cannot manually install or remove management profiles * **Device reset prevention** - Users cannot erase all content and settings * **Find My restrictions** - Users cannot modify Find My settings #### Advanced Management Features * **Single App Mode** - Lock devices to a single application * **Kiosk mode** - Restrict device functionality for specific use cases * **Advanced network controls** - More granular Wi-Fi and network management * **Enhanced parental controls** - Additional restrictions for educational environments * **System app management** - Remove or hide built-in Apple applications #### Corporate Control Features * **Account modification prevention** - Users cannot change account settings * **Cellular data app settings** - Control which apps can use cellular data * **AirDrop restrictions** - Prevent file sharing between devices * **Game Center removal** - Hide gaming features on corporate devices ### Non-Supervised Device Limitations BYOD devices enrolled through manual enrollment have limited management capabilities: #### Available Management * **Basic security policies** - Passcode requirements, FileVault encryption * **Network configuration** - Wi-Fi and VPN profiles * **Certificate deployment** - Device identity certificates * **App distribution** - Corporate app installation * **System preferences** - Basic system configuration #### Unavailable Restrictions * **App Store access** - Users can still install apps from the App Store * **App removal** - Users can remove corporate applications * **Profile management** - Users can remove MDM profiles * **Device reset** - Users can erase and reset their devices * **Advanced restrictions** - Many supervision-only features are unavailable ## Choosing the Right Enrollment Method ### Use Automated Device Enrollment When: Choose ADE when you're deploying corporate-owned devices that need the highest level of security control. This method works well for kiosk deployments, single-app scenarios, educational environments requiring strict controls, and shared devices that need extensive management capabilities. ### Use Manual Enrollment When: Manual enrollment is ideal for BYOD programs where employee privacy is important. Use this method when basic security requirements are sufficient, user flexibility is valued, or you need quick deployment without the complexity of ADE setup. ## Iru Endpoint Library Items and Supervision ### Library Items Available on All Devices Iru Endpoint supports these Library Items on both supervised and non-supervised devices: Passcode for password and biometric requirements, FileVault for Mac disk encryption, Wi-Fi for network configuration, VPN for secure network access, Certificates for device identity and authentication, and Custom Apps for corporate application deployment. ### Library Items Requiring Supervision Some Library Items only work on supervised devices due to Apple's security restrictions. These include App Lock for single application mode, Advanced Restrictions for App Store and system app controls, Parental Controls for enhanced content filtering, System Extensions for advanced system modifications, and Kernel Extensions for low-level system access. ## Best Practices for Supervision Determine which devices need supervision based on ownership and security requirements. Use Automated Device Enrollment for corporate devices and Manual Enrollment for BYOD. Create separate Blueprints for supervised and non-supervised devices with appropriate Library Items. Clearly explain to users what management capabilities are available on their device type. Periodically assess whether your supervision strategy meets your security needs. ## Troubleshooting Supervision Issues **Possible causes:** * Device was enrolled through manual enrollment instead of ADE * Apple Business or Apple School Manager configuration issues * Device was reset after initial enrollment **Solutions:** * Verify enrollment method in Iru Endpoint * Check Apple Business or Apple School Manager device assignment * Re-enroll device through ADE if corporate-owned **Possible causes:** * Library Item requires supervision but device is not supervised * Blueprint configuration issues * Device compliance problems **Solutions:** * Verify device supervision status * Check Library Item requirements * Ensure Blueprint is properly configured **Possible causes:** * Device is not supervised (manual enrollment) * Users have administrative access * Insufficient user communication **Solutions:** * Use ADE for corporate devices to prevent profile removal * Implement user training and communication * Consider device ownership model ## Summary Device supervision is a fundamental aspect of Apple device management that directly impacts what Iru Endpoint can control on your devices. Understanding the differences between supervised and non-supervised devices helps you choose the right enrollment method for your security requirements, set appropriate expectations for management capabilities, configure Blueprints with compatible Library Items, and communicate effectively with users about device management. For maximum security and control, use Automated Device Enrollment with corporate-owned devices. For BYOD programs, manual enrollment provides essential security while respecting user privacy and device ownership. ## Related Articles Set up Automated Device Enrollment for zero-touch deployment and lifecycle management of corporate Apple devices Configure Bring Your Own Device (BYOD) management for Apple devices Configure Apple device enrollment with Automated Device Enrollment (ADE) Configure and manage Activation Lock for Apple devices Set up Shared iPad for multi-user experiences with Managed Apple IDs and guest sessions Configure Liftoff for Mac setup Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms # Configuring Apple Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/apple/configuring-apple-enrollment Configure Apple enrollment in Iru Endpoint: ADE, manual enrollment, enrollment codes, Setup Assistant, MDM profiles, and Blueprints. This guide applies to Apple devices **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). This guide covers Apple device enrollment in Iru Endpoint, including Automated Device Enrollment (ADE) for zero-touch deployment, manual enrollment, and enrollment codes. Through Apple Business or Apple School Manager integration, you can customize Setup Assistant, manage accounts, and configure activation lock options. ## Create an Automated Device Enrollment Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Universal Settings In this section, configure universal Automated Device Enrollment settings that apply across supported Apple device types. The platform-specific sections that follow provide additional settings for each Apple platform. When **Require authentication** is enabled, the enrolling user must complete single sign-on before Setup Assistant can continue. This applies to all Apple platforms except tvOS. See [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) for details. Automated Device Enrollment Library Item showing the Require authentication toggle and related enrollment settings If you use [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), turn off **Prefill initial account creation details** and **Lock pre-filled account creation details**; they conflict with Passport’s account creation flow and can cause Setup Assistant errors. By default, when enrolling devices through Automated Device Enrollment, the MDM profile is not removable. This is by design to keep company devices managed securely. You can select **Allow MDM Profile Removal** if you have a test environment or a specific need to make the profile removable. Iru Endpoint recommends against using this for production environments. Automated Device Enrollment Allow MDM Profile Removal Optionally override the location and contact information for this configuration. These details are shown to users on the Remote Management screen during enrollment. Automated Device Enrollment Override organization details Enrollment-time settings in this Automated Device Enrollment Library Item do not retroactively update devices that were enrolled before you save. In other words, changes apply only to devices that enroll after you save. This does not change how Library Items and Blueprint configuration sync to devices that are already enrolled. ### Options Common to Platform-Specific Sections These Automated Device Enrollment options work the same way on every Apple platform. Open the platform section you need in the Library Item and configure the setting there. Anything that only applies to certain platforms is documented under that platform later in this article. #### Install Library Items during Setup Assistant For **Mac**, **iPhone**, **iPad**, **Apple TV**, and **Vision**, the Automated Device Enrollment Library Item includes **Install Library Items during Setup Assistant**. When you enable it, you build a list of eligible Library Items that must finish installing while the device is still in Setup Assistant. **Passcode**, **Restrictions**, **FileVault**, and **Migration Assistant** install during Setup Assistant on **Automated Device Enrollment** when they are assigned on the **Blueprint**, whether **Install Library Items during Setup Assistant** is on or off. While the device installs this list of Library Items, Setup Assistant displays **Configuring** with the device type (for example **Configuring iPhone** or **Configuring Mac**), **Getting configuration from** your organization's name as registered with Apple Business or Apple School Manager, and a spinning gear. The names of individual Library Items are not displayed, and there is no progress indicator. After these Library Items have been installed, Setup Assistant continues through any remaining Setup Assistant panes so the user can start using the device. Iru Endpoint displays eligible Library Items in the **Select Library Items to require during Setup Assistant** drawer: * Eligible Library Items for the platform appear in the drawer regardless of the device's Blueprint. * Library Items that always install during Setup Assistant appear in the drawer and cannot be deselected. * Library Items that cannot install during Setup Assistant do not appear in the drawer. * Library Items configured for Self Service only (for example some App Store or in-house app setups) do not appear in the drawer; those installs are user-initiated after setup, not during enrollment. **Selected Library Items install only when they are assigned to the device.** Include every Library Item to install during Setup Assistant. **Blueprint** scoping still determines what applies. For example, a **Custom Profile** on the list will not install if your Blueprint does not scope it to the device. See [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). Use these steps in your Automated Device Enrollment Library Item: In the Automated Device Enrollment Library Item, select **Mac**, **iPhone**, **iPad**, **Apple TV**, or **Vision**, then turn on **Install Library Items during Setup Assistant** for each platform where you want this behavior. Select **Add Library Items** to open a drawer listing every eligible Library Item in your Iru Endpoint tenant. Use search and filters to find items, select what you need, then click **Done**. Automated Device Enrollment Add Library Items drawer for selecting Library Items Only Library Items compatible with the platform section you are configuring appear. For example, if you add Library Items from the **iPhone** section, the list only shows items that support iPhone devices. Each row also shows the supported device types. Passport does **not** appear in this drawer for Mac setup. Passport settings are not applied to the device as an install-time Library Item in Setup Assistant; Passport fetches its own settings. By default, the device is released from Setup Assistant after **15 minutes** if something blocks completion. You can change this fail-safe to any value from **1** to **120** minutes (two hours). The device leaves Setup Assistant when every selected Library Item is confirmed installed **or** when that maximum time is reached, whichever comes first. Each Library Item you add increases the time spent in Setup Assistant. If a device is stuck on **Configuring** before the timeout, you can [release the hold manually](#manually-release-devices-held-in-setup-assistant) from the device record. **Install Library Items during Setup Assistant considerations** For Mac onboarding you may also use the [Liftoff Library Item](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item). These behaviors differ: * **Enrollment scope**: **Install Library Items during Setup Assistant** applies only to devices enrolled through Automated Device Enrollment (ADE). It does not run on manually enrolled devices. Liftoff supports manual enrollment, ADE, or both, depending on the **Enrollment trigger** you choose in the Liftoff Library Item. * **What gets installed**: For ADE, you explicitly choose which eligible Library Items install during Setup Assistant using **Select Library Items to require during Setup Assistant**. Liftoff does not offer that kind of pick list; it presents installation for the Library Item types Liftoff covers (see [How Liftoff Works](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item#how-liftoff-works)), and all assignments of those types on the Blueprint follow Liftoff’s flow without per-item selection in Liftoff. * **Using both on one Blueprint**: If you enable **Install Library Items during Setup Assistant** and assign Liftoff to the same Blueprint, Setup Assistant installs only the Library Items you selected for ADE. After Setup Assistant completes, Liftoff installs any Blueprint-assigned items within Liftoff’s scope that were not already installed during Setup Assistant. Larger lists and app installs keep the user on a **Configuring**-style screen longer while downloads and installs finish. If you add many items, particularly applications, plan for longer setup times and stronger network conditions on the device. Avoid assigning Library Items to **Install Library Items during Setup Assistant** when their installers or scripts depend on conditions that are not true during Setup Assistant. That includes scripts that wait for the Dock or a logged-in desktop user, long sleeps or wait loops, branching logic that only succeeds after setup completes, installers that trigger an immediate restart or auto-launch apps right after install, and anything else that can stall or compete with enrollment-time work. Items like these interrupt Setup Assistant and can leave people on **Configuring** with an unclear or uneven ADE experience. Related options and behaviors documented elsewhere: * **Mac Custom App**: [Restart after successful install](/en/endpoint/library/library-items-profiles/custom-apps-overview#restart); [Pre- and post-install scripts](/en/endpoint/library/library-items-profiles/custom-apps-overview#pre-and-post-install-scripts) * **Custom Script**: [Restart after a successful execution](/en/endpoint/library/library-items-profiles/custom-scripts-overview#remediation-and-restart-options) (under **Restart Options**) * **macOS Auto App**: [Options](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#options) (includes **Add to Dock during install**, **Run preinstall script**, and **Run postinstall script**) #### Manually release devices held in Setup Assistant When a device is held in Setup Assistant, it stays on the **Configuring** screen while Apple reports it as awaiting configuration. The hold ends when required work finishes, when **Automatically release device after** is reached, or when you release it manually. You can release any device that reports as awaiting configuration. That usually matters when: * The device is enrolling with Automated Device Enrollment and [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) is enabled, and a Library Item stalls (for example a large app download, a pending Apps and Books license, or poor connectivity). * The device is migrating into Iru Endpoint with [App Preservation](#app-preservation), and Setup Assistant is waiting while managed apps are preserved. **Release hold** sends Apple's DeviceConfigured MDM command so the device can continue through any remaining Setup Assistant panes. Supported on Mac, iPhone, iPad, Apple TV, and Vision. Go to **Devices** and open the device that is held in Setup Assistant. A banner at the top of the record shows when the hold began (in your local time zone). Click **Release hold** to send the DeviceConfigured command. The device leaves the **Configuring** screen and continues Setup Assistant so the user can finish setup. While a release is in progress, **Release hold** is disabled so the command is not sent twice. Click **Check status** to refresh the hold state without reloading the page. The banner clears after the device leaves Setup Assistant, whether you released it manually, the timeout released it, or required Library Items finished installing. Device record banner showing the device is held in Setup Assistant with Check status and Release hold You can also send the release with the Iru Enterprise API. **Manual release considerations** * Use manual release when a device is stuck, not as the usual way to finish enrollment. Library Items that had not finished installing continue through the device's Blueprint after Setup Assistant completes. * **Release hold** appears only while the device reports as awaiting configuration. If the device is not held, the command returns an error, including when you send it through the Enterprise API. * The banner does not refresh on its own. Use **Check status** or reload the page to confirm the device was released. * For Apple's command reference, see [DeviceConfigured](https://developer.apple.com/documentation/devicemanagement/device-configured-command). #### Require Minimum OS Version In the **Mac**, **iPhone**, and **iPad** sections of the Automated Device Enrollment Library Item, **Require minimum OS version** tells the device to finish an operating system update *before* enrollment completes. You set the required minimum OS version in those sections. Apple runs that update during Setup Assistant. This is separate from Managed OS policies you configure for after enrollment. Choose **Version must be greater than or equal to** for a specific OS version, **Latest public release** for the newest public release from Apple (Mac, iPhone, and iPad), or **Custom** with **This is a beta version** and a **Seed Token** for beta enrollment. This is the same flow as [Managed OS **Enforce a Specific Version**](/en/endpoint/library/managed-os/configure-managed-os-for-macos#enforce-a-specific-version). For beta targets, Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) during enrollment. Use this option when the beta upgrade or update must finish *before* the device enrolls into Iru Endpoint. For Managed OS and Software Update Library Item options after enrollment, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment). The **Seed Token** list can be long and difficult to navigate. Changing this option for a device type takes effect without resyncing ADE settings to Apple. Automated Device Enrollment Library Item Require minimum OS version #### App Preservation For **iPhone** and **iPad** devices running iOS 26+ and iPadOS 26+, you can enable **Preserve managed apps during migration** so that when devices are migrated from another device management service to Iru Endpoint, any apps installed on the migrating device that are also present in the device's new Iru Blueprint (and their associated data) remain installed and configured on the device after migration. This avoids re-downloading business-critical apps and preserves user data. Use the **Preserve managed apps during migration** checkbox in the **iPhone** and **iPad** device sections. For more information, see [App Preservation](/en/endpoint/enrollment/apple/device-management-migration#app-preservation) in the Device Management Migration article. While apps are being preserved, the device can be held in Setup Assistant. See [Manually release devices held in Setup Assistant](#manually-release-devices-held-in-setup-assistant) if you need to end the hold early. Automated Device Enrollment Library Item Preserve managed apps during migration option for iPhone and iPad ### Mac Customize the setup experience and configuration for Mac computers. It is recommended not to skip the Location Services unless your organization has a specific need. Location services set the Time Zone and other location-dependent settings. Configure the Setup Assistant screens to skip for Mac computers during Automated Device Enrollment. You can skip specific screens or Auto Advance through Setup Assistant. Automated Device Enrollment Mac skip Setup Assistant screens and Auto Advance options In the **Mac** section, enable **Install Library Items during Setup Assistant** when installs from this section's list must finish during enrollment setup. See [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) for the install experience, building the list, and timeouts. Automated Device Enrollment Mac Install Library Items during Setup Assistant Use **Activation Lock** to choose whether an end user may enable user-based Activation Lock with Find My and a personal [Apple Account](/en/endpoint/enrollment/apple/apple-accounts-overview). Automated Device Enrollment Mac Activation Lock setting Use **Primary account type** to choose whether the first account created during Setup Assistant is an administrator account, a standard account, or whether account creation is skipped. If the primary account is a standard user, you must provision an additional local administrator (see the next step). If you deploy **Passport**, you should also skip primary account creation so the user account can be created after Setup Assistant through the Passport sign-in flow. For more information, see [Passport compatibility with macOS and Iru Endpoint features](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#primary-account-creation). Optionally turn on **Provision local administrator account** to create a local administrator during enrollment. This is required if the primary account is a standard user or if you skip creating the primary account during Setup Assistant. You can use Global Variables in the **Full name** and **Short name** fields. Such as \$FULL\_NAME or \$EMAIL\_PREFIX. This can be useful if you are requiring authentication and automatically assigning the user to the device record. Global Variables cannot be used for the **Password**. Automated Device Enrollment Mac primary account type and provision local administrator account Hide the additional administrator account if desired by selecting **Hide Account**. Select **MDM-enabled user** when the additional local administrator account (auto admin) should be the account designated for user-level MDM profiles. You are choosing which account MDM applies user-channel management to; that account still must register as the MDM-enabled user through an interactive sign-in as described in the warning below. In the rare case where the auto admin account is the primary user of the Mac, still select **MDM-enabled user** so the additional administrator account remains the one specified for user-level MDM profiles. If you turn on **MDM-enabled user**, the additional local administrator (auto admin) account does not register as the MDM-enabled user until someone signs in to that account at the Mac login window using the keyboard (enter the auto admin user name and password). This option is uncommon and may cause problems in your environment. [Contact Iru Support](/en/iru/iru-support/access-to-iru-support) before you enable it. Automated Device Enrollment Mac Hide Account and MDM-enabled user options Optionally use [**Require a minimum OS version**](#require-minimum-os-version). When the option is on, set **Version must be greater than or equal to** to a specific macOS version, to **Latest public release** to require the newest public macOS from Apple, or to **Custom** with **This is a beta version** and a **Seed Token** for beta enrollment during setup. If the installed macOS version does not meet that requirement, Setup Assistant shows a **Software Update** pane with a **60** second countdown before the device updates to a macOS version that meets the requirement. Automated Device Enrollment Mac Require minimum OS version **Options for Automatically advance through all Setup Assistant screens** The following two options are available only when **Automatically advance through all Setup Assistant screens** is selected. Both require Ethernet: **Set region for Mac devices** and **Set language for Mac devices**. Setting the region and language allows a new Mac to enroll and set itself up automatically, without anyone touching the keyboard and mouse. It may take a few minutes from the time the Mac starts up until the Auto-advance process begins. Resist the temptation to touch it! Specify the region for Mac devices. Automated Device Enrollment Mac Set region for Mac devices Specify the language for Mac devices. Automated Device Enrollment Mac Set language for Mac devices ### iPhone Customize the setup experience and configuration for iPhone devices. It is recommended not to skip the Location Services unless your organization has a specific need. Location services set the Time Zone and other location-dependent settings. Use **Skip screens during Setup Assistant for iPhone devices** to choose which Setup Assistant screens appear. When skipping is enabled, select **Specify the screens to skip** to edit the list. You can skip specific screens or specify current and future Setup Assistant panes. **Skip all Setup Assistant screens** does not auto-advance through Setup Assistant. Auto-advance is only available in macOS and tvOS. Automated Device Enrollment iPhone skip Setup Assistant screens In the **iPhone** section, enable **Install Library Items during Setup Assistant** when installs from this section's list must finish during enrollment setup. See [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) for the install experience, building the list, and timeouts. Automated Device Enrollment iPhone Install Library Items during Setup Assistant Optionally enable **Prevent MDM profile installation when restoring from backup**. When it is on, the MDM profile is not installed from a backup restored onto the same device; the device installs its MDM profile through Automated Device Enrollment instead. Automated Device Enrollment iPhone Prevent MDM profile installation when restoring from backup Use **Activation Lock** to choose whether users may enable user-based Activation Lock with Find My and a personal Apple Account. Optionally turn on **Enable device-based Activation Lock** to enable device-based Activation Lock through Apple Business or Apple School Manager. Automated Device Enrollment iPhone Activation Lock Optionally use [**Require a minimum OS version**](#require-minimum-os-version). When the option is on, set **Version must be greater than or equal to** to a specific iOS version, to **Latest public release** to require the newest public iOS from Apple, or to **Custom** with **This is a beta version** and a **Seed Token** for beta enrollment during setup. If the installed version is below that minimum, Setup Assistant presents **Software Update** so the device can update before enrollment completes. The value in **Version must be greater than or equal to** is the minimum the device must meet before setup continues; it is not the OS build **Software Update** will install. When an update is required, Apple installs the **latest public release** available for that device. The list selection does not cap the update to that exact version. Automated Device Enrollment iPhone Require minimum OS version When migrating devices from another device management service, check **Preserve managed apps during migration** if you want apps installed on the migrating device that are also present in the device's new Iru Blueprint (and their associated data) to be preserved on the device after migration. For more information, see [Device Management Migration](/en/endpoint/enrollment/apple/device-management-migration#app-preservation). Automated Device Enrollment iPhone Preserve managed apps during migration ### iPad Customize the setup experience and configuration for iPad devices. It is recommended not to skip the Location Services unless your organization has a specific need. Location services set the Time Zone and other location-dependent settings. Use **Skip screens during Setup Assistant for iPad devices** to choose which Setup Assistant screens appear. When skipping is enabled, select **Specify the screens to skip** to edit the list. You can skip specific screens or specify current and future Setup Assistant panes. **Skip all Setup Assistant screens** does not auto-advance through Setup Assistant. Auto-advance is only available in macOS and tvOS. Automated Device Enrollment iPad skip Setup Assistant screens In the **iPad** section, enable **Install Library Items during Setup Assistant** when installs from this section's list must finish during enrollment setup. See [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) for the install experience, building the list, and timeouts. Automated Device Enrollment iPad Install Library Items during Setup Assistant Optionally enable **Prevent MDM profile installation when restoring from backup**. When it is on, the MDM profile is not installed from a backup restored onto the same device; the device installs its MDM profile through Automated Device Enrollment instead. Automated Device Enrollment iPad Prevent MDM profile installation when restoring from backup Optionally turn on **Shared iPad** in the **iPad** section when you want a multi-user iPad experience during enrollment. Shared iPad can only be enabled during Automated Device Enrollment. See [Configure Shared iPad](/en/endpoint/devices/device-features/apple/configure-shared-ipad) for each setting in the Shared iPad section, including how **User configuration** changes which fields appear. Automated Device Enrollment iPad Shared iPad options Use **Activation Lock** to choose whether users may enable user-based Activation Lock with Find My and a personal Apple Account. Optionally turn on **Enable device-based Activation Lock** to enable device-based Activation Lock through Apple Business or Apple School Manager. Automated Device Enrollment iPad Activation Lock Optionally use [**Require a minimum OS version**](#require-minimum-os-version). When the option is on, set **Version must be greater than or equal to** to a specific iPadOS version, to **Latest public release** to require the newest public iPadOS from Apple, or to **Custom** with **This is a beta version** and a **Seed Token** for beta enrollment during setup. If the installed version is below that minimum, Setup Assistant presents **Software Update** so the device can update before enrollment completes. The value in **Version must be greater than or equal to** is the minimum the device must meet before setup continues; it is not the OS build **Software Update** will install. When an update is required, Apple installs the **latest public release** available for that device. The list selection does not cap the update to that exact version. Automated Device Enrollment iPad Require minimum OS version When migrating devices from another device management service, check **Preserve managed apps during migration** if you want apps installed on the migrating device that are also present in the device's new Iru Blueprint (and their associated data) to be preserved on the device after migration. For more information, see [Device Management Migration](/en/endpoint/enrollment/apple/device-management-migration#app-preservation). Automated Device Enrollment iPad Preserve managed apps during migration ### Apple TV Customize the setup experience and configuration for Apple TV devices. Optionally configure Auto Advance, and specify the Language and Region. Under **Skip screens during Setup Assistant for Apple TV devices**, choose how Setup Assistant runs: **Automatically advance through all Setup Assistant screens** (requires Ethernet) or **Specify which screens to skip during Setup Assistant**. When you choose to specify screens, select **Specify the screens to skip** to edit the list. Either choice determines which Setup Assistant screens appear on the device. Automated Device Enrollment Apple TV skip Setup Assistant screens In the **Apple TV** section, enable **Install Library Items during Setup Assistant** when installs from this section's list must finish during enrollment setup. See [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) for the install experience, building the list, and timeouts. Automated Device Enrollment Apple TV Install Library Items during Setup Assistant **Options for Automatically advance through all Setup Assistant screens** The following two options are available only when **Automatically advance through all Setup Assistant screens** is selected. Both require Ethernet: **Set region for Apple TV devices** and **Set language for Apple TV devices**. Setting the region and language lets Apple TV finish Setup Assistant automatically. From startup, it may take a few minutes before the Auto-advance process begins; keep the device connected to Ethernet until setup continues on its own. Specify the region for Apple TV devices. Automated Device Enrollment Apple TV Set region for Apple TV devices Specify the language for Apple TV devices. Automated Device Enrollment Apple TV Set language for Apple TV devices ### Vision Customize the setup experience and configuration for visionOS devices. Use **Skip screens during Setup Assistant for Vision devices** to choose which Setup Assistant screens appear. When skipping is enabled, select the pencil icon to edit which panes are skipped. Automated Device Enrollment Vision skip Setup Assistant screens In the **Vision** section, enable **Install Library Items during Setup Assistant** when installs from this section's list must finish during enrollment setup. See [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant) for the install experience, building the list, and timeouts. Automated Device Enrollment Vision Install Library Items during Setup Assistant Optionally enable **Prevent MDM profile installation when restoring from backup**. When it is on, the MDM profile is not installed from a backup restored onto the same device; the device installs its MDM profile through Automated Device Enrollment instead. Automated Device Enrollment Vision Prevent MDM profile installation when restoring from backup Use **Activation Lock** to choose whether users may enable user-based Activation Lock with Find My and a personal Apple Account. Optionally turn on **Enable device-based Activation Lock** to enable device-based Activation Lock through Apple Business or Apple School Manager. Automated Device Enrollment Vision Activation Lock ## Change Default ADE Blueprint The default Blueprint can be changed at any time inside the Iru Endpoint Web App. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Click **Edit Defaults** in the Automated Device Enrollment section. Click the Default Blueprint dropdown menu. Select the desired Blueprint from the list. Click **Save**. ## Enrollment Portal Link and Enrollment Code You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The **EnrollmentCodeHere** portion should be the Enrollment code without the dash between the two sets of numbers. ```text Shareable enrollment URL (Apple) icon="link" theme={null} https://subdomain.iru.com/enroll/access-code/EnrollmentCodeHere ``` ## Generating a New Enrollment Code Iru Endpoint allows you to generate a new random **Enrollment code** for each Blueprint. Generating a new code is helpful should the code be distributed to unauthorized users. A new code prevents unwanted devices from being enrolled into that Blueprint. Select **Enrollment** in the navigation bar. Navigate to the **Manual Enrollment** section. Click the arrow next to the name of the Blueprint where you'd like to change the code. Click **Change code**. Distribute the new **Enrollment code** to your desired users. Once changed, the previous code will no longer be valid for new device enrollments. By design, when Stolen Device Protection is enabled on devices running iOS 17.3 or later, MDM enrollment is restricted. ## Troubleshooting If a mobile device is already set up and enrolled in another MDM through Automated Device Enrollment, use one of these approaches: * In Apple Business or Apple School Manager, reassign the device to Iru Endpoint, then erase and re-enroll the device if you need to keep it supervised in Iru Endpoint. * Remove management for the device in the other MDM, then use the [Iru Endpoint Enrollment Portal](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment#enrollment-portal-for-manual-enrollment) for manual enrollment. Only macOS devices remain **Supervised** when you use this path. If you need more help with the migration, [contact support](/en/iru/iru-support/access-to-iru-support). On **macOS Ventura** and later, Mac computers that are registered to your organization must connect to a network during Setup Assistant after an erase or reset. If that connection is missing, the user can complete setup in a way that skips Automated Device Enrollment. Enroll the Mac into **Iru Endpoint** first. That enrollment is how admins ensure newly provisioned devices can no longer skip Automated Device Enrollment. During Automated Device Enrollment, users may stay on **Configuring** while the device completes [Install Library Items during Setup Assistant](#install-library-items-during-setup-assistant). Setup Assistant waits until each selected Library Item is **confirmed installed** (not only downloading). The device can also exit when **Automatically release device after** is reached, whichever comes first. Long install lists, **App Store** applications, and a slow or unreliable network are the most common reasons this phase runs longer than expected. Try the following: * Remove Library Items from the Setup Assistant install list when they do not need to finish during initial setup. Large applications are the most common candidates; assign them so they install after enrollment instead. * When downloads or installs are slow, check the device’s Wi-Fi connection, captive portal behavior, and any bandwidth limits during setup. * If a device is stuck on **Configuring**, [release the hold manually](#manually-release-devices-held-in-setup-assistant) from the device record. * If users are blocked because an install never completes, lower **Automatically release device after** (minimum **1** minute) so the device leaves Setup Assistant when the timer ends, even when not every Library Item finished. Raise the value only when you need additional time for a longer list, up to **120** minutes. ## Apple-Specific Troubleshooting If you don't see your devices available for assignment in your Apple Business or Apple School Manager account, there can be several reasons, with different solutions for each. * **You purchased your devices directly from Apple.** * You may not have registered your **Apple Customer Number** in Apple’s portal. In **Apple Business**, choose **Devices** → **Inventory**, then **Get Started** (first number) or **Add** (additional numbers), pick **Apple Customer Number** as the type, and finish the prompts. See [Manage device suppliers in Apple Business](https://support.apple.com/guide/business/manage-device-suppliers-axmef1c47493/web). In **Apple School Manager**, use Apple’s help for your region to add customer numbers linked to your organization (labels and steps can differ from Apple Business). * To find your Apple Customer Number, check with your Apple account executive, your purchasing department, or Apple sales support. When using an Apple Customer Number, all devices purchased from Apple since March 1, 2011, will be added to your Apple Business or Apple School Manager account. * **You purchased your devices from an Apple Authorized Reseller or a carrier.** * You may not have established a link between your Apple Business or Apple School Manager account and the reseller. * Ask your reseller for its **Reseller Number** (or equivalent identifier) and add it in **Apple Business** under **Devices** → **Inventory** using **Get Started** or **Add**, choosing the reseller number type when prompted ([Manage device suppliers in Apple Business](https://support.apple.com/guide/business/manage-device-suppliers-axmef1c47493/web)). In **Apple School Manager**, follow Apple’s documentation for linking resellers or carriers. * Provide your reseller with your **Organization ID**. In **Apple Business**, open **Settings** → **Organization** and find it under **Details**. In **Apple School Manager**, locate the organization identifier in your portal using [Apple School Manager](https://support.apple.com/guide/apple-school-manager/) documentation. Share that ID with your reseller along with the serial numbers or orders you want added to your Apple Business or Apple School Manager account. Your reseller can choose the "Look-Back" period for devices to be added. * Your devices may not have been purchased through a Device Enrollment-enabled reseller or were not purchased as a business from Apple. During initial setup, macOS allows users to sync their Desktop and Documents folders with iCloud. However, if the Mac later enrolls in Iru Endpoint and this feature is disabled, macOS will remove the previously synced data from the Mac. **Although this may be alarming for users, their data should still reside in their iCloud account.** * When disallowing iCloud Syncing and access to other iCloud features, we highly recommend informing your team before enrolling in Iru Endpoint so that they can make changes to ensure they have access to any critical data. * The **Restrictions Profile** Library Item contains settings related to iCloud that may be disabling the use of various iCloud functionality. * A list of Preferred Device Enrollment Resellers [is available here](https://support.apple.com/en-us/HT213320). * For information about customer numbers and adding devices to Apple Business or Apple School Manager, see Apple's [Using Automated Device Enrollment Support Article](https://support.apple.com/en-us/HT204142). ## Related Articles Set up Automated Device Enrollment for zero-touch deployment and lifecycle management of corporate Apple devices Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms Understand Apple device supervision Configure and manage Activation Lock for Apple devices Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Curate, create, and manage Library Items and add them to Blueprints # Device Enrollment Profile Status Source: https://docs.iru.com/en/endpoint/enrollment/apple/device-enrollment-profile-status Monitor device enrollment profile status for Apple devices in Iru Endpoint. Troubleshoot pending, failed, or stuck enrollment profiles and MDM assignments. This guide applies to Apple devices ## What is a Device Enrollment Profile? Iru Endpoint links a specific profile to devices within your Apple Business or Apple School Manager account via Apple's Device Assignment Services API to enable Automated Device Enrollment. Once Iru Endpoint assigns a profile, the device can complete Automated Device Enrollment automatically. ## Device Enrollment Profile Statuses | **Status** | **Meaning** | | ---------- | ------------------------------------------------------------------------------------------------------------------- | | Pending | The Device Enrollment profile will be assigned shortly; please refresh the page in a moment. | | Assigned | The Device Enrollment profile for the current Blueprint has been assigned. | | Pushed | The Device Enrollment profile was pushed to the device during the enrollment, and the device is currently enrolled. | | Failed | The Device Enrollment profile has failed to assign; please contact Iru Support. | ## Check Device Enrollment Status Before attempting to enroll a device through Automated Device Enrollment, check the status in the Automated Device Enrollment section in your Iru Endpoint web app. Click **Enrollment** in the left-hand navigation. If not already selected, choose **Automated Device Enrollment**. In the upper right-hand corner, select **Awaiting Enrollment** or **All**. The **Profile** column shows the status of the Automated Device Enrollment profile assigned to the device. The **Assigned to Iru Endpoint** column displays the date and time when the enrollment status was set. The Awaiting Enrollment status means that a device is not currently enrolled with Iru Endpoint, but is ready to be enrolled through Automated Device Enrollment. Device Enrollment Profile Status Library Item or profile status interface ### Last Fetch The Last Fetch date and time shown above the Profile column is the last time Iru Endpoint received updated Automated Device Enrollment information from Apple Business or Apple School Manager. ## Timing Considerations When Apple devices connect to the internet during Setup Assistant, they contact Apple to determine if they have a Device Enrollment profile pending. If the device does not have a profile pending at that time, it can be set up as if it were a consumer Apple device. Before connecting your devices to the internet during Setup Assistant, ensure that: * You have [assigned your devices to Iru Endpoint via Apple Business or Apple School Manager](/en/endpoint/getting-started/enrollment/apple-enrollment) * You see the "Assigned" status for the applicable devices in Iru Endpoint If the above conditions aren't met, the device(s) in question may fail to enroll into Iru Endpoint via Automated Device Enrollment. # Device Management Migration Source: https://docs.iru.com/en/endpoint/enrollment/apple/device-management-migration Migrate Apple devices from another MDM solution to Iru Endpoint. Plan the transition, reassign ADE profiles, and ensure continuity of management. This guide applies to iOS devices and iPadOS devices ### About Device Management Migration Iru Endpoint supports Apple's device management migration feature introduced with iOS 26 and iPadOS 26. This feature lets you migrate devices enrolled via Automated Device Enrollment (ADE) from one device management service to another without requiring a factory restore. Instead of a factory restore, the end-user performs a device restart to complete the migration. Activation Lock can also be transferred during the migration. New bypass codes are stored in Iru Endpoint. ### How It Works The migration process starts in Apple Business or Apple School Manager, where you assign a device to a different device management server and set a migration deadline. This deadline determines when the device must complete migration to the new device management service. You can identify migrating devices in Iru Endpoint via the Automated Device Enrollment settings page. There's a new optional column for Migration Deadline that can be added to the table. If a device has a migration deadline, it's migrating from another device management service. #### Activation Lock Preservation If you want to preserve Activation Lock post-migration, ensure your device has an Automated Device Enrollment Library Item in its Blueprint with Activation Lock enabled. We recommend matching the Activation Lock type (user-based vs. device-based) with your original device management service so Activation Lock stays in place after the device moves to Iru Endpoint. For more information, see [Configuring Apple Enrollment](/en/endpoint/enrollment/apple/configuring-apple-enrollment#create-an-automated-device-enrollment-library-item). #### App Preservation Iru Endpoint supports app preservation with device management migration for iPhone and iPad running iOS 26+ and iPadOS 26+. This feature allows apps installed on the migrating device that are also present in the device's new Iru Blueprint to remain installed and configured on the device after migration completes. Business-critical managed apps no longer need to be re-downloaded post-migration, saving users time and preventing configuration issues. While apps are being preserved, the device can be held in Setup Assistant. If the device stays on **Configuring** longer than expected, you can [release the hold manually](/en/endpoint/enrollment/apple/configuring-apple-enrollment#manually-release-devices-held-in-setup-assistant) from the device record. ### Setting Up Device Management Migration Sign in to Apple Business or Apple School Manager and select the **Assign Device Management** option from the device information page. Select **Add Deadline** to configure the date and time the device will be forced to migrate. Once a deadline has been added, this date and time displays in Iru Endpoint under a new optional **Migration deadline** column on the **Enrollment** > **Automated Device Enrollment** page. An Automated Device Enrollment Library Item is optional. It's only needed if you want to preserve Activation Lock or managed apps post-migration. If you want to preserve Activation Lock, ensure devices migrating into Iru Endpoint have an **Automated Device Enrollment** Library Item included in their Blueprint. Enable Activation Lock in the **Automated Device Enrollment** Library Item so Activation Lock is maintained post-migration. We recommend matching the Activation Lock type (user-based vs. device-based) with your original device management service so Activation Lock stays in place after the device moves to Iru Endpoint. If you want to preserve managed apps during migration, enable **Preserve managed apps during migration** in the **Automated Device Enrollment** Library Item. Any apps installed on a migrating device that are also present in the device's new Iru Blueprint will be preserved. Add any App Store apps and in-house apps you want to preserve to the enrollment Blueprint. If these apps use managed app configuration, apply the proper configuration. While preserved apps remain configured post-migration, applying consistent configuration prevents improper overwrites during future device syncs. ### User Experience Shortly after the deadline is set, the device receives a push notification alerting the user to the upcoming migration deadline with a prompt to complete the migration early. The notification appears on the lock screen, home screen, and in Settings. Users can start the migration immediately or defer it until the deadline. The device receives a push notification alerting the user to the upcoming migration deadline. The notification appears on the lock screen, home screen, and in Settings. Users can start the migration immediately or defer it until the deadline. If deferred, the notification persists in the Settings app. Once the migration deadline has been reached, the end user can't defer this notification and the device will force migration. After starting the migration, the user is prompted to restart the device to complete the migration process. After the user performs the restart, they're guided through a setup assistant to complete the device management migration. ### Considerations #### Activation Lock Transfer While Activation Lock transfers to Iru Endpoint, all configured apps, profiles, and declarations installed from the original device management service are removed post-migration unless app preservation is enabled. Recreate these resources in Iru Endpoint and assign them to the migrating device's Blueprint. ### References For more information about Apple's device management migration feature, see [Apple's documentation](https://support.apple.com/guide/business/migrate-devices-to-a-new-management-service-axm3a49a769d/web). # Enrolling Apple TV Devices Source: https://docs.iru.com/en/endpoint/enrollment/apple/enrolling-apple-tv-devices Enroll and manage Apple TV devices in Iru Endpoint using Automated Device Enrollment. Configure ADE profiles and deploy configurations to tvOS devices. This guide applies to Apple TV Iru Endpoint can only manage tvOS devices if they are assigned to Iru Endpoint in your Apple Business or Apple School Manager account. If your Apple TV is not listed there, [follow these steps](https://support.apple.com/en-us/HT208124). Enrollment occurs during the initial setup of an Apple TV. Devices that are already past the initial setup screen must be erased to enroll. ## Assign Apple TV Devices to Iru Endpoint Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com). Click the **Devices** tab at the top middle of the page. Search for a device in the search field. Select the device from the list. Click **Assign Device Management**. Apple Business or Apple School Manager Devices view with Devices selected, Your Devices, selected Apple TV, and Assign Device Management Click **Assign to the following MDM** and choose the Iru Endpoint server you created when enabling MDM with Iru Endpoint. Select **Continue**. Apple Business or Apple School Manager Assign Device Management with MDM server selection and Continue **Confirm** that you want to change the MDM server the device is assigned to. Apple TV confirm change of MDM server assignment dialog ## Set Default MDM Server Assignment In Apple Business or Apple School Manager, click the **Devices** tab at the top middle of the page. In the left sidebar, click **Management**. Under **Management Services**, click **Automatically assign devices to your preferred device management service**. Apple Business or Apple School Manager Management Services with Default Device Assignment On the **Default Device Assignment** page, for **Apple TV**, choose the Iru Endpoint device management service you use for MDM. Apple Business or Apple School Manager Default Device Assignment per device type with Apple TV MDM dropdown ## Confirm Apple TV Devices in Iru Endpoint In the Iru Endpoint Web App, click **Enrollment** in the left-hand navigation. On the **Enrollment** page, select the **Automated Device Enrollment** tab. Confirm that you see the Apple TV device(s) that you assigned from Apple Business or Apple School Manager. If you don't see the Apple TV device(s), click the **Fetch devices** button. To learn how to configure Auto Advance for Apple TV, see [Configure Auto Advance for Apple TV and Mac](/en/endpoint/devices/device-features/apple/configure-auto-advance-for-apple-tv-and-mac). # User Experience with Apple Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/apple/user-experience-with-apple-enrollment Walk through the Apple device enrollment experience step by step. See what users encounter when enrolling Mac, iPhone, or iPad in Iru Endpoint. This guide applies to Apple devices This guide walks you through enrolling your Apple device with your organization's device management system. Apple management uses Apple's MDM framework combined with Iru Endpoint's proprietary agent for advanced management capabilities. You'll need the **Enrollment Portal link** and **Enrollment code** provided by your IT team. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding in the names and surfaces you see when you enroll your device and use organization apps (on Mac, including the menu bar). The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**, and the **Enrollment Portal** shows Iru branding. If a link or screen still says “Kandji,” use the updated steps or link from your IT team. ## What to Expect When you enroll your Apple device, it will be connected to your organization's management system through Apple's MDM framework. Iru Endpoint's macOS agent will be installed to handle advanced management tasks. This allows your IT team to: * Deploy, upgrade, and uninstall company applications and software * Apply security policies and settings * Configure network access (Wi-Fi, VPN) * Monitor device compliance and gather system information Your personal data and applications remain private and won't be affected by the enrollment process. ## Prerequisites Before starting, make sure you have: * **Enrollment Portal link** - provided by your IT team * **Enrollment code** - provided by your IT team * **Work or school account** - your organization email and password * **Apple device** - iPhone, iPad, Mac, or Apple TV Make sure your Apple device is running a supported version of iOS, iPadOS, macOS, or tvOS. Contact your IT team if you're unsure about compatibility. ## Apple Enrollment Process On your Apple device, open Safari and go to the **Enrollment Portal link** provided by your IT team. Enter the **Enrollment code** provided by your IT team. If you have issues with your code, see [Troubleshooting](#troubleshooting). Tap or click **Continue**. If prompted, **sign in** with your **work or school account**. You may be redirected to your company's sign-in page. Use the same email and password you use for work. Tap or click **Enroll**. When prompted, tap or click **Install** to install the management profile. Open your device settings and install the management profile so it can take effect. Follow the steps for your device: a. Open **Settings** b. Tap **General**, then **VPN & Device Management** c. Install the management profile and enter the device Passcode if requested. a. Open **System Settings** b. Click **General** in the sidebar, then **Device Management**. For older versions of macOS, go to **Privacy & Security** > **Profiles** c. Select the profile to complete the installation of the MDM enrollment profile. When prompted, authenticate with an administrator username and password. Once the profile is installed and trusted, enrollment is complete. Your device is now managed by your organization. ## After Enrollment Once enrollment is complete: * **Company applications** will begin installing automatically via the Iru Endpoint macOS agent * **Security policies** will be applied to your device through Apple's MDM framework * **Network settings** (Wi-Fi, VPN) will be configured * **Device sync** happens every 24 hours to keep settings current, with agent check-ins for advanced management tasks It may take several minutes for all company applications and settings to appear on your device. If something doesn't appear immediately, wait a few more minutes and check again. ## Automated Device Enrollment (ADE) After Setup If a Mac has already passed through Setup Assistant without enrolling, it is still possible to enroll it into Iru Endpoint. Please follow the steps below to enroll your device. ### Open Terminal Open Spotlight by pressing Command-Space bar. Type **Terminal**. Press Enter on your keyboard. ### Run Command in Terminal Run the following command in Terminal by copying and pasting it into Terminal and pressing Enter on your keyboard: ``` sudo profiles renew -type enrollment ``` Enter your password when prompted and press Enter on your keyboard. The Mac will display a banner notification in the top-right corner prompting you to enroll the device into Iru Endpoint. Click on the **banner notification**. Device Enrollment banner notification on Mac System Settings will open to confirm the enrollment; click **Allow**. Allow Device Enrollment confirmation dialog Enter your username and password in the prompt. Click **Enroll**. The Mac is now enrolled in Iru Endpoint. ## Troubleshooting **Possible causes:** * Incorrect Enrollment Portal link * Network connectivity issues * Firewall blocking access **Solutions:** * Double-check the Enrollment Portal link provided by your IT team * Try using Safari (recommended for Apple devices) * Check your internet connection * Contact your IT team if the problem persists **Possible causes:** * Incorrect email or password * Account not set up for enrollment * Issues with your company's sign-in page **Solutions:** * Make sure you're using your work or school email and password * Try signing out and signing back in * Contact your IT team if you still can't sign in **Possible causes:** * Incorrect Enrollment code entered * Enrollment code expired or changed **Solutions:** * Double-check the Enrollment code provided by your IT team * Contact your IT team for a new Enrollment code if needed **Possible causes:** * Device restrictions preventing profile installation * Insufficient storage space * Network connectivity issues **Solutions:** * Check that you have enough storage space on your device * Ensure you have a stable internet connection * Try restarting your device and attempting enrollment again * Contact your IT team if the problem persists **Possible causes:** * Enrollment still in progress * Network connectivity issues * Device sync hasn't completed **Solutions:** * Wait 5–10 minutes for your device to finish setting up * Check your internet connection * Restart your device and wait a few more minutes * Contact your IT team if apps still don't appear after 30 minutes ## Additional Considerations ### Automated Device Enrollment (ADE) If your organization uses Automated Device Enrollment, your device may be automatically enrolled during the initial setup process. In this case, you won't need to manually enroll through the portal - the enrollment will happen automatically when you first set up your device. ### Bring Your Own Device (BYOD) Considerations If you're enrolling a personal device (BYOD), be aware that: * Your personal data and applications remain private * Only work-related configurations and applications will be managed * You can remove the management profile if you leave the organization # Blueprint Routing Source: https://docs.iru.com/en/endpoint/enrollment/blueprint-routing Set up Blueprint routing rules in Iru Endpoint to automatically assign devices to the correct Blueprint during enrollment based on device attributes. This guide applies to all device platforms ## What is Blueprint Routing? Blueprint Routing lets you assign devices to Blueprints dynamically during enrollment. Device and user information collected at enrollment is evaluated against your rules, and each device is routed to a Blueprint on a first-match basis. You don't need to hand out Blueprint-specific enrollment codes or assign devices to Blueprints beforehand, for example with [Apple Automated Device Enrollment (ADE)](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment). ## How It Works Blueprint Routing uses blocks of Assignment Rules, similar to [Assignment Maps](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). During enrollment, Iru evaluates initial device and user information against those rules and routes devices to the matching Blueprint. You get a single enrollment entry point across all platforms. ## Configuring Blueprint Routing As an Iru tenant **admin**, go to **Enrollment** and click **Blueprint Routing** in the upper-right corner. Click **Edit**. For Apple devices enrolling with ADE, optionally select a default **ADE Library Item for Apple devices**. Blueprint Routing ADE Library Item default selection Configure your rules in the **if** and **if else** rule blocks, and click **+ add else if** to add additional rule blocks. Blueprint Routing add rules and rule blocks Set a default Blueprint for when no rules match, called the **Fallback** route in the **else** block. Blueprint Routing default Blueprint Fallback selection To change the order in which rules are evaluated, drag rule blocks using the drag handle. Blueprint Routing rule blocks with drag handle for reordering You can optionally add a custom label to each routing block. Labels appear in the upper-right corner of the block, in the Blueprint Routing configuration, and in Activity entries. Blueprint Routing block with custom label Click **Save**. ### Example Blueprint Routing Configuration One way to use Blueprint Routing is to send devices to different Blueprints based on who they’re for and what type they are. In the example below, the first rule assigns all devices whose asset tag contains "MKT-" to the Marketing Blueprint. The second matches on asset tag "WXP-"; those devices (Windows) are sent to the WXP Blueprint. The third sends all iPad devices to the iPad Devices Blueprint. The Fallback sends every other device to a Default Blueprint. Each rule block in this configuration has a label in the upper-right corner, next to the trash can icon, highlighted in blue. Labels make it easy for your team to see the purpose of each block.
Blueprint Routing configuration example showing rule blocks and default Blueprint selection
## Rule Evaluation Rules are evaluated from top to bottom; the first rule that matches determines the device's destination Blueprint. Blueprint Routing supports the same rules as [Assignment Maps](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint), except for FileVault. This includes tags, which you can assign to ADE devices before enrollment and use in routing rules. See [Tags for Devices](/en/endpoint/devices/device-record-management/tags-for-devices#tags-for-automated-device-enrollment) for details. A rule unique to Blueprint Routing, **ADE enrolled and token**, applies only to Apple ADE enrolled devices and is useful when using the Iru Endpoint API for multiple tokens. See [Configure multiple ADE tokens using the Iru Endpoint API](/en/endpoint/settings/apple-integrations/configure-multiple-automated-device-enrollment-tokens). ### When Rules Are Evaluated Blueprint Routing rules are only evaluated during enrollment. For ongoing dynamic configuration management, see [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). Blueprint Routing decides which [Assignment Map](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint) a device should be assigned to, and conditional logic within an [Assignment Map](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint) decides which Library Items the device should receive. ## Blueprint Routing Activity The **Activity** tab of Blueprint Routing shows all activity related to Blueprint Routing, including: * When the Blueprint Routing configuration is edited, who made the change, and when * When devices enroll using Blueprint Routing * Routing actions taken against devices enrolling through Blueprint Routing, including the ruleset that matched and the device information available to Iru at the time the routing decision was made * Manual Enrollment changes for Blueprint Routing, including when it is turned off or on for Manual Enrollment, and/or if the enrollment code is changed Some of these entries also appear on the [Activity Page](/en/endpoint/devices/activity-page), and device enrollment and routing entries are recorded in the device's own activity log. **Device Routed** activity entries include the first ruleset that matched, its position in the routing configuration, and its label (if configured). All device details used to evaluate both the matching ruleset and all preceding rulesets are also listed. Device Routed activity entry showing matched ruleset and device details ## Enrolling with Blueprint Routing Blueprint Routing is available for the following enrollment methods: ### Manual Enrollment with Blueprint Code and Android Work Profile Blueprint Routing appears as a choice at the top of the list of Blueprints in the **Enrollment > Manual Enrollment** section. You can turn Blueprint Routing off or require authentication for it, just like you can with any other Blueprint. Manual Enrollment section showing Blueprint Routing at the top of the Blueprint list ### Automated Device Enrollment #### Assigning Devices to Blueprint Routing Blueprint Routing appears as a choice in the Blueprint selector to assign devices awaiting enrollment. For setting up ADE and syncing devices from Apple Business or Apple School Manager, see [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment). Automated Device Enrollment awaiting enrollment list with Blueprint Routing in the Blueprint selector If you assign a device awaiting enrollment to Blueprint Routing, it will re-enroll through Blueprint Routing on every subsequent enrollment until you reassign it to a different Blueprint. This means Blueprint Routing can be reused on the same device without admin intervention. #### ADE Library Item Assignment Optionally set or override the ADE Library Item for a device (or multiple devices) instead of using the one from Blueprint Routing. In Iru Endpoint, go to **Enrollment** → **Automated Device Enrollment**. Filter by **Awaiting Enrollment** (or **All**) to view unenrolled devices, then select the device(s) whose ADE Library Item you want to set or override. The **ADE Library Item** column shows the name of the ADE Library Item assigned to the Blueprint selected for enrollment or Blueprint Routing, or **None** if none is assigned. ADE Library Item column showing None and Unlink from Blueprint button To override the assignment so you can choose a different ADE Library Item, click **Unlink from Blueprint** or **Unlink from Blueprint Routing**, whichever appears. Once unlinked, choose **Re-link to Blueprint** or **Re-link to Blueprint Routing**, or select an **ADE Library Item** from the list. You can do this for one device or for many via multi-select. ADE Library Item dropdown with Select ADE Library Item and Re-link to Blueprint options A direct assignment is sticky and will always apply to the device unless you manually re-link it to the Blueprint or Blueprint Routing. Re-linking can be done one device at a time or in bulk. #### Tags for ADE Devices You can assign tags to ADE devices before they enroll; those tags carry over to the enrolled device and stay in sync. Tags can be used in Blueprint Routing rules to route devices to Blueprints during enrollment. See [Tags for Devices](/en/endpoint/devices/device-record-management/tags-for-devices#tags-for-automated-device-enrollment) for instructions. ## Considerations for Apple Automated Device Enrollment ### Without Blueprint Routing Automated Device Enrollment (ADE) settings are configured using the ADE Library Item assigned to specific Blueprints. ADE devices awaiting enrollment are also assigned to those Blueprints, so the path is: Devices → Blueprints → ADE Library Item(s). ### With Blueprint Routing Rules are evaluated just in time during enrollment, so you don't know the destination Blueprint until the device enrolls and device and user information is collected. To configure ADE settings for those devices, set the ADE Library Item to use in the Blueprint Routing config itself (see the optional step in Configuring Blueprint Routing). Assignment to Blueprint Routing persists across re-enrollments until the device's awaiting enrollment record is set to a different Blueprint. ## Enterprise API Actions for Blueprint Routing The following are supported for Blueprint Routing via the Enterprise API: * Changing the Manual Enrollment code * Turning Manual Enrollment off or on * Assigning Awaiting Enrollment devices to Blueprint Routing * Viewing Blueprint Routing activity For more details, visit the [Iru Endpoint API documentation](https://api-docs.kandji.io). ## Related Articles Organize and group devices using tags Create a Blueprint with Assignment Maps Use conditional logic in Assignment Maps Create and configure device Blueprints for policy management Set up Automated Device Enrollment for zero-touch deployment and lifecycle management of corporate Apple devices # Configure Require Authentication for Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/configure-require-authentication-for-enrollment Require user authentication during device enrollment in Iru Endpoint. Configure identity verification for Apple, Windows, and Android platforms. This guide applies to all device platforms ## What is Require Authentication? Require authentication is an enrollment setting that requires the enrolling user to complete single sign-on before device enrollment can finish. You choose which SSO connection to use from those configured in **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). Require authentication can also be used alongside [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing), which dynamically assigns devices to Blueprints during enrollment using Assignment Rules. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The manual enrollment portal now uses Iru branding. ## Manual Enrollment (All Devices) On the **Enrollment** page, open the **Manual Enrollment** tab. For each Blueprint, you can enable **Require authentication** so users who enroll through the enrollment portal must complete SSO sign-in before enrollment continues. ### Authentication Methods Require authentication for manual enrollment supports [Passkeys](/en/iru/access/passkeys-and-social-login#passkeys), [Google Social and Microsoft Social](/en/iru/access/passkeys-and-social-login#social-login), [Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on), and [Native SSO](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Prerequisites * Enrollment configured for your platform: [Apple](/en/endpoint/enrollment/apple/configuring-apple-enrollment), [Windows](/en/endpoint/enrollment/windows/configuring-windows-enrollment), or [Android](/en/endpoint/enrollment/android/configuring-android-enrollment) * If using Custom SAML or Native SSO: a working [SSO configuration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) in **Access** * If using Google Social or Microsoft Social: [Limit Authentication to Domain](/en/iru/access/passkeys-and-social-login#limit-authentication-to-domain) enabled for that connection in **Access** **User experience**: Share platform-specific enrollment instructions with your users: [Apple](/en/endpoint/enrollment/apple/user-experience-with-apple-enrollment), [Windows](/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment), or [Android](/en/endpoint/enrollment/android/user-experience-with-android-enrollment). ### Configuring Require Authentication with Manual Enrollment Select **Enrollment** in the navigation bar. Navigate to the **Manual Enrollment** tab. Scroll down to the Blueprint you want. Click the Blueprint tile or the **chevron** (down arrow) on the row to expand it. Manual Enrollment page with Blueprint row and expand chevron Click **Edit Settings**. Manual Enrollment Blueprint row with Edit Settings Check the **Require authentication** box. Choose a connection from the dropdown menu. To use Google Social or Microsoft Social for **Require authentication** during enrollment, **Limit Authentication to Domain** must be enabled for that connection. See [Limit Authentication to Domain](/en/iru/access/passkeys-and-social-login#limit-authentication-to-domain) in Passkeys & Social Login. If desired, check **Assign user to device record**. When enabled, this option tries to match the authenticated user to a user in your directory integration(s) by email address. If a match is found, the user is automatically assigned to the device. Click **Save**. Manual Enrollment Edit Settings panel with options and Save ## Automated Device Enrollment (Apple only) ### Authentication Methods Require authentication for Automated Device Enrollment supports only [Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on), [Google Workspace Native](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native), and [Microsoft Entra ID Native](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-native) authentication methods. ### Prerequisites * A working [SSO configuration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) in **Access** * Apple devices with Automated Device Enrollment configured. See [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment). ### Configuring Require Authentication with Automated Device Enrollment To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. If you already have an Automated Device Enrollment Library Item, open it, click **Edit**, and skip to step 3. Give the new Automated Device Enrollment Library Item a **Name**. Assign it to your [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Check **Require authentication**. This requires a user to authenticate through single sign-on during device enrollment. Under **Connection**, select the single sign-on connector to use for authentication. Optionally, check **Assign user to device record** to automatically assign the authenticated user to the device. When enabled, this option tries to match the authenticated user to a user in your directory integration(s) by email address. If a match is found, the user is automatically assigned to the device. When **Assign user to device record** is enabled, optionally check **Prefill initial account creation details** to prepopulate the new computer account in Setup Assistant with the assigned user's details. If you're using [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), make sure to turn off **Prefill initial account creation details** and **Lock pre-filled account creation details**. These settings conflict with Passport's account creation process and can cause Setup Assistant errors. Optionally check **Lock pre-filled account creation details**. If enabled, the user cannot modify the account creation details. Automated Device Enrollment Require Authentication settings showing the Lock pre-filled account creation details option Configure any remaining settings and click **Save**. ## Considerations ### General An SSO connection does not need to have **Enable Tenant Authentication** turned on to be used for Require authentication. Only enable tenant authentication if you also want Iru Endpoint admins to use that same connection to sign in to the Iru Endpoint Web App. If you use the same connection for both admin access and device enrollment, your end users will see the Iru Endpoint app in their identity provider's catalog. This won't give them admin access to your Iru Endpoint tenant. ### Apple When using Google Workspace as your identity provider, you must create your SSO connection [using Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml). The [built-in Google Workspace integration](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native) will cause a 403 error during enrollment. Here's what happens depending on the user's 2-Step Verification status: **Already set up**: Users see the normal Google authentication window with options for text, authenticator app, or backup codes. **Past enrollment period**: Users get an error message about not meeting the 2-Step Verification policy. They'll need to contact their admin to resolve this. **Never enabled, still in grace period**: Users will see a 404 error. If you're using [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), make sure to turn off **Prefill initial account creation details** and **Lock pre-filled account creation details**. These settings conflict with Passport's account creation process and can cause Setup Assistant errors. ### Windows Make sure the user enrolling the device has local administrator rights on the Windows machine. Make sure the device has internet access and Microsoft Edge browser. You'll also need to open the required firewall ports for enrollment to work. For more information, see [Microsoft's documentation on MDM enrollment](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link). During enrollment, users will see a "This site is trying to open Microsoft account" prompt. Tell them to click **Open** to continue the process. ### Android Make sure Android devices are in a factory restored state before attempting enrollment. Enrollment creates a work profile that keeps work and personal data completely separate. Work apps go in the work profile, while personal apps stay in the personal profile. ## Related Articles Configure Apple device enrollment with Automated Device Enrollment (ADE) Windows device enrollment and management setup Android device enrollment and work profile setup What to expect when enrolling your device through the enrollment portal What to expect when enrolling your Windows device through the enrollment portal What to expect when enrolling your Android devices and setting up a work profile # Configuring Windows Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/windows/configuring-windows-enrollment Configure Windows device enrollment in Iru Endpoint. Set up MDM enrollment URLs, authentication, and group policy for automated Windows management. This guide applies to Windows devices Windows devices in Iru Endpoint enroll through the **Enrollment Portal** (manual flow) or through **[Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot)** when you connect Microsoft Entra ID and register devices with the Autopilot service. Management uses Microsoft's MDM framework and the Iru Agent for app installation, upgrades, and application inventory. For enabling the Windows platform and a quick enrollment overview, see [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup) and [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment). As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ## How Windows Enrollment Works Windows enrollment in Iru Endpoint uses a browser-based portal that connects devices to your organization's management system. When users access the **Enrollment Portal link**, they'll enter the **Enrollment code**, then sign in with your organization's credentials if authentication is required. The code determines which Blueprint is assigned to the device; the Blueprint determines which policies and applications get applied. Blueprints can use Assignment Maps to apply conditional logic based on device attributes, user information, or other organizational criteria. The enrollment process establishes a secure connection between the Windows device and Iru Endpoint through Microsoft's MDM framework, while the Iru Agent handles application management and inventory collection. This gives you centralized management while keeping user flexibility. ## Prerequisites An Iru Endpoint role with permission to view **Enrollment** and **Blueprints** Windows 11 24H2 or 25H2 (Pro, Pro Education, Enterprise, Education). A device serial number is required for enrollment. On virtual machines, you can assign a stable serial number. Windows devices with internet access and Microsoft Edge browser (required for enrollment) (Recommended) **Single sign-on (SSO)** configured for secure authentication Firewall ports opened for enrollment traffic ## Configure Windows Enrollment Sign in to your Iru Endpoint tenant and navigate to **Enrollment** → **Manual Enrollment**. Copy the **Enrollment Portal link**. You'll share this with users. Under the **Select Blueprint to enroll the device into** section, copy the code of the Blueprint you want devices to enroll into. (Recommended) Click the Blueprint and select **Require authentication**. Share the following with each user (email, chat, or help portal): * The **Enrollment Portal link** from **Enrollment** → **Manual Enrollment** * The **Enrollment code** for the correct **Blueprint** * A short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment Consider creating a template email or help article with these instructions to ensure consistency across your organization. ### Enrollment Portal link and Enrollment code You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The **EnrollmentCodeHere** portion should be the Enrollment code without the dash between the two sets of numbers. ```text Shareable enrollment URL (Windows) icon="link" theme={null} https://subdomain.iru.com/enroll/windows/access-code/EnrollmentCodeHere ``` ## Verify Enrollment In Iru Endpoint, open **Devices** Locate the newly enrolled device (search by user email, device name, or serial number) Confirm it shows assigned **Blueprint**, **apps**, and **policies**. Installations will proceed automatically ## Windows Management Architecture Windows device management in Iru Endpoint uses a hybrid approach: * **Microsoft MDM Framework** - Handles device enrollment, policy enforcement, and basic device management * **Iru Agent** - Proprietary agent that manages application installation and upgrade, and collects application inventory This combination uses Microsoft's native MDM for core device policies and the Iru Agent for application management. ## Windows-Specific Considerations ### Device Requirements * **Windows 11 24H2 or 25H2:** You'll need Windows 11 Pro, Pro Education, Enterprise, or Education (24H2 or 25H2 only) for enrollment * **Microsoft Edge browser** - You'll need Microsoft Edge for Windows enrollment (see [Microsoft's MDM enrollment documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link)) * **Local administrator rights** - The enrolling user must have admin access on the device * **Serial number** - Required for enrollment. On virtual machines, you can assign a stable serial number. * **Synchronized time** - Make sure the device clock is synced with a reliable time source Some advanced Windows features may not be available depending on your device configuration and Windows version. ### Network Requirements Devices must have internet connectivity for enrollment. Make sure all required ports are opened in your firewall configuration. Configure proxy settings if your network requires them. For detailed network requirements including specific domains, ports, and firewall configurations, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). ### Security Considerations Always use SSO authentication when possible to ensure only authorized users can enroll devices. This prevents unauthorized access to your organization's device management system. Require strong authentication for enrollment and make sure the Enrollment Portal links are only accessible from trusted networks. Verify device identity before enrollment to maintain security. Windows enrollment supports both SSO authentication and basic authentication, but SSO provides better security and user experience. ## Best Practices Enable "Require authentication." Combined with SSO, this ensures only authorized users can enroll Pre-stage critical items (Wi-Fi, Certificates, SCEP, Password policies) in the Blueprint so devices come online with required trust and connectivity. You can use Assignment Maps within Blueprints for conditional logic if needed. Test the enrollment process with a small group before rolling out to all users Document the enrollment process and provide clear instructions to users ## Additional Windows Management ### Active Directory Integration If your organization requires Active Directory domain join, Azure AD Join, or Hybrid Azure AD join, these must be configured separately from Iru Endpoint enrollment. Coordinate with your Active Directory team to ensure proper domain join procedures are followed. ### Device Sync and Management Windows devices use multiple sync mechanisms: * **Event-driven MDM:** New policies and settings from the Iru Endpoint Web App generally apply within a couple of minutes via Windows Push Notification Services (WNS) * **Daily MDM check-in:** Every 24 hours, MDM remediates local drift from admin intent (for example, if a user manually changed firewall settings) * **Agent check-in:** The Iru Agent checks in every 15 minutes for app deployment, app inventory, and PowerShell scripts From the Iru Endpoint Web App, you can open the device record and click **Perform Recurring Check-In** to push down any MDM policies that were waiting to deploy. That action does not remediate existing policies, and it does not trigger an agent sync. For full timing details, see [Device Check-In](/en/endpoint/devices/device-check-in/device-check-in). ### Policy Application Windows devices automatically receive security policies and restrictions, network configuration (Wi-Fi, VPN), application deployments, and compliance monitoring. **MDM vs. Agent Responsibilities:** * **MDM Framework:** Wi-Fi, Windows Firewall, BitLocker, and other system policies * **Iru Agent:** App deployment, app inventory, and PowerShell scripts ## Related Articles Connect Microsoft Entra ID for zero-touch Windows 11 enrollment during OOBE What to expect when enrolling your Windows device through the enrollment portal Configure Apple device enrollment with Automated Device Enrollment (ADE) Complete guide to Android device enrollment and work profile management Manage Windows Update settings and the end-user update experience on Windows devices # User Experience with Windows Enrollment Source: https://docs.iru.com/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment Walk through the Windows enrollment experience step by step. See what users encounter when enrolling a Windows device in Iru Endpoint via Settings. This guide applies to Windows devices This guide walks you through enrolling your Windows device with your organization's device management system. Windows management uses Microsoft's MDM framework combined with the Iru Agent for app management and inventory. If your IT team issued an **Enrollment Portal link** and **Enrollment code**, follow this article. Devices deployed with **Windows Autopilot** complete enrollment during initial Windows setup instead; ask your administrator which path applies. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding when you enroll your Windows device, including in the **Enrollment Portal**. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. If a link, screen, or instruction still refers to Kandji, use the updated enrollment link or follow the steps your IT team provides. As of **April 8, 2026**, manual enrollment portal branding has transitioned to Iru. For more information, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update). ## What to Expect When you enroll your Windows device, it will be connected to your organization's management system through Microsoft's MDM framework. The Iru Agent will be installed to handle application management. This allows your IT team to: * Deploy, upgrade, and uninstall company applications and software * Apply security policies and settings * Configure network access (Wi-Fi, VPN) * Monitor device compliance and gather application inventory Your personal data remains private and won't be affected by the enrollment process. ## Prerequisites Before starting, make sure you have: * **Enrollment Portal link** - provided by your IT team * **Enrollment code** - provided by your IT team * **Local administrator rights** - on the Windows device you're enrolling * **Microsoft Edge browser** - You'll need Microsoft Edge to enroll your Windows device You need local administrator rights on the device to complete enrollment. If you don't have these rights, contact your IT team for assistance. ## Windows Enrollment Process On your Windows device, open **Microsoft Edge** and go to the **Enrollment Portal link** provided by your IT team. You'll need to use Microsoft Edge browser for Windows enrollment. For more information, see [Microsoft's documentation on MDM enrollment](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link). Enter the **Enrollment code** provided by your IT team. If you have issues with your code, see [Troubleshooting](#troubleshooting). Select **Continue**. If prompted, **sign in** with your **work or school account**. You may be redirected to your company's sign-in page. Use the same email and password you use for work. Select **Enroll**. When you see the **"This site is trying to open Microsoft account"** prompt, select **Open**. In the **Set up a work or school account** screen, enter your **email address**. Leave the URL field as is. Select **Next**. Windows will display: **"Hold on while we register this device with your company and apply policy"**. Once registration completes, you'll see: **"Setting up your device"** - this applies company policies, network settings, and applications. Select **Got it** to complete enrollment and close the window. ## After Enrollment Once enrollment is complete: * **Company applications** begin installing via the Iru Agent (about every 15 minutes for ongoing app work) * **Security policies** and **network settings** (Wi-Fi, VPN) are applied through Microsoft's MDM framework. New admin settings generally apply within a couple of minutes; local changes are corrected about every 24 hours It may take several minutes for all company applications and settings to appear on your device. If something doesn't appear immediately, wait a few more minutes and check again. ## Troubleshooting **Possible causes:** * Incorrect Enrollment Portal link * Network connectivity issues * Firewall blocking access **Solutions:** * Double-check the Enrollment Portal link provided by your IT team * Make sure you're using Microsoft Edge browser * Check your internet connection * Contact your IT team if the problem persists **Possible causes:** * Incorrect email or password * Account not set up for enrollment * Issues with your company's sign-in page **Solutions:** * Make sure you're using your work or school email and password * Try signing out and signing back in * Contact your IT team if you still can't sign in **Possible causes:** * Incorrect Enrollment code entered * Enrollment code expired or changed **Solutions:** * Double-check the Enrollment code provided by your IT team * Contact your IT team for a new Enrollment code if needed **Possible causes:** * You don't have local administrator rights on the device * UAC (User Account Control) is blocking enrollment **Solutions:** * Contact your IT team - you may need administrator rights to complete enrollment * Try running the web browser as an administrator * Temporarily disable UAC if your IT team allows it **Possible causes:** * Enrollment still in progress * Network connectivity issues * Device sync hasn't completed **Solutions:** * Wait 5–10 minutes for your device to finish setting up * Check your internet connection * Restart your device and wait for sync to complete * Contact your IT team if apps still don't appear after 30 minutes ## Related Articles What you may see when a company app installation or update asks you to close a running app first Complete guide to Windows device enrollment and management setup # Configuring Blueprints Source: https://docs.iru.com/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints Create and configure Blueprints in Iru Endpoint to group devices and assign management policies. Define Assignment Maps and Library Item assignments. Create and configure Blueprints to deploy settings, apps, and policies to groups of devices from one place. Blueprints support Apple, Windows, and Android and give you precise control over what gets applied to each device. As of April 1, 2026, all legacy Classic Blueprints were automatically converted to Assignment Maps, which are the default, improved version of Blueprints. ### How It Works You create a Blueprint, add Library Items from the Library (for macOS computers, optionally [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters)), then assign the Blueprint to devices during enrollment. Assignment Maps control which items apply: simple views assign to all devices in the Blueprint; advanced views use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) by device, user, or group. ## Create a Blueprint Navigate to the **Blueprints** page in the Iru Endpoint Web App. Click the **+ Add Blueprint** button. Choose to start from scratch or use one of Iru Endpoint's pre-built templates. Name your Blueprint, and give it an optional description. Click **Create Blueprint**. If you're creating a Blueprint from scratch, you can have your Blueprint open in one tab and your Iru Endpoint Library in another. You can keep your Blueprint in one tab and the Library in another so you can switch between them and grab new items as you build the Blueprint. ## Blueprint Configuration After creating a Blueprint, open it to add Library Items from the Library Item Bank (select **Edit assignments**, then drag items to the Assignment Map). You can add [conditional blocks](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) for scoping by device, user, or group. For **macOS computers**, you can enable [Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) from the **Parameters** tab. Configure enrollment settings (e.g., authentication, Enrollment code) as needed. For detailed information about Blueprints and Assignment Maps, see [Creating a Blueprint](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). ## Next Steps After creating Blueprints: Add items to your Blueprints with [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library) and assign them in the Assignment Map. For macOS computers, [Configure Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) as needed. Once Blueprints are configured, set up enrollment to manage devices: [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Configuring Parameters Source: https://docs.iru.com/en/endpoint/getting-started/blueprints-and-library/configuring-parameters Set up Blueprint parameters in Iru Endpoint to enforce security and compliance policies. Configure user account, FileVault, and system settings. This guide applies to Mac computers Enable Parameters in Blueprints to control system-level behaviors and user account management on Mac computers. Parameters are built-in options you toggle on or off; they work alongside Library Items and apply to all Mac computers in the Blueprint, so you can enforce the right security and management settings at scale. Windows and Android Blueprints use Library Items and Mobile Device Management (MDM) policies instead. Not enrolling Mac computers? Skip ahead to enrollment: ## Available Parameters Iru Endpoint includes built-in Parameters for common device management tasks. Expand a category below to read more. * **[Create User Accounts](/en/endpoint/blueprints/parameters/create-user-accounts)**\ Create Administrator or Standard user accounts if they do not already exist. * **[Demote User Accounts to Standard](/en/endpoint/blueprints/parameters/demote-user-accounts-to-standard)**\ Demotes local accounts to Standard users. At least one administrator user account must be excluded from the demotion process. * **[Don't Allow the Guest User to Log In](/en/endpoint/blueprints/parameters/dont-allow-the-guest-user-to-log-in)**\ The Guest account is considered a security vulnerability because it has no password associated with it. It is recommended the Guest account be disabled on all macOS systems unless there is a clearly demonstrated need. * **[Set umask for all users](/en/endpoint/blueprints/parameters/setting-umask-for-all-users)**\ Sets the umask value to 027. * **[Check Applications folder for appropriate permissions](/en/endpoint/blueprints/parameters/checking-library-and-system-folders-for-world-writable-files#check-applications-folder-for-appropriate-permissions)**\ Verifies applications located anywhere within the /Applications directory are not world writable. * **[Check Library folder for world writable files](/en/endpoint/blueprints/parameters/checking-library-and-system-folders-for-world-writable-files#check-library-folder-for-world-writable-files)**\ Verifies directories in /Library aren't set to be world writable. * **[Check System folder for world writable files](/en/endpoint/blueprints/parameters/checking-library-and-system-folders-for-world-writable-files#check-system-folder-for-world-writable-files)**\ Verifies directories in /System aren't set to be world writable. * **[Monitor Encryption Status of Time Machine Volumes](/en/endpoint/blueprints/parameters/monitor-encryption-status-of-time-machine-volumes)**\ Backup volumes should be encrypted like boot volumes, even when a portable drive holds only non-sensitive data or when encryption would make the drive harder to use with other systems. * **[Report User Accounts with FileVault Recovery Keys Escrowed to iCloud](/en/endpoint/blueprints/parameters/report-user-accounts-with-filevault-recovery-keys-escrowed-to-icloud)**\ It is recommended that FileVault Recovery Keys are not stored in a user's personal iCloud account as there is a possibility that keys can be retrieved by an unknown party. * **[Restart after X Number of Days of Continuous Uptime](/en/endpoint/blueprints/parameters/restart-after-x-number-of-days-of-continuous-uptime)**\ Require devices to restart after a set number of days of uptime. The following Parameters align with CIS benchmark recommendations (e.g., macOS 15 and macOS 26) and are available in Blueprints created from or updated with the CIS Level 1 and Level 2 templates. You can enable them for any Blueprint from the Parameters editor. * **Audit Touch ID settings** Touch ID is integrated with macOS and allows fingerprint use for many common operations. All use of Touch ID requires the presence of a password and the use of that password after every reboot, or when more than 48 hours has elapsed since the device was last unlocked. Touch ID is not a password replacement. The use of Touch ID can, however, make the use of passwords more secure for authorized users with physical access to a Mac. * **Ensure users' accounts do not have a password hint** Password hints that are closely related to the user's password are a security vulnerability, especially in the social media age. Unauthorized users are more likely to guess a user's password if there is a password hint. * **Ensure logging is enabled for sudo** To properly monitor the use of the sudo command, log events for any use of sudo should be captured in the unified log. * **Show location icon in Control Center when system services request your location** When user applications access location an arrow is displayed next to the Control Center in the menu bar to give users an indication when their location is being accessed. By default system services like time zones, weather, travel times, geolocation, "Find my Mac," and advertising services do not indicate the location is accessed. Enabling the "Show location icon in the menu bar when System Services request your location" setting will show an arrow in the control center when a system service accesses the location. * **Ensure Apple Mobile File Integrity (AMFI) is enabled** AMFI uses launchd, code signatures, certificates, entitlements, and provisioning profiles to create a filtered entitlement dictionary for an app. AMFI is the macOS kernel module that enforces code-signing and library validation. If disabled, applications could be compromised with malicious code. * **Audit that Signed System Volume (SSV) is enabled** Running without Signed System Volume on a production system could run the risk of OS software that integrates directly with macOS being modified. * **Report Lockdown Mode status** Lockdown Mode was introduced as a security feature in 2022 and provides additional extreme security protection. Users and organizations that suspect some users are targets of advanced attacks must consider using this control. This parameter will report the status of Lockdown Mode. * **Ensure XProtect is running and up to date** XProtect is the macOS native signature-based antivirus technology. XProtect both finds and blocks the execution of known malware. No matter what other tools are being used, XProtect should have the latest signatures available. You can see all available Parameters when enabling Parameters for a Blueprint. ## Enable Parameters in Blueprints Open your desired Blueprint in the Iru Endpoint Web App. Select **Parameters** at the top of the Assignment Map. Click **Edit Parameters** or **Add Parameters** (first-time setup). To bring in Parameters from another Blueprint instead, choose **Import from existing Blueprint**, select a Blueprint from the list (use **Search Blueprints** if needed), then click **Import Parameters**. Use the left navigation to filter Parameters by category. Type in the search field to find the Parameters you need. You can narrow results with the **Compliance framework** dropdown next to it. Toggle the switch to enable desired Parameters. For Parameters with configurable options, set the desired values. Optionally mute notifications using the bell icon where available. Click **Save** to apply changes. ## Next Steps After configuring Parameters: Once Blueprints and Parameters are configured, set up enrollment to manage devices: [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Managing Library Source: https://docs.iru.com/en/endpoint/getting-started/blueprints-and-library/managing-library Add Auto Apps, custom apps, profiles, and scripts to your Iru Endpoint Library. Organize Library Items and assign them to Blueprints for deployment. The Library is where you add and manage the applications, configurations, and policies you deploy to devices through Blueprints. ## About the Library The Iru Endpoint Library is where you store applications, configurations, and policies that can be deployed to your devices. Library Items can be assigned to Blueprints and deployed to devices based on your organization's needs. ## How It Works The Library is the central place for your deployment assets. You add items to the Library, then assign them to Blueprints via Assignment Maps. When devices enroll and are assigned to a Blueprint, the Library Items in that Blueprint deploy automatically. Use **Search** and **Library Item filters** to find items, and **Sync App Store Apps** to pull recent Apps and Books changes. ## Library Overview The Library contains applications (Auto Apps, App Store Apps, In-House Apps), configurations for device settings and security, and scripts for automation. The section below describes each type and links to detailed docs. ## Add Library Items Navigate to the **Library** page in the Iru Endpoint Web App. Click **+ Add Library Item** at the top right of the Library. Choose the type of Library Item you want to add: * **Auto App** - For pre-packaged applications Iru hosts and manages * **App Store App** - For apps from the App Store (Apps and Books, Apple Business or Apple School Manager) * **In-House App** - For custom applications * **Configuration** - For device settings and policies * **Script** - For custom automation scripts Follow the configuration prompts for your selected item type. Provide required information such as: * **Application details** (for apps) * **Configuration settings** (for policies) * **Script content** (for scripts) Click **Save** when complete. ## Library Item Types ### Auto Apps Auto Apps are pre-packaged applications that Iru Endpoint hosts and manages with automatic updates and version control. You can keep applications up to date automatically and manage specific application versions as needed. For more, see [Auto Apps Overview](/en/endpoint/library/auto-apps/auto-apps-overview). ### App Store Apps App Store Apps (Apps and Books) let you deploy apps from the App Store to Apple devices. Add licenses from Apple Business or Apple School Manager and they appear in the Library; use **Sync App Store Apps** to pull recent changes. For more, see [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books). ### In-House Apps In-House Apps allow you to deploy proprietary or custom applications through internal distribution without App Store approval, for iOS and iPadOS devices. You can control application versions and updates according to your organization's needs. For more, see [Configure the In-House App Library Item](/en/endpoint/library/library-items-profiles/configure-the-in-house-app-library-item). ### Configurations Configurations help you set up device preferences and restrictions, enforce security settings and compliance, and configure Wi-Fi, VPN, and network access settings across your device fleet. Custom profiles (e.g., .mobileconfig for Apple devices) are one type; see [Custom Profiles Overview](/en/endpoint/library/library-items-profiles/custom-profiles-overview) and other configuration Library Items in the docs. ### Scripts Custom Scripts run on Mac and Windows devices to automate tasks, configure settings, install or update software, run maintenance tasks, and enforce security policies. You can also use scripts to collect device information. For more, see [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview). ## Assigning Library Items to Blueprints Go to **Blueprints** and open the Blueprint you want to configure. Select **Edit assignments** to open the Assignment Map view. In the Library Item Bank, search or filter for the Library Items you want. Use **Shift+click** or **Command+click** to select multiple items, then drag them to the Assignment Map. Add conditional blocks and assignment nodes to scope items by device, user, or group. See [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints). Save your Blueprint when done. You can also assign a Library Item to a Blueprint from the item’s **Assignment** section by clicking **Assign** and selecting the desired Assignment Map(s). ## Best Practices Organize your Library Items by category and use descriptive names for easy identification. Test Library Items in a testing Blueprint before deploying to production devices, and document any dependencies between Library Items. Keep track of different versions of applications and configurations to maintain proper version control. For detailed information about Library Items and sections (Auto Apps, Custom Apps, Custom Scripts, etc.), see [Library Overview](/en/endpoint/library/library-items-profiles/library-overview). ## Next Steps After adding Library Items: Use [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) to assign items via the Assignment Map. For macOS computers, [configure Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) as needed. With Blueprints and Library Items in place, set up enrollment: [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Android Enrollment Source: https://docs.iru.com/en/endpoint/getting-started/enrollment/android-enrollment Set up Android work profile enrollment in Iru Endpoint as part of initial setup. Connect Android Enterprise and enroll your first Android device. This guide applies to Android devices Set up work profile enrollment so you can add company-owned Android devices to Iru Endpoint and manage them with the right apps, settings, and security controls. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works You configure the enrollment portal, choose a Blueprint, and share the **Blueprint link** (which has the Enrollment code embedded) with users. Users open the Blueprint link on a secondary device (they can't use the device they're enrolling), sign in if you require authentication, and follow the instructions to scan the QR code. Android Enterprise creates a work profile on the device and it is managed according to your Blueprint. ## Prerequisites Before enrolling Android devices, ensure you have: * **Android Enterprise** configured in Iru Endpoint (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup)) * **Company-owned devices** in factory reset state * **Android 13 and higher** * **Blueprint** configured for Android devices * **(Recommended)** **Single sign-on (SSO)** configured for secure authentication ## Work Profile Enrollment Setup a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint. b. Ensure the **Enrollment Portal** is active. c. Under **Choose an enrollment method**, select **Android work profile** and locate the desired **Blueprint**. Copy the **Blueprint link** for that Blueprint. If **Require authentication** is enabled on the Blueprint, end users will need to authenticate to view the instructions. a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment. Optionally check **Assign user to device record** to match the authenticated user to a user in your directory integration. b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps. a. Share the **Blueprint link** with end users to enroll company-owned Android devices with work profile. b. Provide clear instructions for the Android enrollment process, including the requirement for a secondary device to view the enrollment instructions and QR code. ## Android Enrollment Process ### User Enrollment Steps When users open the Blueprint link on a different device (computer, tablet, or phone), they'll authenticate using SSO if you've enabled that option, then see enrollment instructions including a QR code. They'll scan the QR code with their Android device to set up a work profile. Once the work profile is created, the device gets enrolled and configured according to your Blueprint settings. ### Work Profile Setup The enrollment process creates a work profile on the Android device and configures it according to your assigned Blueprint settings. The device is then registered with Iru Endpoint for management. ## Android Management Features Once enrolled, you can manage work profiles for company-owned devices, deploy applications within the work profile, and enforce policies for compliance monitoring. Iru Endpoint provides security configuration, full device inventory, and reporting. ## Work Profile Benefits The work profile approach provides clear separation between personal and work data, ensuring user privacy while maintaining work security. Personal data remains private and unmanaged, while work data can be managed and secured according to your company policies. This gives users the flexibility to use their personal device while maintaining work security. ## Best Practices Devices must be in factory reset state for enrollment, so test your Blueprints on designated devices before enrolling production hardware. Enable SSO authentication for secure enrollment and provide clear instructions to users about the Android enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page). ## Troubleshooting ### Trial Tenant Device Limit Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again. ### Common Issues If enrollment fails, check your Android Enterprise configuration and device state. For authentication issues, ensure SSO is properly configured and users have the necessary access. Verify that work profiles can be created on the device and that Blueprint policies are applied after enrollment. ### Support Resources Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance. ## Related Articles Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Complete guide to Android device enrollment and work profile management What to expect when enrolling your Android devices and setting up a work profile Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms ## Next Steps After setting up Android enrollment: Test the process with a few Android devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page). To enroll Apple or Windows devices as well, see [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment) or [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment). If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide. # Apple Enrollment Source: https://docs.iru.com/en/endpoint/getting-started/enrollment/apple-enrollment Set up Apple device enrollment in Iru Endpoint as part of initial setup. Configure ADE, create enrollment URLs, and enroll your first Apple device. This guide applies to Mac computers, iOS devices, iPadOS devices, Apple TV, and Apple Vision Pro **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). Set up Apple enrollment so you can add Mac computers, iPhone, iPad, Apple TV, and Apple Vision Pro devices to Iru Endpoint and get the right apps, settings, and security controls applied so people can get to work. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works Iru Endpoint supports two approaches: **Automated Device Enrollment (ADE)** for corporate-owned devices (they enroll automatically during setup), and **manual enrollment** through the Enrollment Portal for Bring Your Own Device (BYOD). For ADE, you assign devices in Apple Business or Apple School Manager to Iru Endpoint, then assign them to a Blueprint in Iru Endpoint. For manual enrollment, you share the Enrollment Portal link and Enrollment code with users; they enter the Enrollment code, then sign in (if you require authentication) and install the enrollment profile. In both cases, devices are assigned to a Blueprint and configured according to your policies. ## Automated Device Enrollment (ADE) ADE allows devices to enroll automatically during the initial setup process. This is the recommended method for corporate-owned devices. ### Prerequisites * [Apple Push Notification service (APNs)](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) configured in Iru Endpoint * Apple Business or Apple School Manager account configured * [Automated Device Enrollment token](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) set up in Iru Endpoint * Devices added to your Apple Business or Apple School Manager account * Blueprints configured for device assignment ### ADE Enrollment Flow When users set up their devices, each device connects to Apple's servers during setup and Iru Endpoint automatically applies the assigned Blueprint. Each device gets enrolled and configured according to your policies, then the user completes setup with pre-configured settings. ### Assign devices in Apple Business or Apple School Manager In Apple Business or Apple School Manager, navigate to **Devices**. Select the devices you want to assign. Choose **Assign to Mobile Device Management (MDM) Server**. Select Iru Endpoint as the MDM server. Confirm the assignment when prompted. ### Configure Blueprint assignment In Iru Endpoint, navigate to **Enrollment** → **Automated Device Enrollment**. Filter by **Awaiting Enrollment** (or **All**) to view unenrolled devices. Select the devices and assign them to the appropriate **Blueprint**. Configure any required authentication settings. See [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) for details. Confirm devices appear and use **Fetch devices** to sync from Apple if they do not. ### ADE Library Item Assignment Optionally set or override the ADE Library Item for a device (or multiple devices) instead of using the one from its Blueprint or Blueprint Routing. In Iru Endpoint, go to **Enrollment** → **Automated Device Enrollment**. Filter by **Awaiting Enrollment** (or **All**) to view unenrolled devices, then select the device(s) whose ADE Library Item you want to set or override. The **ADE Library Item** column shows the name of the ADE Library Item assigned to the Blueprint selected for enrollment or Blueprint Routing, or **None** if none is assigned. ADE Library Item column showing None and Unlink from Blueprint button To override the assignment so you can choose a different ADE Library Item, click **Unlink from Blueprint** or **Unlink from Blueprint Routing**, whichever appears. Once unlinked, choose **Re-link to Blueprint** or **Re-link to Blueprint Routing**, or select an **ADE Library Item** from the list. You can do this for one device or for many via multi-select. ADE Library Item dropdown with Select ADE Library Item and Re-link to Blueprint options A direct assignment is sticky and will always apply to the device unless you manually re-link it to the Blueprint or Blueprint Routing. Re-linking can be done one device at a time or in bulk. ## Manual Enrollment Manual enrollment allows users to enroll their devices through the Iru Endpoint Enrollment Portal. ### Setup Manual Enrollment a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint. b. Ensure the **Enrollment Portal** is active. c. Determine which **Blueprint** you want devices to be added to after enrollment. a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment. b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on, then return and select **Require authentication**. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps. a. Copy the **Enrollment Portal link** from **Enrollment** → **Manual Enrollment**. b. Copy the **Enrollment code** for the Blueprint you chose. c. Share the Enrollment Portal link and Enrollment code with your end users. d. Provide a short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment. ### User Enrollment Process When users access the Enrollment Portal, they'll enter the provided Enrollment code and authenticate using SSO if you've enabled that option. They then download and install the enrollment profile to complete enrollment and receive device configuration. ## Enrollment Authentication ### SSO Authentication To enhance security, you can require SSO authentication during enrollment. Configure SSO in Iru Endpoint (see [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup)), then enable **Require authentication** on your Blueprint. Users will authenticate with their identity provider before enrollment. ### Enrollment Codes Each Blueprint has a unique Enrollment code that users need to enroll their devices. You can share codes directly with users, use SSO authentication to automatically assign users to the correct Blueprint, or create multiple Blueprints for different user groups or departments. ## Best Practices Test your Blueprints on designated testing devices before enrolling production hardware. Use Automated Device Enrollment for corporate-owned devices, as it provides the best user experience. Enable SSO authentication for secure enrollment and provide clear instructions to users about the enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page). ## Troubleshooting ### Trial Tenant Device Limit Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again. ### Common Issues If devices aren't appearing, check your Apple Business or Apple School Manager configuration and device assignment. For enrollment failures, verify your Blueprint configuration and network connectivity. If you're seeing authentication issues, check that SSO is configured correctly and that users have the right access. ### Support Resources Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance. ## Related Articles Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Configure Apple device enrollment with Automated Device Enrollment (ADE) What to expect when enrolling your device through the Enrollment Portal Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms ## Next Steps After setting up Apple enrollment: Test the process with a few devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page). To enroll Windows or Android devices as well, see [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment) or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide. # Windows Enrollment Source: https://docs.iru.com/en/endpoint/getting-started/enrollment/windows-enrollment Set up Windows device enrollment in Iru Endpoint as part of initial setup. Configure enrollment URLs and enroll your first Windows device. This guide applies to Windows devices Set up enrollment so you can add Windows 11 devices to Iru Endpoint and assign the right Blueprint so apps, settings, and security controls apply automatically. Most organizations start with the enrollment portal: pick a Blueprint, then share the **Enrollment Portal link** and **Enrollment code** with users. If you use Microsoft Entra ID and Windows Autopilot for new hardware, complete [Configure Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot) instead of (or alongside) manual portal enrollment for those devices. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works In Iru Endpoint you get an Enrollment Portal link and an Enrollment code; share both with users. When users open the link, they enter the Enrollment code, then sign in (if you require authentication) and complete the on-screen steps. The device enrolls and is assigned to the chosen Blueprint automatically. ## Windows Enrollment Requirements Before enrolling Windows devices, ensure you have: * **Windows 11** (24H2 or 25H2 only): Pro, Pro Education, Enterprise, or Education * **Microsoft Edge browser** (required for enrollment; see [Microsoft's Mobile Device Management (MDM) enrollment documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link)) * **Network connectivity** to Iru Endpoint services (for details, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks)) * **Iru Endpoint role** with permission to view **Enrollment** and **Blueprints** (see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions)) * **Blueprint** configured for Windows devices * **Serial number** (required for enrollment). On virtual machines, you can assign a stable serial number. ## Manual Enrollment Setup a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint. b. Ensure the **Enrollment Portal** is active. c. Determine which **Blueprint** you want Windows devices to be added to after enrollment. a. Under **Select Blueprint to enroll the device into**, copy the code of the Blueprint you want devices to enroll into. Click the **Blueprint** and select **Require authentication** (strongly recommended for security). b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on, then return and select **Require authentication**. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps. a. Copy the **Enrollment Portal link** from **Enrollment** → **Manual Enrollment**. b. Share the link and the **Enrollment code** for the correct Blueprint with your end users. c. Provide a short note that they'll enter the Enrollment code, then sign in (if required), and follow on-screen prompts to complete enrollment. Include the requirement to use Microsoft Edge browser. ### Enrollment Portal link and Enrollment code You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The **EnrollmentCodeHere** portion should be the Enrollment code without the dash between the two sets of numbers. ```text Shareable enrollment URL (Windows) icon="link" theme={null} https://subdomain.iru.com/enroll/windows/access-code/EnrollmentCodeHere ``` Consider creating a template email or help article with these instructions to ensure consistency across your organization. ## Windows Enrollment Process ### User Enrollment Steps When users access the Enrollment Portal on their Windows device, they'll enter the Enrollment code you provided and authenticate using SSO if you've enabled that option. Once authenticated, the device enrolls to Iru Endpoint for MDM management and gets configured according to your Blueprint settings. ### MDM Enrollment Process The device enrolls to Iru Endpoint for MDM management. Once enrolled, MDM automatically pushes the Iru Agent and Self Service apps to the device. The Iru Agent handles app inventory and app lifecycle management, while policies and configurations are delivered through the MDM channel. ## Windows Management Features Once enrolled, you can deploy applications, enforce security policies, and monitor compliance across your Windows devices. Iru Endpoint provides centralized management for user and device inventory, along with remote troubleshooting capabilities. ## Best Practices Test your Blueprints on designated devices before enrolling production hardware. Enable SSO authentication for secure enrollment and provide clear instructions to users about the Windows enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page). ## Troubleshooting ### Trial Tenant Device Limit Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again. ### Common Issues If enrollment fails, check your Blueprint configuration and network connectivity. For authentication issues, ensure SSO is properly configured and users have the necessary access. Verify that the Iru Agent installs correctly and that Blueprint policies are applied after enrollment. ### Support Resources Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance. ## Related Articles Microsoft Entra ID and Autopilot setup for zero-touch Windows enrollment Configure dynamic Blueprint assignment during device enrollment using Assignment Rules Complete guide to Windows device enrollment and management setup What to expect when enrolling your Windows device through the enrollment portal Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms ## Next Steps After setting up Windows enrollment: Test the process with a few Windows devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page). To enroll Apple or Android devices as well, see [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment) or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide. # Admins and Access Source: https://docs.iru.com/en/endpoint/getting-started/foundation/admins-and-access Add team members to Iru Endpoint and set role-based access. Assign administrator, standard, help desk, or auditor levels to control permissions. Add team members and assign an access level so your team can use the Iru Endpoint Web App. More than one administrator reduces the risk of a lockout and splits day-to-day management work. ## Add Additional Administrators To invite one administrator at a time, use the steps below. To invite several administrators from a spreadsheet, see [Import Administrators via CSV](/en/iru/access/import-administrators-via-csv). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Click **+ Administrator** in the top right of the Access page. Fill in the required fields (e.g., email, first name, last name) and choose an [access level](/en/iru/access/team-member-role-permissions) for the new team member. Click **Save** to send the invitation. Invitations expire after 24 hours. If 24 hours pass before the account is created, an existing administrator or account owner must resend the invitation from **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**): click the ellipsis next to the user and select **Resend invite**. ## Access Levels Iru Endpoint provides several access levels to control what team members can do: * **Account Owner**: Full access; cannot be deleted by other team members. * **Administrator**: Full access; can be deleted by other administrators. * **Standard**: Same as Administrator but no **Access** or **Organization** in the Account menu. * **Help Desk**: Read-only Blueprints and Library; can perform all device actions. * **Auditor**: Limited read-only access. * Other access levels exist. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for the full list. For Iru Compliance roles and permissions, see [Compliance Permissions](/en/compliance/compliance-permissions). ## Next Steps After adding team members: See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for secure authentication. See [User Directory Integration](/en/endpoint/getting-started/foundation/user-directory-integration) to sync users from your identity provider. # SSO Setup Source: https://docs.iru.com/en/endpoint/getting-started/foundation/sso-setup Configure single sign-on (SSO) for Iru Endpoint admin access. Connect your identity provider using SAML or native integrations for secure login. Set up Single Sign-On (SSO) so team members can sign in to the Iru Endpoint Web App with your existing identity provider. The same SSO connection can be used for [Require Authentication with Automated Device Enrollment (ADE)](/en/endpoint/enrollment/configure-require-authentication-for-enrollment), keeping access secure and consistent from admin sign-in through device enrollment. ## Configure SSO In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (if needed) and scroll to **Authentication methods**. Click **+ Authentication method**. Enter a display name, select the connection type (**Microsoft Entra ID**, **Google Workspace**, or **Custom SAML** for other providers), and click **Create**. Follow the configuration prompts in Iru Endpoint and in your identity provider (e.g., redirect URL, client ID, client secret). Finish the setup in Iru Endpoint as prompted. When the connection is configured, click the **ellipsis** next to the connection name and select **Allow for tenant authentication** so team members can sign in with SSO. Test sign-in in a private browser window before disabling other authentication methods. ## Supported SSO connection types Iru Endpoint supports the following SSO connection types: * [Microsoft Entra ID (Native)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-native) and [Microsoft Entra ID (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-saml) * [Google Workspace (Native)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native) and [Google Workspace (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml) * [Okta (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-okta-saml), [JumpCloud (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-jumpcloud-saml), [OneLogin (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-onelogin-saml), and [Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on) ## Considerations * **[Passkey, Google Social, and Microsoft Social](/en/iru/access/passkeys-and-social-login)** remain available by default. You can disable them after SSO is configured and tested (ellipsis → **Disable for tenant authentication**). * An SSO connection can be used for [Require Authentication during enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) without being allowed for tenant authentication. * Team members must be invited in **Access** before they can sign in with SSO. Test in a private browser window before disabling other authentication methods to avoid lockout. For detailed configuration for each provider, see [Single Sign-On](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ## Next Steps After configuring SSO: See [User Directory Integration](/en/endpoint/getting-started/foundation/user-directory-integration) to sync users. Set up the platforms you plan to manage. You can enable one, two, or all three: * **[Apple Setup](/en/endpoint/getting-started/platform-setup/apple-setup)**: Configure APNs, Apple Business or Apple School Manager, and Apps and Books * **[Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup)**: Enable the Windows platform and configure settings * **[Android Setup](/en/endpoint/getting-started/platform-setup/android-setup)**: Enable Android and configure Android Enterprise # Set Up User Directory Integration in Iru Endpoint Source: https://docs.iru.com/en/endpoint/getting-started/foundation/user-directory-integration Connect your identity provider to Iru Endpoint for automatic user and group synchronization. Integrate with Okta, Entra ID, Google, or OneLogin. Connect your organization's identity provider to sync users and associate devices with users. [User assignment to devices](/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices) in Iru Endpoint is done via directory integration; users are synced from your IdP. Directory integration is optional but recommended for accurate inventory and user-to-device assignment across your fleet. ## Configure Directory Integration In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Integrations** option in the menu. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper right of the Integrations page. Under **Directory integrations**, click **Add and configure** for the integration you want: **Microsoft Entra ID**, **Google Workspace**, or **SCIM protocol** (for providers like Okta). Follow the on-screen setup (e.g., **Get started**, integration name, sign-in with your IdP). Complete consent or **Allow** as prompted so the directory appears on the Integrations page. Users sync automatically every four hours. Verify users appear under **Users** in Iru Endpoint; you can force a sync from the ellipsis on the integration → **Sync users**. ## Supported Directory Integrations Iru Endpoint supports the following directory integrations: * **[Microsoft Entra ID](/en/endpoint/integrations/directory-services/user-directory-integration)**: Native integration for Microsoft Entra ID (formerly Azure AD). * **[Google Workspace](/en/endpoint/integrations/directory-services/user-directory-integration)**: Native integration for Google Workspace. * **[SCIM Integration](/en/endpoint/integrations/scim/scim-directory-integration)**: For providers like Okta, OneLogin, JumpCloud. ## Benefits * **User-Device Mapping**: Automatically associate devices with users. * **Inventory Management**: Better tracking of who has which device. * **Automated Assignment**: Devices can be automatically assigned to users. * **Compliance Reporting**: Richer reporting with user context. ## Considerations * Directory integration is **optional** but recommended for better inventory management. Device users in Iru Endpoint can only be created and assigned via a directory integration. * Users appear under **Users** once synced; Microsoft Entra ID and Google Workspace sync automatically every four hours. * SCIM allows Just-in-Time provisioning and de-provisioning; see [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) for setup. * Integration requires an account with admin access to the directory you want to integrate. For detailed configuration instructions, see [User Directory Integration](/en/endpoint/integrations/directory-services/user-directory-integration). ## Next Steps After configuring directory integration: Set up the platforms you plan to manage. You can enable one, two, or all three: * **[Apple Setup](/en/endpoint/getting-started/platform-setup/apple-setup)**: Configure APNs, Apple Business or Apple School Manager, and Apps and Books * **[Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup)**: Enable the Windows platform and configure settings * **[Android Setup](/en/endpoint/getting-started/platform-setup/android-setup)**: Enable Android and configure Android Enterprise Use [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library) to get policies and apps ready before enrollment. Once Blueprints are configured, set up [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Getting Started Source: https://docs.iru.com/en/endpoint/getting-started/getting-started Get started with Iru Endpoint for Apple, Windows, and Android device management. Follow the setup checklist to configure your tenant and enroll devices. Iru Endpoint lets you protect and manage every device (Apple, Windows, and Android) from one place. Work through four phases: foundation, platform setup, Blueprints and Library, then enrollment. The guides below walk you through each phase so you can provision work-ready devices, enforce policies, and keep your fleet secure. The diagram shows the order at a glance. If you use **Iru Compliance** for audits and frameworks, see [Getting Started With Compliance](/en/compliance/getting-started-with-compliance). Managed-device evidence from Endpoint can appear in Compliance through the [Iru Endpoint Compliance source](/en/compliance/sources/iru-endpoint-source) when your program maps actions to Endpoint data.
Foundation Setup
Platform Setup
Blueprints and Library
Enrollment Setup
Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## Stay Informed After your initial rollout, use the links below for new features, product changes, announcement emails, and status options. * [Iru Product Updates on iru.com](https://www.iru.com/updates/) - Read release notes and subscribe to announcement emails * [Iru Product Updates](/en/iru/platform-overview/iru-product-updates) - RSS feed, optional weekly status emails in Iru Endpoint, and the system Status page ## Foundation Setup Set up who can manage your tenant, how users and devices are identified, and how people sign in. Do this first so access and identity stay consistent and enrollment and device management run smoothly. * [Admins And Access](/en/endpoint/getting-started/foundation/admins-and-access) - Add team members and assign roles * [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) - Configure single sign-on * [User Directory Integration](/en/endpoint/getting-started/foundation/user-directory-integration) - Connect your identity provider ## Platform Setup Enable the devices you need (Apple, Windows, and Android) and complete the setup steps for each. Skip any platform you won't use and move on to the next. ## Blueprints and Library Define the apps, settings, and security controls you want on your devices. Configure Blueprints and the Library before enrollment so policies and apps are ready when devices enroll. * [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) - Create and configure device Blueprints * [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library) - Add applications and configurations to your Library * [Configuring Parameters](/en/endpoint/getting-started/blueprints-and-library/configuring-parameters) - Set up Parameters for Blueprints (macOS only) ## Enrollment Setup After platform setup and Blueprints, set up enrollment for each platform so devices can be managed. To route devices to Blueprints automatically at enrollment from a single entry point, see [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing). Don't have a trial yet? [Book a demo](https://www.iru.com/request-demo/) to see Iru Endpoint in action. # Android Setup Source: https://docs.iru.com/en/endpoint/getting-started/platform-setup/android-setup Set up Android Enterprise integration in Iru Endpoint. Connect your managed Google Play account and configure Android device management capabilities. This guide applies to Android devices Set up the Android Enterprise integration so you can enroll and manage Android devices with work profiles from one platform. Enable Android in Organization settings and configure Android Enterprise (Google); then configure Blueprints and Library, then set up enrollment. Iru Endpoint uses the Android Management API for company-owned work profile management. ## Prerequisites Before you begin, ensure you have: * **Super admin** access to your organization's Google Admin console ([learn more about super admin roles](https://support.google.com/a/answer/2405986?hl=en\&sjid=10473235341862195521-NA)) * **Company-owned devices** in factory reset state for enrollment * **Android 13 and higher** * **Third-party Android mobile Management** enabled in Google Workspace (see steps below) ### Enable Third-Party Android Mobile Management in Google Workspace In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com). Go to **Devices** → **Mobile & endpoints** → **Settings** → **Third-party integrations**. Select the related organization unit, then select the **Android EMM** block. Check the box for **Enable third-party Android mobile management**, then click **SAVE**. Third-party integrations in Google Workspace showing Android EMM and Enable third-party Android mobile management ## Enable Android Platform Only users with the **Account Owner** role can enable or disable platforms. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for more details. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Organization** in the menu. Screenshot of the account menu with Organization option highlighted Select the **Endpoint** tab. Under **Platforms you use**, click **Edit**. Screenshot of the Organization Endpoint tab showing Platforms you use and Edit button Select **Android** (and optionally Windows if you plan to manage both platforms), then click **Save changes** at the bottom of the page. Screenshot of the platform selector with platform options and Save changes button You can optionally enable the Windows platform at the same time when selecting platforms. ## Configure Android Enterprise If the Configure Android Enterprise window is not open, go to [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**, select **Android** under **Platform integrations**, then click **Configure Android Enterprise**. Only the **Account Owner** can configure Android Enterprise. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for roles and permissions. Enter a name for your Android Enterprise integration. Click **Continue with Google** and sign in with your Google Admin account (super admin role required). Select **Next** when prompted (your Iru Endpoint admin email may be pre-filled). Select **Allow** to allow Iru Endpoint to manage your Android devices. Choose how users sign in to the work profile: select **Enable** to allow users to sign in with their managed Google account, or select **Skip** to prevent sign-in with a managed Google account in the work profile. You will be redirected back to the **Integrations** → **Android** page. Verify that the Android Enterprise integration is active and configured. Android Enterprise integration complete in Iru showing active integration Keep a note of the **Enterprise ID** shown here; you will use it in the next section when selecting the EMM provider in Google Workspace. ## Set EMM in Google Workspace After configuring Android Enterprise in Iru, return to Google Workspace and select the EMM that matches the Enterprise ID shown in Iru. This links your Google organization to the Iru Endpoint Android integration. In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com). Go to **Devices** → **Mobile & endpoints** → **Settings** → **Third-party integrations**. Select the related organization unit, then select the **Android EMM** block. Enable third-party Android mobile management if not already enabled, then select the EMM that matches the **Enterprise ID** from your Iru Endpoint Android integration. Click **SAVE**. Selecting the EMM in Google Workspace that matches the Enterprise ID in Iru ## Disconnecting Android Enterprise To disconnect Android Enterprise, remove the integration from Iru Endpoint. Iru coordinates the EMM binding cleanup with Google when you delete the integration. If you are removing management from enrolled devices, delete each Android device record from Iru Endpoint first. See [Deleting a Device Record and Uninstalling Iru Endpoint](/en/endpoint/devices/device-record-management/deleting-a-device-record-and-uninstalling-iru-endpoint). In Iru Endpoint, go to [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**, then select **Android** under **Platform integrations**. Open the action menu (**...**) on the Android Enterprise integration and select **Delete integration**. Confirm the removal when prompted. Only the **Account Owner** can remove the Android Enterprise integration. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). **Do not disconnect from Google Admin.** Removing Iru as your EMM provider in Google Admin (via **Remove** next to your EMM binding) disconnects the integration outside of Iru Endpoint. After that, you may be unable to delete Android device records or remove the Android Enterprise integration from Iru Endpoint. In Google Admin, do not click **Remove** next to your Iru EMM provider. The confirmation dialog below removes the binding for your entire organization. Associated Android Enterprise devices may be wiped. Remove binding to EMM Provider dialog in Google Admin console. Do not use this to disconnect Iru ## Android Management Requirements Before enrolling Android devices, ensure you have completed the Prerequisites above and have: * **Android Enterprise** configured in Iru Endpoint (completed in this guide). * **Blueprint** configured for Android devices. * **(Recommended)** **Single sign-on (SSO)** configured for secure authentication. ## Android Management Capabilities Iru Endpoint provides the following Android management features: * **Work profile management** for company-owned devices. * **Application deployment** and management. * **Policy enforcement** and compliance monitoring. * **Security configuration** and updates. * **Device inventory** and reporting. ## Considerations * **Account Owner required**: Only the Account Owner can configure Android Enterprise. * **Google Admin access**: You need admin access to the Google Admin console. * **Factory reset required**: Devices must be in factory reset state for enrollment. * **Work profile only**: Iru Endpoint supports company-owned work profile management. * **Disconnect through Iru**: Remove the Android Enterprise integration from Iru Endpoint, not from Google Admin. See [Disconnecting Android Enterprise](#disconnecting-android-enterprise). For detailed information about Android enrollment, see [Configuring Android Enrollment](/en/endpoint/enrollment/android/configuring-android-enrollment) and [User Experience with Android Enrollment](/en/endpoint/enrollment/android/user-experience-with-android-enrollment). ## Next Steps After configuring Android Enterprise: Create and configure Blueprints so policies and apps are ready before enrollment. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library). To manage Apple or Windows devices as well, see [Apple Setup](/en/endpoint/getting-started/platform-setup/apple-setup) or [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup). Once Blueprints are configured, set up enrollment: [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment), [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), or [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment). # Apple Setup Source: https://docs.iru.com/en/endpoint/getting-started/platform-setup/apple-setup Set up Apple platform integrations in Iru Endpoint. Configure APNs, Apple Business Manager, Automated Device Enrollment, and Apps and Books. This guide applies to Mac computers, iOS devices, iPadOS devices, Apple TV, and Apple Vision Pro **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). Set up Apple platform integrations to protect and manage Mac computers, iPhones, iPads, Apple TV, and Apple Vision Pro from one place. You'll configure Apple Push Notification service (APNs), Automated Device Enrollment (ADE), and Apps and Books in that order. ## Configure Apple Push Notification service (APNs) APNs is required for communication with Apple devices. For best results, use a macOS computer. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Integrations** option in the menu. Screenshot of the account menu with Integrations option highlighted Under **Platform integrations**, select **Apple**. Screenshot of the Integrations page with Apple platform selected Under **Apple Push Notifications service**, click **Set up APNs**. Screenshot of the Apple integrations section with Set up APNs button Follow the on-screen instructions to create a new APNs certificate. Use a [managed Apple account](/en/endpoint/enrollment/apple/apple-accounts-overview) that multiple team members can access. Do not attempt to use an existing APNs certificate. Create a new one specifically for Iru Endpoint. APNs certificates must be renewed annually. Iru Endpoint will send email reminders to Team Members with Administrator or Account Owner permissions starting 30 days before certificate expiry. For renewal and troubleshooting, see [Configure Apple Push Notification Service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service). ## Configure Automated Device Enrollment Automated Device Enrollment enables zero-touch deployment for corporate-owned Apple devices. [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your tenant before you set up Automated Device Enrollment. Organizations enroll in [Apple Business](https://business.apple.com/) or [Apple School Manager](https://school.apple.com/) (both are free; verification may take several days). Devices purchased from Apple or authorized resellers are automatically added to your account. To add existing devices, see [Adding Devices to Apple Business or Apple School Manager](/en/endpoint/settings/apple-integrations/adding-devices-to-apple-business-manager). In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Integrations** option in the menu. Screenshot of the account menu with Integrations option highlighted Under **Platform integrations**, select **Apple**. Screenshot of the Integrations page with Apple platform selected Under **Automated Device Enrollment**, click **Set up Automated Device Enrollment**. Screenshot of the Apple integrations section with Set up Automated Device Enrollment button In the setup wizard, continue until Iru Endpoint provides a **PEM** public key file (download or save it when prompted). You will upload this file to Apple Business or Apple School Manager in the next steps. Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) with a Managed Apple Account that can manage device management services. Click the **Devices** tab at the top of the page. In the left sidebar, click **Management**. Scroll to the bottom of the **Management Services** list and click **Add** next to **Add device management service**. Apple Business or Apple School Manager Management Services list with Add device management service In the **Service Name** field, enter a name for this MDM integration (for example, **Iru Endpoint**). If your organization needs it, select **Allow this service to release devices**. Upload the **PEM** file from Iru Endpoint. Click **Next**. Add device management service form with Service Name, release devices option, and public key upload Click **Download Service Token**. Apple Business or Apple School Manager Download Service Token action Click **Done**. Return to Iru Endpoint and upload the **.p7m** service token file when prompted. Complete any remaining steps in the wizard and click **Done**. In Apple Business or Apple School Manager, add Iru Endpoint as your Mobile Device Management (MDM) server and assign devices. Assigned devices will appear in Iru Endpoint as **Awaiting Enrollment**. ## Configure Apps and Books Apps and Books (formerly Volume Purchasing Program) lets you distribute App Store apps to devices. [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your tenant before you set up Apps and Books. You cannot share the same Apps and Books token across multiple MDM servers. [Create a new organizational unit](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant and use a dedicated token. [Create a new organizational unit](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) in Apple Business or Apple School Manager for your Iru Endpoint tenant. In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Integrations** option in the menu. Screenshot of the account menu with Integrations option highlighted Under **Platform integrations**, select **Apple**. Screenshot of the Integrations page with Apple platform selected Click the **Set up Apps and Books** button inside **Apps and Books**. In the new window, sign in to [Apple Business](https://support.apple.com/guide/business/welcome/web) or [Apple School Manager](https://support.apple.com/guide/apple-school-manager/welcome/web) to complete the integration. In Apple Business or Apple School Manager, click your **organization name** at the top right of the page. Click **Settings**. Apple Business or Apple School Manager with organization menu open and Settings option After you open **Settings**, you should already be on **Payments & Billing** → **Apps & Books**. This view is where your organization's Apps and Books content tokens appear. Under **Content Tokens**, click **Download** next to the token you want to use with Iru Endpoint. Apple Business or Apple School Manager Payments and Billing Apps and Books Content Tokens with Download Return to the Iru Endpoint Web App and upload your **token**. Click **Complete Apps and Books setup**. For detailed information about each integration, see [Configure Apple Push Notification Service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service), [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment), [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books), and [Apple Integrations Overview](/en/endpoint/settings/apple-integrations/apple-integrations-overview). ## Next Steps After completing Apple setup: Create and configure Blueprints so policies and apps are ready before enrollment. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library). To manage Android or Windows devices as well, see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) or [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup). Once Blueprints are configured, set up enrollment: [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Windows Setup Source: https://docs.iru.com/en/endpoint/getting-started/platform-setup/windows-setup Configure Windows platform settings in Iru Endpoint. Set up enrollment prerequisites and prepare your tenant for Windows device management. This guide applies to Windows devices Set up the Windows platform to enroll and manage Windows 11 computers from one place. Enable Windows in Organization settings, then configure Blueprints and Library, then set up enrollment. Iru Endpoint supports Windows 11 (24H2 or 25H2 only) on Pro, Pro Education, Enterprise, or Education editions. ## Enable Windows platform Only users with the **Account Owner** role can enable or disable platforms. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for more details. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Organization** in the menu. Screenshot of the account menu with Organization option highlighted Select the **Endpoint** tab. Under **Platforms you use**, click **Edit**. Screenshot of the Organization Endpoint tab showing Platforms you use and Edit button Select **Windows** (and optionally Android if you plan to manage both platforms), then click **Save changes** at the bottom of the page. Screenshot of the platform selector with platform options and Save changes button You can optionally enable Android at the same time when selecting platforms. The Android platform requires additional configuration. See [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) to configure the platform. ## Windows Management Requirements Before enrolling Windows devices, ensure you have: * **Windows 11** (24H2 or 25H2 only). * **Pro, Pro Education, Enterprise, or Education** editions. * **Microsoft Edge browser** (required for enrollment; see [Microsoft's Mobile Device Management (MDM) enrollment documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link)). * **Network connectivity** to Iru Endpoint services. For domains, ports, and firewall configuration, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). * **Serial number** (required for enrollment). On virtual machines, you can assign a stable serial number. * **(Recommended)** Single sign-on (SSO) configured for secure authentication. ## Windows Management Capabilities Iru Endpoint provides the following Windows management features: * **Device enrollment** via enrollment portal or [Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot) (Microsoft Entra ID zero-touch). * **Application deployment** and management. * **Policy enforcement** and compliance monitoring. * **Security configuration** and updates. * **User and device inventory** management. For detailed information about Windows enrollment, see [Configuring Windows Enrollment](/en/endpoint/enrollment/windows/configuring-windows-enrollment) and [User Experience with Windows Enrollment](/en/endpoint/enrollment/windows/user-experience-with-windows-enrollment). To enroll new hardware during OOBE with Microsoft Entra ID, see [Configure Windows Autopilot](/en/endpoint/settings/windows-integrations/configure-windows-autopilot). ## Next Steps After enabling the Windows platform: Create and configure Blueprints so policies and apps are ready before enrollment. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library). To manage Apple or Android devices as well, see [Apple Setup](/en/endpoint/getting-started/platform-setup/apple-setup) or [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup). Once Blueprints are configured, set up enrollment: [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment), [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), or [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment). # Iru MCP Source: https://docs.iru.com/en/endpoint/integrations/ai-assistants/iru-mcp Connect Cursor, Claude Desktop, OpenAI Codex, or other MCP clients to Iru’s Enterprise API by creating MCP-enabled tokens scoped to your tenant. ### Introduction The **Model Context Protocol (MCP)** is an open standard for connecting client applications (**hosts**) to **MCP servers**. Servers expose tools, resources, and prompts so AI assistants can take allowed actions in your environment through one consistent pattern, instead of building and maintaining a separate custom integration for every assistant or workflow you add. The **Iru Model Context Protocol (MCP) server** exposes the Iru **Enterprise API** surface, structured as MCP tools for AI assistants. Connect Cursor, Claude Desktop, OpenAI Codex, or other MCP-enabled clients to query devices, Blueprints, Library Items, and take allowed actions in natural language, without building your own Iru API integration. You can also combine Iru’s tools with tools from other vendors (for example ticketing, chat, or IAM) to create end-to-end workflows orchestrated in natural language. When Iru adds additional Enterprise API capabilities, those capabilities become available through MCP on the same permission model. The Enterprise API (and the MCP backed by it) applies across Iru areas that surface that API, including Endpoint and other products such as Vulnerability Management and Endpoint Detection and Response, depending on your tenant and entitlements. For REST usage (HTTP APIs and bearer tokens outside MCP), see the [Iru API Overview](/en/endpoint/api/iru-api-overview). ### Before You Begin * You need an Iru admin account with permission to create and manage **API tokens** in **Access**, as described in the [Iru API Overview](/en/endpoint/api/iru-api-overview). * You need a **supported MCP client** (such as Claude Desktop, Cursor, or Codex). ### Create an API token with MCP Use **[Generate an API Token](/en/endpoint/api/iru-api-overview#generate-an-api-token)** in the [Iru API Overview](/en/endpoint/api/iru-api-overview) for the full UI walkthrough (screenshots, **Copy Token**, **Next**, **Configure** / **Skip**, permission grids). The steps here match that article; you must turn on **Enable MCP** before **Create** so Iru issues MCP configuration for this token. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. In **Access**, click the **API tokens** tab. Click **Add Token** to create a new API token. Provide a **Name** and a **Description** for your API token. Turn on **Enable MCP** before you click **Create.** For MCP, this step is required; if **Enable MCP** is off, you get an Enterprise API token without MCP access or MCP configuration. Click **Create.** **API rate limits:** The Iru Endpoint Management API enforces **10,000 requests per hour per customer**. MCP calls authenticate with the **`X-API-Key`** value under **`headers`** in **MCP configuration** for that token and count toward **the same tenant hourly limit** as direct REST usage and other integrations. **All API tokens in your tenant share that limit.** For background and troubleshooting, see [Considerations](/en/endpoint/api/iru-api-overview#considerations) in the Iru API Overview and the [Iru Endpoint Management API documentation](https://api-docs.kandji.io/). ### Copy Your Token and MCP Configuration After you create the token, Iru shows a one-time success screen: **Your token has been successfully created!** Copy what you need, store it safely, and remember you will not see it again. Run the steps below in order; **MCP configuration** means the JSON from **Copy MCP configuration** in step 2. For REST or custom scripts, use **Copy** beside the **API token** on the success screen. That value is not used for MCP. In **MCP configuration**, review the JSON, then use **Copy MCP configuration**. Iru’s snippet is built around **`url`**, **`type`**, and **`headers`**: * **URL**: the **`url`** field (the MCP endpoint Iru gives you). * **X-API-Key**: the **`X-API-Key`** entry inside **`headers`**. Copy it exactly as Iru shows it, including the **`sk_live:`** prefix already in the snippet; MCP clients send it as the **`X-API-Key`** HTTP header on each request. * **X-MCP-Profile**: the **`X-MCP-Profile`** entry inside **`headers`**, sent as the **`X-MCP-Profile`** HTTP header. **Copy MCP configuration** is the JSON for MCP. Use the values from **`headers`** exactly as Iru shows them. The **`X-API-Key`** value includes the **`sk_live:`** prefix already in the snippet. Placeholder example only: ```json mcp.json lines theme={null} { "mcpServers": { "iru": { "url": "https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools", "type": "http", "headers": { "X-API-Key": "sk_live:YOUR_API_KEY", "X-MCP-Profile": "YOUR_PROFILE_ID" } } } } ``` Select the confirmation checkbox: **I have copied the token and MCP configuration and understand that I will not be able to see these details again.** Click **Next**. If you lose the token or configuration, **revoke** the token and **create a new one**. ### Configure API permissions After you click **Next**, you’ll see a **Manage API Permissions** screen. These permissions control which Enterprise API endpoints the MCP can access. Choose one of the following: * **Configure** to set permissions now (recommended). * **Skip** to set permissions later. If you clicked **Configure**, use the permissions list to select what this token can do: * Expand a category (for example **Blueprints**) to see individual endpoints. * Check the boxes for the endpoints you want to allow. When you’re done, click **Save**. Verify the token shows **MCP enabled: Yes** if you turned on MCP at creation time, and that the permissions you selected are enabled. If you skipped permission setup, you can configure permissions later by opening the token, clicking **Edit**, then selecting the permissions and clicking **Save**. ### Revoke an API token Revoke the token in **Access** like any other API token. Use **[Revoke a Token](/en/endpoint/api/iru-api-overview#revoke-a-token)** in [Iru API Overview](/en/endpoint/api/iru-api-overview) for the steps and **Activity** notes. ### Considerations The REST API token from **Copy** and the **MCP configuration** JSON are each shown only once on the success screen at creation time. Revoking the token stops API and MCP access that relied on it. For destructive operations (for example erase, delete, lock), your assistant should summarize the impact and require your explicit approval before executing, unless you’ve added that action to an allowlist for the MCP. Follow your organization’s change-management rules. Large list responses are paginated. Ask the assistant to refine filters, move to the next page, or export when you need the full dataset without pulling every row into the chat. **MCP configuration** is JSON with **`url`**, **`type`**, and **`headers`**. **`headers`** holds **`X-API-Key`** and **`X-MCP-Profile`**, which together are what Iru expects on each MCP request. Point your client at **`url`** and forward those two header values unchanged. The **`X-API-Key`** value includes the **`sk_live:`** prefix already in the snippet. ### Best Practices Create a token with only the Enterprise API scopes your automation needs, then enable MCP on that token. For example, use a read-focused token for reporting assistants and a narrower operational token for remediation workflows. If **MCP configuration** leaked, revoke the token in Iru and issue a new one; update every MCP client that still has the old **`url`** or **`headers`** values. **`claude_desktop_config.json`** contains your **`url`** and header values. Do not commit it to source control or share it in chat logs. Treat **MCP configuration** and any REST token you **Copy** for non-MCP use as secrets. Store them in a password manager or secure vault, not in chat logs or screenshots. ### Add the Iru MCP to Your MCP Client Choose a client, then follow the steps for that host. ### Add the Iru MCP to Claude Desktop **Claude Desktop** is Anthropic’s desktop app for chatting with Claude. Register Iru by editing **`claude_desktop_config.json`** with the **`url`** and **`headers`** values from your **MCP configuration**. ### Prerequisites * In Iru, complete [Copy your token and MCP configuration](#copy-your-token-and-mcp-configuration) so you have **`url`** and **`headers`** (**`X-API-Key`**, **`X-MCP-Profile`**). * Install **Node.js 20+** from [nodejs.org](https://nodejs.org/). The installer includes **`npx`**, which Claude Desktop uses to run the Iru MCP connection. Use **`mcp-remote@latest`** in **`args`** so Claude Desktop runs the current **mcp-remote** package. If the MCP connection fails with **`latest`**, temporarily pin to a previous version (for example **`mcp-remote@0.1.13`**). When that failure occurs, the problem is with **mcp-remote**, not with Iru. Download Claude Desktop for macOS, install the app, and sign in: [Download Claude](https://claude.com/download). Open Claude Desktop, then select **Claude → Settings** from the menu bar. In **Settings**, select **Developer**. Under **Developer**, select **Edit Config**. Claude Desktop opens the config folder in **Finder**. Open **`claude_desktop_config.json`** from that folder in your preferred text editor. A new file may show **`{}`**. An existing file may already include **`mcpServers`**, **`preferences`**, or other settings. In that case, add only the **`"iru"`** block inside **`mcpServers`** and leave the rest unchanged. After the closing **`}`** of **`mcpServers`**, add a comma before the next top-level section (for example **`"preferences"`**). Paste into **`claude_desktop_config.json`**. The three highlighted lines are where you add your values from **MCP configuration**. Put your **`X-API-Key`** and **`X-MCP-Profile`** in **`env`**; when Claude Desktop starts, **`mcp-remote`** uses those values for the **`${IRU_X_API_KEY}`** and **`${IRU_X_MCP_PROFILE}`** placeholders in **`args`**. ```json claude_desktop_config.json lines highlight={8,15,16} theme={null} { "mcpServers": { "iru": { "command": "npx", "args": [ "-y", "mcp-remote@latest", "https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools", "--header", "X-API-Key:${IRU_X_API_KEY}", "--header", "X-MCP-Profile:${IRU_X_MCP_PROFILE}" ], "env": { "IRU_X_API_KEY": "sk_live:YOUR_API_KEY", "IRU_X_MCP_PROFILE": "YOUR_PROFILE_ID" } } } } ``` Replace the highlighted placeholders: * **`https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools`** with **`url`** from **MCP configuration** * **`sk_live:YOUR_API_KEY`** with **`X-API-Key`** from **MCP configuration** * **`YOUR_PROFILE_ID`** with **`X-MCP-Profile`** from **MCP configuration** Skip this step if you started from an empty file. When **`preferences`** or other settings already sit below **`mcpServers`**, your file should connect the sections like this. The highlighted line is the comma between **`mcpServers`** and the next top-level key: ```json claude_desktop_config.json lines highlight={4} theme={null} "IRU_X_MCP_PROFILE": "YOUR_PROFILE_ID" } } }, "preferences": { "remoteToolsDeviceName": "your-device-name", "coworkWebSearchEnabled": true } } ``` Save **`claude_desktop_config.json`**, then fully quit Claude Desktop. Closing the window is not enough; select **Claude → Quit Claude** from the menu bar, then relaunch Claude Desktop. Claude Desktop loads MCP configuration on start-up. After Claude Desktop reopens, start a **new chat** and ask: ```text theme={null} List my Iru devices ``` If the connection is working, Claude calls the Iru MCP server and returns a list of your enrolled devices. If you see an error, see [Troubleshooting](#troubleshooting) below. Claude prompts before each Iru MCP tool use. Choose **Allow once** for that run only, or **Always allow** when you want fewer prompts for similar actions. Approve when you want reads or allowed changes in Iru; decline if you do not want the tool to run. In Claude Desktop, open **Settings → Developer** to review the **`iru`** entry, whether the server is running, and any errors the host reports. See [Troubleshooting](#troubleshooting) below. Download Claude Desktop for Windows, install the app, and sign in: [Download Claude](https://claude.com/download). Open Claude Desktop, then select the hamburger menu, **File**, then **Settings**. In **Settings**, select **Developer**. Under **Developer**, select **Edit Config**. Claude Desktop opens the config folder in **File Explorer**. Open **`claude_desktop_config.json`** from that folder in your preferred text editor. A new file may show **`{}`**. An existing file may already include **`mcpServers`**, **`preferences`**, or other settings. In that case, add only the **`"iru"`** block inside **`mcpServers`** and leave the rest unchanged. After the closing **`}`** of **`mcpServers`**, add a comma before the next top-level section (for example **`"preferences"`**). Paste into **`claude_desktop_config.json`**. The three highlighted lines are where you add your values from **MCP configuration**. Put your **`X-API-Key`** and **`X-MCP-Profile`** in **`env`**; when Claude Desktop starts, **`mcp-remote`** uses those values for the **`${IRU_X_API_KEY}`** and **`${IRU_X_MCP_PROFILE}`** placeholders in **`args`**. ```json claude_desktop_config.json lines highlight={8,15,16} theme={null} { "mcpServers": { "iru": { "command": "C:\\Program Files\\nodejs\\npx.cmd", "args": [ "-y", "mcp-remote@latest", "https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools", "--header", "X-API-Key:${IRU_X_API_KEY}", "--header", "X-MCP-Profile:${IRU_X_MCP_PROFILE}" ], "env": { "IRU_X_API_KEY": "sk_live:YOUR_API_KEY", "IRU_X_MCP_PROFILE": "YOUR_PROFILE_ID" } } } } ``` Replace the highlighted placeholders: * **`https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools`** with **`url`** from **MCP configuration** * **`sk_live:YOUR_API_KEY`** with **`X-API-Key`** from **MCP configuration** * **`YOUR_PROFILE_ID`** with **`X-MCP-Profile`** from **MCP configuration** Skip this step if you started from an empty file. When **`preferences`** or other settings already sit below **`mcpServers`**, your file should connect the sections like this. The highlighted line is the comma between **`mcpServers`** and the next top-level key: ```json claude_desktop_config.json lines highlight={4} theme={null} "IRU_X_MCP_PROFILE": "YOUR_PROFILE_ID" } } }, "preferences": { "remoteToolsDeviceName": "your-device-name", "coworkWebSearchEnabled": true } } ``` Save **`claude_desktop_config.json`**, then fully quit Claude Desktop. Closing the window is not enough; right-click the **Claude** icon in the system tray and select **Quit**, then relaunch Claude Desktop. Claude Desktop loads MCP configuration on start-up. After Claude Desktop reopens, start a **new chat** and ask: ```text theme={null} List my Iru devices ``` If the connection is working, Claude calls the Iru MCP server and returns a list of your enrolled devices. If you see an error, see [Troubleshooting](#troubleshooting) below. Claude prompts before each Iru MCP tool use. Choose **Allow once** for that run only, or **Always allow** when you want fewer prompts for similar actions. Approve when you want reads or allowed changes in Iru; decline if you do not want the tool to run. In Claude Desktop, open **Settings → Developer** to review the **`iru`** entry, whether the server is running, and any errors the host reports. When the MCP server runs, Claude may also write **`logs\mcp-server-iru.log`** next to **`claude_desktop_config.json`** in the Claude Desktop app data folder for your install. See [Troubleshooting](#troubleshooting) below. ### Add the Iru MCP to Cursor **Cursor** is an AI-native code editor for writing and editing software with built-in assistance. The Cursor desktop app is available on **macOS**, **Windows**, and **Linux**. Add Iru under **Tools & MCP** so you can use your tenant’s tools from the editor. In Iru, complete [Copy your token and MCP configuration](#copy-your-token-and-mcp-configuration) so you have **`url`** and **`headers`** (**`X-API-Key`**, **`X-MCP-Profile`**). Download Cursor for your platform, install the app, and sign in: [Download Cursor](https://cursor.com/download). Open Cursor **MCP Settings**: * **macOS:** **Cursor → Settings → Cursor Settings**, then **Tools & MCP**. * **Windows/Linux:** **File → Preferences → Cursor Settings**, then **Tools & MCP**. Click **Add Custom MCP**. The **`mcp.json`** file opens in the editor. How you paste depends on whether other MCP servers are already defined. Cursor starts with a placeholder like this: ```json mcp.json lines theme={null} { "mcpServers": {} } ``` Replace the **entire** contents of **`mcp.json`** with the complete **MCP configuration** you copied from [Copy MCP configuration](#copy-your-token-and-mcp-configuration) when you created the token. Select everything in the file (including Cursor’s placeholder), paste, and leave **only** Iru’s JSON in **`mcp.json`**. Do not remove the **`sk_live:`** prefix from **`X-API-Key`** in **`headers`**. If **`mcpServers`** already lists other servers you want to keep, do **not** replace the whole **`mcp.json`** file. Add only the **`iru`** block from **MCP configuration**. Copy from **`"iru": {`** through the closing **`}`** for that server (the second **`}`** after **`headers`**). Add a comma after the closing **`}`** of the server entry that comes immediately before **`iru`**. Keep **`X-API-Key`** exactly as Iru shows it, including the **`sk_live:`** prefix already in the snippet. Example when another server is already configured (highlighted lines show the trailing comma and the **`iru`** block to copy and paste into the **`mcp.json`** file): ```json mcp.json lines highlight={10,11-18} theme={null} { "mcpServers": { "previous-mcp-server": { "url": "https://example.com/mcp", "type": "http", "headers": { "X-API-Key": "sk_live:YOUR_OTHER_KEY", "X-MCP-Profile": "YOUR_OTHER_PROFILE" } }, "iru": { "url": "https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools", "type": "http", "headers": { "X-API-Key": "sk_live:YOUR_API_KEY", "X-MCP-Profile": "YOUR_PROFILE_ID" } } } } ``` Cursor does not save **`mcp.json`** automatically after you paste. Save the file manually before you quit or restart: * **macOS:** **Command+S** * **Windows/Linux:** **Ctrl+S**, or **File → Save** **Fully quit Cursor**, then reopen it. Cursor loads MCP on startup. Return to **Tools & MCP**. Confirm **`iru`** appears and the toggle shows **enabled.** For more on using MCP in Cursor, see [Model Context Protocol (MCP) in Cursor](https://cursor.com/docs/mcp). ### Add the Iru MCP to OpenAI Codex **OpenAI Codex** is OpenAI’s coding agent for building and changing software with AI. Use the **Codex Desktop App** or the **Codex** extension in VS Code to register Iru as an MCP server and work with your tenant from chat. #### Codex Desktop App The Codex Desktop App is available on **macOS** and **Windows**. For platform support, install options (including Intel Mac builds), and other app requirements, see the [Codex app documentation](https://developers.openai.com/codex/app) on OpenAI Developers. In Iru, complete [Copy your token and MCP configuration](#copy-your-token-and-mcp-configuration) so you have **`url`** and **`headers`** (**`X-API-Key`**, **`X-MCP-Profile`**). Download the Codex Desktop App and install it: [Codex](https://chatgpt.com/codex/). Open Codex and sign in with your ChatGPT account or an OpenAI API key. Codex is included with eligible ChatGPT plans. See [Open Codex and sign in](https://developers.openai.com/codex/app) in the Codex app documentation. In Codex, go to **Settings**. Select **MCP servers**. Click **+ Add server**. Enter **Iru MCP** for **Name**. Select **Streamable HTTP**. Enter the **`url`** value from **MCP configuration** in **URL**. Under **Headers**, set **Key** to **`X-API-Key`** and **Value** to the **`X-API-Key`** entry from **`headers`** in **MCP configuration**, copied exactly as Iru shows it, including the **`sk_live:`** prefix already in the snippet. Click **+ Add header**. Set **Key** to **`X-MCP-Profile`** and **Value** to the **`X-MCP-Profile`** entry from **`headers`** in **MCP configuration**. Click **Save**. Fully quit Codex, then open it again so it reloads MCP settings. Start a **new chat** and ask Codex a question about an Enterprise API area your token has permission to use (for example devices or Blueprints). #### Codex IDE extension The **Codex IDE extension** runs OpenAI’s coding agent in your editor. Add Iru through the extension’s MCP settings. In Iru, complete [Copy your token and MCP configuration](#copy-your-token-and-mcp-configuration) so you have **`url`** and **`headers`** (**`X-API-Key`**, **`X-MCP-Profile`**). Install [Visual Studio Code](https://code.visualstudio.com/) if needed. VS Code supports **macOS**, **Windows**, and **Linux**. Install the [Codex extension](https://marketplace.visualstudio.com/items?itemName=openai.chatgpt) from the Visual Studio Marketplace. The extension also works in other VS Code–compatible editors (for example Cursor); menus and platform support may differ. See the [Codex IDE extension](https://developers.openai.com/codex/ide) documentation for install options. Open the Codex sidebar using the OpenAI logo in the activity bar, **Open Codex Sidebar**, or by toggling the secondary sidebar and selecting the **Codex** tab. Click **Sign in with ChatGPT** and authenticate. Codex is included with eligible ChatGPT plans. Follow any prompts to finish setup. In the Codex sidebar, click the **gear** icon, then **Codex settings**. Click **MCP servers**. Click **+ Add server**. Enter **Iru MCP** for **Name**. Select **Streamable HTTP**. Enter the **`url`** value from **MCP configuration** in **URL**. Under **Headers**, set **Key** to **`X-API-Key`** and **Value** to the **`X-API-Key`** entry from **`headers`** in **MCP configuration**, copied exactly as Iru shows it, including the **`sk_live:`** prefix already in the snippet. Click **+ Add header**. Set **Key** to **`X-MCP-Profile`** and **Value** to the **`X-MCP-Profile`** entry from **`headers`** in **MCP configuration**. Click **Save**. If Codex shows **Restart extension**, click it so MCP settings reload. In the **Codex** sidebar, start a conversation and ask about an Enterprise API area your token has permission to use (for example devices or Blueprints). ### Troubleshooting For MCP-wide help (log locations, configuration checks, MCP Inspector, and client debugging beyond the Iru-specific notes below), see the [Model Context Protocol debugging guide](https://modelcontextprotocol.io/docs/tools/debugging). Re-check **`url`** and **`headers`** (**`X-API-Key`**, **`X-MCP-Profile`**) in **MCP configuration**. Remove stray spaces. **`X-API-Key`** must match the full value from Iru, including the **`sk_live:`** prefix already in the snippet. If the backing token was rotated or revoked, create a new one and refresh every client. The Enterprise API scopes on the token can block those operations. Edit the token’s API permissions in **Access**, or create a new token with the scopes you need. Confirm **MCP configuration** in the client matches **`url`** and **`headers`** from Iru, then fully quit and restart the host app so it reloads MCP settings. If the problem persists, use the [Model Context Protocol debugging guide](https://modelcontextprotocol.io/docs/tools/debugging) for host logs, JSON validation, and testing with MCP Inspector. Custom connectors reach your MCP server from Anthropic’s infrastructure. Confirm that **`url`** in **MCP configuration** is correct, that the service is on the public internet, and that any corporate firewall allows Anthropic’s IP ranges. See [Get started with custom connectors using remote MCP](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp) and [Anthropic IP addresses](https://platform.claude.com/docs/en/api/ip-addresses). In Claude Desktop, open **Settings**, then **Developer**. There you can review the **`iru`** server configuration, see whether the server is running, and read any errors the host reports. For Claude log paths, DevTools, and related steps, see **Debugging in Claude Desktop** in the [Model Context Protocol debugging guide](https://modelcontextprotocol.io/docs/tools/debugging). Use **`mcp-remote@latest`** in **`args`** so you stay on the current **mcp-remote** package. If the connection fails, temporarily change that value to a previous version (for example **`mcp-remote@0.1.13`**), save **`claude_desktop_config.json`**, then fully quit and reopen Claude Desktop. Return to **`mcp-remote@latest`** when you can. When this failure occurs, the problem is with **mcp-remote**, not with Iru. Confirm **Node.js 20+** is installed, then open **`claude_desktop_config.json`** and confirm the **`iru`** entry’s MCP URL in **`args`** and the values in **`env`** still match **`url`**, **`X-API-Key`**, and **`X-MCP-Profile`** from **MCP configuration** (**`IRU_X_API_KEY`** must include the **`sk_live:`** prefix). The **`--header`** lines should still use **`${IRU_X_API_KEY}`** and **`${IRU_X_MCP_PROFILE}`**, not your raw key or profile. On macOS, **`command`** should be **`npx`**; on Windows, use the full path **`C:\Program Files\nodejs\npx.cmd`**. Save the file and **fully quit** Claude Desktop (**Claude → Quit Claude** on macOS, tray **Quit** on Windows) before reopening. On Windows, check **`logs\mcp-server-iru.log`** beside **`claude_desktop_config.json`** if **`iru`** still fails. See [Add the Iru MCP to Claude Desktop](#claude-desktop). **Fully quit Cursor**, then reopen it; Cursor loads MCP on startup. If **`mcp.json`** still fails to load, confirm valid JSON. For a new setup, confirm you replaced the **entire** file with **MCP configuration**; if you merged into existing servers, confirm the **`iru`** block and commas are correct. Check that **`url`**, **`X-API-Key`**, and **`X-MCP-Profile`** match **MCP configuration** (see [Add the Iru MCP to Cursor](#cursor)). **`X-API-Key`** must include the **`sk_live:`** prefix already in the snippet. For deeper host issues, see the [Model Context Protocol debugging guide](https://modelcontextprotocol.io/docs/tools/debugging). If Codex shows **Add a project to use Codex** when you chat, open or create a project folder in the editor first, then return to the **Codex** sidebar. If you cannot save or change MCP settings in the UI, edit **`~/.codex/config.toml`** directly. Per [Model Context Protocol in Codex](https://developers.openai.com/codex/mcp), the CLI, **Codex IDE extension**, and **Codex Desktop App** share this file. See [Codex IDE extension](#ide-extension) or [Codex Desktop App](#desktop-app) for the UI setup flows. Open **`~/.codex/config.toml`** in a text editor. The **`~`** is your home folder (for example **`/Users/your-user-name/.codex/config.toml`** on macOS). Set **`url`** and **`http_headers`** from **MCP configuration**, copied exactly as Iru shows them. The **`X-API-Key`** value in **`http_headers`** includes the **`sk_live:`** prefix already in the snippet. Use **Iru MCP** as the server name. In **`config.toml`**, the table name after **`mcp_servers.`** must match how Codex stored that server (often derived from **Iru MCP**, for example **`iru_mcp`**). Example for **Iru MCP**: ```toml config.toml lines theme={null} [mcp_servers.iru_mcp] enabled = true url = "https://YOUR_TENANT.connect.iru.com/mcp-server/connector/kandji/tools" http_headers = { "X-API-Key" = "sk_live:YOUR_API_KEY", "X-MCP-Profile" = "YOUR_PROFILE_ID" } ``` Save the file, then **fully quit** Codex or restart your editor so MCP settings reload. Confirm **Iru MCP** is enabled in Codex MCP settings, **`url`** and **`headers`** match **MCP configuration** (**`X-API-Key`** must include the **`sk_live:`** prefix already in the snippet), then **fully quit** the host app and reopen it so Codex reloads MCP. For the **Codex IDE extension**, this means quitting the editor; for the **Codex Desktop App**, quit Codex completely. For transport-level debugging, see the [Model Context Protocol debugging guide](https://modelcontextprotocol.io/docs/tools/debugging). ### Related Articles REST APIs, tokens, permissions, and Activity for the Enterprise API that MCP exposes as tools. Import the published collection and send authenticated requests outside MCP. Browse endpoints, parameters, and request and response examples for the underlying API. Connect third-party products and map the API permissions each integration needs. # AD CS Integration: AD CS Connector Installation Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation Install and register the Iru Endpoint AD CS Connector on a domain-joined Windows Server to deliver certificates to enrolled Mac and Windows devices. ### About the AD CS Connector This article explains how to install and register the Iru Endpoint AD CS Connector on a domain-joined Windows Server. The Connector does not install on Mac computers or Windows client endpoints. After the Connector is **Active** and **Connected** in Iru Endpoint, AD CS-issued certificates are delivered to enrolled Mac computers and Windows devices through Library Items. For updating an **updated** Connector on Iru Endpoint or migrating from Kandji with AD CS, see [Updating the Iru AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#updating-the-iru-ad-cs-connector) and [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) in **AD CS Integration: Overview**. ### How It Works The Connector uses the WebSocket protocol over TCP port 443 for a persistent connection to Iru Endpoint and the Microsoft [Remote Procedure Call](https://docs.microsoft.com/en-us/windows/win32/rpc/rpc-start-page) (RPC) framework to communicate with your AD CS deployment. After registration, the Connector fulfills certificate requests initiated from Iru Endpoint. ### Prerequisites Confirm the following before you install the Connector on Windows Server. Ensure you have certificate templates in AD CS that match how you deploy to Apple and Windows devices, per your CA documentation and security standards. For the computer certificate on the Connector host, follow [AD CS Integration: Create a Computer Certificate Template](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template). Meet the **AD CS Integration Network Requirements** in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements). For the updated Connector, allow your Iru web app, Iru Identity, tenant API (`subdomain.gateway.iru.com`, `subdomain.gateway.eu.iru.com`, `subdomain.clients.*`), and `adcsconn` endpoints as documented there. Do **not** rely on Auth0 allowlists alone for the updated Connector. Your network must allow traffic between Iru Endpoint, the Connector host, and AD CS, including HTTPS from the Connector to Iru Endpoint without SSL inspection breaking that path. If any hosts still run the **legacy** Connector until you upgrade them to the updated Connector, keep the legacy Auth0 allowlist rows from [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements) until those hosts run the updated Connector. Disable or bypass SSL inspection for required paths between Iru Endpoint and the Connector host when your security policy allows it. Start AD CS integration in the Iru Endpoint web app far enough to obtain the installer. See [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration) for the full wizard, screenshots, and integration card behavior. Download the latest **Iru Endpoint AD CS Connector** from the Connector integration card in your tenant when you install or upgrade. Installers for the **updated** Connector are **2.x** versions; **Integrations** always lists the newest one. Use a physical or virtual **Windows Server 2019 or higher**, domain-joined to the Active Directory forest your issuing CAs serve, with **.NET 8 or later** and the Microsoft Edge WebView2 runtime that the installer provides. For TPM or vTPM and the full checklist, see [AD CS Connector Server Requirements](#ad-cs-connector-server-requirements) below. You need administrative access to the Windows Server that hosts the Connector, and an **Iru Endpoint administrator** account to sign in inside the Connector app and complete browser approval. ### AD CS Connector Server Requirements Install on a physical or virtual Windows Server that meets the following: **Windows Server 2019 or higher** **.NET 8 or later** A functioning **Trusted Platform Module (TPM)** or **virtual TPM (vTPM)** is required. The Connector relies on TPM-backed cryptography. On a VM, enable vTPM in your hypervisor (for example, Hyper-V Generation 2 with vTPM). See the Microsoft Learn article [Trusted Platform Module technology overview](https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview). Microsoft Edge WebView2 (the Connector installer bundles a compatible runtime) The server is domain-joined to the Active Directory forest your issuing CAs serve. ### Installation Transfer the Connector installer file to the Windows server. To begin the installation process, double-click the installer. On the Install Iru Endpoint AD CS Connector screen, click **Start**. Install Iru AD CS Connector wizard welcome screen with Start to begin setup. On the **Authenticate with Certificate Authority** screen, click **Local System** unless your CA policy requires a dedicated account. If you use a service account, choose **Service Account**, enter credentials your CA allows for enrollment, then click **Install**. The account you chose must match the principal that has **Read** and **Enroll** on the computer certificate template in [AD CS Integration: Create a Computer Certificate Template](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template). With **Local System** selected, click **Install**. Authenticate with Certificate Authority screen showing Local System Account and service account credential options. Authenticate with Certificate Authority screen with Service Account selected and domain, username, and password fields. When the UAC prompt appears, click **Yes**. Once the Connector installation is complete, click **Close**. Install success screen confirming the Iru AD CS Connector is installed. For the **updated** **Iru Endpoint AD CS Connector**, the Microsoft Edge WebView2 runtime is bundled with the installer. If needed, the runtime can be [downloaded from Microsoft](https://developer.microsoft.com/en-us/microsoft-edge/webview2/?form=MA13LH) and installed manually on the AD CS Connector Windows Server. ### Initialization If the Connector does not open automatically, open **Iru Endpoint AD CS Connector** from the Windows Start menu. Confirm the tray icon appears. In **Enter Iru domain**, enter your Iru Endpoint tenant URL. Use the **same** tenant where you downloaded the installer. Sign-in fails if you use the wrong tenant. Iru AD CS Connector sign-in window with Enter Iru domain field for the tenant URL. Complete sign-in in the WebView window using the method your tenant requires. After sign-in, open the **registration URL** in a supported browser on a computer where you can approve the request. The registration link expires after **one hour**. Iru AD CS Connector window showing registration URL link and waiting for device approval. If the Connector shows **Unable to obtain a registration URL. Try again later.**, wait briefly and click **New URL**. If the problem persists, verify network access to Iru Endpoint and contact Iru Support with logs. In the Iru Endpoint web app, go to **Approve AD CS connector registration**. Confirm the device name matches your Connector server, then click **Approve** or **Deny**. Approve this device to connect dialog with Approve and Deny actions. If you approve, the Connector shows **Connected** and the integration lists the Connector as **Active**. If you deny, Iru Endpoint removes the Connector entry. Sign in again from the Connector app and click **New URL** if you need another registration link. Connector status showing Connected after successful initialization to Iru Endpoint. You can close the Connector window. It continues running in the tray. Add issuing CAs under the **Servers** tab and use **Assign servers** as described in [Add AD CS servers and assign them to the Connector](#add-ad-cs-servers-and-assign-them-to-the-connector). You can also complete assignment from [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration#assigning-an-ad-cs-server-to-a-connector). Return to Iru Endpoint to [assign AD CS servers to the Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration#assigning-an-ad-cs-server-to-a-connector), then add Library Items to deliver AD CS certificates to devices. For Library Item examples, see [Deliver certificates to Mac computers and Windows devices](#deliver-certificates-to-mac-computers-and-windows-devices). ### Add AD CS servers and assign them to the Connector When the Connector is **Active** in Iru Endpoint and **Connected** from the Windows host: In the AD CS integration, open the **Servers** tab. Add each issuing CA using `ca_server_fqdn\issuing_ca_name` in **Server name** (for example, `subordinateca.example.com\Contoso Issuing CA`). The issuing CA name appears in the Certificate Authority console on the issuing CA server. Click **Add** for each server. New servers show **Disconnected** until you assign them to an **Active**, **Connected** Connector. On the Connector overview, open the action menu (**…**) on the Connector card, then click **Assign servers**. Select the AD CS servers this Connector should use, then confirm. For screenshots of the integration page, see [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration). ### Deliver certificates to Mac computers and Windows devices When at least one Connector is **Active** and **Connected**, and your AD CS servers are assigned, Iru Endpoint can deliver AD CS-backed Library Items to enrolled devices. Go to **Library** and click **Add Library Item**. Add a Library Item that issues certificates through AD CS, such as **Certificate**, **Wi-Fi**, or **VPN**. Select the issuing CA and template. Set subject, subject alternative name, and key usage to match your PKI and how Mac computers and Windows devices use the certificate. Assign the Library Item to the **Blueprints** that should receive it. Use one Library Item when Mac and Windows share the same template and policy. Create separate items when templates or identities differ by platform. Let devices check in. Confirm installation with **Keychain Access** on Mac and **certlm.msc** or **Certificates** in the Microsoft Management Console on Windows, based on your certificate store design. ### Next Steps After the Connector is **Active**, **Connected**, and AD CS servers are assigned: If you use AD CS for user-based 802.1X or similar, see [Active Directory Strong Certificate Mapping Configuration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-strong-mapping-configuration). Build [Certificate](/en/endpoint/library/library-items-profiles/configure-the-certificate-library-item), [Wi-Fi](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item), [Ethernet](/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item), or **VPN** Library Items and assign them to Blueprints. See [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) for the **AD CS setup path** diagram and rollout order. ### Add another Connector host In **Integrations**, open **Active Directory Certificate Services**, then click **Add connector**. Download the installer and repeat install, sign-in, and registration approval on another domain-joined Windows Server. Assign AD CS servers to each Connector according to your network and availability design. ### Updating the AD CS Connector On Windows Server, upgrading the **Iru Endpoint AD CS Connector** on an **Iru** tenant uses the workflow in [Updating the Iru AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#updating-the-iru-ad-cs-connector) in **AD CS Integration: Overview**. If you are moving from **Kandji** with AD CS, follow [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) instead. That path includes tenant upgrade, uninstalling the legacy Connector, and registering the **updated** Connector. ### Uninstalling the AD CS Connector You can remove the Connector and Edge runtime from **Control Panel** > **Programs and Features**. On Windows Server 2019 and later, you can use **Settings** > **Apps** > **Installed apps** instead. Go to the Windows Start menu and open **Control Panel** > **Programs and Features**, or open **Settings** > **Apps** > **Installed apps** on Windows Server 2019 and later. Find the **Iru Endpoint AD CS Connector** and click **Uninstall**. When the Uninstall Iru Endpoint AD CS Connector window appears, click **Uninstall**. When the uninstallation is complete, click **Close**. Find **Microsoft Edge WebView2 Runtime** and click **Uninstall**. Once the components are uninstalled, open **File Explorer**, go to `C:\ProgramData`, then delete the **iru** folder if your security policy requires a clean host. `ProgramData` is hidden by default. ### Troubleshooting If the Connector window reports **Something went wrong** with the toggle off, verify network access to Iru Endpoint, confirm TPM readiness on the server, then try **Re-authenticate** or restart the Connector app from the Windows Start menu. If the state persists, collect logs from `C:\ProgramData\iru` and contact Iru Support. Iru AD CS Connector Something went wrong state with Re-authenticate link. During [Initialization](#initialization), the Connector signs in to your Iru tenant in a WebView window. If sign-in fails, loops, or the window shows **Try Again**, cached sign-in data for the Windows user profile that runs the Connector may be stale. First confirm you entered the correct Iru tenant URL (the same tenant where you downloaded the installer from **Integrations** > **Active Directory Certificate Services**) and that the server can reach Iru Endpoint. See [AD CS Integration Network Requirements](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements) in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). You can also click **Re-authenticate** in the Connector app when it is available. To clear cached Connector data: 1. Close **Iru Endpoint AD CS Connector** from the Windows notification area or Task Manager. 2. Open **File Explorer** and go to `%LOCALAPPDATA%\Iru` (for example `C:\Users\\AppData\Local\Iru`). 3. Delete all files and folders inside **Iru**. 4. Open **Iru Endpoint AD CS Connector** again and repeat [Initialization](#initialization), starting at **Enter tenant URL**. Do not delete `C:\ProgramData\iru` for this step. That directory stores Connector logs and service files, not WebView sign-in cache. See **Review data directory contents** in this section. If authentication still fails after you clear `%LOCALAPPDATA%\Iru`, collect logs from `C:\ProgramData\iru` and contact Iru Support. Confirm you opened the **registration URL**, approved the request under **Approve AD CS connector registration**, and signed in to the correct tenant. Click **New URL** in the Connector app if the registration code expired. If the Iru Endpoint web app reports that the **registration URL** has expired when you try to approve, use **Registration URL expired when you approve registration** in this Troubleshooting section. If **Approve AD CS connector registration** in the Iru Endpoint web app reports that the **registration URL** has expired, you are past the point where **New URL** in the Connector app alone can recover the registration. On the Windows Server, uninstall **Iru Endpoint AD CS Connector** (and the bundled WebView runtime, and remove `C:\ProgramData\iru` if needed) using [Uninstalling the AD CS Connector](#uninstalling-the-ad-cs-connector). Then download the latest installer from **Integrations** > **Active Directory Certificate Services** and repeat [Installation](#installation) and [Initialization](#initialization) on that host. The Connector must be **Active** in Iru Endpoint and **Connected** from the Windows host before you can assign servers. Confirm AD CS servers are added and assigned, the Library Item targets the correct Blueprints, and Mac computers and Windows devices are enrolled. Validate template permissions and subject rules against a test device on each platform. The AD CS Connector app is installed at `C:\Program Files\Iru\AD CS Connector`. Logs, settings, and service files can be found at `C:\ProgramData\iru`. This is a hidden directory on the Windows server. Use the Windows Event Viewer to review AD CS Connector logs at `Event Viewer > Applications and Services Logs > Iru`. Windows installer logs can be enabled using the [Microsoft guide](https://docs.microsoft.com/en-us/troubleshoot/windows-client/application-management/enable-windows-installer-logging). The AD CS Connector runs as a Windows service. Confirm it is running in the **Services** application (`services.msc`). In Task Manager, the Connector process is called **adcs-connector-app**. If the WebView sign-in surface does not render after you enter the Iru Endpoint tenant domain, end the **adcs-connector-app** process and launch **Iru Endpoint AD CS Connector** again from the Windows Start menu. For additional questions, please [contact support](/en/iru/iru-support/access-to-iru-support). ### Best Practices Ensure proper network connectivity between the AD CS Connector and your Iru Endpoint tenant, and confirm TCP port 443 is accessible for WebSocket communication. Disable SSL inspection for required network communications between Iru Endpoint and the AD CS Connector to avoid connection and authentication issues. Use a dedicated service account for the AD CS Connector when your CA template allows it, so enrollment permissions stay scoped to that account. Install the latest **Iru Endpoint AD CS Connector** from your Iru Endpoint tenant (**Integrations** > **Active Directory Certificate Services**) so you receive fixes and security updates. Those updates apply to the **updated** Connector; the legacy Connector does not receive them. ### Considerations The Connector app and **Approve AD CS connector registration** must target the same Iru Endpoint tenant you intend to connect. The Windows server hosting the AD CS Connector must be bound to your Active Directory domain for certificate operations to succeed. Inspect log files under `C:\ProgramData\iru` on the Windows server (this directory is hidden by default). Use these logs together with the Connector application and Windows Event Viewer when you diagnose connection, authentication, or certificate issues. On the Connector Windows Server, open PowerShell and run `Get-Tpm`. Confirm **TpmPresent**, **TpmEnabled**, and **TpmActivated** reflect a usable TPM. For property definitions, see the Microsoft [Get-Tpm](https://learn.microsoft.com/en-us/powershell/module/trustedplatformmodule/get-tpm) reference. For VMs, confirm vTPM is enabled in the hypervisor settings. If TPM is unavailable, resolve firmware, hypervisor, or guest settings before production use. If Connector logs include **`System.Security.Cryptography.CryptographicException`** with the following message, TPM may not be enabled or ready for use; rerun the checks above and review firmware settings: **System.Security.Cryptography.CryptographicException:** The device that is required by this cryptographic provider is not ready for use. # AD CS Integration: Configure the Integration Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration Run the Iru Endpoint AD CS integration wizard to add Certification Authority hosts, assign connector servers, and create certificate Library Items. The AD CS integration is configured from the Iru Endpoint Integrations page in your Iru Endpoint web app. Once setup is complete, you can manage Iru Endpoint AD CS Connector servers, add your AD CS Certification Authority (CA) hosts, and create Library Items, all from the AD CS integration page. ### Prerequisites Confirm the following before you run the AD CS integration wizard in the Iru Endpoint web app. Create a [computer certificate template](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template) in AD CS for use with Iru Endpoint before you rely on the Connector host for enrollment. Ensure you can sign in to the Windows Server designated as the AD CS Connector and transfer or run the installer when the wizard finishes. Firewall and proxy rules must allow the paths in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements) under **AD CS Integration Network Requirements**. The updated Connector uses Iru sign-in (not Auth0). Allow your Iru web app, Iru Identity, tenant API (`subdomain.gateway.iru.com`, `subdomain.gateway.eu.iru.com`, `subdomain.clients.*`), and `adcsconn` as documented there. Your network must allow traffic between Iru Endpoint, the Connector host, and AD CS, including HTTPS from the Connector to Iru Endpoint without SSL inspection breaking that path when inspection is in use. If the **legacy** Connector still runs on some hosts until you finish upgrading them, keep the legacy Auth0 allowlist rows from that same article until those hosts run the updated Connector. The Connector host must meet **Windows Server 2019 or higher**, **.NET 8 or later**, **TPM or vTPM**, **WebView2** (bundled with the installer), and domain membership in the forest your issuing CAs serve. For the full checklist, see [AD CS Connector Server Requirements](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#ad-cs-connector-server-requirements) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). Have the Windows Server online so you can install the AD CS Connector as soon as you finish the steps in **AD CS Integration Setup** below. ### AD CS Integration Setup In the left-hand navigation, select **Integrations**. Near the top-right, select **Discover integrations**. Find the **Active Directory Certificate Services** integration and click **Add and configure**. Add new integration page with Active Directory Certificate Services and Add and configure. Select **Get started** to continue setup. AD CS integration setup screen with Get started highlighted to begin configuration. In the Download window, click **Download connector**. Download window for the Iru Endpoint AD CS Connector installer with Download connector available. You should see an indicator displaying the download progress. Once the download is done, the Iru Endpoint AD CS Connector installer file will be in your default downloads folder. Download progress while the AD CS Connector installer is downloading. Once the download completes, click **Next**. Download complete with Next available to continue the AD CS integration wizard. On the **Connection pending…** screen, read the tasks to perform on the Windows Server designated as the AD CS Connector. Connection pending wizard step with install and authenticate instructions for the AD CS Connector. To go back to the main Integrations page, click **Close**. An AD CS integration card should be visible on the main Integrations page. The status will show as **Pending installation…** until the AD CS Connector has been installed on the Windows server, you have signed in with an Iru Endpoint administrator account, you have completed **registration URL** approval in the browser, and the Connector shows as active in Iru Endpoint. Integrations page showing the AD CS integration card with Pending installation status. On the Windows Server designated as the AD CS Connector, follow [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#installation) to install and register the Connector, including sign-in and **registration URL** approval in the browser. When the Connector app shows **Connected** and the integration lists the Connector as **Active**, continue with the next section. ### Next Steps After you close the setup wizard with the installer downloaded: Complete [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation), including initialization, **registration URL** approval, and verification that the Connector shows **Connected** and **Active**. When the Connector is connected, continue in this article with [Adding AD CS Certificate Authority Servers](#adding-ad-cs-certificate-authority-servers) and [Assigning an AD CS server to a Connector](#assigning-an-ad-cs-server-to-a-connector). ### Overview of the AD CS integration page Use the **Overview** page to review Connector status and open actions such as install instructions, **Redownload Connector**, or delete a Connector row. Click on the AD CS integration card to go to the **Overview** page. On the Overview page, you can see information about the AD CS Connector that was just added. Most of the details will not be populated until the AD CS Connector is installed on the Windows server and a connection is made back to Iru Endpoint. * The domain to which the AD CS Connector server is bound. * The Connector's IP address. * Assigned AD CS servers. Servers can be assigned once the AD CS Connector is connected back to Iru Endpoint. * The version of the Windows server where the AD CS Connector is installed. * Status on the connection between Iru Endpoint and the Iru Endpoint AD CS Connector. The status will remain in a Pending state until the Connector is installed on the Windows server and a connection is made back to Iru Endpoint. * In the Connector action menu (...), you can view the installation instructions, redownload the connector installer, or delete the connector. AD CS integration Overview with the connector card and action menu open for install instructions or installer download. ### Adding AD CS Certificate Authority Servers You must define the FQDN in the Server name field in the AD CS servers tray. On the AD CS Integration page, click the **Servers** tab. On the **Servers** tab, click **+ Add server** to open the tray for adding an issuing CA. AD CS Servers tab empty state with Add server to add issuing CAs. In the tray, add the AD CS server(s) that will be used for creating certificates using the format of: `ca_server_fqdn\issuing_ca_name` (Example: `subordinateca.example.com\QueenBee Issuing CA`). The issuing\_ca\_name is found in the Certificate Authority Snap-in on the issuing CA Windows server. You will be able to assign the server once the Connector shows a status of Connected. Add AD CS servers pane with server name and connector assignment before saving. Click **Add**. Servers tab tray for adding an AD CS CA server using FQDN and issuing CA name format. The status for the AD CS server will show as **Disconnected** until assigned to an AD CS Connector. Once the AD CS Connector status shows **Connected**, you can assign the AD CS CA server(s) to the AD CS Connector. You can edit or delete the AD CS server from the action menu (**...**) on the AD CS server card. AD CS Servers table row action menu with Edit server available. AD CS Servers table row action menu with Delete server available. ### Assigning an AD CS server to a Connector Once the AD CS Connector status shows as Connected, you can assign an AD CS server to the Connector. On the AD CS Integration Overview page, click the action menu (…) on the Connector card. Click **Assign servers**. Connector card action menu with Assign servers selected to link a CA to the AD CS Connector. Select one or more AD CS servers from the list. Click **Add**. Assign AD CS servers dialog to choose servers from the list and confirm with Add. There should now be at least one AD CS server assigned to the Connector. When you replace the **legacy** Connector with the **updated** Connector on the same Windows Server, Iru Endpoint lists the updated registration as a **new** Connector. Use **Assign servers** on the new Connector card to attach your issuing CAs, then delete the legacy Connector entry from the action menu (**...**) on the legacy card. For the full Kandji-to-Iru workflow, see [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) in **AD CS Integration: Overview**. For uninstall and install steps on the server, see [Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#installation) and [Uninstalling the AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#uninstalling-the-ad-cs-connector) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). ### Adding Additional Connectors If needed, additional AD CS Connectors can be added to the AD CS integration. In Iru Endpoint, navigate to **Integrations** and select the **Active Directory Certificate Services** integration card. Click **Add connector**. A new connector appears in **Pending** until you finish installation, sign-in, registration approval, and connection on the Windows Server. ### Create a Library Item from an AD CS server When the AD CS **Servers** tab lists at least one issuing CA, you can start a certificate-related Library Item from the server row instead of starting only from **Library**. On the **Servers** tab, locate the AD CS server row, then open the action menu (**...**). Click **Create Library Item**. AD CS Servers row action menu with Create Library Item selected. In **Specify Library Item type**, pick the profile type you want to create (for example **Certificate** or **Wi-Fi**), then continue. Iru Endpoint opens the usual Library Item editor for that type with AD CS fields available. Specify Library Item type dialog when creating from an AD CS server. ### Remove a Connector from the Integration Removing a single **Connector** row is different from [Removing the Integration](#removing-the-integration) below. Use this when you want to retire one Windows Server registration while keeping the AD CS integration enabled. In **Integrations**, open **Active Directory Certificate Services**, then open the **Overview** tab. On the connector card you want to remove, open the action menu (**...**), then click **Delete connector**. This removes only that Connector registration in Iru Endpoint, not the entire AD CS integration. AD CS Overview connector action menu with Delete connector highlighted. In the confirmation window, confirm removal of that connector from Iru Endpoint. Delete AD CS connector confirmation dialog. Deleting a connector row does not uninstall **Iru Endpoint AD CS Connector** from Windows Server. Remove the app on the host if you decommission that server. See [Uninstalling the AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#uninstalling-the-ad-cs-connector). ### Removing the Integration This integration is a requirement to issue AD CS certificates to your fleet. Deleting this integration cannot be undone. Use the steps below to delete the **Active Directory Certificate Services** integration from your Iru Endpoint tenant. In Iru Endpoint, navigate to **Integrations**. Click on the Active Directory Certificate Services integration that you want to remove. On the main Active Directory Certificate Services page, click the Action menu (**...**) and click **Delete integration**. Active Directory Certificate Services page with the action menu showing Delete integration. In the **Delete AD CS Integration** window, check the box to confirm that you've read the warning, then click the **Delete** button. Once the integration is removed, you will be taken back to the main Integration page. Delete AD CS integration confirmation with checkbox and Delete integration button. Removing the integration in Iru Endpoint does not uninstall **Iru Endpoint AD CS Connector** from your Windows Server; the app remains on the host until you remove it there. On each Connector server, open **Settings** > **Apps** > **Apps & features**, select **Iru Endpoint AD CS Connector**, then choose **Uninstall**. For other uninstall paths (for example **Control Panel** on older Windows Server versions), see [Uninstalling the AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#uninstalling-the-ad-cs-connector). # AD CS Integration: Create a Computer Certificate Template Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template Duplicate and configure an AD CS computer certificate template on your issuing Certification Authority for use with the Iru Endpoint AD CS integration. ### Prerequisites Confirm the following before you create or duplicate a computer certificate template on your issuing CA. You need access to an issuing CA in your Active Directory forest where you can open the Certificate Authority snap-in and manage certificate templates. You need rights sufficient to duplicate the **Computer** template, adjust security (for example **Read** and **Enroll** for the AD CS Connector computer object or a service account), and publish the template for issuance. ### Required Settings for the Certificate Template Below are the tabs and settings that should be configured in the certificate template: * Template type: The template used should be based on the default Computer template. * Certificate Authority compatibility: Windows Server 2016 * Certificate recipients: Windows 10/Windows Server 2016 * Subject name: Supply in the request * Security: Grant **Read** and **Enroll** only to the identity that enrolls for the Connector (the Connector host computer account when the Connector runs as **Local System**, or a dedicated **service account** when the Connector uses **Service Account** at install). Remove broad inherited entries such as **Domain Computers** so other domain-joined computers cannot enroll. If you would like to use an existing AD CS certificate template, the settings in the existing template must align with the settings listed above. ### Create an AD CS Computer Certificate Template Log in to a Certificate Authority (CA) on your domain. On the server, launch the Start menu and search for the Certificate Authority snap-in. Once in the Certificate Authority snap-in, click Issuing CA. The name of the Issuing CA as it appears here in the snap-in will be needed when adding AD CS servers to the Iru Endpoint AD CS integration. Right-click the Certificate Templates folder and click Manage. Certificate Authority snap-in with Certificate Templates folder and Manage option to open template management. In the Certificate Templates window, find the Computer template and right-click it. Then, click Duplicate Template. In the Properties window, click the General tab. Set the display name and template name to something like `IruEndpointDevice`. The template name will be needed when creating Library Items that contain AD CS certificate settings. Next, click the Compatibility tab. For Certificate Authority, select Windows Server 2016. In the change dialog, click **OK**. For Certificate Recipients, select Windows 10 / Windows Server 2016. In the change dialog, click **OK**. Click the Subject Name tab. Select the option to Supply in the request and click **OK** in the warning dialog. Click the **Security** tab. The steps below add the Connector host **computer account**. Use this path when the Connector will run as **Local System** on the Windows Server (the default in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#installation)). Under **Groups or user names**, click **Add**. In the Select Users, Computers, Service Accounts, or Groups window, click Object Types. In the Object Types window, select Computers. Click **OK**. Object Types dialog with Computers selected for choosing the AD CS Connector host principal. In the object names search field, enter the name of the Windows server that will be used to host the AD CS Connector. In the screenshot below, `lab000001` is the computer name being used. Select Users, Computers, Service Accounts, or Groups dialog with the Connector Windows server name entered for search. With the Connector host computer still selected under **Groups or user names**, select **Read** and **Enroll** under **Allow** in the **Permissions** section. **Service account enrollment instead:** If the Connector will use **Service Account** at install, skip the **Object Types** and **Computers** steps above. On the **Security** tab, click **Add**, enter the service account (leave default object types), grant **Read** and **Enroll**, then continue with the next step. Grant **Enroll** only to that service account, not to **Domain Computers**. Remove inherited principals that grant **Enroll** to large groups, such as **Domain Computers**. Leave only the account you granted **Read** and **Enroll** in the previous steps (the Connector host computer account or your service account). A duplicated **Computer** template often allows **Domain Computers** to enroll. On Windows Server 2019 and later, leaving that entry in place can let any domain-joined computer request a certificate from this template. Because the template uses **Supply in the request**, that certificate could represent another principal in your forest and be misused for authentication. Remove those broad principals; keep only your Connector enrollment account. Click Apply and then OK. Go back to the main Certificate Authority snap-in, right-click Certificate Templates again, and select New > Certificate Template to issue. Select the template you created (in our example, `IruEndpointDevice`). Click **OK**. Confirm that the template is shown in the list. ### Next Steps After the template appears in the issuance list: Run the integration wizard and download the Connector installer in [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration). # AD CS Integration: Overview Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview Learn how the Iru Endpoint AD CS integration requests certificates from Microsoft Active Directory Certificate Services and delivers them to managed devices. ### What is Active Directory Certificate Services? [Microsoft Active Directory Certificate Services](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview) (AD CS) creates an on-premises public key infrastructure (PKI) that lets organizations issue, validate, and revoke certificates for internal use. The Iru Endpoint AD CS integration works with your existing Microsoft AD CS setup to request certificates from AD CS. You can then push these certificates to devices through configuration profiles, which enables certificate-based authentication so users can access corporate resources like enterprise Wi-Fi networks. #### Kandji versus Iru Endpoint AD CS On **Kandji**, AD CS uses the **legacy** Connector (Auth0 sign-in). After you [Upgrade to Iru](/en/iru/platform-overview/upgrade-to-iru), **Iru Endpoint** uses the **updated** Connector (Iru identity and registration approval). To move a Kandji AD CS deployment to Iru, see [Migrating from Kandji to Iru with AD CS](#migrating-from-kandji-to-iru-with-ad-cs). If you already run the **updated** Connector on Iru Endpoint and need a newer build, see [Updating the Iru AD CS Connector](#updating-the-iru-ad-cs-connector). The **Iru** Connector has stricter **Windows Server**, **.NET**, **TPM**, and **firewall** expectations than a legacy Kandji setup. See [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#installation) for the host checklist and installation steps, and [Network requirements](#network-requirements) for allowlist differences by Connector generation. ### Certificate Request Flow The diagram summarizes how certificate requests move between Iru Endpoint, the AD CS Connector on your network, Microsoft AD CS, and enrolled devices. Network diagram of the AD CS certificate request flow: WebSocket over TCP 443 between the Iru tenant and the AD CS Connector, Microsoft RPC between the Connector and Microsoft AD CS, and TCP 443 to enrolled devices. Iru Endpoint sends a certificate request to the Iru Endpoint AD CS Connector through a WebSocket connection over TCP port 443. The AD CS Connector generates the certificate key pair locally, then sends the certificate signing request to Microsoft AD CS using DCE/RPC. Private keys are delivered to managed endpoints through Library Items. The Connector does not store device identity private keys. AD CS processes the request, issues the certificate, and sends the signed certificate back to the AD CS Connector. The AD CS Connector sends back an encrypted .p12 file along with the request ID to Iru Endpoint over the WebSocket connection. Iru Endpoint delivers the certificate bundle (.p12 file) to the client device through a configuration profile payload. ### AD CS setup path Use the diagram as your rollout checklist. Start on the left with **Network allowlists**; complete the guidance in **[Network requirements](#network-requirements)** and the **AD CS Integration Network Requirements** tables in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements), then follow the guides in order from left to right. Each article ends with **Next Steps** that point you to the following task.
Network allowlists
Using Iru on Enterprise Networks
Computer certificate template
in AD CS
Configure AD CS integration
in Iru Endpoint
Install AD CS Connector
on Windows Server
Strong certificate mapping
when required
Library Items
deploy to devices
### Network Requirements Confirm the following before you install the Connector or finish the integration wizard. For hostnames, ports, protocols, and the difference between updated and legacy Connector rows, see the **AD CS Integration Network Requirements** section in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements). The updated Connector does **not** use Auth0. Allow your Iru web app, Iru Identity, tenant API, and `adcsconn` destinations as documented there. If any hosts still run the **legacy** Connector during migration, keep the legacy Auth0 allowlist rows from that article until each host runs the **updated** Connector. See [Migrating from Kandji to Iru with AD CS](#migrating-from-kandji-to-iru-with-ad-cs) for the full replacement workflow. ### Next Steps After you finish this overview: See [AD CS Integration: Create a Computer Certificate Template](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template). ### Connector Versions #### Updated connector The **updated** AD CS Connector is the Iru Endpoint package you download from **Integrations** > **Active Directory Certificate Services**. It uses Iru identity for sign-in and shows a **registration URL** after sign-in. Approve the Connector host in **Approve AD CS connector registration**. Product and security updates ship only for this package. Installers are **2.x** versions. #### Legacy connector The **legacy** AD CS Connector is the release for **Kandji** tenants. It uses Auth0-based sign-in. Iru Endpoint does not ship updates for it. After you upgrade the tenant to Iru, uninstall the legacy Connector from Windows Server and install the **updated** Connector from your **Iru** tenant. ### Updating the Iru AD CS Connector Use this workflow when your tenant already runs on **Iru Endpoint** and you need a newer **updated** Connector build on Windows Server, or when you are refreshing the Connector on a host that has already registered with Iru identity. This section is for **updated** Connector builds on an **Iru** tenant. If you are moving from **Kandji** with AD CS, complete [Migrating from Kandji to Iru with AD CS](#migrating-from-kandji-to-iru-with-ad-cs) first. On Windows Server, download the latest **Iru Endpoint AD CS Connector** from **Integrations** > **Active Directory Certificate Services**, run the installer, then complete sign-in and **registration URL** approval when prompted. The integration lists the Connector as **Pending** until you approve registration, then **Active**; the Connector app shows **Connected**. From **Integrations** > **Active Directory Certificate Services**, download the latest **Iru Endpoint AD CS Connector**. On an existing Connector card, open the action menu (**...**) and click **Redownload Connector** instead. On the Connector Windows Server, run the installer. The updater may uninstall the previous build before installing the new one. Connector action menu with Redownload connector highlighted to fetch the installer again. Re-enter your Iru tenant URL and complete sign-in when the Connector app prompts you. Open the **registration URL** in a browser and approve the device in **Approve AD CS connector registration** when Iru Endpoint requests it. For step-by-step initialization, see [Initialization](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#initialization) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). Confirm the Connector app shows **Connected** and the integration card shows **Active**. In **Control Panel** > **Programs and Features** (or **Settings** > **Apps** > **Installed apps** on Windows Server 2019 and later), confirm the installed **Iru Endpoint AD CS Connector** version is the current **2.x** build you expect. If a new **updated** Connector registration appears next to a **legacy** Connector row, open **Assign servers** on the **new** Connector card and attach each issuing CA that was assigned to the **legacy** Connector. When the updated Connector is **Connected** and CAs are assigned, open the action menu (**...**) on the **legacy** Connector card and delete that entry. If you are only upgrading builds on a host that already runs the **updated** Connector and the same Connector card stays **Active**, you do not need to reassign CAs or delete a legacy row. To use a new domain-joined Windows Server, download and install the latest Connector on that server, complete registration, then use **Assign servers** on the new Connector card to move issuing CAs off the old Connector entry. Decommission the old server when you are finished. For install and uninstall details on the host, see [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). ### Migrating from Kandji to Iru with AD CS Complete the platform upgrade to Iru before you replace the AD CS Connector on Windows Server. The legacy Connector may still appear **Connected** in Iru Endpoint immediately after tenant migration until you uninstall the legacy Connector on the server and register the **updated** Connector. In the Kandji web app, AD CS uses the **legacy** Connector. After upgrade, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu) in the sidebar and open **Integrations**. **Settings** is no longer in that location on Iru Endpoint. Follow [Upgrade to Iru](/en/iru/platform-overview/upgrade-to-iru) (**Upgrade Process** tab). In **Settings** > **Access**, click **Start migration**, configure your authentication connections, accept the disclaimer, and click **Complete migration**. Sign in to your new Iru domain (`{{subdomain}}.iru.com`). When the tenant upgrade is complete, return to [Migrating from Kandji to Iru with AD CS](#migrating-from-kandji-to-iru-with-ad-cs) and continue with the next step below to replace the AD CS Connector. In the sidebar, click the **Account Menu Button**, then **Integrations**. Open **Active Directory Certificate Services**. The integration may still show **Connected** if the **legacy** Connector is installed on Windows Server. On the Connector host, open **Control Panel** > **Programs and Features** (or **Settings** > **Apps** > **Installed apps**). Find the legacy **Iru Endpoint AD CS Connector** (or the Kandji-era AD CS Connector entry) and uninstall it. Follow the prompts until the uninstall completes. The legacy build is typically a **1.0.0.x** version. For full uninstall steps, including WebView runtime removal when required, see [Uninstalling the AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#uninstalling-the-ad-cs-connector) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). Refresh the **Active Directory Certificate Services** page in Iru Endpoint. The Connector should show **Disconnected** after you remove the legacy package from the server. Click **Add connector**, then download the **Iru Endpoint AD CS Connector** installer from your **Iru** tenant. If your browser blocks the download, choose **Keep** or **Keep anyway** so the file saves. The integration lists the new Connector as **Pending** until you complete installation and registration. Transfer the installer to the Windows Server and run it. On **Authenticate with Certificate Authority**, select **Local System** unless your CA policy requires a service account, then click **Install**. When installation completes, click **Close**. See [Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#installation) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). Open **Iru Endpoint AD CS Connector** from the Windows Start menu. In **Enter Iru domain**, enter your Iru tenant URL (for example `{{subdomain}}.iru.com`, the same hostname shown in the Iru Endpoint web app). Complete sign-in, open the **registration URL**, and approve the device in **Approve AD CS connector registration** when prompted. The Connector app should show **Connected**. Refresh the AD CS integration in Iru Endpoint and confirm the Connector shows **Connected**. On the Windows Server, open **Programs and Features** again and confirm the installed **Iru Endpoint AD CS Connector** is a **2.x** build, not the legacy **1.0.0.x** release. On the AD CS **Overview** page, open **Assign servers** on the **new** Connector card and attach each issuing CA that was assigned to the **legacy** Connector. When the updated Connector is **Connected** and CAs are assigned, open the action menu (**...**) on the **legacy** Connector card and delete that entry. Keep **legacy** Auth0 firewall allowlist rows until each Connector host runs the **updated** Connector and you remove the legacy Connector entry from Iru Endpoint. See [Network requirements](#network-requirements) and [AD CS Integration Network Requirements](/en/iru/requirements/using-iru-on-enterprise-networks#ad-cs-integration-network-requirements) in [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). # Active Directory Strong Certificate Mapping Configuration Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-strong-mapping-configuration Update AD CS templates and Iru Endpoint Library Items to meet Microsoft KB5014754 strong certificate mapping requirements for AD authentication. Microsoft introduced significant changes to Active Directory Certificate Services (AD CS) certificate authentication with [KB5014754](https://support.microsoft.com/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16). These changes enforce strong certificate mapping to address elevation of privilege vulnerabilities related to certificate spoofing. The changes affect organizations that use Microsoft AD CS for certificate-based authentication that relies on user attributes in certificates (for example, Wi-Fi or Ethernet with 802.1X). **Important:** As of February 11, 2025, Windows enforces these changes by default. If certificates cannot be strongly mapped to Active Directory accounts, authentication will be denied. ### Enforcement Dates and Requirements Review the following enforcement timeline and certificate requirements before you change Library Items or Connector versions. Strong certificate mapping enforcement began by default. Compatibility mode is no longer supported. All certificates used for Active Directory authentication must include the user's security identifier (SID) in the Subject Alternative Name (SAN) field. ### Who Needs to Take Action? This applies to customers who use Microsoft AD CS for certificate-based authentication that relies on user attributes in certificates (for example, Wi-Fi or Ethernet with 802.1X). ### Prerequisites Confirm the following before you update the AD CS Connector, SCIM, or Library Items for strong certificate mapping. [Assign users to device records in Iru Endpoint](/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices) before proceeding with certificate updates. If you use the Iru Endpoint AD CS Connector for certificates issued from AD CS, install **.NET 8 or later** on the **Windows Server 2019 or newer** host that runs the Connector. The Connector host is often not the same machine as your AD CS Certification Authority (CA). For the full requirement list, including TPM or vTPM, see [AD CS Connector Server Requirements](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#ad-cs-connector-server-requirements) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). ### Required Steps #### Update Iru Endpoint AD CS Connector This update is only required if you use the Iru Endpoint AD CS Connector to issue certificates. Strong certificate mapping requires the **updated** Iru Endpoint AD CS Connector at a supported **2.x** version (see the [prerequisites](#prerequisites) above). On Windows Server, download the latest **Iru Endpoint AD CS Connector** from **Integrations** > **Active Directory Certificate Services** (you can use **Redownload Connector** on the Connector card) and install it on the host. For upgrading an **updated** Connector on Iru Endpoint, see [Updating the Iru AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#updating-the-iru-ad-cs-connector). For replacing the **legacy** Kandji Connector after tenant migration, see [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) in **AD CS Integration: Overview**. When a **new** **updated** registration appears next to a **legacy** Connector row, complete **Assign servers** and remove the legacy entry as described in [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) or [Updating the Iru AD CS Connector](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#updating-the-iru-ad-cs-connector). For install, sign-in, and **registration URL** flow, see [Initialization](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation#initialization) in [AD CS Connector Installation](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-ad-cs-connector-installation). #### Update SCIM User Directory Integration These steps pertain to Microsoft Entra SCIM integrations. Native Microsoft Entra ID integrations require no additional configuration. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). Open the portal menu, then select **Entra ID**. On the **Entra ID** menu, select **Enterprise applications**. Locate and open the SCIM app used with Iru Endpoint. Under **Manage**, select **Provisioning**. Under **Manage**, select **Attribute Mapping (Preview)**. Select **Provision Microsoft Entra ID Users**. Scroll to the bottom, check the box to show advanced options. Click **Edit attribute list for Provision Microsoft Entra ID Users**. Add a new field: `onPremisesSecurityIdentifier` (leave type as String). Click **Save**. Return to **Attribute Mapping**, scroll down and click **Add New Mapping**. Configure the mapping: * **Mapping type**: Direct (default) * **Source attribute**: `onPremisesSecurityIdentifier` * **Target attribute**: `onPremisesSecurityIdentifier` Click **OK**, then **Save**. The `onPremisesSecurityIdentifier` will appear in user attributes after the next Entra ID SCIM sync (every 20-40 minutes). #### Update Certificate Library Items ##### For SCEP Certificate Library Items In Iru Endpoint, locate SCEP Library Items assigned in your Blueprints. Click **Edit** on the item. In the **Subject Alternative Name (SAN)** section, click **Add**. Add a Uniform Resource Identifier SAN. Enter this value exactly: `$ADCS_STRONG_MAPPING_ID`. Click **Save**. ##### For Certificate Library Items using the AD CS Connector In Iru Endpoint, locate and open Certificate Library Items assigned in your Blueprints. Click **Edit**. In the **Subject Alternative Name (SAN)** section, click **Add**. Add a Uniform Resource Identifier SAN. Enter this value exactly: `$ADCS_STRONG_MAPPING_ID`. Click **Save**. ##### For Wi-Fi or Ethernet Library Items using SCEP or AD CS certificates for EAP-TLS In Iru Endpoint, locate and open Wi-Fi or Ethernet Library Items assigned in your Blueprints. Click **Edit**. Scroll to the **Identity Certificate** section and click **Configure**. In the **Subject Alternative Name (SAN)** section, click **Add**. Add a Uniform Resource Identifier SAN. Enter this value exactly: `$ADCS_STRONG_MAPPING_ID`. Click **Save**. ### Deployment and Certificate Reissuance After updating Library Items: * Iru Endpoint automatically reissues certificates to devices assigned the updated Library Items through their Blueprints * New certificates will contain the user's SID in the SAN field, satisfying Microsoft's strong certificate mapping requirements * Any reconfigured Wi-Fi or Ethernet connections will automatically use the new certificates ### Next Steps After you save Library Item changes: Run the updates on a small test Blueprint before you expand to production. See [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) for the **AD CS setup path** diagram and rollout order. ### Considerations Incorrectly updating certificates used for network connectivity can cause devices to disconnect from the network. Test these changes on a subset of devices using a test Blueprint with test Library Items before applying changes to production Library Items. # Using Identity Certificates for 802.1X Authentication Source: https://docs.iru.com/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication Deploy identity certificates for 802.1X network authentication using Iru Endpoint. Configure SCEP, certificate authorities, and Wi-Fi or Ethernet profiles. This guide applies to Mac computers ### About Identity Certificates In 802.1X authentication, identity certificates authenticate the client and the server. They are particularly significant in the EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) method. EAP-TLS uses digital certificates to authenticate both the client (supplicant) and the server (authentication server). This mutual authentication guarantees that both parties trust each other's identity before establishing a secure connection. Identity certificates can be used in both the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) and [Ethernet Library Item](/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item). ### Configure an Identity Certificate Certain types of authentication require or allow you to specify an identity certificate to verify the device’s identity. These certificates can come from various sources. For network authentication, make sure the identity certificates include the Client Authentication entitlement in their Extended Key Usage (EKU). Work with your network administrator to ensure the certificate service and templates are properly configured for your network. If you use Microsoft Active Directory Certificate Services, you can issue identity certificates through the [AD CS integration overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview). AD CS servers are added during [AD CS integration configuration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration), and certificate requests rely on the configured [AD CS computer certificate template](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-create-a-computer-certificate-template). ### Obtain an identity certificate using AD CS You can obtain identity certificates using Microsoft Active Directory Certificate Services. To deploy AD CS certificates, the [AD CS integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) must be configured first. For **Identity certificate**, choose **AD CS Certificate**. Click **Configure AD CS Certificate** to open the AD CS configuration drawer. Enter a **Certificate name**. This appears on the configuration profile in System Settings. Enter a **Certificate subject**. This usually identifies the device within the certificate authority. You can use a static value or a global variable such as `$SERIAL_NUMBER`. Add any required **Subject Alternative Names (SANs)** to send in the certificate request. To support strong certificate mapping requirements from Windows update [KB5014754](https://support.microsoft.com/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16), add this URI SAN value: `$ADCS_STRONG_MAPPING_ID`. For full guidance, see [Active Directory Strong Certificate Mapping Configuration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-strong-mapping-configuration). Enter the **Template name** for the AD CS computer certificate template used to generate AD CS certificates, then select an **AD CS server** from the dropdown. Select a **Key size**. Optionally choose **Allow apps to access the private key** and **Prevent the private key data from being extracted from the keychain** based on your security requirements. Click **Done**. ### Obtain an Identity Certificate Using SCEP Using the Simple Certificate Enrollment Protocol (SCEP), you can obtain identity certificates. If you wish to have the client device acquire an identity certificate from a SCEP service, choose **SCEP** for an **Identity certificate**. Click **Configure SCEP Certificate**. A drawer opens to allow you to configure SCEP options. Enter the URL for the SCEP server for **URL**. Optionally, specify a **Name** as needed by your SCEP server (often the name of the CA where the SCEP service is requesting a certificate). Optionally, enter the pre-shared key as the **Challenge** the SCEP server expects. Optionally, enter the expected **Fingerprint** of the certificate authority's certificate. Optionally, provide the name you want to appear as the certificate identity's **Subject**. You can use a static value or a global variable, such as CN=\$EMAIL. Select **Specify Subject Alternative Names (SAN)** if you want to provide SANs for the certificate identity. For each SAN you would like to provide, click **Add SAN Type**, select the SAN type you want to add: **DNS Name**, **RFC 822 Name**, **Uniform Resource Identifier**, or **NT Principal Name**, and enter the associated value you would like to add for each SAN type. You can use a static value or use a global variable. Choose the **Key size**. Work with your network administrator to ensure you choose a compatible key size; longer keys generally provide stronger security. For **Key usage**, choose whether to allow the keys to be used for **Signing**, **Encryption**, **Both signing and encryption**, or **None**. Work with your network administrator to determine which entitlements are necessary. SCEP Certificate details configuration interface If you want the device to retry obtaining a certificate if the first attempt fails automatically, select **Retries**, then enter the number of retries to attempt. The default is 3. If you want to introduce a delay between retries, select **Retry delay** and specify the number of seconds between retries. The default is a 10-second delay between retries. Select **Don't allow key to be extracted** to prevent exporting the certificate identity's private key from the macOS Keychain. Select **Allow access to all apps** if you want to automatically allow all apps to access and use the certificate identity's private key. Select **Certificate expiration notification** and specify the number of days before the certificate expires to start notifying the user. The default is to notify the user 14 days before expiration. Select **Automatic profile redistribution** to automatically renew the certificate the specified number of days before it expires. The default is to automatically renew the certificate 30 days before expiration. When **Automatic profile redistribution** is enabled, specify a user global variable in the Subject Alternative Names (SAN) if user information is required in the certificate. This is necessary because the Wi-Fi Library Item ID is added to the Common Name in the certificate's subject to track certificate renewal. Click **Done** to save the SCEP certificate configuration. ### Import a PKCS #12 File You can provide a single identity certificate for all configured devices by uploading a PKCS #12 formatted file. This means all devices will use the same certificate, making it harder for network administrators to identify individual devices by their login. However, it also means that if the certificate is compromised, it can be used to access the network. Revoking this certificate will block all configured devices from accessing the network. If you wish to provide a certificate in PKCS #12 format, choose **PKCS #12** for the **Identity certificate**. Click **Configure PKCS #12** to open the **Configure PKCS #12** drawer. Upload the PKCS #12 encoded certificate for **Certificate** (drag file or choose file). Accepted file types are `.p12` and `.pfx`. In the **Certificate password** field, enter the password for the certificate. PKCS 12 certificate type with certificate upload and certificate password fields Expand **Apple only settings**, then configure the following as needed: * **Certificate name**: Enter the display name of the certificate. * **Allow apps to access the private key**: Select this option if you want all apps to have access to the private key. * **Prevent the private key data from being extracted in the keychain**: Select this option if you do not want private key data to be extractable from the keychain. By default, private key data is extractable. PKCS 12 Apple only settings with Certificate name and private key options Click **Done** to complete the PKCS #12 certificate configuration. ### Related Articles Compare Wi-Fi authentication types and when to use enterprise vs non-enterprise options Configure the Wi-Fi Library Item for network deployment Configure 802.1X authentication for wired networks Configure EAP types for 802.1X authentication # Microsoft Teams Integration Source: https://docs.iru.com/en/endpoint/integrations/communication/microsoft-teams-integration Connect Microsoft Teams to Iru Endpoint for device management notifications. Receive alerts about enrollment, compliance, and device status in Teams channels. ### About Microsoft Teams Integration Microsoft Teams Integration in Iru Endpoint allows you to receive Iru Agent and system notifications directly in Microsoft Teams channels, providing centralized monitoring and alerting for your device management operations. ### How It Works Integrate Microsoft Teams with Iru Endpoint to receive [Iru Agent](/en/endpoint/agent/iru-agent-and-mdm) and Iru Endpoint System notifications inside public and private Teams channels. For more information on alerts, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article. ### Creating a New Teams Integration The administrative account used to authenticate with Microsoft should either be an owner or member of all Teams and Channels that will be added to the Teams integration and must have a valid Office 365 license assigned. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Click **Discover integrations**. Screenshot of the account menu with Integrations option highlighted Under the **Communication** section, find Microsoft Teams and click **Add and configure**. In the Welcome to Teams modal, click **Get started**. In the Sign in with Microsoft Teams modal, click **Sign in with Microsoft**. In the web browser, enter Microsoft admin credentials and click **yes** to approve the application permissions. Once the connection is established, you will be redirected back to the Teams integration, where you can **Create event notifications** or choose to set up event notifications later. If you choose to **Set this up later**, you will be taken back to the Teams integration details page. In the Team & channels modal, **select a Team** and **specify one or more channels** where notifications should be sent and click **Next**. In the Set up event notifications modal, toggle the events that should trigger a notification and click **Next**. Event triggers can be edited later from the Teams integration details page. In the Event notification details modal, enter a name to describe the event notification and click **Next**. In the Test notification modal, you can choose to **Send a test notification** or click **Done** to complete the setup. The test message should be delivered to the Teams **channel(s)** selected earlier. Once back at the Teams integration details page, you can see the new notification you created along with the Team, selected Channels, and the number of Event triggers chosen. ### Adding Additional Teams Event Notifications Once the initial integration setup is complete, additional notifications can be added from the Microsoft Teams integration overview page. From the Microsoft Teams integration details page, click **Add event notification**. Once the **Add event notification** drawer appears, select a **Team** and **Channel**, give the notification a name, select desired **Triggers** for the new notification, and click **Done**. The Team must be selected before the related Channels will be available as a selection. ### Editing a Notification To edit a Teams notification, select the contextual menu (…) to the right of the notification and click **Edit event notification**. From there, the notification drawer will appear, where you can make changes to the notification. Make sure to click **Done** to save your edits. ### Deleting an Integration or Notification Deletion is permanent and is not reversible. #### Deleting Entire Integration Select the contextual menu (…) in the upper right-hand corner to delete the entire Teams integration and click **Delete integration**. From there, a confirmation modal will appear, displaying what will be removed once the **Delete** button is clicked. #### Deleting Individual Notification To delete an individual notification, select the contextual menu (…) to the right of the notification and click **Delete event notification**. A confirmation modal will appear, asking you to confirm the action by clicking the **Delete** button. ### Considerations **Administrative Requirements**: The administrative account used to authenticate with Microsoft must be an owner or member of all Teams and Channels that will be added to the integration and must have a valid Office 365 license assigned. **Channel Access**: To send notifications to private Teams channels, ensure the Iru Endpoint bot has been added to those channels with appropriate permissions. **Event Triggers**: Event triggers can be edited after initial setup from the Teams integration details page. You can modify which events trigger notifications without recreating the integration. **Deletion Warning**: Deletion of integrations or notifications is permanent and cannot be reversed. Ensure you have backups of any important notification configurations before deletion. **Testing**: Always use the test notification feature to verify that notifications are being delivered to the correct Teams channels before relying on the integration for production monitoring. # Slack Integration Source: https://docs.iru.com/en/endpoint/integrations/communication/slack-integration Connect Slack to Iru Endpoint for device management notifications. Receive alerts about enrollment, compliance, and device status in Slack channels. ### About the Slack Integration The Slack Integration in Iru Endpoint allows you to receive Iru Agent and system notifications directly in Slack channels, providing centralized monitoring and alerting for your device management operations. ### How It Works Integrate your Slack workspace with Iru Endpoint to receive [Iru Agent](/en/endpoint/agent/iru-agent-and-mdm) and Iru Endpoint System notifications inside public and private Slack channels. For more information on alerts, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article. ### Creating a New Slack Integration In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper right corner of the Integrations page. On the **Slack** tile, click **Add and configure**. Click **Get started**. If you have not already signed into a Slack workspace, enter your workspace information and click **Continue**. If you want to use a different Slack workspace, click the menu in the upper right and select **Add another workspace**. In the permissions dialog, click **Allow**. A notification message near the bottom left will let you know if Slack was successfully connected. Depending on how many channels your Slack workspace contains, it may take a while to load before you can add event notifications. Click **Add event notification**. Search for the Slack channel you'd like to use by typing its name or clicking the arrow to display a list of all channels. Select the checkbox next to each channel you want to send notifications to. To send notifications to a private Slack channel, add the Iru Endpoint Slackbot to the channel before searching for it. @mention Iru Endpoint in the private Slack channel and add the app when prompted. Enter an **Event notification name** into the field. Select the appropriate Event triggers. Click **Send test notification** to verify that it's working as expected. Click **Save**. You will see the Slack integration and event notification you just created. Click **Add event notification** to add more event notifications. ### Changing an Existing Event Notification Click the **ellipsis** next to the notification you would like to modify. Select **Edit event notification**. Modify the configuration, then click **Save** or **Cancel**. ### Deleting an Event Notification Click the **ellipsis** next to the notification you would like to delete. Select **Delete event notification**. Click **Delete** to confirm you'd like to delete the notification. ### Deleting a Slack Integration Click the **ellipsis** next to the Slack workspace you would like to delete. Select **Delete workspace**. Click **Delete** to confirm you'd like to delete the workspace. ### Example Notification Below is an example of the Slack notification when a user tries to open a blocked application. ### Considerations **Privacy and Data Processing**: Please review our privacy policy to understand how we process data as it relates to the Slack integration: [https://www.iru.com/legal/terms/](https://www.iru.com/legal/terms/) **Private Channel Access**: To send notifications to a private Slack channel, add the Iru Endpoint Slackbot to the channel before searching for it. @mention Iru Endpoint in the private Slack channel and add the app when prompted. **Workspace Management**: You can use multiple Slack workspaces by clicking the menu in the upper right and selecting **Add another workspace** during the sign-in process. # Microsoft Entra Id Permissions Source: https://docs.iru.com/en/endpoint/integrations/directory-services/microsoft-entra-id-permissions Review the Microsoft Entra ID API permissions required for directory integration with Iru Endpoint. Understand required scopes for user and group sync. This guide applies to Mac computers and Windows devices ### Microsoft Entra ID Permissions Microsoft Entra ID Permissions in Iru Endpoint are the Graph API scopes Iru Endpoint requests for directory integration. With these scopes, Iru Endpoint can sync users and groups and authenticate directory users. ### How It Works #### Integration Overview The Microsoft Entra ID Integration in Iru Endpoint syncs Microsoft Entra ID user and group objects into the Iru Endpoint user directory, so administrators can assign devices to those users. Iru Endpoint uses these delegated permissions through the Microsoft Graph API to sync directory information. #### Permissions Overview The following permissions are automatically requested and required to successfully sync Microsoft Entra ID users and groups into Iru Endpoint. A Microsoft Entra ID Administrator needs to have sufficient permissions to delegate the following permissions to Iru Endpoint. | **Permission** | **Display Text** | **Justification** | | ---------------- | ------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `Group.Read.All` | Read all groups | Allows Iru Endpoint to list groups, and to read their properties and all group memberships on behalf of the signed-in user. | | `User.Read.All` | Read all users' full profiles | Synchronize all AD Users | | `User.Read` | Sign in and read user profile | Store integrating AD administrator's information | | `offline_access` | Maintain access to data you have given it access to | Allows long-term syncing | | `openid` | Allows users to sign in to the app with their work or school accounts and allows the app to see basic user profile information. | Used for legacy OpenID login for Microsoft Entra ID users into Iru Endpoint. (This is now handled by a new independent Microsoft Entra ID application record) | # User Directory Integration Overview and Providers Source: https://docs.iru.com/en/endpoint/integrations/directory-services/user-directory-integration Overview of user directory integration in Iru Endpoint. Sync users and groups from Okta, Microsoft Entra ID, Google Workspace, or OneLogin to your account. ### User Directory Integration User Directory Integration in Iru Endpoint connects Microsoft Entra ID, Google Workspace, or Okta so Iru Endpoint can sync users and groups and assign those users to device records. ### Why Configure a Directory Integration? Iru Endpoint lets you [assign users](/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices) to specific devices. Using a directory integration to import users allows you to manage your Iru Endpoint user assignment centrally. You can configure automatic device assignment based on your directory settings. Device users in Iru Endpoint can only be created and assigned via a directory integration. To import users, you can connect multiple Google Workspace, Microsoft Entra ID, or System for Cross-Domain Identity Management (SCIM) integrations. This article covers adding Active Directory and Google Workspace user directories to Iru Endpoint. These native methods are simple to configure and require only a directory administrator account with access to the directory you are trying to integrate. After the initial user sync, Iru Endpoint will import users and groups every four hours. If you prefer user accounts be added and removed as they are created within your directory, use a SCIM integration. SCIM requires more upfront configuration but allows for Just-in-Time (JiT) account provisioning and de-provisioning. You can use SCIM with [Microsoft Entra ID](/en/endpoint/integrations/scim/scim-directory-integration-with-microsoft-entra-id), [Okta](/en/endpoint/integrations/scim/scim-directory-integration-with-okta), and other directory systems that support it. Refer to [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) for more information. ### Adding Directory Integrations #### Add a Microsoft Entra ID Integration In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. Under Directory integrations, click **Add and configure** under Microsoft Entra ID. Click **Get started**. Enter a unique name, which will be used in Iru Endpoint to show the directory from which a user originates. Click **Sign in with Microsoft Entra ID**. If you are signing in with an account that is not a Global Administrator, you may need to request approval during that sign-in process. Once a Global Administrator approves the request, you can complete the sign-in process. Sign in using a Microsoft Entra ID account with admin access to the directory you want to integrate. Consent on behalf of your organization and click **Accept**. You will see the new user directory on the **Integrations** page. The Google Workspace Integration in Iru Endpoint syncs Google Workspace user and group objects into the Iru Endpoint user directory. Iru Endpoint uses these delegated permissions through the Google API to sync that directory information. #### Add a Google Workspace Integration In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. Under Directory integrations, click **Add and configure** under Google Workspace. Click **Get Started**. Enter a unique name, which will be used in Iru Endpoint to show the directory from which a user originates. Click **Sign in with Google**. Sign in using a Google account with admin access to the directory you want to integrate. Click **Allow**. You will see the new user directory on the **Integrations** page. #### Google Workspace Permissions The following permissions are automatically requested and required to successfully sync Google Workspace users into Iru Endpoint. A Google Administrator must have sufficient permissions to delegate the following permissions to Iru Endpoint. | Permission | Display Text | Justification | | ------------------------------ | ----------------------------------- | ------------------------------------------------------------------------------------------------------------- | | openid | See info about users on your domain | Associate you with your personal info on Google | | userinfo.profile | See info about users on your domain | See your personal info, including any personal info you've made publicly available | | userinfo.email | See info about users on your domain | See your primary Google Account email address | | admin.directory.group.readonly | View groups on your domain | View details (e.g., name, members) and metadata (e.g., login details) of groups on your domain | | admin.directory.user.readonly | See info about users on your domain | Permission to see profile info about your domain users, such as their: Name, Email, Job Title, and Department | #### Disconnect Integration from Google Go to [https://myaccount.google.com/permissions.](https://myaccount.google.com/permissions) Ensure you are signed in with the same account that configured the integration originally. Click Remove for the Iru Endpoint application in the list of applications. ### View Additional Information about a Directory Integration Click the ellipsis on the Directory Integration you would like to view. Select **View details**. **Microsoft Entra ID and Google Workspace integrations** will show the administrator email account used to connect to the directory and the time of the last import. **SCIM integrations** will show the Iru Endpoint email used to connect to the directory, the SCIM API URL, and the time of the last sync. ### Force a User Directory Sync Microsoft Entra ID and Google Workspace directories sync automatically every four hours, but you can force an immediate sync. SCIM uses a push mechanism from the cloud directory so it is not necessary to force-sync a SCIM directory integration. Click the ellipsis on the Directory Integration you would like to sync. Select **Sync users**. ### Re-authenticate a Directory Integration You might need to re-authenticate an existing Microsoft Entra ID or Google directory integration to update credentials, change the account that was used to create the integration, or to update permissions. Click the ellipsis on the Directory Integration you would like to re-authenticate. Select **Re-authenticate**. Sign in using a Google or Microsoft Entra ID account with admin access. You will be redirected back to the Integrations page. ### Remove a Directory Integration Removing the integration will remove users not assigned to devices from Iru Endpoint. Users assigned to devices will remain, but Iru Endpoint will no longer synchronize them with the directory. Click the ellipsis on the Directory Integration you would like to delete. Select **Delete integration**. **Confirm** by typing the name of the integration. Click **Delete**. # Getting Started with Microsoft Device Compliance Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance Get started with the Microsoft Device Compliance integration in Iru Endpoint. Connect Intune, configure compliance policies, and validate device posture. This guide applies to Mac computers, iOS devices, and iPadOS devices ### About Microsoft Device Compliance Iru Endpoint's Microsoft Device Compliance (MSDC) integration combines Iru Endpoint device management with Microsoft Conditional Access. Only devices that Iru Endpoint manages and reports as compliant can access resources those policies protect. MSDC supports macOS, iOS, and iPadOS. ### How It Works MSDC is built through [Microsoft's device compliance partner program](https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-partners). It sets up the connection between Iru Endpoint and Microsoft and deploys the registration apps from the Iru Endpoint Library: the **Microsoft Company Portal** Auto App on Mac, and **Microsoft Authenticator** and **Iru Self Service** on iPhone and iPad. Once devices are registered with Microsoft, Iru Endpoint's device inventory and compliance data can be used in Microsoft Conditional Access policies. ### Prerequisites #### All Devices * Devices must be managed by Iru Endpoint * A [Microsoft user directory integration](/en/endpoint/integrations/directory-services/user-directory-integration) must be set up in your Iru Endpoint tenant * A user from the configured directory integration [must be assigned to the device record](/en/endpoint/devices/device-record-management/assigning-and-unassigning-users-to-devices) * Device users must be assigned an Enterprise Mobility + Security license, which includes Microsoft Entra ID Premium and [Microsoft Intune](https://learn.microsoft.com/en-us/mem/intune/fundamentals/licenses) * A Microsoft user account that can accept requested app permissions ### Microsoft Device Compliance Setup Path Use the diagram as your rollout checklist. Complete **Prerequisites** first, then follow the guides in order from left to right. Each article ends with **Next Steps** that point you to the following task.
Prerequisites
directory, licenses, users
Add partner
in Intune
Configure MSDC
integration in Iru
Deploy SSO profiles
and apps
User registration
on devices
Validate compliance
in Entra
### Next Steps After you finish the prerequisites and review this overview: See [Add Iru Endpoint as a compliance partner in Intune](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-adding-iru-endpoint-as-a-device-compliance-partner-in-intune). # Add Iru Endpoint as a compliance partner in Intune Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-adding-iru-endpoint-as-a-device-compliance-partner-in-intune Add Iru Endpoint as a third-party device compliance partner in Microsoft Intune. Configure the integration to report Mac and iOS compliance status. This guide applies to Mac computers, iOS devices, and iPadOS devices ### About Adding Iru Endpoint as a Device Compliance Partner in Intune Adding Iru Endpoint as a Device Compliance Partner in Intune allows you to establish Iru Endpoint as a trusted device compliance partner in Microsoft Intune, enabling the Microsoft Device Compliance integration to function properly. ### How It Works Before you can configure the Microsoft Device Compliance integration within Iru Endpoint, it's necessary to first establish Iru Endpoint as a device compliance partner in Microsoft Intune. See [Getting Started with Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance) for the **Microsoft Device Compliance setup path** diagram and rollout order. Log in to your Intune portal at [intune.microsoft.com](https://intune.microsoft.com). Navigate to the Partner compliance management section: * Click on **Tenant administration**, then select **Connectors and Tokens**. * Select **Partner compliance management**. * Click **Add compliance partner**. From the Compliance partner dropdown menu, select **Iru Endpoint Device Compliance**. Select the desired Apple device platform. Only one compliance partner can be configured per device platform. Select the user groups in scope for device compliance. Do not select the **Add all users** option. This is a special case and is not compatible with this integration. Review the selection, and click **Create**. For more details, see Microsoft's [Support third-party device compliance partners in Intune](https://learn.microsoft.com/en-us/mem/intune/protect/device-compliance-partners) support article. ### Next Steps After Iru Endpoint is added as a compliance partner in Intune: See [Microsoft Device Compliance: Integration Configuration](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-integration-configuration). # Microsoft Device Compliance: Integration Configuration Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-integration-configuration Configure the Microsoft Device Compliance integration between Iru Endpoint and Microsoft Intune. Set up API connections, tokens, and sync settings. This guide applies to Mac computers, iOS devices, and iPadOS devices Be sure to have the appropriate [prerequisites](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance#prerequisites) in place before starting the MSDC integration setup. See [Getting Started with Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance) for the **Microsoft Device Compliance setup path** diagram and rollout order. ### Configuring the MSDC Integration in Iru Endpoint In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover Integrations**. In the Security section, find **Microsoft Device Compliance**. Click **Add and configure**. Review the [Prerequisites](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance#prerequisites) and click **Next**. Enter your Microsoft primary domain URL on the next page and click **Sign in with Microsoft**. Follow the Microsoft OAuth prompts and **Accept** the permissions requested by the Iru Endpoint Device Compliance enterprise app. On the Device platforms page, select the device platforms and appropriate Microsoft user groups that will be in scope for device compliance. The selected platforms and user groups should match what was configured in Intune when [adding Iru Endpoint as a device compliance partner](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-adding-iru-endpoint-as-a-device-compliance-partner-in-intune). Click **Next** to complete the initial setup. You will be redirected to the MSDC integration details page, where you can see information about configured Microsoft tenants, configured device platforms, and selected user groups. ### Deleting the MSDC Integration from Iru Endpoint Complete the following steps to delete the MSDC integration from your Iru Endpoint tenant: In the sidebar, click the **Account Menu Button**, then select **Integrations**. Locate the Microsoft Device Compliance integration. Screenshot of the account menu with Integrations option highlighted Click the **Action** menu. Select **Delete Integration**. In the modal that appears, review the provided information and select **Delete Integration**. As part of the deletion, Iru Endpoint will send a de-provisioning request to Intune, terminating the connection between Iru Endpoint and your Microsoft Intune tenant. This will prevent any device inventory or compliance data from being sent from Iru Endpoint to Microsoft. To add the integration back to Iru Endpoint again, follow the steps in the Configuring the MSDC Integration in Iru Endpoint section above. ### Next Steps After the MSDC integration is connected in Iru Endpoint: Complete [Microsoft Device Compliance: Library Item Configuration](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-library-item-configuration) for Single Sign-on profiles, the Microsoft Company Portal Auto App (macOS), or Authenticator and Self Service (iOS and iPadOS). Deploy Single Sign-on profiles first if they are not already in place. See [Single Sign-on Profiles](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-library-item-configuration#single-sign-on-profiles). # Microsoft Device Compliance: Library Item Configuration Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-library-item-configuration Configure the Microsoft Device Compliance Library Item in Iru Endpoint. Define compliance rules, validation criteria, and enforcement actions for devices. This guide applies to Mac computers, iOS devices, and iPadOS devices Deploy Single Sign-on profiles and registration apps after the MSDC integration is configured. See [Getting Started with Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance) for the **Microsoft Device Compliance setup path** diagram and rollout order. ### Single Sign-on Profiles Before users register for Microsoft Device Compliance, deploy Single Sign-on so devices can authenticate to Microsoft Entra ID during registration. Skip this section if the Microsoft Single Sign-on Extension, or Platform SSO with Microsoft Entra ID, is already deployed for the platforms you configured. If you use [Platform SSO with Microsoft Entra ID](/en/endpoint/library/library-items-profiles/configure-the-platform-sso-with-microsoft-entra-id-library-item), complete that configuration first. Have each user register with Platform SSO before they register for Microsoft Device Compliance. If you do not use Platform SSO with Microsoft Entra ID, create a [Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item) for Mac. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Enter a **Name** for the Single Sign-On Extension Library Item. Set **Installs On** to **Mac** only. Assign the Library Item to your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). Configure the extension using [Microsoft Single Sign-on Extension macOS settings](https://learn.microsoft.com/en-us/mem/intune/configuration/use-enterprise-sso-plug-in-macos-with-intune?tabs=prereq-other-mdm%2Ccreate-profile-other-mdm#create-a-single-sign-on-app-extension-configuration-policy). For field-level guidance in Iru Endpoint, see [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item). Click **Save**. Create a [Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item) for iPhone and iPad. On iOS and iPadOS, deploy the app that contains the SSO extension through Apps and Books before you assign the profile. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Enter a **Name** for the Single Sign-On Extension Library Item. Set **Installs On** to **iOS** and **iPadOS** only. Assign the Library Item to your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). Configure the extension using [Microsoft Single Sign-on Extension iOS and iPadOS settings](https://learn.microsoft.com/en-us/intune/intune-service/configuration/use-enterprise-sso-plug-in-ios-ipados-with-intune?tabs=prereq-intune%2Ccreate-profile-other-mdm#create-a-single-sign-on-app-extension-configuration-policy). For field-level guidance in Iru Endpoint, see [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item). Click **Save**. ### Microsoft Company Portal Auto App (macOS) To add the **Microsoft Company Portal** Auto App Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Optionally, assign a **Label** and assign to your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. If this is the first time deploying Microsoft Device Compliance (MSDC), it is a good idea to deploy to a test Blueprint scoped to a limited number of macOS devices so that you can see how it functions when deployed. For the Installation type, choose **Install and continuously enforce**. Select an option from the Version Enforcement dropdown. Your options include the following: * Do not manage updates * Automatically enforce new updates * Manually enforce a minimum version * Manually enforce a specific version Click **Save**. For additional information on settings and options for Auto Apps, please refer to our [Auto Apps Overview](/en/endpoint/library/auto-apps/auto-apps-overview) support article. ### Microsoft Authenticator & Iru Self Service (iOS & iPadOS) To configure MSDC for iOS and iPadOS, you must first [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books), and add the Microsoft Authenticator and **Iru Self Service** App Store apps to your Iru Endpoint library. For instructions on adding apps from Apps and Books to Iru Endpoint, follow this [guide](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint). Navigate to **Library** in the left-hand navigation bar. Under App Store Apps, select **Microsoft Authenticator**. Assign to your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). If this is the first time deploying MSDC, it is a good idea to deploy to a test blueprint scoped to a limited number of iOS/iPadOS devices so that you can see how it functions when deployed. Under Installation Type, choose **Install and continuously enforce**. If Microsoft Authenticator is installed on some devices, this process will not reinstall the app; instead, Iru Endpoint will take over its management. In the Microsoft Device Compliance section, toggle the switch **On**. Click **Save**. Repeat the above steps for **Iru Self Service**. Apply both apps to the same Blueprints. ### User Registration #### macOS Once the Microsoft Company portal is installed on the Mac, the Iru Agent will attempt to launch the app automatically, following a specific process required by Microsoft so that end users can begin the registration process. For more information about what users should expect, see our [Microsoft Device Compliance: User Registration Experience](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-user-registration-experience) support article. #### iOS & iPadOS Once the Microsoft Authenticator app is installed on a mobile device, users will find an option in the **Iru Self Service** app labeled 'Microsoft Device Compliance Device.' This is where they can start the registration process. #### How to Reset Microsoft Device Registration You can use the **Reset Microsoft Registration** action on macOS, iOS, and iPadOS to reset the registration. This command does not require any supervision. **Prerequisites that should be in place before the action will appear in the action menu** * The Microsoft Device Compliance integration should be set up both in Iru Endpoint and in Microsoft Intune portal. * On macOS, the Microsoft Company Portal Auto App Library Item is scoped to the device and installed. * On iOS and iPadOS, the Microsoft Authenticator App Store app Library Item is scoped to the device and the Microsoft Device Compliance setting is toggled on and installed. **Existing Iru Endpoint device record (record not removed) and same user is re-registering the device** Navigate to the Device record. Open the **Device Action Menu**. Select **Reset Microsoft registration**. Click **Reset Device Registration**. Iru Endpoint sends an update to Microsoft Entra ID that the device is no longer managed and is not compliant. Iru Endpoint resets the MSDC registration status for the device record in Iru Endpoint. The end-user can now [re-register](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-user-registration-experience) the device. * On macOS, the Iru Agent sees that the device is no longer registered and prompts the user to register their device again. * This will happen at agent check in or if a manual check in is performed on the Mac. * If the Microsoft Company Portal app is open, it will need to be closed to get the re-registration prompt. * If the Microsoft Company Portal app is closed, once the device checks in with the Iru Agent, they will receive a prompt to re-register. * If the Microsoft Company Portal app is closed, re-launching the Microsoft Company Portal will prompt to re-register immediately. * On iOS and iPadOS, the user can follow the registration process as if registering the device for the first time. Iru Endpoint updates the device record in Microsoft Entra ID letting Entra know that the device is now managed by Iru Endpoint again and compliant. **Possible error messages and their descriptions** Below are possible error messages that you could see in Iru Endpoint when sending the action to reset Microsoft registration.
Message Description
"No active Microsoft device registration found." This means that the device has a record in Iru Endpoint, and there is a Microsoft device registration for the device in Iru Endpoint but is not active. This is generally due to the device no longer being enrolled in Iru Endpoint either because the MDM profile was removed locally on the device or the erased device action was sent from Iru Endpoint.

To remediate, the device needs to be reenrolled to Iru Endpoint and the MSDC registration needs to be completed again locally on the device.
"Device is not registered" This means that the device has all of the prerequisites in place but has not yet registered with Microsoft through the Iru Endpoint MSDC integration.

If the device was registered with Microsoft previously through another MDM solution, the end-user will need to complete the registration process again through the Iru Endpoint integration.

See MSDC registration for more details.
"Reset Registration failed" Default error message if none of the above.
### Compliance Status After a user has registered their device, see [Microsoft Device Compliance Validating Compliance](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-validating-compliance) to verify the compliance status. ### Next Steps After SSO profiles and registration apps are deployed: See [Microsoft Device Compliance: User Registration Experience](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-user-registration-experience). # Microsoft Device Compliance: User Registration Experience Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-user-registration-experience Walk through the user registration experience for Microsoft Device Compliance. See what users encounter when registering devices for Intune compliance. This guide applies to Mac computers, iOS devices, and iPadOS devices ### About Microsoft Device Compliance User Registration Experience Microsoft Device Compliance User Registration Experience in Iru Endpoint guides users through the process of registering their managed devices with Microsoft using the Microsoft Company Portal app, enabling device compliance reporting and conditional access. ### How It Works Users register after SSO profiles and registration apps are deployed. See [Getting Started with Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance) for the **Microsoft Device Compliance setup path** diagram and rollout order. ### Registering Your Mac with Microsoft After installing the Microsoft Company Portal app, you will need to register your managed Mac with Microsoft. The Iru Agent will automatically launch the Microsoft Company Portal application. Please do not attempt to sign into the Company Portal app until you receive a prompt from Iru Endpoint. Click the Iru Endpoint prompt to **Register Your Mac**. Alternatively, you can click the Iru Endpoint Menubar item and click on **Open** next to Register Your Mac. When the Company Portal opens, click **Sign-in**. Enter your Microsoft credentials and sign in. If multi-factor authentication (MFA) is required, respond to the prompts. Once signed in, the Company Portal will verify your registration. Click **Done**. ### Registering Your iPhone or iPad with Microsoft The **Iru Self Service** app is required to initiate the iOS/iPadOS device registration process. After installing the **Iru Self Service** app and Microsoft Authenticator app, follow these steps to register your managed iOS/iPadOS device with Microsoft: Open the **Iru Self Service** app. Tap **More**. Tap **Register for Microsoft Device Compliance.** The Microsoft Authenticator app will open. Enter your Microsoft credentials and sign in. If multi-factor authentication (MFA) is required, respond to the prompts. Once signed in, the Microsoft Authenticator app will verify your registration. Tap **Done**. ### Next Steps After users finish registration: See [Microsoft Device Compliance Validating Compliance](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-validating-compliance). # Microsoft Device Compliance Validating Compliance Source: https://docs.iru.com/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-validating-compliance Validate device compliance status with the Microsoft Device Compliance integration. Troubleshoot compliance check failures and sync issues in Intune. This guide applies to Mac computers, iOS devices, and iPadOS devices ### About Microsoft Device Compliance Validation Microsoft Device Compliance Validation in Iru Endpoint lets you verify a device's compliance status after the user completes registration, and confirm that Iru Endpoint reported that status to Microsoft Entra ID. ### How It Works You can verify the Compliance status of a device after the user has followed the steps in the [Microsoft Device Compliance: User Registration Experience](/en/endpoint/integrations/microsoft-device-compliance/microsoft-device-compliance-user-registration-experience) support article. Microsoft Entra may take up to 24 hours to process and display the device compliance status information received from Iru Endpoint. During this processing period, the compliance status may display as "N/A" in the Entra portal. Log in to your [Microsoft Entra admin center](https://entra.microsoft.com/). Navigate to **Devices** from the left-hand navigation. Select **All Devices**. The **Join Type** can either be Microsoft Entra registered or Microsoft Entra joined. The **MDM** will be listed as Microsoft Intune. The **Compliant** status will be Yes if the device successfully enrolls through Microsoft Device Compliance. * If a device has been registered with the Company Portal but is not listed as Compliant, [please contact Iru Support](/en/iru/iru-support/access-to-iru-support) for assistance. If Intune Partner device management is enabled and you set up partner compliance management, users who belong to the security group associated with partner compliance management will not be able to sign in to the Company Portal app. When they attempt to sign in, they will see a message stating, "Company Portal temporarily unavailable." ### Next Steps After compliance is validated: See [Getting Started with Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance) for the **Microsoft Device Compliance setup path** diagram and rollout order. # Okta Desktop Password Sync User Experience Source: https://docs.iru.com/en/endpoint/integrations/okta-desktop-password-sync-user-experience Walk through the Okta Desktop Password Sync user experience. See what users encounter when syncing their macOS password with Okta credentials. This guide applies to Mac computers ### About Okta Desktop Password Sync Okta Desktop Password Sync for macOS syncs the local macOS account password with the user's Okta password. ### How It Works Desktop Password Sync for macOS allows users to synchronize their local macOS account password with their Okta password. This integration ensures that when users change their Okta password, their local macOS password automatically updates to match, eliminating the need to manually update passwords across systems. ### Prerequisites * Before registering Okta Verify and setting up Desktop Password Sync, ensure Touch ID has been set up on your computer. ### Initial Registration A notification will be presented showing Registration Required. Click **Register**. Okta Desktop Password Sync registration notification showing the Registration Required message and Register button that needs to be clicked to start the setup process Enter your current computer password when prompted. macOS password prompt dialog showing the password field where users need to enter their current computer password for Okta Desktop Password Sync registration Start the Okta Verify setup process by clicking **Set up** in the popup window. Okta Verify setup popup window showing the Set up button that needs to be clicked to begin the Okta Verify configuration process You will continue the process in your web browser. Okta Desktop Password Sync setup screen showing the message that the process will continue in the web browser Log into your Okta account in your web browser. Okta login page in web browser showing the username and password fields where users need to authenticate with their Okta credentials Once your identity is verified you can close your web browser window. You will be prompted to enable Touch ID. Touch ID setup prompt showing the option to enable Touch ID for Okta Desktop Password Sync authentication Next, you will be prompted to authenticate to sync your Okta password to your local account. Click **Continue**. Okta Desktop Password Sync authentication prompt showing the Continue button to proceed with password synchronization Click **Sign In** on the notification that appears. Okta Desktop Password Sync sign-in notification showing the Sign In button that needs to be clicked to authenticate Enter your Okta password and click **Sign in**. Okta password entry dialog showing the password field and Sign in button for authenticating with Okta credentials You will see a notification letting you know your password has been synchronized. Okta Desktop Password Sync success notification confirming that the password has been synchronized successfully ### Password Changes In Users & Groups settings, in the Password field, the Change button is not available. This is to help keep your Mac password in sync with your Okta password. If your Okta password changes, there are a few ways to change your Mac password to match your Okta password. Until you update your password, you will continue to use your old password to log in to your Mac. #### Okta Verify Notification When you see the **Authentication Required** notification, click **Sign In**. Okta Desktop Password Sync authentication required notification showing the Sign In button for password updates Enter your new Okta password and click **Sign In**. Okta password entry dialog showing the password field and Sign In button for entering the new Okta password You will see a notification that your password has been updated. Okta Desktop Password Sync success notification confirming that the password has been updated successfully #### Lock Screen You can use your new Okta password at the macOS Lock Screen (not the FileVault unlock screen or Login Window) which will automatically update the local account password on successful authentication. ### System Settings (macOS 14+ Only) After your password is changed in Okta, open **System Settings** and select **Users & Groups**. Click the **info** icon next to your user name. macOS System Settings Users & Groups page showing the info icon next to the user name that needs to be clicked to access user details In the **Platform Single Sign-on** section, click **Authenticate**. macOS System Settings user details page showing the Platform Single Sign-on section with the Authenticate button that needs to be clicked Enter your new Okta password when prompted. macOS password prompt dialog showing the password field where users need to enter their new Okta password for synchronization You will see a notification that your password has been synchronized. Okta Desktop Password Sync success notification confirming that the password has been synchronized successfully through System Settings ### Considerations **Touch ID Requirements**: Touch ID must be set up on your computer before registering Okta Verify and setting up Desktop Password Sync. **Password Management**: The Change button in Users & Groups settings is disabled to maintain synchronization between your Okta password and local macOS password. **Lock Screen vs. Login Window**: Password updates work at the macOS Lock Screen but not at the FileVault unlock screen or Login Window. **System Settings Method**: The System Settings method for password synchronization is only available on macOS 14 and later versions. # Deploy Okta Desktop Password Sync and Platform SSO Source: https://docs.iru.com/en/endpoint/integrations/okta-desktop-password-sync/deploy-okta-desktop-password-sync-and-platform-single-sign-on Deploy Okta Desktop Password Sync with Platform SSO on Mac using Iru Endpoint. Configure SCEP, Custom Profile Library Items, and the Okta Verify Auto App. This guide applies to Mac computers ### About Okta Desktop Password Sync and Platform SSO Okta Desktop Password Sync with Platform Single Sign-On (SSO) in Iru Endpoint keeps local macOS passwords aligned with Okta and extends Okta sign-in to the macOS login window. ### How It Works Okta Desktop Password Sync is currently in Okta "Early Access" release. See Okta's resource: [Manage Early Access and Beta](https://help.okta.com/oie/en-us/content/topics/security/manage-ea-and-beta-features.htm). Deploy Desktop Password Sync with the **Okta Verify Auto App** Library Item. If the App Store version of Okta Verify is already on your Blueprint, see [Switch to the Okta Verify Auto App](#switch-to-the-okta-verify-auto-app) later in this guide. ### Requirements #### Okta Requirements * You use Okta Identity Engine. * Your macOS computers must run **macOS 14 Sonoma or later**, which supports **Platform SSO 2.0** and Desktop Password Sync from the login window. * The Desktop Password Sync application is available for your organization in Okta. If you can't locate the Desktop Password Sync app in the app catalog, contact your Okta account representative. * The Okta Verify authenticator is set up in your org. * An **Okta Verify** Auto App Library Item in your Library, assigned to the Blueprints where you deploy Desktop Password Sync. #### Additional Requirements * Two Custom Profile mobileconfig templates from this guide (see **Edit the mobileconfig template files**) and a **Single Sign-on Extension** Library Item for Okta Platform SSO (see **Configure the Okta Platform SSO Single Sign-on Extension Library Item**). ### FileVault Support for macOS 15+ Okta authentication policies can require stronger checks on macOS 15 and later, including the FileVault interface during Desktop Password Sync. Configure that in Okta; see [FileVault network requirements](https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/about-psso-version-history.htm#fvnetwork). ### Create Device Access SCEP Certificates #### Configure a Desktop SCEP Certificate Authority in Okta Log in to your Okta admin portal. In the left-hand navigation, select **Security**. In the expanded menu, select **Device Integrations**. In the Device Integration pane, select **Device Access**. Click **Add SCEP configuration**. Select **Static SCEP URL**. Click **Generate**. Copy the **SCEP URL**. Copy the **Secret key**. Record the secret key now. This is the only time you can view it. Okta stores a hash afterward. Click **Save**. If you need to **Reset the secret key**, you can do so from the **Actions** menu to the right of the integration. #### Add the SCEP Library Item To add this Library Item to your Iru Endpoint Library, see the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. #### Configure the SCEP Library Item Name the Library Item. Assign it to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). In the **URL** field, paste the SCEP server URL you copied earlier. Enter a **Name** (optional). In the **Challenge** field, paste the secret key you copied earlier. In the **Subject** field, enter CN=\$SERIAL\_NUMBER. When you save the SCEP Library Item, Iru Endpoint appends the PROFILE\_UUID to the CN. Set **Subject Alternative Name** type to **None**. For **Key Size**, select 2048. For **Key Usage**, select Signing. Select **Retries** and enter **5**. Change this if your environment needs a different retry count. Select **Retry delay** and enter **30** seconds. Change this if your environment needs a different delay. Select **Allow apps to access the private key**. Select **Prevent the private key data from being extracted in the keychain**. Select **Automatic profile redistribution** and enter **30** days before the certificate expires. Change this if your environment needs a different interval. Click Save. For more information about the Iru Endpoint SCEP Library Item, see [Configure the SCEP Library Item](/en/endpoint/library/library-items-profiles/configure-the-scep-library-item). ### Create and Configure the Desktop Password Sync App Integration in Okta In the Okta Admin Console, go to **Applications** > **Applications Catalog**. Search for **Desktop Password Sync** and select the app. Click **Add Integration**. If you see **This feature isn't enabled**, contact your Okta account representative. Open Desktop Password Sync from your **Applications** list to configure it. On the **General** tab, you can edit the application label or use the default label. On the **Sign on** tab, record the **Client ID**. You need it when you edit the Okta Verify mobileconfig template. Assign the app to individual users or groups on the **Assignments** tab. Users must be assigned the app to use Desktop Password Sync. Click **Save**. ### Edit the Mobileconfig Template Files Download and edit these two mobileconfig templates with a plain text editor such as Visual Studio Code, Sublime Text, or BBEdit: * `Okta_Associated_Domains_Configuration_Template.mobileconfig`: Associated Domains for Okta Verify and the auth-service extension * `Okta_Verify_Configuration_Template.mobileconfig`: Okta tenant URL and Desktop Password Sync client ID for Okta Verify and the auth-service extension Upload each finished file as a Custom Profile Library Item in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint). Download **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** from the support GitHub repository ([GitHub](https://github.com/kandji-inc/support/blob/main/Configuration%20Profiles/Okta_Associated_Domains_Configuration_Template.mobileconfig)). Download **Okta\_Verify\_Configuration\_Template.mobileconfig** from the support GitHub repository ([GitHub](https://github.com/kandji-inc/support/blob/main/Configuration%20Profiles/Okta_Verify_Configuration_Template.mobileconfig)). #### Okta Associated Domains template The **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file deploys a **com.apple.associated-domains** payload. It connects Okta Verify and the Okta auth-service extension to your Okta tenant for Platform SSO and Desktop Password Sync. Open the **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file in your text editor. In the first **Configuration** entry, update **AssociatedDomains** and replace the example domain with your Okta tenant address. * Example: authsrv:accuhive.okta.com ```xml theme={null} ApplicationIdentifier B7F62B65BN.com.okta.mobile.auth-service-extension AssociatedDomains authsrv:accuhive.okta.com ``` In the second **Configuration** entry, update **AssociatedDomains** for **com.okta.mobile** and replace the example domain with your Okta tenant address. * Example: authsrv:accuhive.okta.com ```xml theme={null} ApplicationIdentifier B7F62B65BN.com.okta.mobile AssociatedDomains authsrv:accuhive.okta.com ``` Save the mobileconfig file. You will upload it as a Custom Profile Library Item in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint). #### Okta Verify template Open the **Okta\_Verify\_Configuration\_Template.mobileconfig** file in your text editor. In the **com.okta.mobile** payload, set **OktaVerify.OrgUrl** to your Okta tenant URL. * Example: [https://accuhive.okta.com](https://accuhive.okta.com) ```xml theme={null} OktaVerify.OrgUrl https://accuhive.okta.com ``` In the **com.okta.mobile** payload, set **OktaVerify.PasswordSyncClientID** to the Desktop Password Sync app **Client ID** you recorded earlier. ```xml theme={null} OktaVerify.PasswordSyncClientID YOUR_CLIENT_ID ``` In the **com.okta.mobile.auth-service-extension** payload, set **OktaVerify.OrgUrl** to your Okta tenant URL. ```xml theme={null} OktaVerify.OrgUrl https://accuhive.okta.com ``` In the **com.okta.mobile.auth-service-extension** payload, set **OktaVerify.PasswordSyncClientID** to the Desktop Password Sync app **Client ID** you recorded earlier. ```xml theme={null} OktaVerify.PasswordSyncClientID YOUR_CLIENT_ID ``` Save **Okta\_Verify\_Configuration\_Template.mobileconfig**. ### Configure the Okta Platform SSO Single Sign-on Extension Library Item Use a **Single Sign-on Extension** Library Item to deploy the Okta Verify redirect extension and Platform SSO settings on enrolled Mac computers. Finish the **Okta Associated Domains** and **Okta Verify Configuration** Custom Profiles before you assign this Library Item. See the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article to add Library Items in Iru Endpoint. For field descriptions, see [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item). Enter a **Name** for the new Library Item (for example **Okta Platform SSO**). Select **Mac** as the **Install on** platform. Assign the Library Item to the same [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) as your SCEP Library Item and Custom Profile Library Items for this deployment. Under **Extension type**, select **Redirect**. For **Extension identifier**, enter: ```text theme={null} com.okta.mobile.auth-service-extension ``` For **Team identifier**, enter: ```text theme={null} B7F62B65BN ``` Add these **URLs**, replacing `accuhive.okta.com` with your Okta org hostname (the same hostname you used in the Associated Domains and Okta Verify templates): ```text theme={null} https://accuhive.okta.com/device-access/api/v1/nonce ``` ```text theme={null} https://accuhive.okta.com/oauth2/v1/token ``` ```text theme={null} https://accuhive.okta.com/v1/auth/device-sign ``` Leave **Hosts** empty. Toggle **Platform SSO** on. Under **Authentication method**, select **Password**. Desktop Password Sync requires password authentication at the macOS login window. Enter a **Registration token** only if Okta or your org requires one for Platform SSO registration. Under **Platform SSO**, turn on any **macOS 15 and later** options your org needs for Desktop Password Sync or FileVault. See [FileVault Support for macOS 15+](#filevault-support-for-macos-15) and [Okta's macOS PSSO version history](https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/about-psso-version-history.htm). Set default permissions for **Existing Users** (Standard or administrator, or a group you configure in a later step). Set default permissions for **New Users**. Select **Use shared device keys**. This setting is required for Desktop Password Sync. Turn on **Allow authorization (with identity provider account)** so users can approve system prompts with their Okta credentials. If you want local accounts created automatically at the login window, enable **Allow creation of new users at login window**. Local account creation requires the device to be online at the login window with FileVault unlocked, and Iru Endpoint must have a valid bootstrap token for the device. If your org uses device attestation, turn on the option to send the device UDID and serial number in Platform SSO attestations (macOS 15.4 and later). Enter an **Account display name** users will recognize in notifications and sign-in prompts (often your company name). This value is system-wide and visible to every user on the Mac. Specify **Require full login** in seconds. The default in Iru Endpoint is 18 hours (64800 seconds). The minimum is 1 hour (3600 seconds). Under **Token mapping**, configure **AccountName** and **FullName**, plus any other attributes you need for new user creation and authorization. Use attribute names from your Okta tenant for Platform SSO or Desktop Password Sync. If you aren't sure which values to use, ask your Okta administrator or see **Configure login options** in [Configure the Single Sign-On Extension Library Item](/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item#login-options--groups). Optional: configure **Admin groups**, **Additional groups**, and **User groups**: * **Admin groups** are groups from Okta that should receive administrator access on the device. * **Additional groups** are custom groups to create in the device's local directory. * **User groups** map macOS system rights (for example `sudo` or printer management) to local directory groups. Click **Save**. If you deploy Platform SSO during Setup Assistant on **macOS 26** or later, configure the **Mac macOS 26 and later** section of this Library Item. See [Enable Registration During Setup Assistant (macOS 26 and later)](#enable-registration-during-setup-assistant-macos-26-and-later). ### Enable Registration During Setup Assistant (macOS 26 and later) On **macOS 26** and later, Platform SSO can run during Setup Assistant so the Mac registers with Okta earlier in enrollment. Set registration during setup, first-user creation, profile picture sync, and Authenticated Guest Mode in the **Mac macOS 26 and later** section of your **Okta Platform SSO** Single Sign-on Extension Library Item. When you deploy Platform SSO with Automated Device Enrollment, do not set **Primary account type** to **Skip primary account creation** in the **Mac** section of your [Automated Device Enrollment Library Item](/en/endpoint/enrollment/apple/configuring-apple-enrollment). Setup Assistant is where the user sets the local account password. Skipping that step leaves the password unset and can stall enrollment. On Mac computers with Apple silicon and some other models, credentials are stored in the [Secure Enclave](https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web). See Apple's documentation for which devices include a Secure Enclave. **Skip primary account creation** is for [Passport](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#primary-account-creation) workflows, not Platform SSO. In the **Library**, open your **Okta Platform SSO** Single Sign-on Extension Library Item, click **Edit**, then go to **Mac macOS 26 and later** in the **Platform SSO** section. For **Enable registration during Setup Assistant**, select **Yes** to register with Okta during Setup Assistant. For **Create first user during Setup Assistant**, select **Yes** when the Mac should create its first local account during Setup Assistant from the Okta identity. Select **No** if you provision the first account another way. For **Synchronize profile picture**, select **Yes** to copy the user's Okta profile picture to the local macOS account during setup, or **No** to skip it. Turn on **Enable Authenticated Guest Mode** for shared Macs where users sign in temporarily with Okta. Leave it off for standard single-user Macs. Under **New user authentication methods**, select the methods for newly created accounts. Include **Password** and **SmartCard** as your org requires. Click **Save**. #### Install Platform SSO Library Items during Automated Device Enrollment When you use registration during Setup Assistant, the SCEP Library Item, both Custom Profile Library Items, the **Okta Platform SSO** Single Sign-on Extension Library Item, and the **Okta Verify Auto App** must install before Setup Assistant finishes. Add and assign those Library Items in [Add Library Items in Iru Endpoint](#add-library-items-in-iru-endpoint), then configure Automated Device Enrollment: In the **Library**, open your **Automated Device Enrollment** Library Item and go to the **Mac** section. Turn on **Install Library Items during Setup Assistant** for **Mac** so selected Library Items install during enrollment setup instead of after Setup Assistant completes. Select **Add Library Items** and add each item from this guide: * SCEP Library Item * Okta Associated Domains (Custom Profile): `Okta_Associated_Domains_Configuration_Template.mobileconfig` * Okta Verify Configuration (Custom Profile): `Okta_Verify_Configuration_Template.mobileconfig` * Okta Platform SSO (Single Sign-on Extension Library Item) * Okta Verify Auto App A Library Item in this list installs during Setup Assistant only when it is also on the device's Blueprint **Assignment Map**. Add every item you need during setup to that map. Click **Save** on the Automated Device Enrollment Library Item. See [Install Library Items during Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#install-library-items-during-setup-assistant) for the install experience, timeouts, and other considerations. If a device is stuck on **Configuring**, see [Manually release devices held in Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#manually-release-devices-held-in-setup-assistant). ### Add Library Items in Iru Endpoint Add your SCEP Library Item, Custom Profile Library Items, **Okta Platform SSO** Single Sign-on Extension Library Item, and **Okta Verify Auto App** to Iru Endpoint. See the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article if you need the basics. Name the Library Item (for example **Okta Associated Domains**). Assign it to your [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Upload your edited **Okta\_Associated\_Domains\_Configuration\_Template.mobileconfig** file, then click **Save**. If you haven't already, complete [Configure the Okta Platform SSO Single Sign-on Extension Library Item](#configure-the-okta-platform-sso-single-sign-on-extension-library-item) and assign it to the same Blueprint(s). Create a Custom Profile Library Item for **Okta\_Verify\_Configuration\_Template.mobileconfig** (for example **Okta Verify Configuration**). Assign it to the same Blueprint(s), upload the file, and click **Save**. In the Library, go to **Auto Apps** and open **Okta Verify**. Assign the Library Item to the same Blueprint(s) as the SCEP Library Item, Custom Profile Library Items, and **Okta Platform SSO** Single Sign-on Extension Library Item. After devices receive the Library Items and **Okta Verify Auto App**, users are prompted to register and sync their Okta password. ### Assignment Maps Assign the SCEP Library Item, both Custom Profile Library Items, the **Okta Platform SSO** Single Sign-on Extension Library Item, and the **Okta Verify Auto App** on the Blueprint **Assignment Map**. Use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) when you need to scope Library Items to specific device groups. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) for Blueprint basics. ### Switch to the Okta Verify Auto App If Okta Verify is already on the Blueprint through another Library Item, switch to the **Okta Verify Auto App** without redoing Desktop Password Sync setup. Your Custom Profile Library Items, **Okta Platform SSO** Single Sign-on Extension Library Item, and Okta configuration stay on the device. Make assignment changes in one Assignment Map edit session. Assign the **Okta Verify Auto App** before you select **Save**. Do not leave computers without an assigned Okta Verify app after you save. Open the Blueprint **Assignment Map**, then select **Edit assignments**. Remove the existing **Okta Verify** Library Item from the Assignment Map. Add the **Okta Verify Auto App** Library Item to the same Assignment Map scope as your SCEP, Custom Profile, and **Okta Platform SSO** Library Items. Select **Save** to apply the Assignment Map changes. The previous Okta Verify app is removed from devices. The Associated Domains profile, **Okta Platform SSO** Single Sign-on Extension configuration, and Okta Verify Custom Profile remain. On the next Iru Agent check-in (within about 15 minutes), Iru Endpoint installs the **Okta Verify Auto App**. If you also use [Okta Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust), see [Configure Okta Verify for Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item#migrate-from-the-app-store-app-to-the-auto-app-macos) when you need to update ODT on the Auto App. ### User Experience and Next Steps With Platform SSO enabled, macOS hides the **Change** button in the Password field under **Users & Groups** (System Settings). Apple designed this behavior for Platform SSO. After deployment, send users to [User Experience with Okta Desktop Password Sync](/en/endpoint/integrations/okta-desktop-password-sync-user-experience) for registration steps. # Okta Device Trust Source: https://docs.iru.com/en/endpoint/integrations/okta-device-trust-main/okta-device-trust Overview of Okta Device Trust integration with Iru Endpoint. Enforce device trust policies for conditional access and passwordless authentication. This guide applies to Mac computers, iOS devices, and iPadOS devices **Product Name Update**: Throughout this guide, you may notice references to both "Kandji" and "Iru Endpoint." Our product is now called Iru Endpoint, but some integration interfaces may still display the previous name. This is a temporary situation that will be resolved as our integration partners update their systems. ### About Okta Device Trust Okta Device Trust (ODT) lets Okta check that Iru Endpoint manages an Apple device before the user can open Okta-protected apps. That is what makes Okta FastPass available without a password. ### How It Works ### About the Integration ODT is built on [Okta Identity Engine](https://help.okta.com/oie/en-us/content/topics/identity-engine/oie-index.htm) (OIE). During setup, Iru Endpoint checks that the Okta tenant is ready for ODT on OIE, then deploys ODT configurations to devices in the scope of Okta Device Trust. On iPhone, iPad, and Mac, FastPass can use Face ID and Touch ID. Okta FastPass is a feature of Okta Identity Engine. ### Before You Begin Configure the following in your Okta tenant before you set up ODT with Iru Endpoint. * The Okta tenant must be migrated from Okta Classic Engine to [Okta Identity Engine](https://help.okta.com/oie/en-us/content/topics/identity-engine/oie-index.htm). * The user setting up ODT needs an Okta account with the **super admin** role. Super admin credentials are only required for initial authentication and adding the API Service Integration. * [Okta FastPass](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm) must be enabled in the Okta tenant. * [Okta Adaptive MFA](https://www.okta.com/products/adaptive-multi-factor-authentication/) is required to add Device integrations in Okta. ### Prerequisites Complete the following in Iru Endpoint before or during ODT setup. Iru Endpoint checks for these items during integration setup and shows a warning if any are missing. * Make **Okta Verify** available in your Library from Apps and Books in [Apple Business](https://business.apple.com/) or [Apple School Manager](https://school.apple.com/). * On **macOS**, assign the **Okta Verify Auto App** Library item from **Auto Apps**. * On **iOS** and **iPadOS**, assign the **Okta Verify** App Store app Library item from **App Store Apps**. * If one Blueprint includes Macs and mobile Apple devices, use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) in the Assignment Map to assign each Library item to the correct platform. ### Configuration Steps Below are high-level steps to set up and deploy ODT with Iru Endpoint. Set up the Okta Device Trust integration in Iru Endpoint. Add and configure device platforms in Okta. Add and configure Okta device platforms in Iru Endpoint. Configure the Okta Verify Library item to deploy Okta Device Trust. On Mac, use the **Okta Verify Auto App**. See [Configure Okta Verify for Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item) for setup and migration from the App Store app. ### What Settings Are Deployed to Devices Once ODT is set up, enabled, and scoped to your blueprints, the following settings payloads are automatically configured and delivered to Apple devices in the scope of Okta Device Trust in Iru Endpoint. | Payload setting | Platform | Description | | ---------------------------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Dynamic SCEP certificate | macOS | This is a unique Okta SCEP certificate per device. The certificate is used in the device registration process. | | OktaVerify.EnrollmentOptions | macOS | Okta Verify `SilentEnrollmentEnabled` configuration is sent to macOS devices. This will launch Okta Verify automatically if an unregistered device attempts to access Okta resources and prefill the Organization URL for the user. | | Okta Verify Login item | macOS | This payload adds Okta Verify as a login item on macOS and will start Okta Verify at user login. | | Managed app config | iOS and iPadOS | This App Config contains the `OktaVerify.OrgUrl` and device `managementHint` used to register the device as managed in Okta. | | SSO Extension payload | macOS, iOS, and iPadOS | The SSO extension forwards requests from the browser or app to Okta Verify, and users do not receive the Open Okta Verify browser prompt. Not supported on Chrome or Firefox. | The EDR Plugin setting is not deployed with the ODT integration, but can be delivered via a separate configuration profile if needed. Doing so will not impact any settings listed in the table above. (example [EDR plugin profile](https://github.com/kandji-inc/support/tree/main/Configuration%20Profiles/okta-verify)) ### End User Device Registration with Okta If you are already deploying a manual configuration of ODT (aka Okta device attestation) there should not be any impact to existing devices when switching over to the Iru Endpoint ODT Integration. Once the Iru Endpoint ODT integration is configured and deployed to devices, the Device attestation Library items can be set to inactive or removed. After Okta Verify and the required settings are on the device, the end user will go through the following steps to register their managed Apple devices with Okta. Please review Okta’s [Device registration](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/device-registration.htm) article for additional information. **For previously registered devices with Management status of "Not Managed"** If a device has already registered with Okta through Okta Verify but has not yet been configured for Okta Device Trust (i.e. has a Management status in Okta of "Not managed") via the ODT integration with Iru Endpoint or Okta Device Attestation (manual ODT configuration), the device record will need to be deleted from the Okta Universal directory, and the end user will need to sign out of the Okta Verify app on the device before re-registering the device with Okta using the following the steps below. #### macOS Open the Okta Verify app. (Okta verify should auto launch at login on macOS) Sign in with Okta credentials and set up Touch ID for passwordless authentication. Launch a web browser and sign in to their Okta Dashboard (example: .okta.com), authenticating with Okta FastPass. Open an app in the Okta Dashboard. Done. #### iOS and iPadOS Open the Okta Verify app. Tap **Add Account**. Tap **Organization**. Choose **No, Sign in Instead** as the sign-in method. (the end user can also use the QR code method if available) Tap the screen to tap the **Next** button. (The **Organization's Sign-in URL** should be pre-populated) Sign in to Okta. Choose to allow or skip push notifications on the device. Enable Touch ID or Face ID. Done. Once the above process is complete, the device record should show as managed in the Okta Universal Directory. ### Up Next Set up the [Okta Device Trust integration](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-integration-setup). # Okta Device Trust: Add Device Platforms Source: https://docs.iru.com/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-add-device-platforms Add macOS, iOS, and iPadOS device platforms to your Okta Device Trust integration with Iru Endpoint. Enable platform-specific trust verification policies. This guide applies to Mac computers, iOS devices, and iPadOS devices **Product Name Update**: Throughout this guide, you may notice references to both "Kandji" and "Iru Endpoint." Our product is now called Iru Endpoint, but some integration interfaces may still display the previous name. This is a temporary situation that will be resolved as our integration partners update their systems. ### About Adding Device Platforms to Okta Device Trust Adding device platforms to Okta Device Trust allows you to configure which device types (iOS, iPadOS, macOS) are supported in your Okta Device Trust integration with Iru Endpoint. ### How It Works This article is used in conjunction with the [Okta Device Trust: Integration Setup](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-integration-setup) support article. On Mac, deploy ODT with the **Okta Verify Auto App** Library item. If you still use the App Store app on Mac, see [Migrate from the App Store app to the Auto App (macOS)](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item#migrate-from-the-app-store-app-to-the-auto-app-macos) in Configure Okta Verify for Device Trust. ### Adding device integrations in Okta Log in to the Okta admin portal. In the left-hand navigation, click **Security > Device Integrations**. Click **Add Platform**. ### Add macOS as a Device Integration On the **Select Platform** step, select **Desktop (Windows and macOS only)**, click **Next**. On the **Configure Management Attestation** step, for **Certificate Authority**, select **Use Okta as Certificate Authority**. For **SCEP URL Challenge Type**, select **Dynamic SCEP URL** and **Generic**. Next to **SCEP URL**, click the **Generate** button. Copy the SCEP URL, Challenge URL, Username, and Password to a safe place. This info will be used later in Iru Endpoint when setting up macOS as a device platform. Please copy the **password**, as it will be the only time you can view it. You can rotate the password later in the menu from the main Device integrations page in Okta if needed. Click **Save**. ### Add iOS as a Device Integration On the **Select Platform** step, select **iOS**, click **Next**. On the **Configure Management Attestation** step, copy the **Secret Key** to a safe place for use later in Iru Endpoint when adding iOS as a device platform in Iru Endpoint. Please copy the **Secret key**, as it will be the only time you can view it. You can rotate the password later in the menu from the main Device integrations page in Okta if needed. For **Device Management Provider**, enter something like **Iru Endpoint MDM**. For **Enrollment Portal link**, enter your Iru Endpoint tenant's Enrollment Portal link (e.g. [https://subdomain.iru.io](https://subdomain.iru.io)). Click **Save**. ### Modifying a Device Integration in Okta #### Rotate a macOS Challenge Password or iOS Secret Go to the Device Integrations page. Next to the integration that you want to change, click the **Actions** menu. Click the reset option for that platform. Click the **Reset** button in the modal that appears. #### Delete a macOS Challenge Password or iOS Secret Go to the Device Integrations page. Next to the integration that you want to change, click the **Actions** menu. Click **Delete**. Click the **Delete** button in the modal that appears. # Configure Okta Verify for Device Trust Source: https://docs.iru.com/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item Configure the Okta Verify Library Item in Iru Endpoint for Device Trust and FastPass, and deploy Okta Verify on Mac, iPhone, and iPad devices. This guide applies to Mac computers, iOS devices, and iPadOS devices **Product Name Update**: Throughout this guide, you may notice references to both "Kandji" and "Iru Endpoint." Our product is now called Iru Endpoint, but some integration interfaces may still display the previous name. This is a temporary situation that will be resolved as our integration partners update their systems. ### About Configuring the Okta Verify Library Item Configuring the Okta Verify Library Item in Iru Endpoint allows you to deploy Okta Device Trust (ODT) to your devices, ensuring required settings, configurations, and resources are applied automatically to devices in scope. ### How It Works After configuring the [Okta Device Trust (ODT) Integration](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-integration-setup) in Iru Endpoint, assign an Okta Verify Library Item to deploy ODT to your Apple devices. After you turn on ODT, Iru Endpoint applies the required settings and deploys them to devices in scope. On **macOS**, use the **Okta Verify Auto App** Library Item from **Auto Apps** for ODT. See [Okta deployment options for macOS](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/ov-install-options-macos.htm) for more information from Okta. If one Blueprint includes Macs, iPhones, and iPads, use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) in the **Assignment Map** to assign each Library Item to the right platform. For example, assign the Auto App when **Device family** is **Mac**, and assign the App Store app when **Device family** is **iPhone** or **iPad**. ### Prerequisites * Make **Okta Verify** available in your Iru Endpoint Library via Apps and Books in [Apple Business](https://business.apple.com/) or [Apple School Manager](https://school.apple.com/). * For **iOS** and **iPadOS** ODT, assign the **Okta Verify** App Store app Library Item from **App Store Apps**. * To cover multiple Apple platforms from one Blueprint, configure both Library Items with ODT enabled, then scope each assignment with [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) in the Assignment Map. ### Configuring Okta Verify for ODT In Iru Endpoint, go to the **Library**. Open the correct Okta Verify Library Item: * **macOS:** In **Auto Apps**, open **Okta Verify**. * **iOS and iPadOS:** In **App Store Apps**, open **Okta Verify**. Assign the Library Item to one or more Blueprints. If the Blueprint has only Macs or only iPhones and iPads, assign the matching Library Item on the Assignment Map. If the Blueprint has both, configure both Library Items with ODT enabled, then use [conditional logic](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) in the Assignment Map to assign each app by **Device family**. For a first ODT rollout, use a test Blueprint scoped to a limited number of devices. For the installation type, choose **Install and continuously enforce**. If Okta Verify is already installed on some devices, this process will not reinstall the app, but Iru Endpoint will take over the management of the app. In the **Okta Device Trust** section, turn on the **toggle**. You will see a modal letting you know that Managed AppConfig for iPhone and iPad will be disabled in the Library Item and will be managed by the ODT integration. Click **Yes, turn on Okta Device Trust** to continue. Once turned on, you will see the device families that are configured for ODT and the configured Okta domain. Okta Verify Library Item showing ODT configuration with device families and Okta domain Click **Save**. ### Migrate from the App Store app to the Auto App (macOS) If Mac devices already receive ODT through the **Okta Verify** App Store app, you can move to the **Okta Verify Auto App** without reconfiguring ODT in Iru Endpoint or re-registering devices in Okta. Complete the App Store and Auto App assignment changes in one Assignment Map edit session. Assign the Auto App with ODT enabled before you select **Save**. Do not leave Macs without an ODT-enabled Okta Verify assignment after you save. Open the Blueprint **Assignment Map** where the App Store **Okta Verify** Library Item is assigned, then select **Edit assignments**. Remove the **Okta Verify** App Store app Library Item from the Assignment Map. Add the **Okta Verify** Auto App Library Item to the same Assignment Map. Turn on **Okta Device Trust** on that Library Item if it is not already enabled. Select **Save** to apply the Assignment Map changes. Iru Endpoint removes the App Store app from Macs, but ODT configurations stay on the device. On the next Iru Agent check-in (within about 15 minutes), Iru Endpoint installs the **Okta Verify Auto App** and keeps the ODT integration configuration. ### What Settings Are Deployed to Devices Once ODT is set up, enabled, and scoped to your blueprints, the following settings payloads are automatically configured and delivered to Apple devices in the scope of Okta Device Trust in Iru Endpoint. | Payload setting | Platform | Description | | ---------------------------------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Dynamic SCEP challenge certificate | macOS | This is a unique Okta SCEP certificate per device. The certificate is used in the device registration process and will automatically renew when it expires. | | OktaVerify.EnrollmentOptions | macOS | Okta Verify `SilentEnrollmentEnabled` configuration is sent to macOS devices. This will launch Okta Verify automatically if an unregistered device attempts to access Okta resources and prefill the Organization URL for the user. | | Okta Verify Login item | macOS | This payload adds Okta Verify as a login item on macOS and will start Okta Verify at user login. | | Managed app config | iOS and iPadOS | This App Config contains the `OktaVerify.OrgUrl` and device `managementHint` used to register the device as managed in Okta. | | SSO Extension payload | macOS, iOS, and iPadOS | The SSO extension forwards requests from the browser or app to Okta Verify, and users do not receive the Open Okta Verify browser prompt. Not supported on Chrome or Firefox. | # Okta Device Trust: Integration Setup Source: https://docs.iru.com/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-integration-setup Set up Okta Device Trust integration with Iru Endpoint for passwordless authentication. Configure FastPass, device trust policies, and verification rules. This guide applies to Mac computers, iOS devices, and iPadOS devices **Product Name Update**: Throughout this guide, you may notice references to both "Kandji" and "Iru Endpoint." Our product is now called Iru Endpoint, but some integration interfaces may still display the previous name. This is a temporary situation that will be resolved as our integration partners update their systems. ### About Okta Device Trust Integration Setup Okta Device Trust Integration Setup in Iru Endpoint lets you ensure that Iru Endpoint manages your devices before end users can access Okta-protected apps, enabling passwordless authentication and FastPass functionality. ### How It Works Okta Device Trust lets you ensure that Iru Endpoint manages your Apple devices before end users can access Okta-protected apps from their devices. This integration enables Okta FastPass for a passwordless authentication experience, allowing users to sign in to Okta and their Okta resources without needing a password. For iOS, iPadOS, and macOS devices specifically, FastPass lets users sign in with Face ID and Touch ID. Okta FastPass is a feature of Okta Identity Engine. ### Before You Begin Configure the following in your Okta tenant before you start integration setup in Iru Endpoint. * The Okta tenant must be migrated from Okta Classic Engine to [Okta Identity Engine](https://help.okta.com/oie/en-us/content/topics/identity-engine/oie-index.htm). * [Okta FastPass](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm) must be enabled in the Okta tenant. * The Okta user setting up ODT should have the [super admin](https://help.okta.com/oie/en-us/content/topics/security/administrators-super-admin.htm) role in Okta. Super admin credentials are only needed for initial authentication and adding the API Service Integration. * [Okta Adaptive MFA](https://www.okta.com/products/adaptive-multi-factor-authentication/) is required to add Device integrations in Okta. ### Prerequisites Iru Endpoint checks for the following during integration setup and shows a warning if any are missing. * Make **Okta Verify** available in your Library via [Apps and Books in Apple Business or Apple School Manager](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint). * On **macOS**, assign the **Okta Verify Auto App** from **Auto Apps**. ### Integration Setup Log in to your Iru Endpoint tenant. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover Integrations**. In the Security section, find **Okta Device Trust**. Click **Add and configure**. In the **Welcome to Okta Device Trust** modal, click **Get Started**. In the **Specify your Okta Domain** modal, enter your Okta tenant URL and click **Next**. In the **Sign in with Okta** modal, click **Sign in with Okta**. This will open a new browser window and navigate you to your Okta tenant, where you will create an **API Service Integration**. Once that is done, you will return to Iru Endpoint to continue the ODT integration setup. The Okta user used to configure ODT must have the [super admin](https://help.okta.com/oie/en-us/content/topics/security/administrators-super-admin.htm) role in Okta. Once signed into Okta, you should be on the **Authorize Kandji Device Trust** integration page. On this page, click **Install & Authorize**. The Kandji API Service integration uses the following scopes: * okta.devices.manage * okta.devices.read * okta.authenticators.read On the **Copy your client secret** modal, copy the client secret to a safe place for use later in Iru Endpoint. This is the only time you will be able to view it. Click **Done**. On the **Kandji Device Trust** overview page, copy the **Client ID** to a safe place for use later in Iru Endpoint. Head back to Iru Endpoint to continue the ODT integration setup. In the **Complete the following tasks in Okta** modal, click **Next**. In the **API Service Integration Credentials** modal, enter the Client ID and Client Secret copied from earlier. Click **Connect to Okta**. Iru Endpoint will check in the background to ensure the Okta tenant is on Okta Identity Engine and Okta FastPass is enabled. ### Configuring Device Platforms in Okta This section outlines creating device integration in Okta. This information is used when adding device platforms in Iru Endpoint. Okta [Adaptive MFA](https://www.okta.com/products/adaptive-multi-factor-authentication/) is required to add Device integrations in Okta. #### Adding Device Integrations in Okta Log in to the Okta admin portal. In the left-hand navigation, click **Security > Device Integrations**. Click **Add platform**. #### Adding macOS as a Device Integration On the **Select platform** step, select **Desktop (Windows and macOS only)**. Click **Next**. On the **Configure management attestation** step, select **Use Okta as certificate authority**. For **SCEP URL challenge type**, select **Dynamic SCEP URL** and **Generic**. Next to **SCEP URL**, click **Generate**. Copy the SCEP URL, Challenge URL, Username, and Password to a safe place. Later, in Iru Endpoint, this information will be used to set up MacOS as a device platform. This will be the only time you can view the password. If needed, you can rotate it later in the menu from the main Device integrations page in Okta. Click **Save**. #### Adding iOS as a Device Integration On the **Select platform** step, select **iOS**. Click **Next**. On the **Configure management attestation** step, copy the **Secret key** to a safe place for use later in Iru Endpoint when adding iOS as a device platform in Iru Endpoint. This will be the only time you can view the secret key. If needed, you can rotate the key later in the menu from the main Device integrations page in Okta. For **Device management provider**, enter a descriptive, user-friendly value. For **Enrollment Portal link**, enter your Iru Endpoint tenant's Enrollment Portal link. (Example: `https://accuhive.iru.com/enroll` where `accuhive` should be your tenant subdomain.) Click **Save**. ### Modifying a Device Integration in Okta #### Rotating a macOS Challenge Password or iOS Secret Go to the Device Integrations page. Next to the integration that you want to change, click the **Actions** menu. Click the reset option for that platform. Click the **Reset** button in the modal that appears. #### Deleting a macOS Challenge Password or iOS Secret Go to the Device Integrations page. Next to the integration that you want to change, click the **Actions** menu. Click **Delete**. Click the **Delete** button in the modal that appears. ### Configuring Device Platforms in Iru Endpoint In the **Configure device platforms** modal, select the platforms to configure. You can configure macOS, iOS, or both. Click **Next**. If selecting macOS, enter the required information in the **Add macOS as a device platform** modal and click **Next**. If selecting iOS, enter the required information in the **Add iOS as a device platform** modal and click **Finish setup**. In the **Okta Device Trust setup complete** modal, you can choose **View integration settings** to see additional information about the ODT integration in Iru Endpoint or choose **Go to Library item** to configure Okta Verify for ODT deployment. On Mac, use the **Okta Verify Auto App**. ### Next Steps Deploy ODT to your Apple devices using the [Okta Device Trust: Configuring the Okta Verify Library item](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust-configuring-the-okta-verify-library-item) support article. # Authorize Your Iru Tenant for Okta Workflows Source: https://docs.iru.com/en/endpoint/integrations/okta-workflows/authorize-your-iru-tenant-for-okta-workflows Authorize your Iru Endpoint tenant for Okta Workflows integration. Generate API tokens, configure the connector, and enable automated device workflows. This guide applies to Mac computers and Windows devices In Okta Workflows, the connector is still listed as **Kandji**. The steps in this guide that create an API token and copy your domain are performed in **Iru Endpoint**. When you configure the connection in Okta Workflows, select **Kandji** and enter your Iru Endpoint API token and domain. ### About Authorizing Your Iru Tenant for Okta Workflows Authorizing your Iru Endpoint tenant for Okta Workflows lets Okta Workflows connect to your tenant through the **Kandji** connector, so you can automate device management tasks in your workflows. ### How It Works The **Kandji** connector in Okta Workflows connects to your Iru Endpoint tenant using an API token and domain. After you configure the connection, you can build workflows that respond to user lifecycle events and device management tasks without manual steps in Iru Endpoint. ### Prerequisites Before you begin, ensure you have: * Okta Workflows admin credentials * Iru Endpoint administrator access * API access enabled in your Iru Endpoint tenant After successfully authorizing your Iru Endpoint tenant for Okta Workflows, you can [use Kandji connector action cards in Okta Workflows](/en/endpoint/integrations/okta-workflows/use-kandji-connector-action-cards-with-okta-workflows). ### Authorizing Your Iru Tenant Authorization has two parts: create an API token and copy your domain in **Iru Endpoint**, then configure the **Kandji** connector in **Okta Workflows** with those values. When you add a **Kandji** card to a workflow for the first time, Okta Workflows prompts you to configure the connection. You can save the connection and reuse it for future workflows. You can create and manage multiple connections from your **Connections** page. #### Creating an API Token in Iru Endpoint Complete these steps in the **Iru Endpoint** web app. To create an API token for the Kandji connector in Okta Workflows: Sign in to the Iru Endpoint web app with administrator credentials. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. Screenshot of the account menu with Access option highlighted On the **API tokens** tab, click **Add Token**. In the **Name** field, enter a name such as Okta Workflows. In the Description field, enter a description such as *Allow Okta Workflows to use the Iru Endpoint API*. Click **Create**. In the **Copy your API token** dialog, click **Copy Token**. Store the copied token in a safe place. If you lose the text for the token, you can delete it before you use it and create a new one with the steps above. You'll use this token in step 4 of the next section. Select the checkbox for **I have copied the token and understand that I will not be able to see these details again.** Click Next. In the **Manage API Permissions** dialog, click **Configure**. In the Permissions section, select the checkbox for each area to which you want Okta Workflows to have access. For example, select the checkbox for **Blueprints Management** to enable all permissions for inspecting and modifying Blueprints. Note: You can click the disclosure triangle to the right of the permission type to display more specific permissions. Review the permissions you've configured for the API token. Click **Save** then **Close**. On the **API tokens** tab, confirm that your new token is displayed. In **Your organization's API URL is** field, copy or make a note of your Iru Endpoint domain. Iru Endpoint API URL field showing the organization's API URL that needs to be copied for the Okta Workflows connection #### Setting Up the Kandji Connector in Okta Workflows Complete these steps in **Okta Workflows**. You need the API token and domain from the previous section. You can create more than one connection. For example, you might have multiple Iru Endpoint tenants or be testing multiple API tokens. The API token must include at least **Devices: Device Information: Device list** permission. Grant additional permissions based on the workflow actions you plan to use. For example, to list all devices, the token needs: | Permission | Description | | ----------------------------------------------- | ---------------------------------------------------- | | **Devices: Device Information: Device list** | Get a list of all devices in the Iru Endpoint tenant | | **Devices: Device Information: Device details** | Get the full details for a specific device | In Okta Workflows, from the Connections page or any card, click **New Connection**. Okta Workflows Connections page showing the New Connection button that needs to be clicked to create a new connection In the New Connection window, scroll if necessary, then select **Kandji**. This is the connector name in Okta Workflows; it connects to your Iru Endpoint tenant. Okta Workflows New Connection window showing the list of available connectors with Kandji highlighted for selection In the **Connection Nickname** field, enter a unique name that will help you distinguish multiple Iru Endpoint tenants or multiple Iru Endpoint API keys. In the **API key** field, enter or paste the text of the API token you generated in step 7 of the previous section. In the **Kandji domain** field, enter your full Iru Endpoint domain from step 16 of the previous section. Okta Workflows labels this field **Kandji domain**, but the value is your Iru Endpoint API URL (for example, *accuhive.api.kandji.io* or *accuhive.api.eu.kandji.io*). Click **Create**. Okta Workflows connection configuration form showing the Connection Nickname, API key, and Iru Endpoint domain fields filled out with the Create button ready to be clicked The **Kandji** connector is now configured and connected to your Iru Endpoint tenant. You can use it with the available connector cards. #### Using the Connection in Workflows In Workflows go to the Flows section and click **+New Flow**. Click **Add app action**. In the **My Connected Apps** section, click **Kandji**. Okta Workflows still displays this app name; it provides access to your Iru Endpoint tenant. Okta Workflows My Connected Apps section showing Iru Endpoint as an available connected app that can be selected for workflow actions Select a connector card. Configure the card and continue building your workflow. Okta Workflows connector card selection interface showing available Iru Endpoint action cards that can be selected for the workflow # Use Kandji Connector Action Cards with Okta Workflows Source: https://docs.iru.com/en/endpoint/integrations/okta-workflows/use-kandji-connector-action-cards-with-okta-workflows Use the Iru Endpoint connector action cards in Okta Workflows. Automate device management tasks like lookups, tagging, and Blueprint assignment changes. This guide applies to Mac computers and Windows devices ### Iru Endpoint Connector with Okta Workflows Iru Endpoint Connector with Okta Workflows allows you to integrate Iru Endpoint device management with Okta Workflows to automate critical components of the user lifecycle and reduce manual errors. ### How It Works You can use the Iru Endpoint connector to integrate Iru Endpoint device management with Okta Workflows to help automate critical components of the user lifecycle that are prone to friction or manual error. The first step is to [Authorize your Iru tenant for Okta Workflows](/en/endpoint/integrations/okta-workflows/authorize-your-iru-tenant-for-okta-workflows). After you set up an Iru Endpoint connection, you can use the following Iru Endpoint connector action cards in a Workflow. For more information about available connector cards, visit the [Okta Workflows ReadMe](https://github.com/kandji-inc/support/tree/main/Okta%20Workflows) in our support GitHub Repo. | **Action** | **Description** | | ----------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [Assign Library Item](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#assign-library-item) | Given a Library Item ID and a Blueprint ID, assign the Library Item to the Blueprint. To assign a Library Item to an Assignment Map, you must also provide the Assignment Map ID. | | [Clear Passcode](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#clear-passcode) | Clear the iOS or iPadOS device passcode. | | [Create Blueprint](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#create-blueprint) | Create a Blueprint. | | [Create Note](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#create-note) | Create a note in Iru Endpoint for the device. | | [Create Tag](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#create-tag) | Create a Tag. | | [Custom API Action](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#custom-api-action) | Make an authenticated HTTP request to the Iru Endpoint API. | | [Erase Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#erase-device) | Send [Erase Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#erase-device) MDM command. | | [Get (Mac) Recovery Lock Password](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-mac-recovery-lock-password) | Given a Device ID, This request returns the Recovery Lock password for a Mac with Apple Silicon, or the legacy EFI firmware password for an Intel-based Mac. | | [Get (Mac) Unlock PIN](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-mac-unlock-pin) | Get the unlock PIN for a locked Mac. | | [Get Activation Lock Bypass Codes](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-activation-lock-bypass-codes) | Get the Activation Lock Bypass Code for a Mac. | | [Get Blueprint](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-blueprint) | Get a Blueprint by Blueprint ID or by name. | | [Get FileVault Recovery Key](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-filevault-recovery-key) | Get the FileVault Recovery Key for a Mac. | | [Get ADE Integration](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-ade-integration) | Given an Automated Device Enrollment (ADE) integration token, return information about the integration. | | [Get Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-device) | Given a Device ID, get high-level details about the device. | | [Get Threats Summary](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#get-threats-summary) | Return top-level information about the number of threats detected. Return status\_code of 404 if EDR is not turned on for the tenant. Return status\_code of 401 if the API key does not have permission to read threats. | | [List Blueprints](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-blueprints) | List all Blueprints in the Iru Endpoint tenant. | | [List ADE Devices in ADE Integration](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-ade-devices-in-ade-integration) | Given an Automated Device Enrollment (ADE) integration token, return a list of all devices associated with that token, as well as their enrollment status. When the mdm\_device key value is null, this indicates that the device is awaiting enrollment. | | [List ADE Integrations](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-ade-integrations) | Return a list of configured Automated Device Enrollment (ADE) integrations. | | [List Custom Apps](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-custom-apps) | Return a list of all Custom App Library Items. | | [List Device Activity](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-device-activity) | Given a Device ID, list Activity for the device. | | [List Device Apps](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-device-apps) | Given a Device ID, return a list of all apps installed on the device. | | [List Device Library Items](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-device-library-items) | Given a Device ID, return a list of all the Library Items for the device and their statuses. | | [List Device Notes](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-device-notes) | Given a Device ID, return a list of all the notes in Iru Endpoint for the device. | | [List Devices](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-devices) | Return a list of all enrolled devices. Optional query parameters can be used to filter the results. | | [List Library Item Activity](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-library-item-activity) | Given a Library Item ID, get a list of Activity for the Library Item. | | [List Library Item Statuses](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-library-item-statuses) | Given a Library Item ID, get the Statuses for the Library Item. | | [List Library Items](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-library-items) | Given a Blueprint ID, return a list of the Library Items for the Blueprint. | | [List Tags](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-tags) | List all tags. | | [List Users](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#list-users) | Return a list of all users from directory integrations. | | [Lock Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#lock-device) | Send [Lock Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#lock-device) MDM command. | | [Manage Apple Remote Desktop](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#manage-apple-remote-desktop) | Use MDM to turn Apple Remote Desktop for a Mac on or off. | | [Play Lost Mode Sound](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#play-lost-mode-sound) | Send the MDM command to an iOS or iPadOS device in Lost Mode to play the Lost Mode sound. | | [Reinstall Iru Agent](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#reinstall-kandji-agent) | Use MDM to reinstall the Iru Agent on a Mac. | | [Remove Library Item](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#remove-library-item) | Given a Library Item ID and a Blueprint ID, unassign the Library Item from the Blueprint. To remove a Library Item from an Assignment Map, you must also provide the Assignment Map ID. | | [Restart Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#restart-device) | Send Restart MDM command. | | [Send MDM Blank Push](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#send-mdm-blank-push) | Send Blank Push MDM command. | | [Set Device Name](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#set-device-name) | Send an MDM command to set the device name. | | [Shutdown Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#shutdown-device) | Send Shutdown MDM command. | | [Turn Off Lost Mode](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#turn-off-lost-mode) | Turn off Managed Lost Mode for an iOS or iPadOS device. | | [Turn On Lost Mode](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#turn-on-lost-mode) | Turn on Managed Lost Mode for a Supervised iOS or iPadOS device. | | [Unlock (Local) User Account](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#unlock-local-user-account) | Send Unlock Account MDM command. | | [Update Lost Mode Location](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#update-lost-mode-location) | Send the MDM command to an iOS or iPadOS device in Lost Mode to update the location data. | | [Update Device](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#update-device) | Given a device, update its assigned Blueprint, user, or asset tag. | | [Update Inventory](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#update-inventory) | Send [Update Inventory](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#update-inventory) MDM command. | | [Update Tag](https://github.com/kandji-inc/support/blob/main/Okta%20Workflows/ReadMe.md#update-tag) | Given a Tag ID, update the name of the tag. | # Integrating Third-Party Apps Using the Iru Endpoint API Source: https://docs.iru.com/en/endpoint/integrations/overview/integrating-third-party-apps-using-the-iru-endpoint-api Integrate third-party applications with Iru Endpoint using the REST API. Build custom automations, sync device data, and extend management capabilities. ### Third-Party App Integrations Third-party app integrations in Iru Endpoint let you connect external applications and services with Iru Endpoint using the API. This helps you automate workflows and manage devices across your infrastructure. ### How It Works External applications connect to Iru Endpoint through the REST API using authentication tokens. The integrations let external systems pull device information, manage configurations, and automate workflows based on device status and compliance data. Here's how the integration process works: * Create an API token in Iru Endpoint with the right permissions * Configure the third-party application with your Iru Endpoint API credentials * Set up automated workflows or data sync between systems To set up third-party integrations, you need access to the Iru Endpoint API. If you don't already have access, please contact your Customer Success Manager to enable API access for your tenant. ### Using this Guide Third-party applications use API tokens created in Iru Endpoint to make requests. First, follow the steps in our [Iru Endpoint API support article](/en/endpoint/api/iru-api-overview) to generate an API token, then use the API permissions outlined below to set up your integration. ### Available Third-Party App Integrations | Third-Party App | Required API Permissions | Resources | | ---------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------ | | **[AssetPanda](https://www.assetpanda.com/)** | Please see vendor documentation for details | [AssetPanda Vendor Documentation](https://help.assetpanda.com/Kandji.html#permissions) | | **[Drata](https://www.drata.com/)** | • Device details
• Device list
• Application list
• Device Library Items | [Drata Vendor Documentation](https://help.drata.com/en/articles/5831405-kandji-connection) | | **[Diamond Assets](https://www.diamondassets.com/)** | • Blueprints Management
• List Blueprints
• Device Details
• Device Information
• Device List
• Application List | | | **[Foqal](https://www.foqal.io/)** | • Device list
• Send a blank push
• Lock device
• Restart device
• Set a device name
• Shutdown device
• Account unlock
• Install Iru Agent | [Foqal Vendor Documentation](https://www.foqal.io/integrations/kandji) | | **[Oomnitza](https://www.oomnitza.com/)** | Please see vendor documentation for details | [Oomnitza Vendor Documentation](https://oomnitza.zendesk.com/hc/en-us/articles/6670453867927-Adding-your-Kandji-details-in-Oomnitza) | | **[PacketFence](https://www.packetfence.org/)** | • Device information
• Device ID
• Device list | [PacketFence Vendor Documentation](https://www.packetfence.org/doc/PacketFence_Installation_Guide.html#_kandji) | | **[Reftab](https://www.reftab.com/)** | • Device details
• Device list | [Reftab Vendor Documentation](https://www.reftab.com/blog/faq/how-to-setup-kandji-integration-with-reftab/) | | **[Secureframe](https://www.secureframe.com/)** | • Device details
• Device list
• Device ID
• Application List
• Device Library Items | [Secureframe Vendor Documentation](https://app.secureframe.com/login) | | **[Snipe-IT](https://snipeitapp.com/)** | • Update a device
• Device details
• Device list
• Device ID
• Device Activity | [Snipe-IT Vendor Documentation](https://github.com/grokability/kandji2snipe/) | | **[Tugboat Logic](https://www.tugboatlogic.com/)** | • List Blueprints
• Device details
• Device list
• Application list | | | **[Vanta](https://www.vanta.com/)** | • Device details
• Device list
• Device ID
• Application list
• Device Library Items | [Vanta Vendor Documentation](https://help.vanta.com/hc/en-us/articles/360062532551-Integrating-Vanta-Kandji) | ### Next Steps Once you've copied your API URL and configured the Iru Endpoint API token, go back to your third-party application and paste them into the corresponding fields. # SCIM Directory Integration Source: https://docs.iru.com/en/endpoint/integrations/scim/scim-directory-integration Set up SCIM-based user directory synchronization in Iru Endpoint. Automatically provision and deprovision users and groups from your identity provider. ### About SCIM Directory Integration SCIM, or the [System for Cross-domain Identity Management](https://scim.cloud/), is a protocol designed to make managing user identities across different systems simpler and more efficient. It's particularly useful when you're using multiple cloud-based applications, as it helps automate the process of adding and removing users. ### How It Works SCIM involves two main roles: * **Client** - This is usually an identity provider or identity access management system, like Microsoft Entra ID or Okta, that manages core identity data. * **Service Provider** - A software-as-a-service (SaaS) application, like Iru Endpoint, that uses identity data to manage user access and permissions. SCIM supports several operations, including provisioning, synchronization, and deprovisioning. This one-way sync allows you to automatically create user accounts in Iru Endpoint, keep user attributes up-to-date between your MDM and IdP, and automatically remove or disable user accounts when they are no longer needed. ### Configuring SCIM in Iru Endpoint To configure a SCIM integration between your Identity Provider (IdP) and Iru Endpoint, you will need to: * Create a new SCIM Directory Integration in Iru Endpoint * Obtain the SCIM API URL and API token from Iru Endpoint to use with your IdP. * Access your IdP to create an app integration, map SCIM attributes, and push desired user groups. #### Creating a New SCIM Directory Integration In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. On the **SCIM protocol** tile, click **Add and configure**. Add new integration page with SCIM protocol tile and Add and configure button Click **Get started**. Enter a unique name for the SCIM integration. Click **Generate token**. The SCIM user directory integration uses an HTTP authorization header with a Bearer Token as the authentication method. Configure a SCIM user integration screen with name field and Generate token button Click **Copy token**. The token will not be visible again after you click Done. Store it securely before continuing. Confirm that you have copied the token by checking the box, then click **Done**. You will return to the **Integrations** page. Copy token and configure with your identity provider dialog with Copy token button #### Obtaining the SCIM API URL Your SCIM API URL is available from the integration details in Iru Endpoint. You will need to provide this URL to your identity provider when configuring the SCIM connection. Click the **ellipsis** on the SCIM directory integration you just created. Select **View Details**. Directory integrations list with SCIM integration and ellipsis menu showing View details, Rename, Rotate token, Delete **Copy** the SCIM API URL (e.g. `https://subdomain.api.iru.com/api/v1/scim`). Your identity provider will require this. The URL displayed in your tenant may still show the `api.kandji.io` domain. The `api.kandji.io` version of the SCIM API URL will also work for this purpose. Click **Close**. View user integration details modal with SCIM API URL and copy button ### Renaming a SCIM Integration To change the name of an existing SCIM directory integration: Click the **ellipsis** on the SCIM directory integration you want to rename. Select **Rename**. SCIM integration ellipsis menu with Rename option Enter the new name for the integration and save. Rename SCIM integration prompt or dialog with name field ### Rotating the SCIM Token Rotate the SCIM API token when you need to invalidate the current token (for example, after a security concern or when reconfigured in your IdP). After rotating, update the new token in your identity provider. Click the **ellipsis** on the SCIM directory integration. Select **Rotate token**. SCIM integration ellipsis menu with Rotate token option Confirm the rotation in the prompt. The previous token will no longer work. Rotate token confirmation prompt for SCIM integration Copy the new token and update it in your IdP. Copy the new SCIM token after rotation ### Deleting a SCIM Integration Removing a SCIM directory integration stops synchronization from your IdP and removes the integration from Iru Endpoint. Update or remove the SCIM app in your IdP to avoid errors. Click the **ellipsis** on the SCIM directory integration you want to remove. Select **Delete integration**. SCIM integration ellipsis menu with Delete integration option Confirm that you want to delete the integration in the prompt. Delete SCIM integration confirmation prompt ### SCIM Schema and Supported Attributes Iru Endpoint supports the following SCIM attributes. Refer to these attributes when mapping your SCIM application in your IdP. Iru Endpoint does not use any attributes that are not in the list below. To limit the attributes sent, please modify the attributes configured in the SCIM app in your IdP. **User attributes** | **Attribute** | **Description** | **Required** | | -------------- | --------------------------------------------------------------------------------------------------------------- | ------------ | | userName | Unique identifier for the user, used to authenticate to the service provider | Yes | | name.formatted | The user's full name (for example, "John Doe"). This attribute or the displayName attribute is required | No | | displayName | The user's full name (for example, "John Doe"). This attribute or the name.formatted attribute is required | Yes | | title | The user's title, such as "Vice President." | No | | active | The user's status within the identity provider. This attribute is automatically added by the Identity Provider. | Yes | | emails.value | The user's email address as a subattribute of emails. Iru Endpoint only stores the first email in the list. | Yes | | department | Identifies the name of a department. | No | **Group attributes** | **Attribute** | **Description** | **Required** | | ------------- | ------------------------------------ | ------------ | | displayName | A human-readable name for the Group. | Yes | | members | A list of members in the Group. | Yes | When using SCIM to sync users from a directory, the SCIM app automatically sends new information to Iru Endpoint, so there is no need for a Sync Now button that you would see when using the native Entra ID or Google Workspace directory integrations. Each cloud IdP has its own standard for syncing SCIM data. Please check with your identity provider's documentation to understand how SCIM sync is configured. ### Related Articles Configure SCIM in your identity provider using the article for your IdP. Iru Endpoint's SCIM implementation follows the SCIMv2 specification. Connect Okta to Iru Endpoint for automatic user and group provisioning via SCIM Connect Microsoft Entra ID (Azure AD) to Iru Endpoint for SCIM-based user and group provisioning Connect OneLogin to Iru Endpoint for automatic user and group provisioning via SCIM # SCIM Directory Integration with Microsoft Entra ID Source: https://docs.iru.com/en/endpoint/integrations/scim/scim-directory-integration-with-microsoft-entra-id Configure SCIM directory integration between Microsoft Entra ID and Iru Endpoint. Automatically provision and deprovision users and groups via SCIM. ### About SCIM Directory Integration with Microsoft Entra ID SCIM Directory Integration with Microsoft Entra ID in Iru Endpoint allows you to set up SCIM-based user directory synchronization between Microsoft Entra ID and Iru Endpoint, enabling automatic user and group provisioning and deprovisioning. ### How It Works The SCIM integration creates a secure connection between Microsoft Entra ID and Iru Endpoint, enabling automatic synchronization of user and group data. When users or groups are added, modified, or removed in Microsoft Entra ID, these changes are automatically reflected in Iru Endpoint through the SCIM protocol. ### Prerequisites * Be sure to review the supported user and group attributes listed in the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration#scim-schema-and-supported-attributes) article. * Ensure that nested groups are not included with SCIM as Microsoft does not support this functionality. ### Get the SCIM Token and API URL Complete these steps in Iru Endpoint first. You will need the SCIM access token and API URL when configuring Microsoft Entra ID. For full details, see the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) article. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. On the **SCIM protocol** tile, click **Add and configure**. Add new integration page with SCIM protocol tile and Add and configure button Click **Get started**. Enter a unique name for the SCIM integration. Click **Generate token**. The SCIM integration uses an HTTP authorization header with a Bearer Token. Configure a SCIM user integration screen with name field and Generate token button Click **Copy token**. The token will not be visible again after you click Done. Store it securely, as you will need it in the **Microsoft Entra ID** tab. Confirm that you have copied the token by checking the box, then click **Done**. You will return to the **Integrations** page. Copy token and configure with your identity provider dialog with Copy token button Click the **ellipsis** on the SCIM directory integration you created. Select **View Details**. Directory integrations list with SCIM integration and ellipsis menu showing View details, Rename, Rotate token, Delete Copy the SCIM API URL (e.g. `https://subdomain.api.iru.com/api/v1/scim`). Your identity provider will require this. The URL displayed in your tenant may still show the `api.kandji.io` domain. The `api.kandji.io` version of the SCIM API URL will also work for this purpose. Click **Close**. View user integration details modal with SCIM API URL and copy button Keep the token and API URL available, then switch to the **Microsoft Entra ID** tab to create and configure the SCIM app integration. Complete the **Iru Endpoint** tab first to obtain the SCIM token and API URL. You will enter these in the steps below. ### Creating the SCIM Integration in Microsoft Entra ID Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). Open the portal menu and then select **Entra ID**. On the **Entra ID** menu, select **Enterprise apps**. Select **New application**. If you have already created a SAML single sign-on application, you can select that application and add SCIM. Microsoft Entra ID Enterprise applications All applications with New application button Select **Create your own application**. Microsoft Entra ID Browse gallery with Create your own application Give the application a name. Select **Integrate any other application you don't find in the gallery (Non-gallery)**. Click **Create**. Microsoft Entra ID Create your own application dialog with app name and Non-gallery option You will be taken to the Overview page for the newly created app. Under **Manage**, select **Provisioning**. Microsoft Entra ID Iru SCIM Overview with Provisioning in Manage Click **New Configuration**. Microsoft Entra ID Provisioning Get started with New configuration button In the **Select authentication method** dropdown, choose **Bearer authentication**. Microsoft Entra ID New provisioning configuration with Bearer authentication, Tenant URL, and Secret token Paste the SCIM API URL you copied from the **Iru Endpoint** tab into the **Tenant URL** field. Paste the token you obtained in the **Iru Endpoint** tab into the **Secret token** field. Click **Test connection**. You should see a successful test notification. Microsoft Entra ID Provisioning test connection success message Click **Create**. In the Manage section, click **Provisioning**. Microsoft Entra ID Provisioning configuration Overview Expand the **Mappings** reveal triangle and ensure that both Groups and Users are enabled. Expand the **Settings** reveal triangle. For **Scope**, choose **Sync only assigned users and groups**. Set the **Provisioning Status** to On. Click **Save**. Microsoft Entra ID Provisioning Mappings and Settings with Scope and Provisioning Status Click the **X** in the upper-right corner to close the settings. ### Assigning Users and Groups Under **Manage**, select **Users and groups**. On the menu, select **Add user/group**. On the **Add Assignment** dialog, select the link under **Users and groups**. A list of users and security groups is displayed. You can search for a specific user or group or select multiple users and groups that appear in the list. Select the user(s) and group(s) you would like to be assigned. Click **Select**. Select **Assign** to finish assigning users and groups to the app. Confirm that the users and groups you added appear in the **Users and groups** list. If you see a message indicating that a free tier is being used, it means you can only add users (not groups) to the SCIM Enterprise App. ### Considerations #### Syncing User syncing is one-way, meaning the Microsoft Entra ID SCIM app will send user information to Iru Endpoint only when new information is needed. If a user or group is added to the SCIM app in Microsoft Entra ID after the app was created, a sync will happen every 40 minutes (set by Microsoft Entra ID). If you want the sync to happen sooner, you can stop/start the provisioning in the SCIM app on the Microsoft Entra ID. This will not impact existing users/groups in Iru Endpoint. #### Removing Users * If Entra ID sets a user to inactive, the user will be set as inactive in your Iru Endpoint tenant. * If Entra ID deletes a user, the user will be deleted from your Iru Endpoint tenant. #### Blueprint Conditional Logic If you use [Assignment Map](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) conditional logic with groups, you must explicitly add each group you want to have provisioned in Iru Endpoint to the SCIM app. Groups will not sync automatically by adding users that happen to be members of the group. #### AD CS Strong Certificate Mapping If you use Microsoft Active Directory Certificate Services for certificate-based authentication, ensure your SCIM attribute mappings support strong certificate mapping requirements. For required mapping and certificate updates, see [Active Directory Strong Certificate Mapping Configuration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-strong-mapping-configuration). #### Microsoft Device Compliance If you are using an Entra ID SCIM user directory integration and the Microsoft Device Compliance integration, ensure that the user and group attribute mappings for the **externalId** attribute in your SCIM application map to objectId as listed below. The **objectId** is used by Iru Endpoint to map user and group resources in Intune.
User Attribute User Value
externalId objectId
Group Attribute Group Value
externalId objectId
**Updating User Mappings and Group Mappings** Navigate to the SCIM enterprise application in the [Microsoft Entra admin center](https://entra.microsoft.com). Select **Provisioning**. Select the **Attribute mapping (Preview)** section. If you are updating user attributes, click on **Provision Microsoft Entra ID Users.** If you are updating group attributes, click on **Provision Microsoft Entra ID Groups**. Verify that externalId is mapped to objectId. If it is not, click the **Edit** button to the right of the attribute and select objectId from the list. Click **Save**. Click the **X** to go back. Once back on the Provisioning overview page, if any values were changed, you need to push the updated values to Iru Endpoint immediately by stopping and then starting the provisioning service. Click the **Pause provisioning** button. Click the **Start provisioning** button.
# SCIM Directory Integration with Okta Source: https://docs.iru.com/en/endpoint/integrations/scim/scim-directory-integration-with-okta Configure SCIM directory integration between Okta and Iru Endpoint. Automatically provision and deprovision users and groups via the SCIM protocol. ### About SCIM Directory Integration with Okta SCIM Directory Integration with Okta in Iru Endpoint allows you to set up SCIM-based user directory synchronization between Okta and Iru Endpoint, enabling automatic user and group provisioning and deprovisioning. ### How It Works The SCIM integration creates a secure connection between Okta and Iru Endpoint, enabling automatic synchronization of user and group data. When users or groups are added, modified, or removed in Okta, these changes are automatically reflected in Iru Endpoint through the SCIM protocol. ### Prerequisites * Ensure you’re using Okta’s **Advanced Lifecycle Management** plan, which supports built-in, standards-based provisioning for SCIM. * Be sure to review the supported user and group attributes listed in the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration#scim-schema-and-supported-attributes) article. ### Get the SCIM Token and API URL Complete these steps in Iru Endpoint first. You will need the SCIM access token and API URL when configuring Okta. For full details, see the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) article. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. On the **SCIM protocol** tile, click **Add and configure**. Add new integration page with SCIM protocol tile and Add and configure button Click **Get started**. Enter a unique name for the SCIM integration. Click **Generate token**. The SCIM integration uses an HTTP authorization header with a Bearer Token. Configure a SCIM user integration screen with name field and Generate token button Click **Copy token**. The token will not be visible again after you click Done. Store it securely, as you will need it in the **Okta** tab. Confirm that you have copied the token by checking the box, then click **Done**. You will return to the **Integrations** page. Copy token and configure with your identity provider dialog with Copy token button Click the **ellipsis** on the SCIM directory integration you created. Select **View Details**. Directory integrations list with SCIM integration and ellipsis menu showing View details, Rename, Rotate token, Delete Copy the SCIM API URL (e.g. `https://subdomain.api.iru.com/api/v1/scim`). Your identity provider will require this. The URL displayed in your tenant may still show the `api.kandji.io` domain. The `api.kandji.io` version of the SCIM API URL will also work for this purpose. Click **Close**. View user integration details modal with SCIM API URL and copy button Keep the token and API URL available, then switch to the **Okta** tab to create and configure the SCIM app integration. Complete the **Iru Endpoint** tab first to obtain the SCIM token and API URL. You will enter these in the steps below. ## Creating the SCIM Integration in Okta The Iru Endpoint application available in the Okta Integration Network (OIN) cannot be provisioned for SCIM. A new Application Integration must be created for SCIM. This new app integration will not interfere with any existing Okta SSO integration that uses the OIN Iru Endpoint application. Log in to your Okta admin console at login.okta.com. Once logged in, in the left-hand navigation, expand the **Applications** section and choose **Applications**. Click **Create App Integration**. Okta Applications page with Create App Integration button Select **SAML 2.0** as the application type and click **Next**. Create a new app integration dialog with SAML 2.0 selected In **General Settings**, give the app a **name** and check the box in the **App visibility** section. Then click **Next**. Create SAML Integration General Settings with app name and App visibility In **SAML Settings**, enter a placeholder URL in the **Single sign-on URL** and **Audience URI (SP Entity ID)** fields. Do not change any other settings. Create SAML Integration Configure SAML step with Single sign-on URL and Audience URI Click **Next**. In **Help Okta Support understand how you configured this application**, select the checkbox for **This is an internal app that we have created**, and click **Finish**. Create SAML Integration Feedback step with This is an internal app that we have created and Finish Since we will not be using this application integration for SSO, the URLs do not need to be valid; however, you must enter URLs in these fields to proceed. If you decide to enable SAML SSO in Iru Endpoint, you can use this same app to do so. ## Configuring SCIM Settings In the Okta SCIM app you just created, navigate to the **General** tab. In the **Settings** section, click **Edit**. Select **SCIM** in the Provisioning setting. Do not modify any other settings, and click **Save**. Okta General tab with SCIM selected in Provisioning setting In the **Provisioning** tab, click **Edit** in the Integration section. Okta Provisioning tab with SCIM Connection and Edit button For **SCIM connector base URL**, enter the SCIM API URL you copied from the **Iru Endpoint** tab (e.g. `https://subdomain.api.iru.com/api/v1/scim`). The `api.kandji.io` version of the SCIM API URL will also work for this purpose. For **Unique identifier field for users**, enter **userName**. For **Supported provisioning actions**, select **Push New Users**, **Push Profile Updates**, and **Push Groups**. For **Authentication Mode**, select **HTTP Header**. For **Authorization**, enter the Bearer Token you obtained in the **Iru Endpoint** tab. Click **Test Connector Configuration** to test the integration. Okta SCIM Connection with base URL, userName, provisioning actions, HTTP Header, and Bearer token In the list of detected features, confirm that only the following items display a checkmark to indicate success: * Create Users * Update User Attributes * Push Groups Okta Test Connector Configuration dialog showing Connector configured successfully and detected features Click **Save**. While still on the **Provisioning** tab, go to the **To App** section and click **Edit**. Okta Provisioning To App section with Provisioning to App and Edit In the **Provisioning to App** section, enable **Create Users**, **Update User Attributes**, and **Deactivate Users**. Okta Provisioning to App settings with Create Users, Update User Attributes, and Deactivate Users Click **Save**. (optional) In the **Attribute Mappings**, edit the user attributes to send to Iru Endpoint. Iru Endpoint will only store and use the attributes mentioned in the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration#scim-schema-and-supported-attributes) article. ## Assigning Users to Iru Endpoint In Okta, the same group cannot be used on both the Assignments tab and the Push Groups tab. To avoid that conflict, create one assignment group for SCIM app access (for example, `iru_endpoint_users`) and keep it in sync with the users in your pushed groups. Then assign that assignment group to the SCIM app. This is one example of assigning users to Iru Endpoint through Okta SCIM. ### Create the assignment group In a new browser tab, navigate to **Directory > Groups** and click **Add Group**. Give the group a meaningful name like **iru\_endpoint\_users** and click **Save**. ### Add members with a group rule Use this when people in your push groups (for example, Sales and Engineering) should automatically become members of `iru_endpoint_users`. If you follow these steps, you do not need to bulk-add those users by hand. Go to Directory > Groups > Rules and click **Add Rule**. Okta Directory Groups Rules page with Add Rule Enter a rule name (for example, `Update iru_endpoint_users group membership`). Under IF, select **Use basic condition** and **Group membership**, then set **includes any of the following** and choose the groups you plan to push (for example, Sales and Engineering). Under **Then Assign to**, select `iru_endpoint_users`, then click **Save**. Okta group rule IF condition with Use basic condition and Group membership Back on the Rules page, open **Actions** for the new rule and click **Activate**. Okta Group Rules list with Actions menu and Activate ### Add members manually Use this when you are **not** using a group rule, for example, to add test users before push groups and rules are in place, or for people who must be in `iru_endpoint_users` but are not in any pushed group yet. Search for `iru_endpoint_users` and add the users who should have the SCIM app. ### Assign the group to the SCIM app Navigate back to the browser tab where the Okta SCIM app is open. Go to the **Assignments** tab, click **Assign > Assign to Groups**. Search for the newly created group and click **Assign** > **Save and Go Back**. Confirm that the group was assigned and click **Done**. The group should now appear in the Assignments tab's **Groups** section. If the group does not display, try refreshing the browser tab. All users in `iru_endpoint_users` are provisioned to Iru Endpoint and appear in the Users module. To sync groups for [conditional logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints), continue with the next section. #### Pushing Groups to Iru Endpoint In this section, learn how to push user groups to Iru Endpoint. When planning to push Okta groups to Iru Endpoint for use with [conditional logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints), for each group that you would like to push, add it to the **Push Groups** tab in the SCIM app. Per this [Okta article](https://help.okta.com/oie/en-us/Content/Topics/users-groups-profiles/usgp-about-group-push.htm), groups used to assign users in the Assignment tab cannot be used in the Push Groups tab. Okta recommends creating additional groups containing the same users and adding the new groups to the Push Groups tab for consistent group membership. If the same group is added in both places, the assignment tab will take precedence, and the group may not be pushed. One way to handle this is to create a single "user assignment" group containing all your Iru Endpoint users and add that group to the Assignment tab. From there, you can use your existing Okta groups as Push Groups. Remember that for the user-group association to work, the members of the pushed groups must also be members of the Iru Endpoint users group assigned to the SCIM app. ### Add groups on the Push Groups tab On the SCIM app, add every Okta group that should appear in Iru Endpoint. Open the Push Groups tab, click **Push Groups**, then **Find groups by name** (or **Find groups by rule**). Search for the group and select it. Select **Create Group**. Click **Save & Add Another**. Add any other groups to push to Iru Endpoint. ### Pushing Group Updates User and group syncing is one-way, meaning the SCIM app sends user and group data to Iru Endpoint only when there is new or updated data. For this reason, a "Sync Now" option is not needed in the Iru Endpoint Web App. * If you add users to the group assigned to the SCIM app in Okta, be sure to also update the groups you have added as Push Groups. * Updates should be seen in Iru Endpoint fairly quickly; to push group updates immediately, use **Push Now** on the Push Groups tab in Okta. See the [Okta article](https://help.okta.com/oie/en-us/content/topics/users-groups-profiles/usgp-enable-group-push.htm). ### Deleting Pushed Groups Use the following steps to stop pushing group updates or optionally delete a pushed group from Iru Endpoint. Go to the Push Groups tab for the app in Okta. In the Push Status column, select **Unlink push group**. Select **Delete the group in the target app (recommended)**. This removes the group in Iru Endpoint but does not delete user accounts. User accounts stay tied to the assignment group on the Provisioning tab. Click **Unlink**. You should no longer see the group listed on the Push Groups tab. # SCIM Directory Integration with OneLogin Source: https://docs.iru.com/en/endpoint/integrations/scim/scim-directory-integration-with-onelogin Configure SCIM directory integration between OneLogin and Iru Endpoint. Automatically provision and deprovision users and groups via the SCIM protocol. ### About SCIM Directory Integration with OneLogin SCIM Directory Integration with OneLogin in Iru Endpoint allows you to set up SCIM-based user directory synchronization between OneLogin and Iru Endpoint, enabling automatic user and group provisioning and deprovisioning. ### How It Works The SCIM integration creates a secure connection between OneLogin and Iru Endpoint, enabling automatic synchronization of user and group data. When users or groups are added, modified, or removed in OneLogin, these changes are automatically reflected in Iru Endpoint through the SCIM protocol. ### Prerequisites * Be sure to review the supported user and group attributes listed in the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration#scim-schema-and-supported-attributes) article. ### Get the SCIM Token and API URL Complete these steps in Iru Endpoint first. You will need the SCIM access token and API URL when configuring OneLogin. For full details, see the [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) article. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. On the **SCIM protocol** tile, click **Add and configure**. Add new integration page with SCIM protocol tile and Add and configure button Click **Get started**. Enter a unique name for the SCIM integration. Click **Generate token**. The SCIM integration uses an HTTP authorization header with a Bearer Token. Configure a SCIM user integration screen with name field and Generate token button Click **Copy token**. The token will not be visible again after you click Done. Store it securely, as you will need it in the **OneLogin** tab. Confirm that you have copied the token by checking the box, then click **Done**. You will return to the **Integrations** page. Copy token and configure with your identity provider dialog with Copy token button Click the **ellipsis** on the SCIM directory integration you created. Select **View Details**. Directory integrations list with SCIM integration and ellipsis menu showing View details, Rename, Rotate token, Delete Copy the SCIM API URL (e.g. `https://subdomain.api.iru.com/api/v1/scim`). Your identity provider will require this. The URL displayed in your tenant may still show the `api.kandji.io` domain. The `api.kandji.io` version of the SCIM API URL will also work for this purpose. Click **Close**. View user integration details modal with SCIM API URL and copy button Keep the token and API URL available, then switch to the **OneLogin** tab to create and configure the SCIM app integration. Complete the **Iru Endpoint** tab first to obtain the SCIM token and API URL. You will enter these in the steps below. ### Creating the SCIM Integration in OneLogin Log into your OneLogin admin console. (example: [https://accuhive.onelogin.com/admin2](https://accuhive.onelogin.com/admin2)) In the top navigation, hover over **Applications**. Click **Applications** in the dropdown menu. OneLogin top navigation with Applications menu Near the top-right, click **Add App**. OneLogin Applications page with Add App button In the text field, enter **SCIM Provisioner with SAML (SCIM v2 Enterprise)**. Click on **SCIM Provisioner with SAML (SCIM v2 Enterprise)**. OneLogin Add App search with SCIM Provisioner with SAML option ### Configuring SCIM Settings Once in the **SCIM Provisioner with SAML (SCIM v2 Enterprise)** application, use the following steps to configure the SCIM settings. The following steps include provisioning users and groups (roles). #### Application Information (optional) Update the app **Display Name** to something like **Iru Endpoint SCIM Provisioner** (optional) Choose whether to make the app visible in the OneLogin portal. (optional) Add an icon. (optional) Add a description. After completing the basic configuration, click **Save**. OneLogin SCIM app basic configuration with Display Name and Save #### Parameters Navigate to the **Parameters** page. Click the add **(+)** button on the right. OneLogin Parameters page with add parameter button Enter **email.value** into the **Field name**. OneLogin new parameter with email.value field name Click **Save**. Select **Email** from the Value dropdown. OneLogin email.value parameter with Email value selected Click **Save**. #### Configuration Navigate to the **Configuration** page. In the **SCIM Base URL** field, paste the SCIM API URL you copied from the **Iru Endpoint** tab (e.g. `https://subdomain.api.iru.com/api/v1/scim`). The `api.kandji.io` version of the SCIM API URL will also work for this purpose. In the **SCIM Bearer Token** field, paste the token you obtained in the **Iru Endpoint** tab. Click **Enable** to turn on the API Connection. Click **Save**. OneLogin Configuration page with SCIM Base URL and Bearer Token fields #### Provisioning Go to the **Provisioning** page. Select the box to **Enable provisioning**. Uncheck the boxes next to **Create user**, **Delete user**, and **Update user**. For the option **When users are deleted in OneLogin, or the user's app access is removed...**, choose **Delete**. For the option **When user accounts are suspended in OneLogin...**, choose **Suspend**. Now, in the top-right, click **Save** to keep the initial configuration. OneLogin Provisioning page with Enable provisioning and user operations ### Provisioning Users and Roles to Iru Endpoint Use the following steps to send users and OneLogin roles to Iru Endpoint via the SCIM integration. OneLogin roles are synonymous to groups in Iru Endpoint, and are assigned to the SCIM configuration. When users are assigned to roles in OneLogin, they are then pushed to Iru Endpoint. Additionally, any roles assigned to the SCIM app are pushed to Iru Endpoint as groups. #### Creating a Role In the top navigation, hover over **Users**. In the dropdown menu, click **Roles**. Click **New Role**. Give the Role a name. Select the apps that should be assigned to the role. In this case, we selected the SCIM app. Click **Save**. #### Assigning Users to the Role Click back into the role that was just created. Click **Users**. Under **Users Added Automatically**, click **New Mapping**. Give the Mapping a name. Create the conditions that meet your needs. For this example, choose **Group membership** as the criteria, but you can use other criteria like department. Under **Actions**, choose the role that should be applied. Click **Save**. OneLogin only allows a user to be member of one group, so you can think of OneLogin groups like an attribute that describes the user similar to department or location. Use OneLogin roles if a user needs to be a member of more than one "group". For more information on Group provisioning, please see OneLogin's documentation [here](https://developers.onelogin.com/scim/create-app). If desired, users can also be added to the SCIM apps manually from each user's record. #### Adding a Rule to the SCIM App Use the steps below to push one or more roles (Iru Endpoint groups) to Iru Endpoint in the OneLogin SCIM app. In the SCIM app, click **Rules**. Click **Add Rule**. Give the rule a name. Under **Actions**, choose **Set Groups in** from the first dropdown. Select **Map from OneLogin**. In the **For each** field, choose **role** from the dropdown. In the **with value that matches** field, enter the SCIM Role to push to Iru Endpoint as a group. Click **Save**. ### Pushing Updates **Syncing**: User and group syncing is one-way, meaning the SCIM app will send user information to Iru Endpoint only when there is new or updated information to be sent. For this reason, a "Sync Now" option is not needed in the Iru Endpoint web app. If the SCIM app is updated in OneLogin, you will need to save the change and then use the **Reapply entitlement mappings**. Hover over the **More Actions** menu. Click on the **Reapply entitlement mappings** option. # Amazon S3 Activity Log Integration Source: https://docs.iru.com/en/endpoint/integrations/security/amazon-s3-activity-log-integration Configure the Amazon S3 integration in Iru Endpoint to export unified tenant activity logs, including Endpoint, Detections, and Compliance events. ### About the Amazon S3 Activity Log Integration Amazon S3 Activity Log Integration in Iru Endpoint enables organizations to export unified tenant activity logs to a self-hosted S3 bucket for centralized collection and analysis with SIEM services. ### How It Works This integration pushes event data to your specified S3 bucket using cross-account access via an Iru Endpoint-provided IAM role. Once configured, it delivers the same tenant activity events you review on [Unified Activity](/en/iru/platform-overview/unified-activity). That includes activity across **Tenant** (System), **Endpoint**, **Detections**, **Vulnerabilities**, and **Compliance**. Use Unified Activity to browse and filter what was recorded; use your S3 bucket for long-term storage, SIEM ingestion, or offline analysis. For event field definitions and API details, refer to the activity log [API documentation](https://api-docs.kandji.io/#06022d9d-426b-4aea-826a-d7f084e4f1e3). The first log collection after the Integration is connected only includes the previous hour of activity. Subsequent activity log collection will occur hourly. ### Prerequisites Before configuring this integration, ensure the following: * You have an active AWS account. * You have permissions to create a new S3 bucket. * You have permissions to create an IAM Role with AssumeRole and S3 write permissions. ### Setting Up AWS Access #### Iru Endpoint Integration Setup In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. Under Security integrations, click **Add and configure** under Amazon S3 Activity Log Integration. Copy the value for **IRU\_ENDPOINT\_IAM\_ROLE** and store the value in a secure location. Copy the value for **IRU\_ENDPOINT\_AWS\_ACCOUNT\_ID** and store the value in a secure location. These values will be used as part of your IAM role permissions in the next section. #### Creating S3 Bucket You must create a new S3 Bucket to use the Amazon S3 Activity Log Integration. Log in to AWS. Navigate to Amazon S3 > Buckets. Click **Create bucket**. Choose the **General purpose** bucket type. Enter a memorable **Bucket name**. * This name will be referenced in policies. Under **Block Public Access settings for this bucket**, ensure that the **Block all public access** option is selected. Under **Bucket Versioning**, keep the **Disable** option selected. Under **Encryption type**, select **Server side encryption with Amazon S3 managed Keys (SSE-S3)**. Under **Bucket Key**, select **Enabled**. Iru Endpoint currently only supports the default encryption options defined above. Click **Create bucket**. Select the bucket you just created. Click the **Permissions** tab. Under **Bucket policy**, click **Edit**. Add the following bucket policy to the role permissions. Click **Save changes**. Replace all reference to **BUCKET\_NAME** with the name of the bucket you just created. ``` { "Version": "2012-10-17", "Statement": [ { "Sid": "AllowSSLRequestsOnly", "Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": [ "arn:aws:s3:::BUCKET_NAME/*", "arn:aws:s3:::BUCKET_NAME" ], "Condition": { "Bool": { "aws:SecureTransport": "false" } } } ] } ``` In AWS, navigate to **IAM > Roles**. Click **Create role**. Select **Custom trust policy**. Add the **Custom trust policy** below to allow Iru Endpoint to assume this role when writing to your S3 bucket. * Replace the **IRU\_ENDPOINT\_AWS\_ACCOUNT\_ID** and **IRU\_ENDPOINT\_IAM\_ROLE** text with the values you made a note of at the beginning of the article. ``` { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::IRU_ENDPOINT_AWS_ACCOUNT_ID:role/IRU_ENDPOINT_IAM_ROLE" }, "Action": "sts:AssumeRole" } ] } ``` Click **Next**. On the **Add permissions screen**, select Next without selecting any of the listed **Permissions policies**. Add a **Role name** and **Description**. Click **Create role**. Select the **IAM Role** you just created. Click on the **Permissions** tab. Click **Add permissions**. Click **Create inline policy**. Click the **JSON** tab. Enter the following for the inline policy: Replace BUCKET\_NAME - replace this with the name of the bucket you created that Iru Endpoint will place the activity log files in. ``` { "Version": "2012-10-17", "Statement": [ { "Action": "s3:ListBucket", "Effect": "Allow", "Resource": "arn:aws:s3:::BUCKET_NAME" }, { "Action": "s3:*", "Effect": "Allow", "Resource": "arn:aws:s3:::BUCKET_NAME/*" } ] } ``` Click **Next**. Enter a **Policy name**. Click **Create policy**. ### Setting Up the Integration in Iru Endpoint Once the above is configured in your AWS account, you can proceed to setting up the integration in your Iru Endpoint account. In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Click **Discover integrations** in the upper-right of the Integrations page. Under Security integrations, click **Add and configure** under Amazon S3 Activity Log Integration. Click **Next**. Enter the **AWS Account ID**. Enter the **S3 Bucket Name** for the bucket that was created earlier in this guide. Optionally, enter a **Destination Path**. Enter the **IAM Role ARN** for the IAM Role that was created earlier in this guide. Enter the **AWS Region**. Click **Connect to S3**. Iru Endpoint will attempt to upload and delete a test file in the provided S3 bucket. If Iru Endpoint is unable to successfully integrate to your S3 bucket, you will not be able to save and will need to follow the error messages surfaced in the UI to fix the connection. Check your S3 bucket to confirm that Iru Endpoint is pushing activity log data. This will take a maximum of two hours, provided that tenant activity events have been generated on your account. ## Considerations **Activity Log Frequency**: Activity log events are updated hourly, with the first collection including only the previous hour of activity. Exported events match [Unified Activity](/en/iru/platform-overview/unified-activity) scope (all supported Tenant, Endpoint, Detections, Vulnerabilities, and Compliance activity types). **IAM Role Permissions**: The IAM role must have the necessary permissions to allow Iru Endpoint to assume that role and write to the S3 bucket. **S3 Bucket Policy**: You may need to adjust the S3 Bucket policy to allow Iru Endpoint to write objects to the bucket. **Security Requirements**: Ensure the S3 bucket has proper encryption enabled and public access is blocked for security compliance. **Data Retention**: Consider implementing S3 lifecycle policies to manage log data retention and storage costs. **Monitoring**: Set up CloudWatch alarms to monitor S3 bucket access and activity log delivery. ### Related Articles Browse, search, and filter the same tenant activity events in the Iru web app before or after they export to S3. Current Endpoint activity timeline, available alongside Unified Activity while it is in Preview. # ServiceNow integration: Iru Endpoint configuration Source: https://docs.iru.com/en/endpoint/integrations/servicenow/servicenow-integration-iru-endpoint-configuration Connect Iru Endpoint to ServiceNow with OAuth and a service account, and optionally send Mac application inventory and usage data when SAM Pro is licensed. ### Before You Begin Follow [ServiceNow integration: ServiceNow configuration](/en/endpoint/integrations/servicenow/servicenow-integration-servicenow-configuration) so the Kandji ServiceNow app is installed in your tenant before you continue here. ### Setting Up ServiceNow Integration Install the Kandji ServiceNow app from the ServiceNow store before you select **Connect to ServiceNow** in Iru Endpoint. Log in to Iru Endpoint. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select **Discover integrations**. In the Asset Management section, select **ServiceNow**, then **Add and configure**. Enter only your ServiceNow tenant prefix, the part before `.service-now.com` (for example, `acme` for `acme.service-now.com`). Enter the Client ID from the ServiceNow OAuth app that you created earlier. Enter the Client Secret from the ServiceNow OAuth app that you created earlier. Enter the service account username you created earlier. Enter the service account password you created earlier. If you have not installed the Kandji ServiceNow app yet, install it from the ServiceNow store and complete [ServiceNow configuration](/en/endpoint/integrations/servicenow/servicenow-integration-servicenow-configuration) before you finish setup in Iru Endpoint. Click **Connect to ServiceNow**. If you are licensed for Software Asset Management Professional (SAM Pro), select **Edit**, turn on the option to send Mac application inventory and usage data to ServiceNow nightly, then select **Save**. Settings modal with Send Mac application inventory and usage data from Prism to ServiceNow (requires SAM Pro) enabled After setup completes, Iru Endpoint starts syncing Apple device data to ServiceNow. ### Managing the Integration After the integration connects, open the ServiceNow integration details page in Iru Endpoint to view connection status, tenant information, and the OAuth app in use. #### Reauthentication If the ServiceNow credentials used to configure the integration need to be updated, re-authenticate from the integration details page in Iru Endpoint. When the ServiceNow integration requires re-authentication, Iru Endpoint displays a banner in the tenant until you complete re-authentication. Iru Endpoint also sends email reminders to Team Members with Admin or Account Owner permissions starting 30 days before the ServiceNow OAuth credentials expire. In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted In the Asset Management section, select **ServiceNow**. In the top-right corner, select the **ellipsis** (⋯). Select **Re-authenticate**. Verify that the ServiceNow tenant domain and client ID are still accurate and enter the new account credentials. Click **Connect to ServiceNow**. If the credentials are accepted, you will be returned to the integration details page for ServiceNow. #### Deleting the Integration Use the following steps to remove the ServiceNow integration in Iru Endpoint. This action cannot be undone. Device asset data stops syncing to ServiceNow as soon as you delete the integration. In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted In the Asset Management section, select **ServiceNow**. In the top-right corner, select the **ellipsis** (⋯). Select **Delete Integration**. Read the confirmation carefully before you select **Delete Integration**. ## Considerations Install the Kandji ServiceNow app from the ServiceNow store before you finish this integration in Iru Endpoint. Store OAuth app credentials securely and rotate them on your organization's schedule. When ServiceNow OAuth credentials are approaching expiry, Iru Endpoint displays a banner in the tenant and sends email reminders to Team Members with Admin or Account Owner permissions starting 30 days before expiry. Re-authenticate from the ServiceNow integration details page when prompted. Test with a small set of devices before you roll the integration out broadly. Device inventory syncs automatically after the integration connects. ### Related Articles How device inventory syncs from Iru Endpoint to ServiceNow staging and target tables, and how SAM Pro app data syncs when enabled. Install the Kandji ServiceNow app, create OAuth and a service account, and fix discovery source if Kandji does not appear. # ServiceNow integration: Overview Source: https://docs.iru.com/en/endpoint/integrations/servicenow/servicenow-integration-overview Sync Apple device inventory from Iru Endpoint to ServiceNow in real time over OAuth 2.0, with optional nightly app data sync for SAM Pro tenants. ### About the ServiceNow Integration The ServiceNow integration pushes Apple device inventory from Iru Endpoint to ServiceNow in real time so your ServiceNow records stay current. If your ServiceNow tenant is licensed for Software Asset Management Professional (SAM Pro), you can also send application installation and usage data nightly. ### How It Works The integration connects Iru Endpoint to your ServiceNow instance over OAuth 2.0 with a dedicated service account. **Authentication**: OAuth 2.0 with a service account in ServiceNow. **Data sync**: Iru Endpoint discovers managed Apple devices and syncs fields such as serial number, model, OS version, and assigned user to ServiceNow. With SAM Pro, you can also send application inventory and usage data nightly. ### Setup Overview Follow these steps at a glance. Install the [Kandji ServiceNow app](https://store.servicenow.com/sn_appstore_store.do#!/store/application/e330778897bfe150f89bf7021153af52/1.0.0?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%25253Bgenerative_ai%25253Bsnow_solution%26q%3Dkandji\&sl=sh) in the ServiceNow integration hub. Configure an OAuth client app so Iru Endpoint can call the ServiceNow Import Set API. Create a ServiceNow user account that can access the ServiceNow API. In Iru Endpoint, finish the ServiceNow integration using the OAuth app and service account you created. When setup is complete, Iru Endpoint starts pushing device asset data to ServiceNow. The assigned user from Iru Endpoint must already exist in ServiceNow for that user to appear on the computer record. ### High-Level Data Flow When a device enrolls in Iru Endpoint or its record changes, the integration does the following: Iru Endpoint detects changes to device inventory. If you turned on SAM Pro app sync in Iru Endpoint, app inventory and usage are prepared nightly. Iru Endpoint pushes these changes to ServiceNow staging tables via the ServiceNow Import Set API. For device data, ServiceNow runs a [transform map](https://www.servicenow.com/docs/r/zurich/integrate-applications/system-import-sets/c_CreatingNewTransformMaps.html) to map staging columns to target tables. Application data uses an [ETL definition](https://www.servicenow.com/docs/r/zurich/integrate-applications/system-import-sets/etl-definition-overview.html) with the [Robust Transform Engine](https://www.servicenow.com/docs/r/zurich/integrate-applications/system-import-sets/define-rte-operations.html). ServiceNow then creates or updates device and MDM records, and can also update software install and usage records when SAM Pro data sync is enabled. ```mermaid actions={false} theme={null} %%{init: {'theme': 'base', 'themeVariables': { 'lineColor': '#8b93a6', 'primaryTextColor': '#1f2937', 'fontSize': '13px'}}}%% flowchart TD A["Iru Endpoint (external)
API / export / integration"] --> B["ServiceNow - staging
Import set: MDM"] A --> C["ServiceNow - staging
Import set: Computer"] A --> D["ServiceNow - staging
Import set: Apps"] B --> E["MDM lane
Transform: Iru Endpoint MDM Transformer"] E --> F["x_kandj_kandji_mdm"] C --> G["Computer lane
Transform: Iru Endpoint CI Transformer"] G --> H["CMDB IRE
discovery_source = Kandji"] H --> I["cmdb_ci_computer"] D --> J["Apps lane: RTE then ETL
Iru Endpoint Apps RTE"] J --> K["Iru Endpoint Apps ETL"] K --> L["ETL: Import"] L --> M["ETL: Temp"] M --> N["cmdb_sam_sw_install"] N --> O["SAM usage
Scheduled: Software Usage Publisher"] O --> P["samp_sw_usage"] I -. "CI resolution for installs" .-> J classDef source fill:#eef6ff,stroke:#3b82f6,stroke-width:1.5px,color:#1f2937; classDef mdm fill:#f5f3ff,stroke:#8b5cf6,stroke-width:1.5px,color:#1f2937; classDef computer fill:#ecfdf5,stroke:#10b981,stroke-width:1.5px,color:#1f2937; classDef apps fill:#fff7ed,stroke:#f97316,stroke-width:1.5px,color:#1f2937; classDef usage fill:#fef9c3,stroke:#ca8a04,stroke-width:1.5px,color:#1f2937; class A source; class B,E,F mdm; class C,G,H,I computer; class D,J,K,L,M,N apps; class O,P usage; ``` ### ServiceNow Tables The following tables are used in the Iru Endpoint integration with ServiceNow. | **Table** | **Description** | | ------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | | `cmdb_ci_computer` | Built-in ServiceNow table with hardware details for Mac, iPhone, iPad, and tvOS devices. | | `cmdb_sam_sw_install` | ServiceNow SAM Pro table used to record software installs when app inventory and usage sync is enabled in Iru Endpoint. | | `samp_sw_usage` | ServiceNow SAM Pro usage table populated by a nightly usage-publisher job in ServiceNow. | | `x_kandj_kandji_mdm` | Custom table built by Iru Endpoint to store additional MDM-related data about device assets. | | `x_kandj_kandji_kandji_import_set_computer` | Import set staging table used to stage device asset information before it is pushed to the `cmdb_ci_computer` table. | | `x_kandj_kandji_kandji_import_set_mdm` | Import set staging table used to stage MDM-related device asset information before it is pushed to the `x_kandj_kandji_mdm` table. | | `x_kandj_kandji_kandji_import_set_apps` | Import set staging table used to stage application inventory and usage information before RTE/ETL processing. | ### Iru Endpoint Device Attributes Iru Endpoint sends the device asset fields below. Additional fields may be added over time. #### Table: `cmdb_ci_computer` | **Iru Endpoint** | **ServiceNow** | **Description** | | ------------------------------------- | ----------------------------------------- | ------------------------------------------------------------------------------- | | `assigned_user` | `assigned_to` | User assigned to the device asset | | `device_capacity` | `disk_space` | Total storage capacity | | `device_name` | `name` | Name of the device | | `Discovery source` (not shown in Iru) | `discovery_source` | Constant value set to "Kandji" | | `model_name` | `model` | Device model name | | `os_type` | `os` | Operating system name (for example, macOS, iOS, iPadOS, or tvOS) | | `os_version` | `os_version` | Operating system version | | `serial_number` | `serial_number` | Device serial number; also coalesces to the computer table record in ServiceNow | | `manufacturer` | `manufacturer` | Constant value set to "Apple" | #### Table: `x_kandj_kandji_mdm` | **Iru Endpoint** | **ServiceNow** | **Description** | | ------------------------------------- | ----------------------------------------- | -------------------------------------------------------------------------------- | | `device_id` | `kandji_device_id` | Iru Endpoint device ID | | `blueprint_id` | `kandji_blueprint_id` | Iru Endpoint blueprint ID; also coalesces to the MDM table record in ServiceNow. | | `serial_number` | `computer` | References the CI computer record in ServiceNow. | | `Discovery source` (not shown in Iru) | `discovery_source` | Constant value set to "Kandji" | #### Table: `cmdb_sam_sw_install` | **Iru Endpoint (Prism)** | **ServiceNow** | **Description** | | ------------------------------------------------ | ----------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `App ID` (not shown in Iru) | `instance_key` | A unique key used to identify a piece of software on a specific device | | `name` | `name` | The name of the app | | `developer_name` | `publisher` | The developer of the software | | `version` | `version` | Version of the software | | `path` | `install_location` | Install path on the device | | `serial_number` | `installed_on` | Reference to the computer CI record | | `last_opened` | `last_used` | The date the software was last used | | `is_removed` (removed apps are not shown in Iru) | `active` | **Active install** on `cmdb_sam_sw_install`: `true` while the app is on the device; `false` when Iru reports removal. Removed apps still sync with `active` = `false` so ServiceNow keeps the install row for history (see [Application inventory](#application-inventory)). | | `Discovery source` (not shown in Iru) | `discovery_source` | Constant value set to "Kandji" | #### Table: `samp_sw_usage` | **ServiceNow** | **Description** | | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------- | | `configuration_item` | Reference to the computer CI record | | `norm_product` | The normalized record of the app from ServiceNow | | `reclamation_type` | `'last_used'`. Iru populates `last_used` entries. | | `last_used_time` | Date and time the software was last used. Iru sends dates only here to avoid extra custom tables in ServiceNow. | ### Application Inventory When application inventory is enabled, Iru Endpoint still sends removed apps to ServiceNow with `active` set to `false`. ServiceNow keeps those install rows for history instead of deleting them when the app leaves the device. ## Considerations For the computer record in ServiceNow to show the user assigned in Iru Endpoint, that person must already exist in ServiceNow. Device inventory syncs in real time. App inventory and usage data syncs nightly when that option is enabled. SAM Pro must be licensed in ServiceNow, and you must enable the option in Iru Endpoint integration settings. Removed apps still sync with `active` = `false` so ServiceNow keeps historical install rows instead of deleting them. When ServiceNow OAuth credentials are approaching expiry, Iru Endpoint displays a banner in the tenant and sends email reminders to Team Members with Admin or Account Owner permissions starting 30 days before expiry. Re-authenticate from the [ServiceNow integration details page](/en/endpoint/integrations/servicenow/servicenow-integration-iru-endpoint-configuration#reauthentication) in Iru Endpoint. The integration writes to built-in ServiceNow tables and custom Kandji tables so CMDB and MDM views stay complete. Data moves through ServiceNow's Import Set API and transform flows. ### Related Articles Install the Kandji ServiceNow app, create an OAuth client and service account, and verify discovery source in ServiceNow. Connect Iru Endpoint to your tenant, enter OAuth and service account credentials, and optionally enable nightly app inventory and usage for SAM Pro. # ServiceNow integration: ServiceNow configuration Source: https://docs.iru.com/en/endpoint/integrations/servicenow/servicenow-integration-servicenow-configuration Install the Kandji ServiceNow app, create OAuth credentials and a service account, and verify discovery source settings for the Iru Endpoint integration. ### Installing the Kandji ServiceNow App If the app is not installed yet, install the Kandji ServiceNow app in your ServiceNow instance. The install adds dependencies your tenant needs for the integration. Go to the [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). In the store, search for **Kandji** to find the **Kandji ServiceNow app**. Install the Kandji ServiceNow app by selecting **Get**. Sign in to the ServiceNow store if prompted. The account you use must be allowed to install Integration Hub store apps. ### Creating an OAuth App Iru Endpoint uses a ServiceNow OAuth API client with grant type **Resource Owner Password Credentials (ROPC)** to get access and refresh tokens for your instance. On ServiceNow **Zurich** and later releases, set **Scope Restriction** to **Broadly scoped** when you create the OAuth API endpoint for external clients. If this field is set to a narrower scope, inbound API calls from Iru Endpoint can fail with errors such as *OAuth client does not have unrestricted access to unscoped APIs is not allowed*. For more information, see ServiceNow [KB2731346](https://support.servicenow.com/kb?id=kb_article_view\&sysparm_article=KB2731346). Using a ServiceNow admin account, log in to your ServiceNow tenant (.service-now\.com). In the **Filter navigator**, search for **System OAuth**. Click **Application Registry**. Click **Create an OAuth API endpoint for external clients**. Give the OAuth app a name (for example, `kandji_oauth_api`). In the **Redirect URL** field, enter [**https://kandji.io**](https://kandji.io). Click **Submit**. Go back to the OAuth app that you just created. Highlight and copy the **Client ID**. Reveal the **Client Secret** by clicking the padlock. Copy the **Client Secret**. If you set your own client secret, select **Update** to save it. ### Adding a Service Account The service account user credentials are used to configure the ServiceNow integration in Iru Endpoint. Any ServiceNow user account can be used as long as it has access to web services and has the roles **cmdb\_read**, **import\_transformer**, and **rest\_api\_explorer**. Create a dedicated service account for this integration when possible. Using a ServiceNow admin account, log in to your ServiceNow tenant (.service-now\.com). In the **Filter navigator**, search for **Users**. Under User Administration, click **Users**. Click **New** to add a new user. Enter a descriptive name for the user (for example, `kandji_rest_api_user`). Copy the username to a secure location. You need it when you configure the integration in Iru Endpoint. * Optionally, enter any additional information required by your organization. Select **Web service access only**. Click **Submit**. Open the user you just created, then select **Set Password**. Click **Generate** to create the new password. Copy the new password. Click **Save Password**. Store the password in a secure location. You enter it in Iru Endpoint when you configure the ServiceNow integration. Click **Close** to go back to the Users page. While still on the user page, go to **Roles**. Click **Edit**. Add the following roles to the service account user: * cmdb\_read * import\_transformer * rest\_api\_explorer You should see six roles in total: three you added directly and three inherited. To complete the user creation, click **Save**. ### Troubleshooting #### Verify that Kandji is a Discovery Source In ServiceNow, enter **Dictionary** in the **Filter navigator**. Under System Definition, click **Dictionary**. In Dictionary Entries, select **Column name**, then enter **discovery\_source**. Select the **cmdb\_ci** table. Scroll down and select the **Choices** tab. Confirm **Kandji** is listed. If it does not appear, search for the label **Kandji**. #### If Kandji does not show up as a Discovery Source Run **kandji\_fix\_script** manually if **Kandji** does not appear as a discovery source after you install the Kandji ServiceNow app. In ServiceNow, enter **Fix Script** in the **Filter navigator**. Under System Definition, click **Fix Scripts**. In Fix Scripts, select **Name**, then enter **kandji\_fix\_script**. Open the **kandji\_fix\_script** record. Click **Run Fix Script**. In the Run Fix Script modal, click **Proceed in Background**. Kandji should now appear as a discovery source choice in ServiceNow. ## Considerations Prefer a dedicated account for this integration instead of reusing an interactive user, so access and changes are easier to audit. On **Zurich** and later, set **Scope Restriction** to **Broadly scoped** when you create the OAuth app (see [Creating an OAuth App](#creating-an-oauth-app)). Set the redirect URL to `https://kandji.io` and store client credentials securely. The service account needs **cmdb\_read**, **import\_transformer**, and **rest\_api\_explorer**. After install, confirm **Kandji** appears under discovery source choices for **cmdb\_ci** in Dictionary. If discovery source or sync looks wrong, run the **kandji\_fix\_script** fix script and confirm the service account has the three roles above. ### Related Articles How inventory flows from Iru Endpoint to ServiceNow tables and transforms, and how SAM Pro data flows when enabled. Connect Iru Endpoint with your OAuth app and service account, and manage the integration after ServiceNow is ready. # SAML-based Single Sign-On Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on Set up SAML-based single sign-on for Iru Endpoint admin access. Configure your identity provider with SAML metadata, attributes, and assertions. ### About SAML-based Single Sign-On SAML, or Security Assertion Markup Language, is a standard that helps different systems communicate about user authentication and authorization. It's mainly used for Single Sign-On (SSO), which means you can log in once and access multiple applications without entering your credentials again. In Iru Endpoint, you can use SAML for [Iru Endpoint Web App access](/en/endpoint/getting-started/foundation/admins-and-access) and [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### How It Works There are three components that make up a SAML configuration: * **Identity Provider (IdP)** - This is the system that verifies your identity. It checks your credentials and shares this information with the service you want to use. * **Service Provider (SP)** - This is the application or service you're trying to access. It trusts the IdP to confirm your identity and lets you in based on that information. * **SAML Assertions** - These are messages that carry information about your identity and access rights from the IdP to the SP. There are three types: * **Authentication Assertion** - Confirms your identity and how you were authenticated. * **Attribute Assertion** - Shares extra details about you. * **Authorization Decision Assertion** - States whether you can access the service. The SAML authentication process generally works like this: The user attempts to access a service provider, in this case, Iru Endpoint. Iru Endpoint generates a SAML authentication request and redirects the user to the IdP. The IdP authenticates the user, usually by prompting them to log in if they aren't already authenticated. Once the user is authenticated, the IdP generates a SAML response, which includes a SAML assertion. This assertion contains information about the user, such as their identity and any attributes or roles they have. The SAML response is sent back to Iru Endpoint via the user's browser. Iru Endpoint receives the SAML response and validates the SAML assertion. This involves checking the digital signature to ensure it comes from a trusted IdP. If the assertion is valid, Iru Endpoint grants the user access to log into the Iru Endpoint Web App, or enroll during Automated Device Enrollment. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### Setting Up a SAML Connection These instructions cover how to create a generic Custom SAML SSO connection. For more information on creating IdP-specific Custom SAML connections, please see the following support articles: * [Single Sign-On with Okta (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-okta-saml) * [Single Sign-On with Google Workspace (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml) * [Single Sign-On with JumpCloud (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-jumpcloud-saml) * [Single Sign-On with Microsoft Entra ID (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-saml) * [Single Sign-On with OneLogin (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-onelogin-saml) In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**, then enter a display name for the SSO Connection and select **SAML**. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. Leave this browser tab open as you proceed with the instructions below. ### Configuring SAML Connection Once you have created the connection, you will see the following configuration options displayed in the modal. #### Configuration Options **Metadata File**: This is the URL to the metadata file for the service provider details. Provide this metadata file to your identity provider if it supports metadata files. Note that this link will not be live until you save the connection page. **Configuration Information**: If your identity provider does not support metadata files, click **Configuration information**. The Configuration information section, which is covered later in this article, contains information from within the metadata file. **Name**: Provide a display name for the connection. This will be shown on the login page. **Sign-In URL**: This is the application sign-in URL provided by your identity provider. **IdP Entity ID**: This is the Entity ID coming from your identity provider (Google, Okta, Entra, etc.), not the Entity ID from the Iru side. This field is required and must match the Entity ID configured in your identity provider. **Signing Certificate**: Paste the contents of the signing certificate in X.509 PEM format from your identity provider. This certificate is used to evaluate the validity of an incoming SAML claim. Paste the full contents of the certificate, including the BEGIN CERTIFICATE and END CERTIFICATE header/footer. **User ID Attribute**: Specify the attribute within the SAML claim that should attempt to match against an existing administrator. Typically this will be the NAME ID URI (example below) as long as your identity provider is configured to send the user's email for the NAME ID value. Otherwise, match against any additional custom attribute that you intend on sending within the claim. ``` http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier ``` **Sign Request**: Choose if the request from the Service Provider (Iru Endpoint) to the Identity Provider should be signed. **Sign Request Algorithm**: Select the signing algorithm required by your identity provider. **Sign Request Algorithm Digest**: Select the signing algorithm digest required by your identity provider. **Request Binding**: How should the Service Provider (Iru Endpoint) direct requests to the identity provider (typically HTTP-Redirect). **Save**: Saves your SAML configuration. #### Required Claim Attributes The following attributes are required in your SAML claim. **NameID** is technically optional within Iru Endpoint so long as another attribute is specified to match the email address. If the surname and given name attributes are missing from your claim, the email address will be used for these values.
**Attribute URI** Needed Value Reasoning
NameID [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier) The email of the user matching the email of a team member in your Iru Endpoint tenant. Needed to match the user authenticating to Iru Endpoint.
[http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname) The last name of the user. Needed to update the user's last name.
[http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname) The first name of the user. Needed to update the user's first name.
#### Advanced Details If your identity provider does not support configuring a service provider application via a metadata file, you will manually fill in this information. This is the URL to the metadata file for the service provider details. Provide this metadata file to your identity provider if it supports metadata files. The URL that a SAML assertion should be sent to. The entity ID of the service provider (this is also the SP Issuer ID used for SLO requests). This certificate is used to sign requests from the Service Provider to the Identity Provider. ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ## Considerations **Security**: Ensure that your identity provider has appropriate security policies configured for SAML authentication. **Certificate Management**: Keep track of certificate expiration dates and ensure timely renewal to maintain SAML functionality. **Testing**: Always test the SAML integration with a small group of users before rolling out to your entire organization. **Attribute Mapping**: Proper attribute mapping is crucial for successful user authentication and profile synchronization. # Single Sign-On Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on Set up single sign-on (SSO) for Iru Endpoint admin access. Choose from native OAuth or SAML integrations with Okta, Entra ID, Google, and more. ### About Single Sign-On Single Sign-On (SSO) in Iru Endpoint allows team members to log into the Iru Endpoint Web App using their existing identity provider credentials, providing centralized authentication management. ### How It Works [Team Members](/en/iru/access/team-member-role-permissions) have four options for logging into the [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access): **Passkeys**, **Google Social**, **Microsoft Social** and **Single Sign-On (SSO)**. By default, Passkeys, Google Social, and Microsoft Social authentication are activated for all tenants, offering login through Passkeys, Google Social, and Microsoft Social. Admins have the option to enable SSO using either native integrations or Custom SAML. Once an SSO setup is complete, the default connections can be turned off, allowing SSO to be the only login method. SSO can also be used for [Require Authentication for Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### SSO Connection Types Iru Endpoint currently supports the following Single Sign-On connection types. Click on one of the following connection types to learn how it can be configured. * [Single Sign-On with Microsoft Entra ID (Native)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-native) * [Single Sign-On with Microsoft Entra ID (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-saml) * [Single Sign-On with Google Workspace (Native)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native) * [Single Sign-On with Google Workspace (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml) * [Single Sign-On with Okta (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-okta-saml) * [Single Sign-On with JumpCloud (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-jumpcloud-saml) * [Single Sign-On with OneLogin (SAML)](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-onelogin-saml) * [Custom SAML-based Single Sign-On](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on) ### Allowing Tenant Authentication and Managing Connections Once you have configured an SSO connection in both Iru Endpoint and your identity provider (IdP), you can allow the SSO connection to be used for tenant authentication. Click the **ellipsis** next to the connection name. Click **Allow for tenant authentication** from the menu. Connections can also be re-configured, deleted, and disabled from this menu. #### Considerations for Allowing Tenant Authentication * An SSO connection does not need to be **allowed for tenant authentication** to be used for **Require Authentication** during Device Enrollment. * A connection should only be set to **Allow tenant authentication** in **Access** if you want to authenticate Iru Endpoint administrators to the [web app](/en/endpoint/getting-started/foundation/admins-and-access) with that connection. * Authentication to the [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) using SSO requires that the user has been invited as a Team Member. ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. Before disabling Passkey, Google Social, and Microsoft Social, ensure your SSO connection is functioning correctly. We suggest verifying this by using a private browser window. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Click the ellipsis next to **Passkey**. Click **Disable for tenant authentication** Repeat the previous steps for the Google Social and Microsoft Social connections. If you lose access to your Iru Endpoint tenant via SSO and need to have Passkey, Google Social, or Microsoft Social connections re-enabled, please [contact Iru Endpoint support](/en/iru/iru-support/access-to-iru-support). ### Disabling or Deleting SSO Connections If you decide to stop using SSO, you can delete it or disable it for tenant authentication using the same ellipsis used to enable it. When there is only one SSO connection enabled for tenant authentication, and Passkey, Google Social, and Microsoft Social are disabled, you will not be able to disable that SSO connection to prevent tenant lockout. You would first need to enable another connection, and authentication with that other connection before disabling the SSO connection. ## Best Practices **Testing**: Always test your SSO connection thoroughly before disabling Passkey, Google Social, and Microsoft Social connections to prevent tenant lockout. **User Management**: Ensure all necessary users have been invited as Team Members before relying solely on SSO authentication. **Backup Access**: Keep at least one of the Passkey, Google Social, or Microsoft Social connections enabled until you're confident your SSO setup is working correctly for all users. **Support**: If you encounter issues with an SSO connection, Passkey, Google Social, or Microsoft Social connections can be re-enabled by contacting Iru Endpoint support. # Single Sign-On with Google Workspace (Native) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-native Configure native Google Workspace SSO for Iru Endpoint using OAuth2 and OpenID Connect. Enable one-click sign-in for admins with Google credentials. ### About Google Workspace Native Integration Google Workspace Native integration in Iru Endpoint lets you set up native Google Workspace integration for SSO. Users authenticate using their Google Workspace credentials without requiring custom SAML configuration. #### How It Works When users attempt to access Iru Endpoint, they're redirected to Google Workspace for authentication using OAuth2/OpenID Connect protocols. After successful authentication, Google Workspace sends an access token back to Iru Endpoint, which validates the user's identity and grants access to the platform. If you're [requiring authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) for iOS enrollments and using Google Workspace as your identity provider, the Single Sign-On entry must be created [using Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml). The built-in Google Workspace integration is not supported. ### Prerequisites Before you begin, ensure you have: * [Access to the Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) as an Admin or Account Owner * A Super Admin account in Google Workspace to complete the Google Workspace configuration steps ### Configuring Iru Endpoint Connection Follow these steps to configure the connection in Iru: In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **Google Workspace**. Click **Create**. Copy the **Redirect URL** into a text document for later use. You'll need this for the Google Workspace configuration. Iru Endpoint SSO Redirect URL to copy for Google Workspace Keep the Iru Web App configuration modal open, then switch to the Google Workspace Configuration tab to continue. After completing the Google Workspace configuration, return here to finish setting up the SSO connection in Iru Endpoint. You'll need the Client ID, and Client secret you copied from Google Workspace. Follow these steps to complete the configuration: Enter your **Google Workspace domain** from Google Workspace. Paste the **Client ID** you copied from Google Workspace into the **Client ID** field. Paste the **Client secret** you copied from Google Workspace into the **Client secret** field. Iru Endpoint Client secret field for Google Workspace Click **Save**. Your connection has now been successfully configured and may be enabled and tested. ### Allow for Tenant Authentication Once you have configured the OIDC connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the OIDC connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Setting Up Google Workspace Application Before starting the Google Workspace configuration, complete the initial setup in the **Iru Web App Configuration** tab to get the Redirect URL. You'll need this value to configure the Google Workspace application. Follow these steps to configure your Google Workspace application: **Log in** to the Google Developer [API Console.](https://console.developers.google.com/) Then click **Create project**. Enter a **Project name**. Select the **Organization** from the dropdown menu. Select the **Location**. Google API Console project Location dropdown Click **Create**. In the sidebar, click **Credentials**. If this is your first time creating a client ID, you may also be prompted to [configure your consent screen](https://support.google.com/googleapi/answer/6158849#zippy=%2Cuser-consent). Google consent screen configuration prompt On the right side of the window, near the top, click **+ Create credentials**. From the menu that appears, select **OAuth Client ID**. Google Create credentials OAuth Client ID For "**Application Type**," click the menu and select "**Web application**". In the **Name** field, enter a **Name** for your OAuth client. For **Authorized JavaScript Origins**, use just the domain section from the Redirect URL you copied from the Iru Web App Configuration (e.g., `https://vpriix.id.iru.com`). This domain is unique to each Iru tenant. For **Authorized redirect URIs**, enter the complete Redirect URL you copied from the Iru Web App Configuration (e.g., `https://vpriix.id.iru.com/federated-auth/oidc/callback`). Single Sign-On with Google Workspace (Native) documentation showing Authorized redirect URIs configuration Click **Create**. Copy the text from the **Client ID** field and save it for later use. Copy the text from the **Client Secret** field and save it for later use. Google OAuth Client ID and Client Secret fields Click **OK**. After completing the Google Workspace Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SSO connection using the Client ID, and Client secret you copied from Google Workspace. # Single Sign-On with Google Workspace (SAML) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml Configure SAML-based SSO between Google Workspace and Iru Endpoint. Set up the SAML app in Google Admin Console and map user attributes for login. ### About Google Workspace SAML Integration Google Workspace SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with Google Workspace for users accessing Iru Endpoint through their Google Workspace credentials. #### How It Works When users attempt to access Iru Endpoint, they're redirected to Google Workspace for authentication. After successful authentication, Google Workspace sends a SAML assertion back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### Setting Up the SAML Connection You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Google Workspace. After copying the Entity ID and ACS URL, switch to the [**Google Workspace Configuration**](#google-workspace-configuration) tab and continue with [**Configuring Google Workspace Application**](#configuring-google-workspace-application). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **SAML** for the Authentication method. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Google Workspace configuration. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Google Workspace configuration. Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL Keep the Iru Endpoint configuration modal open, then switch to the [**Google Workspace Configuration**](#google-workspace-configuration) tab to continue with [**Configuring Google Workspace Application**](#configuring-google-workspace-application). ### Configuring Iru Endpoint SAML Connection After completing the Google Workspace configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the SSO URL, Entity ID, and certificate from Google Workspace. Go back to the Custom SAML modal in Iru Endpoint. Scroll down to **User Matching** section. Set **IdP attribute** to **Attribute**. Set **Attribute name** to **email**. Set **User attribute** to **User Principal Name (UPN)**. Iru Endpoint User attribute set to User Principal Name UPN Scroll down to **Identity provider** section. Paste the **Entity ID** you copied from Google Workspace into the **IdP Entity ID** field. Paste in the **IdP Single Sign-in URL** you copied from Google Workspace. Upload the certificate you downloaded from Google Workspace. Upload certificate from Google Workspace in Iru Endpoint Scroll down to **Request Configuration** section. Set the **Request Binding** to **HTTP-POST**. Ensure that the **Request Signature Algorithm** is set to **RSA-SHA256**. Ensure that **Sign Request Algorithm Digest** is set to **SHA256**. Ensure that **Sign SAML Authentication Request** is enabled. Sign SAML Authentication Request enabled in Request Configuration Scroll down to **Response Validation** section. Set **Response Signature Verification** to **Response**. Leave the optional **Destination** blank. Set **Allowed Signature Algorithm** to **RSA-SHA256**. Set **Allowed Digest Algorithm** to **SHA256**. Click **Save**. Save button for SAML configuration in Iru Endpoint ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Testing the Integration Add a user to the **Admin Team** in Iru Endpoint by clicking **New User**. Fill in all of the corresponding user information. This user must exist in Google Workspace and must be assigned to the Iru Endpoint SSO app in your Google Workspace tenant. Click **Submit**. Once the invite is submitted, close the Invite User window. Refresh the Access page in Iru Endpoint. You should see the user you just added. Check the user's email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection. Before starting the Google Workspace configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Google Workspace application. ### Configuring Google Workspace Application In a new browser tab, log in to [admin.google.com](https://admin.google.com) with a Google Workspace admin account. Click the menu symbol at the top left. Select **Apps**. Select **Web and mobile apps**. Google Admin Console Apps Web and mobile apps Click the **Add app** dropdown. Select **Add custom SAML app**. Google Workspace Add app dropdown with Add custom SAML app On the App details page: 1. Set an **App name**. 2. Optionally, add a **Description**. 3. Upload an optional **App icon**. 4. Click **Continue**. Google Workspace SAML app details with App name Description and Continue On the Google Identity Provider Details page, use **Option 2: Copy the SSO URL, entity ID, and certificate.** 1. Copy the **SSO URL** and save it to a text document for later use. You'll need this to complete the Iru Web App Configuration. 2. Copy the **Entity ID** and save it to a text document for later use. You'll paste this into the **IdP Entity ID** field in Iru Endpoint. 3. Download the **Certificate** and save it. You'll need this to complete the Iru Web App Configuration. 4. Click **Continue**. Google Identity Provider Details SSO URL Entity ID and Certificate with Continue On the Service Provider Details page: 1. In the ACS URL field, paste the **Iru Endpoint Assertion Consumer Service URL** you copied from the Iru Web App Configuration. 2. Paste the Iru Endpoint Entity ID you copied from the Iru Web App Configuration in the **Entity ID** field. 3. Ensure that the **Signed response** option is checked. 4. Set the Name ID Format to **EMAIL**. 5. For NameID, make sure that **Basic Information > Primary email** is selected. 6. Click **CONTINUE**. Google Service Provider Details ACS URL Entity ID Signed response and CONTINUE On the Attribute Mapping page: 1. Click **ADD MAPPING**. 2. Select the **Primary email** attribute in the **Basic information** dropdown menu. 3. Enter **email** in the **App attributes** field. 4. Click **Finish**. Google Attribute Mapping ADD MAPPING Primary email and Finish On the resulting app page, check under User Access to ensure that the service is turned on and that either a user group or organizational unit is selected. 1. If it displays **OFF for everyone**, click on the disclosure triangle in the user access panel to assign a user group or organizational unit to the app. Google Workspace app User Access disclosure to assign group or OU 2. Optionally, please select a group or organizational unit to enable the service (by default, it will display all organizational units). 3. Set service status to **ON for everyone**. 4. Click **Save**. Google Workspace User Access ON for everyone and Save The Required Claim Attributes section of the [SAML-based Single Sign-on](/en/endpoint/integrations/single-sign-on-integrations/saml-based-single-sign-on) knowledge base article provides more about Iru Endpoint attribute mappings. After completing the Google Workspace configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Google Workspace. ## Considerations **Security**: Ensure that your Google Workspace tenant has appropriate security policies configured for SAML authentication. **User Management**: Users must exist in both Google Workspace and Iru Endpoint to successfully authenticate via SSO. **Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization. **Attribute Mapping**: Proper attribute mapping is crucial for successful user authentication and profile synchronization. # Single Sign-On with JumpCloud (SAML) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-jumpcloud-saml Configure SAML-based SSO between JumpCloud and Iru Endpoint. Create the SAML application in JumpCloud and map user attributes for admin authentication. ### About JumpCloud SAML Integration JumpCloud SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with JumpCloud for users accessing Iru Endpoint through their JumpCloud credentials. #### How It Works When users attempt to access Iru Endpoint, they're redirected to JumpCloud for authentication. After successful authentication, JumpCloud sends a SAML assertion back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### Setting Up the SAML Connection You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for JumpCloud. After copying the Entity ID and ACS URL, switch to the [**JumpCloud Application Configuration**](#jumpcloud-application-configuration) tab and continue with [**Configuring JumpCloud Application**](#configuring-jumpcloud-application). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **SAML** for the Authentication method. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. You'll need this for the JumpCloud configuration. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the JumpCloud configuration. Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL Keep the Iru Endpoint configuration modal open, then switch to the [**JumpCloud Application Configuration**](#jumpcloud-application-configuration) tab to continue with [**Configuring JumpCloud Application**](#configuring-jumpcloud-application). ### Configuring Iru Endpoint SAML Connection After completing the JumpCloud Application Configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Sign-in URL, IdP Entity ID, and certificate from JumpCloud. Go back to the Custom SAML modal in Iru Endpoint. Keep the **IdP attribute** setting as **Subject**. Leave the **Attribute name** blank. Set **User attribute** to **User Principal Name (UPN)**. Iru Endpoint User attribute set to User Principal Name UPN Paste the unique **IdP Entity ID** you created earlier in JumpCloud into the **IdP Entity ID** field in Iru Endpoint. Paste in the **Sign-in URL** you copied from JumpCloud: [https://sso.jumpcloud.com/saml2/iru](https://sso.jumpcloud.com/saml2/iru). Upload the **certificate** you downloaded from JumpCloud. Iru Endpoint upload certificate from JumpCloud Set the **Request Binding** to **HTTP-POST**. Ensure that **Request Signature Algorithm** is set to **RSA-SHA256**. Ensure that **Request Digest Algorithm** is set to **SHA256**. Ensure that **Sign SAML Authentication Request** is enabled. Iru Endpoint Sign SAML Authentication Request enabled Set **Response Signature Verification** to **Assertion**. Leave the optional **Destination** blank. Set **Allowed Signature Algorithm** to **RSA-SHA256**. Set **Allowed Digest Algorithm** to **SHA-256**. Click **Save**. Iru Endpoint Save for SAML configuration ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Testing the Integration Add a user to the **Admin Team** in Iru Endpoint by clicking **New User**. Fill in all of the corresponding user information. This user must exist in JumpCloud and must be assigned to the Iru Endpoint SSO app in your JumpCloud tenant. Click **Submit**. Once the invite is submitted, close the Invite User window. Refresh the Access page in Iru Endpoint. You should see the user you just added. Check the user's email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection. ## Considerations **Security**: Ensure that your JumpCloud tenant has appropriate security policies configured for SAML authentication. **User Management**: Users must exist in both JumpCloud and Iru Endpoint to successfully authenticate via SSO. **Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization. **Certificate Management**: Keep track of certificate expiration dates and ensure timely renewal to maintain SSO functionality. Before starting the JumpCloud configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the JumpCloud application. ### Configuring JumpCloud Application Log in to the [JumpCloud Admin Portal](https://console.jumpcloud.com/login/admin). In the lefthand navigation bar's **Access** section, select **SSO Applications**. JumpCloud Access SSO Applications Click on the **+ Add New Application** button, or, if this is your first application, click **Get Started**. JumpCloud Add New Application or Get Started At the bottom of the screen, click **Select** in the Custom Application tile. JumpCloud Custom Application Select Click **Next**. JumpCloud Next Select **Manage Single Sign-On (SSO)**. Select **Configure SSO with SAML**. Click **Next**. JumpCloud Manage SSO Configure SSO with SAML Next On the **Enter** **General Info** tab: 1. Add a name for the **Display Label**. 2. Add a **Description** if desired. 3. Choose either a color Indicator or upload a logo for the **Display Portal Image**. 4. Optionally, choose to show the application in the User Portal. 5. Expand the disclosure triangle beside **Advanced Settings**. 6. In the **SSO IdP URL** field, enter **iru**. The full URL should read [https://sso.jumpcloud.com/saml2/iru](https://sso.jumpcloud.com/saml2/iru). 7. Click **Save Application**. JumpCloud General Info Display Label SSO IdP URL iru Save Application After your application is saved, click **Configure Application**. JumpCloud Configure Application On the **SSO** tab of the configuration modal: 1. For the **IdP Entity ID**, create a unique Entity ID (e.g. `iru-saml-jumpcloud`) and enter it in the **IdP Entity ID** field. Save this unique IdP Entity ID for use in Iru Endpoint later. 2. Copy the **Entity ID** from Iru Endpoint that you saved earlier and paste it into the **SP Entity ID** field in JumpCloud only (do not paste it into the IdP Entity ID field). JumpCloud SSO tab IdP Entity ID and SP Entity ID 3. Copy the **Assertion Consumer Service URL** from Iru Endpoint that you saved earlier and paste it into the **ACS URL** field. 4. Leave the **SAML Subject NameID** set to **email**. 5. In the **SAML Subject NameID-Format** field, select **urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress** from the dropdown menu. 6. Set the **Signature Algorithm** to **RSA-SHA256**. 7. Select **Assertion** in the **Sign** section. 8. Ensure the **IDP URL** is [https://sso.jumpcloud.com/saml2/iru](https://sso.jumpcloud.com/saml2/iru). If it is not, you will need to delete the integration and create a new one. Copy this URL and save it for use in Iru Endpoint later. 9. Click **Save**. JumpCloud SSO tab ACS URL NameID Signature Assertion Save Click **Action** at the top right. Click **Download Certificate**. It will be used in Iru Endpoint later. Click on the **User Groups** tab. JumpCloud User Groups tab Add a user group to the SSO application. If you want to restrict who can access the SSO app, create another user group in your JumpCloud console and assign it to the SSO app. JumpCloud assign user group to SSO application After completing the JumpCloud Application Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the Single Sign-on URL, IdP Entity ID, and certificate you copied from JumpCloud. # Single Sign-on with Microsoft Entra ID (Native) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-native Configure native Microsoft Entra ID SSO for Iru Endpoint using OAuth2 and OpenID Connect. Enable one-click sign-in for admins with Entra credentials. ### About Microsoft Entra ID Native Integration Microsoft Entra ID Native integration in Iru Endpoint lets you set up native Microsoft Entra ID integration for SSO. Users authenticate using their Microsoft Entra ID credentials through OAuth2/OpenID Connect. #### How It Works When users attempt to access Iru Endpoint, they're redirected to Microsoft Entra ID for authentication using OAuth2/OpenID Connect protocols. After successful authentication, Microsoft Entra ID sends an access token back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). Microsoft Entra ID [is the new name](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/new-name) for Azure AD (Azure Active Directory) > Because client secrets have a maximum life of 24 months, we recommend that you configure [SAML based Single Sign-On](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-saml) instead of using the method described in this document. ### Prerequisites Before you begin, ensure you have: * [Access to the Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) as an Admin or Account Owner * An administrator account in Microsoft Entra ID with permissions to create app registrations (such as Global Administrator, Application Administrator, or Cloud Application Administrator) ### Configuring Iru Endpoint Connection Follow these steps to configure the connection in Iru: In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **Microsoft Entra ID** for the Authentication method. Click **Create**. Copy the **Redirect URL** into a text document for later use. You'll need this for the Microsoft Entra ID configuration. Iru Endpoint Copy Redirect URL for Entra ID Keep the Iru Web App configuration modal open, then switch to the **Microsoft Entra ID Configuration** tab to continue. Follow these steps to complete the configuration: After completing the Microsoft Entra ID configuration, return here to finish setting up the SSO connection in Iru Endpoint. You'll need the Client ID and Client secret you copied from Microsoft Entra ID. Enter the **Tenant ID** that the application was registered within into the **Microsoft Entra ID Domain** field. Please refer to [Microsoft's documentation to locate your Tenant ID](https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/find-tenant-id-domain). Enter the **Client ID** you previously copied from the Entra admin center. Enter the **Client Secret** you previously copied from the Entra admin center. Click **Save**. Iru Endpoint Tenant ID Client ID Client Secret Save After saving, a new dialogue box will appear with a link to **authorize your connection.** A Microsoft Entra ID administrator for your domain must click the link and complete this process to authorize the application. This box will not go away after authorization is completed. In the new window that launches, sign in and click **Accept**. After clicking **Accept,** you will be brought to an authorization success page. Your connection has now been successfully configured and may be enabled and tested. If you encounter the error "Failed to obtain access token," it may be because the secret ID was used instead of the correct value. ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Renewing the Client Secret Follow the steps in the **Microsoft Entra ID Configuration** tab above to create a new client secret. Complete steps "Access Certificates and Secrets" through "Copy Secret Value" to create a new client secret and copy the value. After copying the value, return to the **Iru Web App Configuration** tab and follow steps 1-3 from the **Configuring Iru Endpoint Connection** section. Click on the ellipsis next to the SSO integration that was created earlier in this article. Choose **Edit**. Iru Endpoint ellipsis next to SSO integration Edit Click the **Edit client secret** button. Iru Endpoint Edit client secret button Paste the new **Client secret** value that was copied earlier. Click **Save**. Iru Endpoint Save after updating client secret Be sure to test the configuration by signing into the Iru Endpoint web app and choosing the Native SSO login option that was created. You'll want to test this with a private browser window/incognito window and verify that you are able to sign in to the Iru Endpoint web app. You can then optionally delete the previous client secret from the App registration in Entra ID. ### Setting Up Microsoft Entra ID Application Before starting the Microsoft Entra ID configuration, complete the initial setup in the **Iru Web App Configuration** tab to get the Redirect URL. You'll need this value to configure the Microsoft Entra ID application. Follow these steps to configure your Microsoft Entra ID application: Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). In the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **App registrations**. Click **+ New registration** to register a new application. Entra ID App registrations New registration In the **Name** field, specify a name for the application (such as "Iru Native SSO"). For "**Supported account types**," select **Accounts in this organizational directory only**. In the **Redirect URI** field, select **Web** from the dropdown menu. Enter the complete Redirect URL you copied from the Iru Web App Configuration (e.g., `https://vpriix.id.iru.com/federated-auth/oidc/callback`). Click **Register**. Entra ID Name Supported account types Redirect URI Register On the new page, copy the **Application (client) ID** and save this for later. This will be used as the **Client ID** in Iru. Entra ID Application client ID copy Click **Certificates and Secrets**. Click **New client secret**. Entra ID Certificates and Secrets New client secret Give the client secret a **Description** such as "Iru Native SSO." Set the expiration to **24 months**. Click **Add**. Entra ID Client secret Description expiration Add Copy the **Value** of the client secret, and save this for later. **Note that the client secret Value is distinct from the client secret ID.** Entra ID Copy client secret Value After completing the Microsoft Entra ID Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SSO connection using the Client ID and Client secret you copied from Microsoft Entra ID. ## Considerations **Security**: Ensure that your Microsoft Entra ID tenant has appropriate security policies configured for OAuth2/OpenID Connect authentication. **Client Secret Management**: Client secrets expire after 24 months and must be renewed regularly. Consider using SAML-based SSO for longer-term solutions. **Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization. **User Management**: Users must exist in both Microsoft Entra ID and Iru Endpoint to successfully authenticate via SSO. # Single Sign-On with Microsoft Entra ID (SAML) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-microsoft-entra-id-saml Configure SAML-based SSO between Microsoft Entra ID and Iru Endpoint. Set up the enterprise application in Entra and map user attributes for login. ### About Microsoft Entra ID SAML Integration Microsoft Entra ID SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with Microsoft Entra ID for users accessing Iru Endpoint through their Microsoft Entra ID credentials. #### How It Works When users attempt to access Iru Endpoint, they're redirected to Microsoft Entra ID for authentication. After successful authentication, Microsoft Entra ID sends a SAML assertion back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). Note: Microsoft Entra ID [is the new name](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/new-name) for Azure AD (Azure Active Directory) ### Setting Up the SAML Connection You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Microsoft Entra ID. After copying the Entity ID and ACS URL, switch to the [**Microsoft Entra ID Configuration**](#microsoft-entra-id-configuration) tab and continue with [**Configuring Microsoft Entra ID Application**](#configuring-microsoft-entra-id-application). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **SAML** for the Authentication method. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Entra ID configuration. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Entra ID configuration. Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL Keep the Iru Endpoint configuration modal open, then switch to the [**Microsoft Entra ID Configuration**](#microsoft-entra-id-configuration) tab to continue with [**Configuring Microsoft Entra ID Application**](#configuring-microsoft-entra-id-application). ### Configuring Iru Endpoint SAML Connection After completing the Microsoft Entra ID configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from Microsoft Entra ID. Go back to the Custom SAML modal in Iru Endpoint. Set **IdP attribute** to **Subject**. Leave **Attribute name** blank. Set **User attribute** to **User Principal Name (UPN)**. Paste the **Microsoft Entra Identifier** you copied earlier into the **IdP Entity ID** field. Paste in the **Sign In URL** you copied from Entra ID. Upload the **certificate** you downloaded from Entra ID. Iru Endpoint upload certificate from Entra ID Set the **Protocol Binding** to **HTTP-POST**. Ensure that the **Request Algorithm** is set to **RSA-SHA256**. Ensure that **Sign Request Algorithm Digest** is set to **SHA256**. Ensure that **Sign Request** is enabled. Set the **Response Signature Verification** to **Assertion**. Leave the **Destination** field blank. Set **Allowed Signature Algorithm** to **RSA-SHA256**. Set **Allowed Digest Algorithm** to **SHA256**. Click **Save**. Iru Endpoint Save for SAML configuration ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ## Considerations **Security**: Ensure that your Microsoft Entra ID tenant has appropriate security policies configured for SSO authentication. **User Management**: Users must exist in both Microsoft Entra ID and Iru Endpoint to successfully authenticate via SSO. **Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization. ### Testing the Integration Add a user to the **Admin Team** in Iru Endpoint by clicking **New User**. Fill in all of the corresponding user information. This user must exist in Microsoft Entra ID and must be assigned to the Iru Endpoint SSO app in your Microsoft Entra ID tenant. Click **Submit**. Once the invite is submitted, close the Invite User window. Refresh the Access page in Iru Endpoint. You should see the user you just added. Check the user's email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection. Before starting the Microsoft Entra ID configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Microsoft Entra ID application. ### Configuring Microsoft Entra ID Application Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). In the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **Enterprise apps**. Select **+ New application**. Entra ID Enterprise apps New application Select **Create your own application**. Entra ID Create your own application Give the application a **name**. Select **Integrate any other application you don't find in the gallery (Non-gallery)**. Click **Create**. Entra ID Name app Non-gallery Create Under **Manage**, select **Single sign-on**. Select the **SAML** tile. Entra ID Single sign-on SAML tile Click the **Edit** pencil in the Basic SAML configuration box Entra ID Edit Basic SAML configuration Click the Add Identifier link in the Identifier (Entity ID) section. Paste the Entity ID that you copied earlier into the Identifier (Entity ID) field. In the Reply URL (Assertion Consumer Service URL) section, paste the Assertion Consumer Services URL that you copied earlier. Click **Save**. Click the **X** at the top right of the pane to close it. Entra ID Identifier and Reply URL Save and close Leave the settings in the **Attributes & Claims section** set to their default. Click **Download** to download the Base 64 certificate in the SAML Certificates section. This certificate will be used in the Custom SAML configuration in Iru Endpoint. In the **Set up \[App Name]** section, copy the Login URL and paste it into a secure text document for later use. Copy the **Microsoft Entra Identifier** and save it in a text document. You will paste this into the **IdP Entity ID** field in Iru Endpoint. You can find this in the **Overview** section of your application. Entra ID Set up section Login URL and Microsoft Entra Identifier Go to **App registrations**. Select your newly created app. Entra ID App registrations select your app Navigate to the **Token configuration** section under **Manage**. Click **+ Add optional claims**. Entra ID Token configuration Add optional claims Check the **ID** radio button. Check the **acct** box. Check the **email** box. Check the **upn** box. Click **Add**. Entra ID Optional claims ID acct email upn Add Check the **Turn on the Microsoft Graph email, profile permission (required for claims to appear in token)** box. Click **Add**. Entra ID Turn on Microsoft Graph email profile permission Add The Microsoft Entra Identifier is used in the Iru configuration as the IdP Entity ID. ### Assigning Users and Groups In **Enterprise apps** navigate to your newly created app. Under **Manage**, select **Users and Groups**. On the menu, select **Add user/group**. Entra ID Users and Groups Add user or group On the **Add Assignment** dialog, select the link under **Users and groups**. Entra ID Add Assignment Users and groups link A list of users and security groups is displayed. You can search for a certain user or group, as well as select multiple users and groups that appear in the list. After you have selected your users and groups, select **Select**. Entra ID Select users and groups then Select Select **Assign** to finish assigning users and groups to the app. Entra ID Assign to finish assigning users and groups Confirm that the users and groups you added appear in the **Users and groups** list. Entra ID Users and groups list showing assigned users Alternatively, if you don't want to assign users and groups, you can set the app to not require assignment. Navigate to your newly created app in **Enterprise apps**. Click **Properties** under Manage. Set **Assignment required?** to **No**. Click **Save**. Entra ID Properties Assignment required No Save If you see a message about free tier limitations, it means that a free tier is being used. The Single Sign-On Enterprise App lets you add users (not groups) only. After completing the Microsoft Entra ID configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Microsoft Entra ID. # Single Sign-On with Okta (SAML) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-okta-saml Configure SAML-based SSO between Okta and Iru Endpoint. Create the SAML application in Okta and map user attributes for admin authentication. ### About Okta SAML Integration Single Sign-On with Okta (SAML) in Iru Endpoint lets you set up SAML-based SSO integration with Okta for users accessing Iru Endpoint through their Okta credentials. #### How It Works Okta SAML integration lets users authenticate to Iru Endpoint using their existing Okta credentials. Once configured, users can access Iru Endpoint through a single sign-on experience. The integration works by establishing a trusted relationship between Iru Endpoint and Okta, where Okta acts as the identity provider (IdP) and Iru Endpoint acts as the service provider (SP). When users attempt to access Iru Endpoint, they're redirected to Okta for authentication, and upon successful login, Okta sends a SAML assertion back to Iru Endpoint confirming the user's identity. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### Setting Up the SAML Connection You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Okta. After copying the Entity ID and ACS URL, switch to the [**Okta Configuration**](#okta-configuration) tab and continue with [**Configuring Okta Application**](#configuring-okta-application). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **SAML** for the Authentication method. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Okta configuration. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Okta configuration. Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL Keep the Iru Endpoint configuration modal open, then switch to the [**Okta Configuration**](#okta-configuration) tab to continue with [**Configuring Okta Application**](#configuring-okta-application). ### Configuring Iru Endpoint SAML Connection After completing the Okta configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from Okta. Go back to the Custom SAML modal in Iru Endpoint. Set **IdP attribute** to **Subject**. Leave **Attribute name** blank. Set **User attribute** to **User Principal Name (UPN)**. Paste the Single Sign-On URL you copied from Okta into the **Sign In URL** text field. Paste the **Issuer** information you copied from Okta into the **IdP Entity ID** field. Upload the Okta certificate you downloaded earlier. Iru Endpoint upload Okta certificate Set the **Protocol Binding** to **HTTP-POST**. Ensure that the **Request Algorithm** is set to **RSA-SHA256**. Ensure that **Sign Request Algorithm Digest** is set to **SHA256**. Ensure that **Sign Request** is enabled. Set the **Response Signature Verification** to **Assertion**. Leave the **Destination** field blank. Set **Allowed Signature Algorithm** to **RSA-SHA256**. Set **Allowed Digest Algorithm** to **SHA256**. Click **Save**. Iru Endpoint Save for SAML configuration ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Testing the Integration Add a test user to the **Admin Team** in Iru Endpoint by clicking **New User**. Fill in all of the corresponding user information. This user must exist in Okta and must be assigned to the Okta SSO app in your Okta tenant. Click **Submit**. Once the invite is submitted, close the Invite User window. Refresh the Access page in Iru Endpoint. You should see the user who was added. Go to the user's email to accept the invite and log in with the new SAML SSO connection. Before starting the Okta configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Okta application. ### Configuring Okta Application In a new browser tab, log in to the **Admin Console** in your Okta tenant. On the left-hand side, click the reveal triangle next to **Applications**, then click **Applications**. Click **Create App Integration**. Okta Admin Console Create App Integration Select **SAML 2.0** as the app integration type. Click **Next**. Okta Select SAML 2.0 and Next Enter an **App name**. Upload an optional **App logo**. Click **Next**. Okta App name and App logo and Next In the **Single sign-on URL** field, paste the Iru Endpoint Assertion Consumer Service URL that was copied earlier. In the **Audience URI (SP Entity ID)** field, paste the Iru Endpoint Entity ID that was copied earlier. Ensure that the **Name ID format** is set to **Unspecified**. Ensure that the **Application username format** is set to **Email**. Ensure that **Update application username on** is set to **Create and update**. Select **Next**. Okta SAML Single sign-on URL Audience URI and Next Select **This is an internal app that we have created**. Click **Finish**. Okta This is an internal app and Finish Back at the **Sign On** tab, find the link to **View SAML setup instructions** and open it in a new browser tab. Okta Sign On tab View SAML setup instructions Copy the **Identity Provider Single Sign-On URL** and save it in a text document for later use in Iru Endpoint. Copy the **Identity Provider Issuer** information and save it in a text document. You will paste this into the **IdP Entity ID** field in Iru Endpoint. Download the certificate file and save it for use in Iru Endpoint. Okta SAML setup instructions and download certificate ### Assigning Users to the Okta App Go back to the Okta app and click the **Assignments** tab. Click the **Assign** dropdown menu and click **Assign to People** or **Assign to Groups**. Okta app Assignments tab with Assign dropdown for Assign to People or Assign to Groups Search for users or groups to assign. Click **Assign** next to the user or group. Okta Assign next to user or group Click **Save and Go Back**. Okta Save and Go Back after assigning user Once the user is assigned, click **Done**. Okta Done to complete user assignment You should see the users or groups that you have selected in the list. Okta Assignments list showing assigned users or groups After completing the Okta Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Okta. # Single Sign-On with OneLogin (SAML) Source: https://docs.iru.com/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-onelogin-saml Configure SAML-based SSO between OneLogin and Iru Endpoint. Create the SAML application in OneLogin and map user attributes for admin authentication. ### About OneLogin SAML Integration Single Sign-On with OneLogin (SAML) in Iru Endpoint lets you set up SAML-based SSO integration with OneLogin for users accessing Iru Endpoint through their OneLogin credentials. #### How It Works OneLogin SAML integration lets users authenticate to Iru Endpoint using their existing OneLogin credentials. Once configured, users can access Iru Endpoint through a single sign-on experience. The integration works by establishing a trusted relationship between Iru Endpoint and OneLogin, where OneLogin acts as the identity provider (IdP) and Iru Endpoint acts as the service provider (SP). When users attempt to access Iru Endpoint, they're redirected to OneLogin for authentication, and upon successful login, OneLogin sends a SAML assertion back to Iru Endpoint confirming the user's identity. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment). ### Setting Up the SAML Connection You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for OneLogin. After copying the Entity ID and ACS URL, switch to the [**OneLogin Configuration**](#onelogin-configuration) tab and continue with [**Configuring OneLogin Application**](#configuring-onelogin-application). In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Screenshot of the account menu with Access option highlighted Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**. Click **+ Authentication method**. Enter a display name for the SSO Connection. Select **SAML** for the Authentication method. Click **Create**. Click **Configuration information** if that section is not already expanded. Copy the **Service provider entity ID** into a text document for later use. You'll need this for the OneLogin configuration. Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the OneLogin configuration. Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL Keep the Iru Endpoint configuration modal open, then switch to the [**OneLogin Configuration**](#onelogin-configuration) tab to continue with [**Configuring OneLogin Application**](#configuring-onelogin-application). ### Configuring Iru Endpoint SAML Connection After completing the OneLogin configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from OneLogin. Go back to the Custom SAML modal in Iru Endpoint. Set **IdP attribute** to **Subject**. Leave **Attribute name** blank. Set **User attribute** to **User Principal Name (UPN)**. Paste the **Issuer URL** you copied from OneLogin into the **IdP Entity ID** field. Paste the **SAML 2.0 Endpoint (HTTP)** URL you copied from OneLogin into the **IdP Single Sign-on URL** field. Upload the OneLogin certificate you downloaded earlier. Iru Endpoint upload OneLogin certificate Set the **Protocol Binding** to **HTTP-POST**. Ensure that the **Request Algorithm** is set to **RSA-SHA256**. Ensure that **Sign Request Algorithm Digest** is set to **SHA256**. Ensure that **Sign Request** is enabled. Set the **Response Signature Verification** to **Assertion**. Leave the **Destination** field blank. Set **Allowed Signature Algorithm** to **RSA-SHA256**. Set **Allowed Digest Algorithm** to **SHA256**. Click **Save**. Iru Endpoint Save for SAML configuration ### Allow for Tenant Authentication Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). ### Limit Authentication to Domain When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains. ### Enforcing Single Sign-On Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions. ### Testing the Integration Add a test user to the **Admin Team** in Iru Endpoint by clicking **New User**. Fill in all of the corresponding user information. This user must exist in OneLogin and must be assigned to the Iru Endpoint SSO app in your OneLogin tenant. Click **Submit**. Once the invite is submitted, close the Invite User window. Refresh the Access page in Iru Endpoint. You should see the user you added. Go to the user's email to accept the invite and log in with the new SAML SSO connection. Before starting the OneLogin configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the OneLogin application. ### Configuring OneLogin Application In OneLogin, create a new app using the **Add SAML Custom Connector (Advanced)** app. Navigate to: ``` https://{YourSubdomain}.onelogin.com/apps/new/110016 ``` Set the **name**. Set whether the app should be visible in the portal. Set the **icons** for the app. Set the **Description**. Click **Save**. OneLogin app name portal visibility icons description Save Click the **Configuration** tab. Paste the **Iru Entity ID** (Service provider entity ID) into the **Audience (EntityID)** field. Paste the **Iru ACS URL** (Assertion consumer service URL) into the **Recipient**, **ACS (Consumer) URL Validator**, and **ACS (Consumer) URL** fields. OneLogin Configuration Audience Entity ID Recipient ACS URL Set the **SAML initiator** to **OneLogin**. Set the **SAML nameID format** to **Email**. Set the **SAML issuer type** to **Generic**. Set the **SAML signature element** to **Assertion**. OneLogin SAML initiator nameID format issuer signature Assertion Click the **Parameters** tab. Ensure that the **Name ID** value is set to **Email**. OneLogin Parameters Name ID set to Email Click the **SSO** tab. Set the **SAML Signature Algorithm** to **SHA-256**. Copy the **Issuer URL** and save it. You will paste this into the **IdP Entity ID** field in Iru Endpoint. Copy the **SAML 2.0 Endpoint (HTTP)** URL and save it. You will use this for the **IdP Single Sign-on URL** in the Iru configuration. Click **Save**. OneLogin SSO tab Issuer URL SAML 2.0 Endpoint Save Click the **SSO** tab. Click **View Details**. OneLogin SSO tab View Details for certificate Click **Download**. OneLogin Download certificate After completing the OneLogin Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from OneLogin. # Auto Apps Overview Source: https://docs.iru.com/en/endpoint/library/auto-apps/auto-apps-overview Deploy pre-packaged Auto Apps to Mac and Windows devices from Iru Endpoint. Browse available apps, configure settings, and assign to Blueprints. This feature is available for Mac computers and Windows devices Auto Apps are pre-packaged applications that you can deploy directly from the Iru Endpoint Web App. Iru manages installation, updates, and configuration profiles automatically, so you can ensure applications remain compliant and up to date with minimal effort. Auto apps deploy to the system, meaning they are installed for all users on the device. If a user has installed a version of the app in their own profile, it will not be updated or managed by the Auto Apps process. ### What are Auto Apps? Auto Apps are pre-packaged applications from software vendors that Iru Endpoint manages automatically. Instead of manually downloading, packaging, and deploying applications, you can select from a curated list of business applications that Iru maintains and updates. ### How Auto Apps Work Iru Endpoint maintains relationships with software vendors to provide pre-packaged, tested versions of popular business applications. When you deploy an Auto App, Iru handles the entire lifecycle: * **Download and validation** from the vendor's official source * **Automatic updates** when new versions are released * **Platform-specific configuration** for macOS and Windows * **Security validation** including code signing verification * **Profile management** for required system permissions ## Auto Apps Capabilities Windows and macOS Auto Apps are listed as separate Library Items. You configure and assign each platform’s version independently (for example, a Chrome Auto App for Windows and a Chrome Auto App for macOS are two distinct Library Items). In the Iru Endpoint Web App you configure: * **Automated Updates**: Iru enforces updates for these applications according to your configuration. * **[Label](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels)**: Distinguish multiple instances of the same Auto App in the Iru Endpoint Web App (e.g., by Blueprint or behavior). * **Blueprint assignment**: Control which devices or users receive the Auto App. * **Installation method**: **Continuously enforce** (install and keep up to date), **Install on-demand from Self Service**, or **Update only** (enforce updates only when the app is already installed). * **Self Service**: When the app can be offered in Self Service: category, **Recommended** placement, and customization such as custom name, description, and an optional support or documentation link on the item detail page. * **Version enforcement:** Choose whether updates are unmanaged, automatically enforced after release (with timeframe and time), or a minimum version is enforced with a deadline. Settings differ by platform. Select **macOS** or **Windows** below for platform-specific options and step-by-step configuration guides. ### macOS-Specific Capabilities * **Background Items**: Auto Apps automatically configure background processes. * **Customizable Notifications**: You can manage how notifications behave for each app. * **Privacy Preferences Policy Control**: Iru installs required profiles to ensure apps comply with privacy settings. * **Rosetta 2 for Apple Silicon**: If required, the Iru Agent will install Rosetta 2 automatically. * **System Extensions and Kernel Extensions**: Required extensions are automatically approved. * **Version enforcement**: In addition to the shared options, you can use **Manually enforce a specific version** and [**Phased rollout**](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#phased-rollout). For all macOS Auto App settings, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos). ### Windows-Specific Capabilities * **Architecture Support**: Many Auto Apps are available in both ARM64 and x64 versions. x64 apps can generally run in emulation mode on ARM64 devices if no native ARM64 app exists. * **Self Service customization**: You can configure optional support or documentation links on the app details view in Self Service. Enforcement always runs in each device's local time zone (no separate time zone selector). For all Windows Auto App settings, see [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows). For a full list of available Auto Apps, see the **Library Items** section of the Iru Endpoint Web App. ## Setting Up Auto Apps Go to **Library** and select **Add Library Item**. For more information about the Library interface, see [Library Overview](/en/endpoint/library/library-items-profiles/library-overview). Click the **Auto Apps** category on the left. Use the **Supported on** filter at the top of the section to choose **Mac** or **Windows**. Search for and select the desired Auto App from the available options. Optionally add a **Label** to distinguish multiple versions of the same app. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. Select the **Blueprint(s)** to assign the Auto App to. ### Installation Configuration Configure how Auto Apps are deployed to devices: * **Continuously Enforce** - Automatically install and maintain the app * **Install-on-demand from Self Service** - Make available for users to install * **Update Only** - Only update existing installations ### Self Service Configuration When enabling Self Service availability, you can select a **Category** and customize the user experience. ### Version Enforcement Choose how updates are managed: * **Do not manage updates** - Let apps update through their own mechanisms * **Automatically enforce new updates** - Deploy updates as they become available * **Manually enforce a minimum version** - Set a minimum version floor with a deadline When enforcing updates, configure the **Enforcement timeframe** or deadline and time. On macOS you select an Enforcement Time Zone (including **Device's Local Timezone**); on Windows enforcement always uses each device's local time. The tabs below cover platform-specific options; for full configuration steps, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos) and [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows). ### macOS-Specific Configuration In addition to the shared **Version enforcement** options, you can use **Manually enforce a specific version** and **Phased rollout**. For details, see [Enforcement](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#enforcement) in Understanding Auto App Settings for macOS. #### Notification Management You can manage notification settings for Auto Apps on macOS. When managing notifications, users cannot change the settings you configure. When notification settings are modified, an updated Configuration Profile will not be redistributed until the next daily MDM check-in. To trigger an immediate check-in, run `sudo update-mdm` locally on the Mac. **Notification Options:** * **Unmanaged** - End users control notification settings for this app * **Disallow notifications** - Prevent users from turning notifications on * **Allow notifications** - Force notifications on with customization options If an Auto App does not support notifications, you'll see: "This application does not support notifications." #### Additional macOS Options * **Add to Dock during install** * **Preinstall** or **Postinstall** scripts For all macOS Auto App settings and step-by-step configuration, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos). ### Windows-Specific Configuration You can customize how Auto Apps appear in Self Service on Windows, including optional support or documentation links on the app details view. Enforcement time is always in the device's local time zone. For all Windows Auto App settings and step-by-step configuration, see [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows). ## Update Only Mode Use **Update Only** when you don't want Iru to deploy an app but still want to enforce updates for existing installations. * Updates apply if the app is already installed (based on matching Bundle ID for macOS and custom detection logic for Windows) * The app will not be newly installed by Iru * No configuration profiles (e.g., PPPC, System Extensions, Notifications) will be deployed for macOS ## Considerations ### Update Enforcement When enforcement options are chosen and an application is below the required minimum version, setting the installation method to "Update Only" ensures that updates are applied to applications installed outside of Iru, as long as the Bundle ID (macOS) or the custom detection logic Iru uses for Windows matches. This setting will not install the app via Iru if it's not already present; it will only keep the app up to date. Similarly, when enforcement options are selected and the application version is below the minimum enforced version, setting the installation method to Install on-demand from Self Service will also apply updates to applications installed outside of Iru, provided the Bundle ID on macOS or custom Windows detection logic matches. ### Update Process When a new update is released, Iru caches it on assigned devices. You must select an Enforcement Time to determine when to enforce the update. #### macOS Update Process With **Phased rollout** enabled (**Automatically enforce new updates**, **Manually enforce a minimum version**, or **Manually enforce a specific version**), devices are offered the update gradually over the rollout period instead of all at once. The enforcement deadline can use a named time zone or **Device's Local Timezone**. After the app is successfully cached, if the app is running, users are notified of the pending installation. If the app is not running, Iru Agent will update the app silently without requiring any user interaction. Per-device phased rollout timing is shown in the Library Item **Status** tab. For configuration details, see [Enforcement](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#enforcement) in Understanding Auto App Settings for macOS. #### Notifications If Auto App updates are configured to be managed, they will automatically install a profile via MDM to allow the application to receive notifications. For enforcement timing and notification options, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos). #### Windows Update Process If the app is open during installation, the update may not finish until the user closes it or the enforcement deadline arrives. Pending **Auto App** and **Windows Custom App** updates appear in the Iru system tray **Updates** list; users can install from there or let **Iru Agent** retry silently about every **15 minutes** in the background. The close-app dialog appears when a user clicks **Update** or **Update All** in the tray while the app is still open, not during background attempts. End-user details are in [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray). Enforcement always runs in the device's local time zone. For enforcement and Self Service options, see [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows). ## Adding Multiple Auto Apps to Your Library Iru allows you to add the same Auto App to your Library multiple times. This feature is useful when configuring different settings for various Blueprints. For instance, you can set up an Auto App to automatically install on devices within one Blueprint while making it available in Self Service for another. When you configure the same Auto App multiple times, you can add a **Label**. This label helps distinguish each Auto App Library Item from others in your Library. These labels are not visible to end users but are displayed throughout the Iru Endpoint Web App. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. ## Auto App Security Information Auto Apps come directly from their respective software vendors. Iru ensures the fidelity of all updates by performing strict signature validations during download and packaging. ### Code Signing Confirmation * Iru affirms that the application code is properly signed using an Apple-issued certificate. * Iru verifies that the Apple-assigned Team Identifier matches the known identity of the registered developer. * Iru validates that the code signing identifier for the app bundle exactly matches the expected value. * Iru assesses notarization to certify that there are no code-signing issues and that the software is free of known malicious content. ### Signing Authority Validation As part of the internal QA process, Iru confirms the signing authority for Auto Apps. This process establishes a chain of trust: the app's signing certificate was issued by Apple's intermediate and root certificate authorities. It guarantees that the Auto App's code signature precisely matches the developer's name and identifier. These values, issued by Apple, cannot be spoofed or falsified. All Auto App installers are signed with valid Developer ID certificates issued by Apple under the registered Apple Developer program used by Gatekeeper. These certificates, issued either to Iru or a third-party vendor, establish a trust relationship that verifies the integrity of the installer. ### Security Validation * Iru performs certificate validation for installers. * Iru confirms the installer integrity using a SHA-256 hash check. These processes ensure that Auto Apps originate from trusted sources and have not been tampered with prior to deployment. ## User Experience For details on how users interact with Auto Apps, see [User Experience with Auto Apps](/en/endpoint/library/auto-apps/user-experience-with-auto-apps). On Windows, pending **Auto App** and **Windows Custom App** updates appear in the Iru system tray, and users can respond to close-app prompts when they start an update from the tray. See [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray) for the end-user experience. ## Migrating from a Custom App If you previously deployed an app as a **Custom App**, you can migrate to Auto Apps for better management and automatic updates. For more information about Custom Apps, see [Custom Apps Overview](/en/endpoint/library/library-items-profiles/custom-apps-overview). Add the Auto App to the same Blueprint. Deploy the Auto App. Iru will not overwrite an existing installation but will apply update enforcement if needed. Delete or deactivate the Custom App item. For macOS, remove any related System Extension or PPPC profiles. Auto Apps include required profiles automatically. ## Requesting New Auto Apps You can suggest new Auto Apps from the account menu. Suggested apps must not be available in the Mac App Store, Apple Business, or Apple School Manager and must be business or enterprise applications. For more details, see [Submit Feature Requests & Ideas](/en/endpoint/settings/submit-feature-requests-and-ideas). In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Organization**. Click the **Resources** tab. Click the **Auto App request** button to submit your request. ## Best Practices Test Auto Apps on a small group of devices before rolling out to your entire fleet. Set up monitoring to track Auto App update deployments and any issues. Communicate with users about Auto App deployments and update schedules. Regularly review and update Auto App versions to ensure security and compatibility. ### Related Articles Configure version enforcement, notifications, and install options for Auto Apps on macOS Configure installation, Self Service, and update enforcement for Auto Apps on Windows What to expect when using Auto App updates and Self Service Curate, create, and manage Library Items and add them to Blueprints Learn how to submit feature requests and ideas for Iru Endpoint Deploy custom applications to Mac and Windows devices Step-by-step setup for Mac Custom Apps (PKG, DMG, ZIP) Step-by-step setup for Windows Custom Apps (MSI, EXE) # Suppressing Helper Tool Installation Prompts Source: https://docs.iru.com/en/endpoint/library/auto-apps/suppressing-helper-tool-installation-prompts Reduce macOS helper tool installation prompts during app updates by managing updates through MDM or deploying a Custom Script on Mac computers. This guide applies to Mac computers ### What are Helper Tools? Helper tools in macOS let applications perform privileged operations without running the full app with elevated privileges. They handle tasks that need higher permissions than the main application, such as managing file permissions, creating or deleting files, opening privileged ports, and modifying system settings. ### How Helper Tools Work A helper tool runs as a separate process with elevated privileges while the main application runs as a standard user. When the app needs a privileged operation, it calls the helper tool to perform it. ### When to Expect Prompts about Helper Tools On macOS, apps in the system **Applications** folder require administrator credentials to update, regardless of how they were installed. If an app checks for updates automatically, standard users may be prompted for administrator authentication so a helper tool can install the update. Users with administrator credentials should not see these prompts. ### How to Avoid Helper Tool Prompts Manage app updates through MDM when you can. Some vendors provide an MDM payload to disable automatic update checks; others need a scripted solution. Contact the vendor if you are unsure what a given application supports. For MDM in Iru, see [MDM Overview](/en/endpoint/agent/iru-agent-and-mdm). Iru also maintains a Custom Script to suppress helper tool prompts for many Auto App titles. The method for disabling automatic updates varies by application. Not all titles support it. ### Suppress App Update Helper Tool Prompts This solution applies to macOS apps that prompt for administrator credentials to add a helper tool for a pending update. It will not cover every scenario, but it prevents most update helper tool prompts. If end users must enter administrator credentials to update apps outside the Auto Apps catalog, consider [KAPPA](https://github.com/kandji-inc/KAPPA/), [kpkg](https://github.com/kandji-inc/kpkg), [AutoPkg](https://github.com/autopkg/autopkg), or [Installomator](https://github.com/Installomator/Installomator) to apply updates per your organization policy. Many third-party apps try to add helper tools when a new version is available. macOS then shows an authorization prompt for administrator credentials. Without those credentials, the user may not be able to finish the update. Iru provides `suppress_helper_prompts.zsh` in the [Support GitHub repository](https://github.com/kandji-inc/support/tree/main/Auto%20App%20Resources/Suppress%20Update%20Helper%20Tools). The script changes one authorization right in the macOS authorization database (`com.apple.ServiceManagement.daemons.modify`) so non-root processes are denied silently before the helper prompt appears. Root processes, including `mdmclient` and the **Iru Agent**, are not affected. Iru continues to deliver settings and Auto App updates as expected. The change persists across logins, logouts, restarts, OS updates, and major upgrades, and it is reversible. See the project [README](https://github.com/kandji-inc/support/tree/main/Auto%20App%20Resources/Suppress%20Update%20Helper%20Tools) for details. #### Deploy the script To add this Library Item, see [Library Overview](/en/endpoint/library/library-items-profiles/library-overview). For execution frequency and audit script options, see [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview). Copy the contents of `suppress_helper_prompts.zsh` from the [Support GitHub repository](https://github.com/kandji-inc/support/blob/main/Auto%20App%20Resources/Suppress%20Update%20Helper%20Tools/suppress_helper_prompts.zsh). In **Library**, click **Add Library Item**, select **Custom Script**, then click **Add and configure**. Give the Custom Script Library Item a **Name**. Assign the Library Item to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Test with a subset of devices first. Select **Install once per device** as the **Execution Frequency**. The setting persists after the first successful run. Because the script is idempotent, you can use **Run daily** instead if you prefer. Paste the script into the **Audit Script** field. Click **Save**. # Understanding Auto App settings for macOS Source: https://docs.iru.com/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos Configure Auto App settings for macOS in Iru Endpoint, including version enforcement, phased rollouts, update notifications, and Self Service availability. This guide applies to Mac computers Auto App settings for macOS control how the application is installed, how it appears in Self Service, how updates are enforced, and optional install behavior (such as adding the app to the Dock). For Auto App settings on Windows, see [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows). ## Label Add a **Label** to distinguish this Library Item from other instances of the same Auto App (e.g., "For Marketing, Notifications Off"). Labels are not displayed to end users; they appear only in the Iru Endpoint Web App. Use labels when you add the same Auto App multiple times with different Blueprint assignments or settings. For steps that apply to any Library Item, see [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview. ## Assignment (Blueprint) Under **Assignment** → **Assignment Maps**, use **Blueprint** and **+ Assign** to control which devices or users receive this Auto App. Assign the Library Item to the Blueprint(s) that should receive it. ## Installation Method Under **Installation**, choose how the Auto App is installed: * **Continuously enforce**: The app is installed and kept up to date automatically on assigned devices. * **Install on-demand from Self Service**: The app is not pushed; users install it from Self Service when ready. * **Update only**: Updates are enforced if the app is already installed, but the app is not installed on new computers and is not made available in Self Service. ## Self Service Under **Self Service**, add this Library Item to Self Service by turning on the **Available in Self Service** toggle. Then configure: * **Category**: Specify the Self Service category this Library Item displays under. Categories help users find apps in the Self Service library. Recommended items are also displayed in a "Recommended" section at the top of the Self Service library page and categories list. * **Recommended**: When selected, the item appears in that Recommended section. Use **Customize** to change the name and content that display in Self Service (see Self Service customization below). Use **Collapse previews** to show or hide the preview cards of how the item will appear. ### Self Service Customization Click **Customize** to change the name and content that display in Self Service. The description is shown on the item detail page in Self Service. Turn on the toggle to override the default Library Item name displayed in Self Service. Enter a custom name (maximum 30 characters). Turn on the toggle to show a description on the item detail page. Choose **Display provided description** (from the Auto App) or **Display custom description** (up to 4,000 characters). A **Copy** button is available to copy the provided description. Optionally check **Require users to read the description before installing** so users must view the description before they can install. Turn on the toggle to include a support article or documentation link on the item detail page. Set **Text button label** (e.g., "More information"; maximum 32 characters) and **Button URL**. Any URL scheme recognized by the OS can be used, including **https\://**, **mailto://**, and **file://**. ## Enforcement Under **Version enforcement**, choose how updates are managed for the Auto App. The controls below appear in the Library Item in this order, depending on the option you select. ### Do not manage updates Iru installs the latest available version of the Auto App but does not update existing installations as new versions are released. ### Automatically enforce new updates With this option, updates are enforced automatically after release and Iru installs the latest update of the Auto App. Under **Enforcement timeframe**, select how long after an update is released before it is enforced: **Available options:** 1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, 3 months Then set the time zone and time as described in [Time zone and time](#time-zone-and-time), and optionally configure [Phased rollout](#phased-rollout). At the bottom of the **Enforcement** section, the Library Item shows the current minimum allowed version and the upcoming schedule of when newer versions will be enforced based on the **Enforcement timeframe**. ### Manually enforce a minimum version Specify a **Minimum version** (the floor) for the Auto App. Useful for critical security updates or aligning devices to a version by a date. With this option, Iru installs the latest update on devices below the minimum; it does not leave devices on the minimum version if a newer update is available. Configure [Enforcement deadline](#enforcement-deadline), [Time zone and time](#time-zone-and-time), and optionally [Phased rollout](#phased-rollout). ### Manually enforce a specific version Under **Select a version**, choose the exact Auto App version to enforce, including a version lower than the latest available. This is the only Version enforcement option that does not always update devices to the latest version of the Auto App. Configure [Enforcement deadline](#enforcement-deadline), [Time zone and time](#time-zone-and-time), and optionally [Phased rollout](#phased-rollout). ### Enforcement deadline Set the date by which the version requirement must be met, then set the time zone and time as described in [Time zone and time](#time-zone-and-time). ### Time zone and time These controls appear under **Enforcement timeframe** or **Enforcement deadline**, depending on the option. Select a named time zone or **Device's Local Timezone**, then choose the time of day. For a named time zone, enforcement is determined server-side from that zone (for example, 5:00 PM PST). For **Device's Local Timezone**, the selected time applies in each device's local time. The update is cached on devices. Iru tries to install it automatically if the app is closed. If the app is open, users can voluntarily update before the enforcement time. ### Phased rollout Optionally select **Enable phased rollout**, then set **Rollout window (hours)** to a whole number between **24 and 168** hours (1-7 days). Devices are offered the update gradually over that window, which helps reduce download and caching spikes for large installers. Initial installs are not affected. When phased rollout is enabled, Iru uses an algorithm that considers the configured rollout window together with device-specific data to determine when each device becomes eligible. Per-device timing appears in the Library Item **Status** tab. For more, see [Library Item Status Activity Timeline](/en/endpoint/library/library-items-profiles/library-item-status-activity-timeline). If [Vulnerability Response](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) settings are in use, they override the **Phased rollout** settings. ## Auto App Notifications When notification settings are modified, an updated Configuration Profile is not redistributed until the next daily MDM check-in. To trigger an immediate check-in, run **sudo update-mdm** on the client Mac. * **Unsupported**: If an Auto App does not post to Notification Center, notifications are not available to customize. * **Unmanaged**: End users control notification settings. This is the default when an Auto App is added and configured for the first time. * **Managed**: A Configuration Profile with a notifications payload is installed alongside the Auto App. Use the following steps to configure it: Turn on the toggle to enforce management of notifications for the Auto App. Set whether notifications are **allowed** or **disallowed**. If disallowed, no further options are available and notifications are disabled for the Auto App. Select **None** (available in Notification Center only), **Banner** (default; upper-right corner, auto-dismiss), or **Alert** (stays until dismissed). Optionally enable **critical alerts** so the app can ignore Do Not Disturb and ringer settings. Toggle **Show notifications on lock screen** and **Show in Notification Center**. Toggle **Badge app icon** and **Play sound for notifications**. Choose **Always**, **When unlocked**, or **Never**. Choose **Automatic** (default), **By app**, or **Off**. If notification settings are updated from **Managed** to **Unmanaged**, when the user is prompted to allow notifications depends on the Auto App (e.g., when the app opens or when it next posts). If an Auto App was configured before this customization existed, edit and save the Library Item so that the granular notification controls apply. ## Options At the end of the Auto App configuration, the **Options** section includes the following: * **Add to Dock during install**: When enabled, Iru adds the app icon to the Dock during initial app install, or during re-install if the app is found to be missing. Iru does not automatically re-add the icon to the Dock if the app is updated. * **Run preinstall script**: The script runs before the app is installed. It must have an exit code of 0 to be considered successful. * **Run postinstall script**: The script runs after the app is installed. It must have an exit code of 0 to be considered successful. ## Related Articles Deploy pre-packaged applications across platforms Configure installation, Self Service, and update enforcement for Auto Apps on Windows # Understanding Auto App Settings for Windows Source: https://docs.iru.com/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows Configure Auto App settings for Windows in Iru Endpoint. Control installation behavior, Self Service availability, and update enforcement policies. This guide applies to Windows devices Auto App settings for Windows control how the application is installed, how it appears in Self Service, and how application updates are enforced. For macOS-specific settings, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos). For what end users see when pending **Auto App** or **Windows Custom App** updates are available, including the Iru system tray **Updates** list, [when a running app must close first](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#when-an-app-must-close), and [enforcement deadlines](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#enforcement-deadline), see [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray). ### Label Add a **Label** to distinguish this Library Item from other instances of the same Auto App (e.g., "For Marketing"). Labels are not displayed to end users; they appear only in the Iru Endpoint Web App. Use labels when you add the same Auto App multiple times with different Blueprint assignments or settings. For steps that apply to any Library Item, see [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview. ### Blueprint Assignment Use **Blueprints** and **Assign** to control which devices or users receive this Auto App. Assign the Library Item to the Blueprint(s) that should receive it. ### Installation Method Under **Settings**, choose how the Auto App is installed: * **Install and Continuously Enforce:** The app is installed and kept up to date automatically on assigned devices. * **Install on-demand from Self Service:** The app is not pushed; users install it from Self Service when ready. * **Update Only:** Updates are enforced if the app is already installed, but the app is not installed on new computers and is not made available in Self Service. An **Available in Self Service** toggle controls whether the item appears in the Self Service catalog when the installation method allows it. ### Self Service When the Auto App can be offered in Self Service, you can configure: * **Available in Self Service:** Toggle visibility in the Self Service catalog. * **Category:** Self Service category this Library Item displays under. Categories help users find apps in the Self Service library. * **Recommended:** When selected, the item also appears in a "Recommended" section at the top of the Self Service library and in the categories list. #### Self Service Customization Click **Customize** to open the Self Service customization options. The description is displayed on the item detail page in Self Service. * **Customize name:** Override the default Library Item name displayed in Self Service (toggle on to enable). * **Display a description:** Show a description on the item detail page. Choose **Display provided description** (from the Auto App) or **Display custom description** (up to 4,000 characters). A **Copy** button is available to copy the provided description. * **Display a link:** Add a support article, documentation, setup instructions, or support portal link on the item detail page in Self Service. When enabled, set: * **Text button label:** Label for the button (e.g., "More information"). Maximum 32 characters. * **Button URL:** Any URL scheme recognized by the OS can be used, including **https\://**, **mailto://**, and **file://**. ### Enforcement (Update Management) Under **Enforcement**, choose whether updates are not managed, are automatically enforced after release, or a minimum application version is enforced. When enforcement is used, the latest update of the Auto App is always installed on devices below the required version. Updates are cached on devices and users can voluntarily update before the enforcement deadline. **Windows Auto App updates are always enforced in the device’s local time zone.** The time you set is applied in each device’s local time, not server time. #### Do Not Manage Updates Iru Endpoint does not enforce a specific version of the application. Existing installations are left as-is. #### Automatically Enforce New Updates Updates are enforced automatically after release. Configure the **Enforcement Timeframe** (how long after release) and **Enforcement Time** (time of day). Enforcement occurs at that time in each device’s local time zone. The interface shows the currently enforced (minimum allowed) version. Select the **Enforcement Timeframe**, the amount of time after an update is released before it is automatically enforced. **Available options:** 1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, 3 months Select the **Enforcement Time** (e.g., 12:00 PM). Enforcement occurs at this time in each device's local time zone. The interface shows the currently enforced version (e.g., "App 25.1.20937.0 is currently the minimum allowed version"). If you enforce an older version, you may see when newer version(s) will be enforced. #### Manually Enforce a Minimum Version Specify a minimum version (the "floor") and an enforcement deadline (date and time). Useful for critical security updates or aligning all devices to a version by a date. The latest update is always installed for devices below the minimum. Enforcement occurs at the specified time in each device’s local time zone. Select the **Minimum Version** from the dropdown. Devices that do not meet this requirement receive the update so they reach at least this version. Set the **Enforcement Deadline** (date and time) by which the minimum version must be met. Updates are cached and users can voluntarily update before this deadline. ### Related Articles Deploy pre-packaged applications across platforms Configure version enforcement, notifications, and install options for Auto Apps on macOS # User Experience with Auto Apps Source: https://docs.iru.com/en/endpoint/library/auto-apps/user-experience-with-auto-apps See what users experience when Auto Apps install or update on their devices. Understand notifications, deferral options, and Self Service interactions. This guide applies to Mac computers and Windows devices On macOS, if the app is open when an **Auto App** update is available, the user sees a notification that an update is available and is prompted to close the application so the update can install. On Windows, **Iru Agent** installs a required **Auto App** update without extra steps when no configured blocking processes are running. Pending **Auto App** and **Windows Custom App** updates also appear in the Iru system tray **Updates** list. See [App updates in the Iru system tray](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray) in **User Experience with Windows Apps**. If an install or update you start from the tray waits on a running app, you may see the [close-app flow](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#when-an-app-must-close) described there. ### How Auto App Updates Work Auto App updates are managed automatically by the Iru Agent running on each device. The update process varies depending on whether the application is currently running and which platform the device is using. ### Silent Updates When an Auto App update is available and the application is not currently running, Iru Agent will: * Download the update in the background * Install the update silently without user interaction * Complete the update process automatically ### User-Initiated Updates When an Auto App update is available and the application is currently running, users will see a notification indicating that an update is available. The system will prompt the user to close the application to allow the update. Once the app is closed, the update installs automatically and users receive confirmation when the update is complete. ### Self Service Updates Users can also manually check for and install Auto App updates through Iru Self Service. Open **Iru Self Service** and look for available app updates in the main list of available apps. Click **Update** to install available updates. For more information about Self Service, see [Self Service Overview](/en/endpoint/settings/self-service/self-service-settings). ### Silent Updates When Nothing Blocks the Install When no configured blocking processes are running, Auto App updates on Windows typically: * Download automatically in the background * Install without extra user steps * Complete without separate notifications ### Updates in the Iru system tray Pending **Auto App** updates appear in the **Updates** section of the Iru system tray app. You can update apps individually, use **Update All**, or let **Iru Agent** install updates silently in the background. See [App updates in the Iru system tray](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray) in **User Experience with Windows Apps**. ### When a running app blocks the install If your administrator configured processes that must be closed first, the close-app dialog appears when you click **Update** or **Update All** in the tray and that app is still open. It does not appear during automatic background install attempts. See [When an app must close](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#when-an-app-must-close). ### Automatic Retry If an update cannot complete immediately: * **Iru Agent** automatically retries about every **15 minutes** until it can finish * Background retries install silently when the app is not open; if the app is open, the agent waits and retries on the next cycle without showing the close-app dialog * You can also start an update from the tray **Updates** list; see [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray) ### Windows Self Service Windows users can access Auto App updates through the Iru Self Service application. Open **Iru Self Service** and look for available app updates in the main list of available apps. Support or documentation links configured for an Auto App appear on the app details view so users can open them before or after installing. ### Related Articles The Iru system tray Updates list, close-app prompts, and enforcement countdowns on Windows User guide for accessing and using Self Service application on macOS devices Access and use Self Service on iOS, iPadOS, and visionOS # Configure a Custom Desktop Picture Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/configure-a-custom-desktop-picture Deploy a custom desktop wallpaper image to managed Mac computers using Iru Endpoint. Lock the setting so users cannot change it with a custom profile. This guide applies to Mac computers This method will lock the desktop picture so that the end user cannot change it. ### Prerequisites You will first need to obtain your desktop image(s) and [compress the file(s)](https://support.apple.com/en-gb/guide/mac-help/mchlp2528/mac). ### Create Custom App Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Deploy Your Desktop Image Give the new Custom App Library Item a descriptive name. Assign to the desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Set your installation method and choose **ZIP File** for the Install method. Provide an **Unzip Location** that will match the desktop picture path in your profile. Upload your compressed image. Click **Save** to complete the Custom App Library Item setup. ### Download and install iMazing Profile Editor Download iMazing Profile Editor from the Mac App Store or [their website](https://imazing.com/profile-editor/download). iMazing Profile Editor is also available as an [Auto-App](/en/endpoint/library/auto-apps/auto-apps-overview). If downloaded directly from their website, open the DMG and drag iMazing Profile Editor.app to your Applications folder. ### Create Your Desktop Picture Profile Once you have iMazing Profile Editor open, follow these steps: Select the **General** domain on the left side and configure the basic profile settings: * Set **Name** to whatever you would like the profile name to be * Set **Identifier** to a unique string * Set **Organization** to your Organization's name * Set **Payload Description** to describe the profile's purpose Configure the payload scope and target device: * Set Payload Scope to **System** * Set Target Device Type to **Mac** In the upper right-hand search box, search for **Desktop Picture**, and **Add the Configuration Payload**. Configure the appropriate options inside of the Desktop Picture payload. Navigate to the Menu Bar and click File > **Save**, then select a save location and **Save** your profile. ### Upload Your Custom Desktop Picture Profile to Iru Endpoint To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Custom Profile Library Item a descriptive name. Assign to the desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Drag and drop your profile to upload it. Click Save to complete the setup. Devices enrolled in the selected Blueprints will display the customized Desktop Picture after their next check-in with Iru Endpoint. # Configure EAP Extensible Authentication Protocol Types Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/configure-eap-extensible-authentication-protocol-types Configure EAP authentication types for 802.1X on Apple devices using Iru Endpoint. Set up TLS, TTLS, PEAP, and EAP-FAST for Wi-Fi and Ethernet profiles. This guide applies to Mac computers Numerous options are available for authenticating to Wi-Fi or wired networks, especially if your infrastructure supports more than one authentication type. Each option has unique settings you need to configure. This article covers the most common configuration options. For more information about configuring enterprise networks, see our [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) and [Configure the Ethernet Library Item](/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item) support articles. Your network infrastructure must support the chosen EAP types and be configured correctly to allow authentication. If you do not know how your network is configured, work with your network administrators to determine how they want network clients to connect. ### Configure EAP-TLS EAP-TLS uses Transport Layer Security and an identity certificate to authenticate devices to the network. You must provide an identity certificate to use EAP-TLS. Select TLS under **Accepted EAP Types**. To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow. If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use. Select a method to provide an identity certificate and configure applicable settings. See [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) to learn more. EAP-TLS with SCEP identity certificate ### Configure EAP-TTLS Tunneled Transport Layer Security uses a TLS tunnel to encrypt another authentication protocol. It does not require an identity certificate. Devices can use a username and password or device-based directory credentials to authenticate. Username and password authentication: Choose **Username and password** for **Authentication**. Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables), such as \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network. Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password. If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. EAP-TTLS username and password authentication Device-based directory authentication for a Mac bound to a directory service: Choose either **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account. Configure the remaining TTLS settings: When you select TTLS, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.** For **Inner authentication**, choose the authentication protocol to use inside the TLS tunnel. Optionally specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity. To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow. If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use. ### Configure EAP-LEAP Lightweight Extensible Authentication Protocol is an older authentication method based on MS-CHAP and Dynamic WEP. It does not use an identity certificate. Devices can use a username and password or device-based directory credentials to authenticate. Username and password authentication: Choose **Username and password** for **Authentication**. Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables), such as \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network. Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select **Every time the user connects to the network**, the device will not remember the password. If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. EAP-LEAP username and password authentication Device-based directory authentication for a Mac bound to a directory service: For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account. ### Configure EAP-PEAP Protected Extensible Authentication Protocol addresses shortcomings of previous Extensible Authentication Protocols such as LEAP. Like EAP-TTLS, PEAP uses a TLS tunnel to encrypt another authentication protocol. It does not require an identity certificate. Devices can use a username and password or device-based directory credentials to authenticate. Username and password authentication: Choose **Username and password** for **Authentication**. Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables). For example, \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network. Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password. If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. Device-based directory authentication for a Mac bound to a directory service: For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account. Configure the remaining PEAP settings: When you select PEAP, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.** To prevent using older and weaker TLS versions, select the **TLS minimum version** you would like to allow. If your infrastructure does not support the latest versions of TLS, select the **TLS maximum version** you want to use. Optionally, specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity. ### Configure EAP-FAST Flexible Authentication via Secure Tunneling (FAST) uses a TLS tunnel to encrypt additional authentication information. FAST also supports fast re-establishment of the tunnel through Protected Access Credentials (PAC). It does not require an identity certificate. A username and password or device-based directory credentials can provide authentication. Username and password authentication: Choose **Username and password** for **Authentication**. Optionally, provide the **Username**. You can use a static value or one of [Iru Endpoint's global variables](/en/endpoint/library/library-items-profiles/global-variables). For example, \$EMAIL. If you do not enter a username, the device prompts the user to enter one when connecting to the network. Select how often to prompt the user for their password. If you choose **Once** and don't provide a password, the device will prompt the user once for their password and remember it. If you select, **Every time the user connects to the network**, the device will not remember the password. If devices use a shared username and password, enter the password in the **Password** field. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. Device-based directory authentication for a Mac bound to a directory service: For **Authentication,** choose **Computer AD system authentication** to use the Active Directory computer account or **Computer OD system authentication** to use the Open Directory computer account. Configure the remaining EAP-FAST settings: When you select EAP-FAST, your device will use a username and password or device directory credentials for authentication. If your network requires an identity certificate as a second authentication factor, select **Require Two-Factor Authentication.** Optionally specify **Outer identity.** It is different from the identity used inside the tunnel and is specified to prevent exposing the inner identity. To use Protected Access Credentials, select **Use PAC**. To use Protected Access Credentials, select **Provision PAC**. If you would like to provision the PAC anonymously, select **Provision PAC anonymously**. ### Configure EAP-SIM This authentication method is compatible with the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) only. EAP-SIM uses a device’s Subscriber Identity Module (SIM) for a Global System for Mobile Communications (GSM) network to authenticate to Wi-Fi. This EAP type is used in very few environments (for example, if you are a Mobile Network Operator (MNO) or a Mobile Virtual Network Operator (MVNO)). It does not require an identity certificate. Choose the **Minimum number of RAND** **values** the devices requires from the server. The available options are **3** (default), **2**, or **Don't specify**. More RAND challenges result in stronger keying material. EAP-SIM minimum number of RAND values ### Configure EAP-AKA This authentication method is compatible with the [Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) only. EAP-AKA (Authentication and Key Agreement) uses a device’s identity module for a Universal Mobile Telecommunications System (UMTS) and CDMA2000 network to authenticate to Wi-Fi. This EAP type is used in very few environments (for example, if you are a Mobile Network Operator (MNO) or a Mobile Virtual Network Operator (MVNO)). It does not require an identity certificate. There are no options to configure for this EAP type. EAP-AKA accepted EAP type ### Related Articles Compare Wi-Fi authentication types and when to use enterprise vs non-enterprise options Configure the Wi-Fi Library Item for network deployment Configure 802.1X authentication for wired networks Use identity certificates for 802.1X authentication # Configure FileVault Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/configure-filevault Enable and configure FileVault disk encryption on managed Mac computers using Iru Endpoint. Escrow recovery keys and enforce encryption at enrollment. This guide applies to Mac computers ### About FileVault & Recovery Keys [FileVault](https://support.apple.com/en-us/HT204837) is a built-in feature of macOS that encrypts the boot drive. During setup, FileVault generates a **Recovery Key**, allowing an additional method of access to the drive should all FileVault enabled users' passwords be forgotten. * [Learn more](https://support.apple.com/en-us/HT204837) about how FileVault secures your Mac devices and changes login behavior * [Learn how](/en/endpoint/devices/device-actions/reset-a-macos-user-password) to use the FileVault Recovery Key to reset a user's password * [Learn about](/en/endpoint/library/library-items-profiles/filevault-user-experience) the User Experience with FileVault ### About the FileVault Library Item The FileVault 2 Library Item enforces all enrolled macOS devices to enable FileVault disk encryption. Mac devices will be prompted to complete FileVault setup upon restart. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### FileVault Configuration Options Configure FileVault using the steps below. Enforcement and user experience are part of the same flow as the Library Item settings. Use the **FileVault enforcement** drop-down to choose: * **Enforce immediately upon next login** (Recommended): FileVault is required at the next login. The **Enforce during Setup Assistant for Automated Device Enrollment** option appears when this is selected. * **Allow user deferral before enforcing** (Not Recommended): The **Prompt for restart if FileVault is not enabled** option is hidden; a **User Deferral** drop-down appears instead so you can select how many login attempts are allowed before FileVault is enabled. **Recommended:** Check this option to attempt to enforce FileVault during Setup Assistant for devices running macOS 14+ that enroll using Automated Device Enrollment. This selection ignores a FileVault skip screen setting in the [Automated Device Enrollment Library item](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment#mac). See [Enforcement and user experience during Setup Assistant](#enforcement-and-user-experience-during-setup-assistant) for the full end-user flow and screenshots. Check this option to configure forcibly restarting the Mac or reminding the end user to restart to enforce FileVault encryption. When enabled, set **Prompt type** (e.g., Force a restart after, or Remind to restart every...) and **Force after** (e.g., 30 minutes) as needed. FileVault enforcement settings By default, the FileVault recovery key is shown to the end user when the recovery key is created or regenerated. A common security practice is to not show the recovery key to the end user and allow team members to view the escrowed recovery key in Iru Endpoint. This option sends the recovery key to Iru Endpoint where it can be viewed by team members. If FileVault is currently enabled, this option will cause the Iru Endpoint agent to prompt the user for authentication before regenerating the recovery key. Check this option to automatically rotate the recovery key on a regular schedule. When enabled, set **Rotate keys after they are escrowed to Iru Endpoint in** to the desired period (e.g., 90 days). This is done via the RotateFileVaultKey MDM command. FileVault recovery keys settings including escrow and automatic rotation ### Enforcement and user experience during Setup Assistant When you enable **Enforce during Setup Assistant for Automated Device Enrollment (macOS 14+)**, Iru Endpoint attempts to enforce FileVault during Setup Assistant for devices running macOS 14+ that enroll using Automated Device Enrollment. This selection ignores a FileVault skip screen setting in the [Automated Device Enrollment Library item](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment#mac). The end user first sees a FileVault Disk Encryption dialog: the organization has enabled FileVault for the Mac, and the user can turn on FileVault disk encryption and click **Continue** to encrypt the disk (no restart required). A **Skip** option may appear depending on configuration. FileVault Disk Encryption dialog during Setup Assistant The next screen displays the FileVault Recovery Key in a clear, prominent format and instructs the user to write it down and keep it in a safe place so they do not lose access to their data. FileVault Recovery Key during Setup Assistant ### View FileVault Recovery Keys Navigate to the Device Record. Click on the **Device Action Menu**. Click **View FileVault2 recovery key**. Device Action Menu with View FileVault2 recovery key option You can force the Mac to generate a new FileVault recovery key by running the following command on any Mac via Terminal. Iru Endpoint will then capture the newly generated key if the escrow option is enabled. ```bash Terminal icon="terminal" theme={null} sudo fdesetup changerecovery -personal ``` ### Parameter: Report user accounts with FileVault Recovery Keys escrowed to iCloud macOS allows users to store Recovery Keys with their iCloud account. This is not recommended for enterprise-owned Mac devices, as it's possible that keys can be retrieved by an unknown party. Use this parameter to be alerted if a Recovery Key is stored in iCloud. This alert is a helpful reminder to pair with the user to remove the recovery key from their iCloud account. Report user accounts with FileVault Recovery Keys escrowed to iCloud ### Encryption Status With APFS volumes, only the Data volumes will show as **Encrypted: Yes** in the Volumes section of the Device Details. This is expected behavior. Device Details Volumes showing APFS Data volume Encrypted Yes The startup disk is always encrypted on Mac computers with the Apple T2 Security Chip or Apple Silicon, so FileVault encryption is nearly immediate. On other Mac computers, FileVault encryption can take longer depending on the amount of data, but it continues in the background. ### User Experience with FileVault If you have enabled the **Escrow recovery keys to Iru Endpoint** setting in your FileVault Library Item, any Mac that enrolls into Iru Endpoint that previously had FileVault enabled will automatically prompt your end users to regenerate their FileVault Key so it can be escrowed. When FileVault is set to **Automatically rotate keys**, and the Passcode Profile has the **Maximum Passcode Age** option enabled, a password older than the maximum age will be expired, and the user will need to create a new password before they can rotate and escrow their FileVault Recovery key. Please visit the [User Experience with FileVault](/en/endpoint/library/library-items-profiles/filevault-user-experience) article for more information. # Deploy Bitdefender as a custom app on Mac Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-bitdefender-endpoint-security-tool-as-a-custom-app Deploy the Bitdefender Endpoint Security Tool to Mac computers as a custom app in Iru Endpoint. Package the installer, configure PPPC, and assign to devices. This guide applies to Mac computers Please note that depending on the specific application and version you have installed, the app path, privacy access, and system extension requirements may vary. As a best practice, we recommend thoroughly testing any Custom Apps before deploying them to a Mac in a production environment. ### Prerequisites * Bitdefender installer package(s) from your [Bitdefender admin portal](https://gravityzone.bitdefender.com/). Ensure that an **uninstall password** is set in the package settings * If you have a mixed environment of both Intel and Apple Silicon Mac computers, you will need to download both the macOS kit (Intel x86) and macOS kit (Apple Silicon) packages, but you will only need to include one of the install.xml files. The post-install script used in this guide will account for both installer types * If you are only deploying to one architecture, you will still need that install package and the included install.xml file * Bitdefender PFX Certificate Generator script ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/bitdefender_cert_generator.zsh)) * Bitdefender Settings Profile ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/bitdefender_settings.mobileconfig)) * This configuration profile enables full disk access for Notifications, [System Extensions](/en/endpoint/library/library-items-profiles/system-extensions-overview-and-guide), Bitdefender SSL CA certificate, Privacy Preferences (PPPC), and a Network content filter * Bitdefender macOS 15+ Settings Profile ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/bitdefender_settings_macOS15.mobileconfig)) * This configuration profile includes the NonRemovableFromUISystemExtensions field for macOS 15+ devices * Bitdefender Service Management Profile ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/bitdefender_service_management.mobileconfig)) * This configuration profile allows managed background items for Bitdefender * Bitdefender Audit and Enforce Script ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/bitdefender_ae_script.zsh)) * Bitdefender Postinstall Script ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/bitdefender/post-install.sh)) ### Creating a PFX Certificate This section steps through the creation of a PFX certificate for Bitdefender that can be uploaded to Iru Endpoint in a Certificate Library Item. Bitdefender requires that a PFX certificate be created and deployed to macOS. This section is based on [BitDefender's guide](https://www.bitdefender.com/business/support/en/77209-157498-install-security-agents---use-cases.html#UUID-00e93090-1040-8119-d7cf-c48320a8d6b7), which you can refer to for more information. Open the **PFX Certificate Generator script** in a text editor or IDE such as VScode or BBEdit. Fill in the certificate information section of the script: ```bash lines theme={null} VARIABLES # Cert info COUNTRY="" # US - 2 letter country code STATE="" # Georgia - state or province LOCAL="" # Atlanta - locality name ORG_NAME="Endpoint" # Leave as default CERT_NAME=" BitDefender CA SSL" # Leave as default ``` Save the updated script to your Desktop. Open **Terminal.app**. Run the following command in Terminal: ```bash theme={null} zsh '/Users//Desktop/bitdefender/bitdefender_cert_generator.zsh' ``` When prompted, enter and verify the password used in the Bitdefender installer settings you defined in your Bitdefender portal. When the script is finished, you should see the password hash used to generate the certificate. Copy the generated hash and paste it in the password field when creating the Certificate Library Item in Iru Endpoint: ```bash theme={null} Password hash: 626cacdec63355c2680dbd6747c8d755 ``` A Finder.app window should open on your Desktop, showing the **certificate.pfx** file. Upload this certificate to Iru Endpoint in a [Certificate Library Item](/en/endpoint/library/library-items-profiles/configure-the-certificate-library-item). Certificate Library Item with PKCS #12 certificate.pfx uploaded ### Add a Custom Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Configure the Bitdefender Profiles Give the profile a Name. For **Install on**, select Mac. Assign your Custom Profile to a Blueprint. Upload the `bitdefender_settings.mobileconfig` file you downloaded previously. Click **Save**. Repeat the previous steps for the `bitdefender_settings_macOS15.mobileconfig` and the `bitdefender_service_management.mobileconfig` files you downloaded in the [prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-bitdefender-endpoint-security-tool-as-a-custom-app#prerequisites) section. Custom Profile with bitdefender_settings.mobileconfig uploaded ### Zipping the Installer Files Before uploading the installer files to Iru Endpoint, you will need to zip them up together first. Go to the Bitdefender installer files that you downloaded from the Bitdefender console earlier. If you downloaded the Intel and Apple ARM DMG files, you might need to mount them first and then pull the installer files out. Put the installer package(s), **installer.xml** file, and **certificate.pfx** file in the same location, such as your Desktop. Only one **installer.xml** file is needed; either the one from the Intel download or the ARM download will work. Select all of the files at one time. Hold the Control(⌃) key and click on the selected files. Then, in the menu, click **Compress**. You should see a dialog showing the compression progress. An **Archive.zip** file should be created in the same directory. Feel free to rename the file to something like **bitdefender\_install.zip**. This is the file that will be uploaded to Iru Endpoint in the next section. ### Custom App To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the Custom App a name. Optionally, add a custom icon. Assign to your desired blueprint. Change the installation type to **Audit and enforce**. Copy the bitdefender\_ae\_script.zsh script you downloaded in the [prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-bitdefender-endpoint-security-tool-as-a-custom-app#prerequisites) section and paste into the **Audit & Enforce** text box. No modification needed. The script looks for two profile identifiers and the name of the installed Bitdefender app before attempting an install. Additionally, the script looks for two Launch Daemons on computers where the app is already installed to ensure that the app is running as expected. If you would like to use this script with another profile, update the profile identifier prefix information to match what is in your profile: ```bash lines theme={null} Settings Profile prefix: io.kandji.bitdefender.D0DF2C14 Background Service Management Profile prefix: io.kandji.bitdefender.service-management App name: "Endpoint Security for Mac.app" Processes: "com.bitdefender.epsecurity.BDLDaemonApp", "com.epsecurity.bdldaemon" ``` Custom App Audit and enforce script for Bitdefender Select **ZIP File (unzip contents into specified directory)** as the deployment type. Set the **Unzip Location** to **/var/tmp**. Upload the installer zip file downloaded earlier. Click **Add Postinstall Script**. Copy the post-install script you downloaded in the [prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-bitdefender-endpoint-security-tool-as-a-custom-app#prerequisites) section and paste it into the post-installer text field. Be sure to copy all text, including the #!/bin/sh (shebang) line at the top. * Ensure that the package names match the names downloaded from Bitdefender * Ensure that the certificate file name matches the cert file you created using the Bitdefender KB Click **Save**. Custom App ZIP install with Bitdefender postinstall script ### Deploying with Assignment Maps Two of the Bitdefender Custom Profiles need conditional logic to ensure they are deployed to the correct devices. An Assignment Map provides an easy solution for all of your devices in one convenient view. Please review our [Creating a Blueprint](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) articles. Start with the **For All devices on this Blueprint** conditional block. Assign the **Bitdefender** **Custom App** to the block. If multiple Custom Apps are needed, create a conditional block with conditions for the different versions of the installer. Assign the **Bitdefender Certificate Library Item** to the conditional block. Assign the **bitdefender\_settings** Custom Profile to the conditional block. Set the top of the conditional block to **If macOS is greater than or equal to 13.0**. Assign the **bitdefender\_service\_management** Custom Profile to the conditional block. Set the top of the conditional block to **If** **macOS is greater than or equal to 15.0**. Assign the **bitdefender\_settings\_macOS15** Custom Profile to the conditional block. Assignment Map with Bitdefender conditional logic by macOS version # Deploy CrowdStrike as a Custom App Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app Deploy the CrowdStrike Falcon sensor to Mac computers as a custom app in Iru Endpoint. Package the installer, add the customer ID, and approve extensions. This guide applies to Mac computers ### Prerequisites Intel-based Mac computers require the KEXT version of the Crowdstrike settings profile when using Crowdstrike's Firmware Analysis feature. If you are not using Firmware Analysis, we recommend using the non-KEXT versions of the custom settings below. * CrowdStrike installer from the vendor (Hosts > Sensor Downloads) * Crowdstrike Custom Settings * **All Mac Architectures** * macOS 15 (Sequoia) and later ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings_macOS15.mobileconfig)) * **Apple Silicon** * All macOS Versions ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings.mobileconfig)) * **Intel with KEXT** * All macOS Versions ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_settings_with_kext.mobileconfig)) * CrowdStrike Service Management Profile * macOS 13 (Ventura) and later ([GitHub Link](https://github.com/kandji-inc/support/blob/main/custom-apps/crowdstrike/crowdstrike_service_management.mobileconfig)) * CrowdStrike Audit Script ([GitHub Link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_falcon_ae_script.zsh)) * CrowdStrike Postinstall script ([GitHub Link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_falcon_postinstall_script.zsh)) ### Considerations * The **CrowdStrike Settings Profiles** approve CrowdStrike for network content filters, kernel extensions, system extensions, PPPC, and web-filtering requirements. This profile is compatible with both the older Falcon agent using kernel extensions and the latest version using system extensions * You will need to deploy both the **crowdstrike\_settings\_macOS15** and **crowdstrike\_settings** profiles following the steps in the [Deploying with Assignment Maps](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#deploying-with-assignment-maps) section to assign them correctly * The **CrowdStrike Service Management Profile** handles essential login and background processes * If you require it, the **Legacy System Extension (KEXT) Settings Profile** can be accessed via this [GitHub link](https://github.com/kandji-inc/support/tree/main/custom-apps/crowdstrike/crowdstrike_settings_with_kext.mobileconfig) * This profile supports both the Falcon agent with kernel extensions and the newer version with system extensions * The KEXT payload is necessary only when using the CrowdStrike Firmware Analysis feature on Intel-based Mac computers * Please note that depending on the specific CrowdStrike product and version you have installed, there may be variations in app paths, privacy access settings, and kernel or system extension requirements. As with any Custom App, we strongly recommend thorough testing before deploying it to a production Mac ### Add and Configure the Custom Profiles The service management profile for Crowdstrike Falcon is compatible with macOS 13 Ventura and later. For macOS Monterey 12 and earlier, an Assignment Map must be used for advanced scoping to prevent the service management profile from being assigned to those devices. To learn more about deploying Crowdstrike in Assignment Maps, follow the [Deploying with Assignment Maps](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#deploying-with-assignment-maps) section. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your Custom Profile a **Name**. For **Install on**, select Mac. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Upload the CrowdStrike Settings Profile (or Legacy System Extension (KEXT) settings profile). Custom Profile with crowdstrike_settings.mobileconfig uploaded Click **Save**. Repeat the previous steps in this section for the **crowdstrike\_settings\_macOS15** and **crowdstrike\_service\_management** profiles. ### Add and Configure the Custom App To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the Custom App a **Name**. Optionally, add a custom icon. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Change the **Installation** to Audit and Enforce. Copy and paste the crowdstrike\_ae\_script.zsh script from the [prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#prerequisites) into the **Audit & Enforce** text box. No modification is required. Custom App Audit and enforce script for CrowdStrike Select Installer **Package (install .pkg or .mpkg)** as the deployment type. Upload the installer package. Paste the **Postinstall Script** referenced in the [Prerequisites](/en/endpoint/library/deployment-guides/apple/deploy-crowdstrike-as-a-custom-app#prerequisites). * In the Post-Install script, update the **customerIDChecksum** variable on line 55 with your Customer ID * Optionally, paste your install token on line 59 inside the **installToken** variable; otherwise, leave it blank Custom App postinstall script for CrowdStrike FalconSensorMacOS.pkg Click **Save**. ### Deploying with Assignment Maps There are four Crowdstrike Custom Profiles that need conditional logic to ensure they are deployed to the correct devices. An Assignment Map provides an easy solution for all of your devices in one convenient view. Please review our [Creating a Blueprint](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) articles. Start with the **For All devices on this Blueprint** conditional block. Assign the **Crowdstrike** Custom App to the block. If multiple Custom Apps are needed, create a conditional block with conditions for the different versions of the installer. Set the top of the conditional block to **If** **macOS is greater than or equal to 15.0**. Assign the **crowdstrike\_settings\_macOS15** Custom Profile to the conditional block. Set the top of the conditional block to **If** **Chip type is Apple Silicon**. Assign the **crowdstrike\_settings** Custom Profile to the conditional block. Set the bottom conditional block to **else if Chip type is Intel**. Assign the **crowdstrike\_settings\_with\_kext** Custom Profile to the conditional block. Set the top of the conditional block to **If macOS is greater than or equal to 13.0**. Assign the **crowdstrike\_service\_management** Custom Profile to the conditional block. Assignment Map with CrowdStrike conditional logic by macOS version and chip type # Deploy Fonts Using a Custom App Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-fonts-using-a-custom-app Deploy desktop-licensed fonts to Mac computers using a custom app in Iru Endpoint. Package font files, configure Self Service access, and assign to devices. This guide applies to Mac computers In this example, we'll deploy a ZIP file containing a folder of desktop-licensed fonts to a path accessible to all users. We'll set this to run once and have the option to make the item available on-demand in Self Service in case users need the ability to reinstall the fonts. Iru Endpoint's maximum file upload size is 5 GB. ### Prepare Your Fonts Select, then right-click your font files or folders and choose compress. Optionally, give your new ZIP archive file a descriptive name. ### Add a Custom App To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Configure the Custom App Give your Custom App a descriptive name. **Assign** your Custom App to the desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select **Install once per device** as the execution frequency. Optionally, toggle the option to make the Library Item available in **Self Service,** choosing any desired customizations. Select **ZIP File.** To ensure the fonts are accessible to all users of a computer, specify an **Unzip Location** of **/Library/Fonts**. Upload your **ZIP File**. Custom App with ZIP File install type selected, Unzip Location set to /Library/Fonts, and Fonts.zip uploaded Click **Save** to complete the Custom App setup. # Deploy Google Remote Desktop Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-google-remote-desktop Deploy Google Chrome Remote Desktop to Mac computers using Iru Endpoint. Install Chrome, configure the extension, and add privacy profiles for access. This guide applies to Mac computers To deploy [Google Remote Desktop](https://remotedesktop.google.com/access/) to user devices you will need to deploy a Privacy item, a Chrome Extension and the Google Remote Desktop installer. The two mobileconfig files listed below need to be uploaded as [Custom Profile Library Items](/en/endpoint/library/library-items-profiles/custom-profiles-overview) in Iru Endpoint. ### Configuration Profiles * [Google Chrome Extension Profile](https://github.com/kandji-inc/support/tree/main/Configuration%20Profiles/ChromeRemoteDesktop-ChromeExtension.mobileconfig) * [Google Remote Desktop Privacy Profile](https://github.com/kandji-inc/support/tree/main/Configuration%20Profiles/ChromeRemoteDesktop-PPPC.mobileconfig) As outlined in the [Apple Documentation](https://developer.apple.com/documentation/devicemanagement/privacypreferencespolicycontrol/services) regarding Privacy settings, profiles cannot be used to enforce screen capture permissions but can be configured to allow a standard user to allow the app as needed. The first time a user launches Google Remote Desktop they will be shown the necessary steps to allow screen capture. ### Downloading the Google Remote Desktop Installer Along with the two profiles provided in the list below, you will also need to obtain the latest Google Remote Desktop installer. This can be found by opening the Google Remote Desktop portal and choosing the 'Accept & Install' option within the 'Share This Screen' tile. This will download a DMG file, which will have the PKG file within it that is required. This PKG can be uploaded to Iru Endpoint as a [Custom App](/en/endpoint/library/library-items-profiles/custom-apps-overview). As part of the Custom App created with the above PKG file, you can use our Audit & Enforce script template available [here](https://github.com/kandji-inc/support/tree/main/Scripts/audit-enforce-scripts) with the below changes to ensure Google Remote Desktop is installed on devices. ``` ###################################################################################### ###################################### VARIABLES ###################################################################################### # Make sure that the app name matches the name of the app that will be installed. This # script will dynamically search for the app in the Applications folder. So there is # no need to define an app path. The app must install in the /Applications, "/System # /Applications", or /Library up to 3 sub-directories deep. APP_NAME="ChromeRemoteDesktopHost.app" ``` ### End User Experience The first time a user attempts to share their screen using Google Remote Desktop, they will be required to confirm the access rights that Google Remote Desktop requires. The steps are outlined below. The end user navigates to the [Google Remote Desktop](https://remotedesktop.google.com/support) portal in Google Chrome and selects 'Generate Code' within the 'Share this screen' section. If this is the first time the user has opened Remote Desktop they will need to grant the app some access rights. When prompted, select **Open Screen Recording Preferences**. The end user will see System Settings open on their device. The two options for 'ChromeRemoteDesktopHost' and 'RemoteAssistanceHost' should be enabled. Thanks to the privacy policy we deployed above, users will not need administrator rights to approve this. Once these options have been enabled, the user should be able to go back to the Google Remote Desktop portal and they should now see a code under the 'Share this screen' title. This can be given to the remote support agent who can use this to access the device remotely. # Deploy Homebrew Using a Custom Script Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-homebrew-using-a-custom-script Install Homebrew on managed Mac computers using a custom script in Iru Endpoint. Automate the package manager deployment for developer tools and utilities. This guide applies to Mac computers ### What is Homebrew? Homebrew is a free and open-source package management system for macOS that simplifies software installation. It has become a popular tool among developers and system administrators for its ease of use and extensive package availability. As with all scripts, please test thoroughly before deploying to Mac computers in production. ### How Homebrew Works Homebrew integrates into the command-line interface (CLI) and allows local administrators to install required software via the CLI. This tool is particularly useful for developers and system admins who need to install libraries and tools efficiently. ### Prerequisites * Copy the InstallHomebrew\.zsh script from the Iru Endpoint support GitHub repository ([GitHub Link](https://github.com/kandji-inc/support/blob/main/Scripts/InstallHomebrew.zsh)) ### Add a Custom Script To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. For high-level Custom Script options such as naming the Library Item, Blueprint assignment, execution frequency, and Self Service, see [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview#add-a-custom-script-library-item). ### Configure the Homebrew Script Paste the script from the prerequisites into the **Audit Script** field. Click **Save** in the lower right-hand corner to complete the Custom Script setup. Custom Script Save button to complete Homebrew setup # Deploy SAP Privileges Auto App with Privileges Checker Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/deploy-sap-privileges-auto-app-with-privileges-checker Deploy SAP Privileges with the Privileges Checker script in Iru Endpoint. Automate temporary admin access and enforce standard user permissions on Mac. This guide applies to Mac computers SAP Privileges 2 includes native support for much of the functionality provided by Iru Endpoint's Privileges Checker. For detailed guidance on managing SAP Privileges 2, visit [SAP's wiki](https://github.com/SAP/macOS-enterprise-privileges/wiki/Managing-Privileges). A sample .mobileconfig containing all available settings for SAP Privileges 2 can be found in their [GitHub repo](https://github.com/SAP/macOS-enterprise-privileges/blob/main/source/Privileges/Privileges.mobileconfig). ### About SAP Privileges SAP Privileges is an open-source tool for macOS that allows users to temporarily elevate their user accounts from standard to administrative when needed. This is particularly useful in environments where security best practices suggest that users should operate with the least privileges necessary for daily tasks but occasionally need administrative rights for specific actions. ### How SAP Privileges Works The SAP Privileges app for macOS allows users to elevate their privileges to perform administrative tasks temporarily. The built-in functionality of SAP Privileges supports time-based rights expiration, but only if the privileges are first granted by right-clicking the Dock icon and selecting the "Toggle Privileges" option. This means that the app will revert the user to standard privileges after a set period if they use this specific method to elevate their rights. However, users can also launch the full SAP Privileges app to elevate their privileges, which bypasses the Dock icon method. To address this, we have released companion code that enforces the timeout even when privileges are escalated through other methods, such as launching the full app. ### Configuring SAP Privileges in Iru Endpoint #### Requirements * Privileges Checker audit script ([GitHub Link](https://github.com/kandji-inc/support/blob/main/PrivilegesChecker/audit_privileges_checker.zsh)) * Privileges Checker remediation script ([GitHub Link](https://github.com/kandji-inc/support/blob/main/PrivilegesChecker/install_privileges_checker.zsh)) * A tool for custom profile creation, such as [iMazing Profile Editor](https://imazing.com/profile-editor/download) * The SAP Privileges Auto App, Custom Script, and Custom Profile must all be added to the same Blueprint(s) * The Demote user accounts to standard Parameter must be disabled on any Assignment Maps where Privileges is assigned #### Adding the SAP Privileges Auto App This Auto App deploys a configuration profile allowing background items for SAP Privileges and Privileges Checker. This is to ensure core functionality for the add-on, and has no impact if Privileges Checker is not present. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Assign the Auto App to a test **Blueprint**. Select desired installation method and hit **Save**. #### Adding and Configuring the Privileges Checker Script Once this script is deployed, Privileges Checker will revoke rights for the logged-in user after the set timeout has expired. **Add a Custom Script Library Item** To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Accessory & Storage Access Library Item a **Name**. Assign to your desired [Assignment Maps](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select **Run every 15 minutes** as the **Execution Frequency**. Paste the audit script you downloaded earlier into the **Audit Script** text field. Edit the script on line 65 to set a Boolean value for **USE\_PROFILE\_TIMEOUT**, and a string value for **USERS\_TO\_EXCLUDE**. **For USE\_PROFILE\_TIMEOUT:** * Set to either **True** or **False**: Enforces a timeout in minutes from **DockToggleTimeout** key set in the Privileges configuration profile (see below) * If the value is marked **True** but no profile is installed, or if the **DockToggleTimeout** key is not defined, the timeout will default to **MINUTES\_TO\_WAIT**. Otherwise, the configuration profile will override the locally set value **MINUTES\_TO\_WAIT** **For USERS\_TO\_EXCLUDE:** * If no admin is defined, all admins will get demoted * Admin names must be placed inside the double quotes Custom Script audit script with USE_PROFILE_TIMEOUT and USERS_TO_EXCLUDE Paste the remediation script you downloaded earlier into the **Remediation Script** text field. Edit the script on line 56 to set an integer value for **MINUTES\_TO\_WAIT.** This is the number of minutes an end user should be allowed admin rights once granted. Edit the script on line 64 to set a Boolean value for **USE\_PROFILE\_TIMEOUT**. * Set to either **True** or **False**: Enforces a timeout in minutes from **DockToggleTimeout** key set in the Privileges configuration profile (see below) * If the value is marked **True** but no profile is installed, or if the **DockToggleTimeout** key is not defined, the timeout will default to **MINUTES\_TO\_WAIT**. Otherwise, the configuration profile will override the locally set value **MINUTES\_TO\_WAIT** Edit the script on line 72 to set a string value for **USERS\_TO\_EXCLUDE**. * Admin names must be placed inside the double quotes Click **Save**. Custom Script remediation script with MINUTES_TO_WAIT and USE_PROFILE_TIMEOUT ### Create a Custom Profile Profile creation steps are optional if you are setting the rights timeout via script. You can also review additional profile options that SAP Privileges supports on [their GitHub page](https://github.com/SAP/macOS-enterprise-privileges/wiki/Managing-Privileges). If the EnforcePrivileges key in the Custom Profile is set with any value, it will disable the PrivilegesCLI used in the Privileges Checker and override its ability to demote users. Open iMazing Profile Editor. On the left side, locate and click **SAP Privileges** under Available System Domains. Click **Add Configuration Payload**. Enter a value for **Dock Toggle Timeout**. If Privileges is configured with the DockToggleTimeout payload, but Privileges Checker is not deployed, timed rights revocation will only occur if a user right-clicks the Privileges Dock icon and selects Toggle privileges. Optionally, configure any additional settings for SAP Privileges as desired. Click the **General** section; populate the required values for **Name** and **Identifier**. Hit **Command+S** to save your profile. iMazing Profile Editor SAP Privileges Dock Toggle Timeout ### Add and Configure the Custom Profile To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the profile a **Name**. **Assign** your custom profile to a test **Blueprint**. Set the **Device Families** to Mac. **Upload** the **.mobileconfig** you customized and saved above. **Save** your custom profile. Technical details about Privileges Checker can be found in our [Iru Endpoint Support GitHub repo](https://github.com/kandji-inc/support/tree/main/PrivilegesChecker). # Google Chrome Browser Cloud Management Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/google-chrome-browser-cloud-management Enroll Google Chrome into Browser Cloud Management on Mac using Iru Endpoint. Deploy enrollment tokens, manage extensions, bookmarks, and browser policies. This guide applies to Mac computers You can use Iru Endpoint to enroll the Google Chrome browser into Chrome Browser Cloud Management on macOS. This will allow you to set bookmarks, allow extensions, and manage other settings in Google Chrome. ### Chrome Browser Cloud Management You can manage the browser on a computer using Google's Chrome Browser Cloud Management by delivering a configuration profile that contains a cloud management enrollment token from Google. This token will direct Google Chrome to allow management by the associated organization. ### Set Up Cloud Management Begin setup by following the instructions in the [Chrome Browser Cloud Management support guide](https://support.google.com/chrome/a/answer/9116814). ### Generate a New Cloud Management Enrollment Token Once you have completed the setup in Google Admin, you will need to [generate an enrollment token](https://support.google.com/chrome/a/answer/9301891) in Google. This token is used in the Custom Profile uploaded to Iru Endpoint. ### Modify the Configuration Profile Template with Your Enrollment Token Download the [configuration profile template](https://github.com/google/ChromeBrowserEnterprise/blob/main/mobile/ChromeBrowserCloudManagement.mobileconfig). Open the template in a text editor of your choice. Replace XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX in line 25 with your **Cloud Management Enrollment Token** generated above. Save the file locally with a descriptive name. ### Create a Custom Profile in Iru Endpoint To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your profile a name. Set the device family to Mac. Assign the profile to your desired Blueprints. Upload your .mobileconfig file. Google Chrome cloud management showing configuration or enrollment interface Click **Save**. ### Using iOS AppConfig iOS and iPadOS devices can use [AppConfig](/en/endpoint/library/library-items-profiles/using-appconfig) for Google Chrome and customize it for your organization. Before you configure AppConfig, acquire licenses for the **Google Chrome** App Store app. Follow the instructions to [add apps from Apps and Books to Iru Endpoint](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint), and search for Google Chrome in Apple Business or Apple School Manager. Acquire enough licenses for each iOS and iPadOS device you want to manage. Then open the **Google Chrome** App Store App Library Item and add this AppConfig dictionary: ``` CloudManagementEnrollmentToken XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX ``` Scroll to the bottom of the Library Item, and select **Set app configuration**. Paste the dictionary into the **Configuration dictionary** section and replace `XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX` with your **Cloud Management Enrollment Token**. Click **Save**. Google Chrome cloud management policy or enrollment Save ### Removing Chrome Browser Cloud Management To unenroll a Chrome Browser, please reference the [Unenroll a Device section](https://arc.net/l/quote/nrkujybb) of Google's Chrome Browser Cloud Management Documentation. # Installing Rosetta 2 on Mac Computers with Apple Silicon Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/installing-rosetta-2-on-mac-computers-with-apple-silicon Learn how Iru Endpoint handles Rosetta 2 installation for Intel-based apps on Mac computers with Apple silicon. Auto App and custom app compatibility. This guide applies to Mac computers Apple silicon processors are built on the arm64 Apple silicon CPU architecture, which differs greatly from the x86\_64 Intel architecture. Software applications must be recompiled to run on the new architecture and can then be distributed as universal binary packages that include both the new Apple silicon version and the Intel version. Some software titles have not been updated to include an Apple silicon version in a universal binary package and include only the Intel version of the application. Mac computers with Apple silicon are still capable of running software built for Intel processors using the [Rosetta 2 translation environment](https://developer.apple.com/documentation/apple_silicon/about_the_rosetta_translation_environment). This translation technology is not pre-installed on computers with Apple silicon but can be installed by the user or with the *softwareupdate* command-line tool. ### Automatic Rosetta 2 Installation for Auto Apps When an Auto App requires Rosetta 2 to run on a Mac computer with Apple silicon, you will see the warning below on the Library Item. In this event, the Iru Agent will automatically check for and install Rosetta 2 as needed. Please note that these banners may be removed without notice as developers shift to universal binaries. Installing Rosetta 2 on Mac Computers with Apple Silicon configuration or interface ### Intel-based Custom Apps Require Rosetta 2 As of November 2020, when [Apple first introduced computers with Apple silicon](https://support.apple.com/en-us/HT211814), many of the Auto Apps from Iru Endpoint were available only as Intel-based software applications. When a computer with Apple silicon detects an installer package for Intel-based software, it will send that package to the Rosetta 2 translation environment for processing. If Rosetta 2 is not already installed, then one of two things will happen. * If the user opens the installer package, [the user will be prompted by the system to install Rosetta 2](https://support.apple.com/en-us/HT211861). * If Iru Endpoint runs the installer package, the installation will stop because Rosetta 2 is unavailable on the system. To prevent a failed installation, or a prompt for the end user when deploying a Custom App that requires Rosetta 2, the Rosetta 2 translation environment must be installed on the Mac via Iru Endpoint. Below is a script that will allow the system to install the Rosetta 2 translation environment, if it is not already present, on a computer with Apple silicon. ### Install Rosetta 2 with Iru Endpoint To install Intel-based Custom Apps on a computer with Apple silicon, the Iru Endpoint Blueprint for that computer will need to install Rosetta 2 first. This can be accomplished by adding a custom script to your Blueprint. You should name this script *00 Install Rosetta 2 for Apple Silicon* to ensure that it runs first before any other items. You can follow the steps below to create this custom script in your Iru Endpoint tenant. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Set the script's name to *00 Install Rosetta 2 for Apple Silicon*. Assign the item to the Blueprints as necessary. Set the execution frequency to **Once per device**. In the script details, paste in the script block that appears below. Click **Save** to complete the Custom Script setup. ### Rosetta 2 Installation Script The [Install Rosetta 2 script](https://github.com/kandji-inc/support/blob/main/Scripts/InstallRosetta2.sh) is maintained in the [Iru Endpoint Support GitHub repo](https://github.com/kandji-inc/support/). # Licensing the Microsoft Defender Auto App Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/licensing-the-microsoft-defender-auto-app License and activate the Microsoft Defender Auto App on Mac using Iru Endpoint. Deploy the onboarding package and configure Defender for Endpoint settings. This guide applies to Mac computers ### Prerequisites * Add the Microsoft Defender [Auto App](/en/endpoint/library/auto-apps/auto-apps-overview) to your Library ### Download the Defender Onboarding Package Log in to your Defender portal. Navigate to **Settings > Endpoints > Onboarding**. Select **macOS** as the operating system. Select **Mobile Device Management** as the deployment method. Select Download onboarding package (WindowsDefenderATPOnboardingPackage.zip). ### Prepare the Onboarding Package Extract WindowsDefenderATPOnboardingPackage.zip you downloaded. Locate the WindowsDefenderATPOnboarding.plist downloaded as part of your Onboarding Package. Change file extension from .plist to .mobileconfig. ### Add a Custom Profile To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Custom Profile a descriptive name. Assign to your desired [Assignment Maps](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). **Upload** the WindowsDefenderATPOnboarding.mobileconfig you created earlier. Click **Save** to complete the Custom Profile setup. # Modifying the macOS Dock Source: https://docs.iru.com/en/endpoint/library/deployment-guides/apple/modifying-the-macos-dock Customize the macOS Dock on managed Mac computers using Iru Endpoint. Add app icons, remove defaults, and lock the Dock layout with a custom profile. This guide applies to Mac computers After deploying applications to your macOS devices, adding their icons to the dock can make them easier for your users to find. Adding icons to the dock can be accomplished by creating a custom profile. This method will lock the dock so that the end user cannot change it. If you would like a scriptable option to allow users to change their dock, please see our article on the [Iru Agent Command Line Interface](/en/endpoint/agent/iru-agent-command-line-interface#dock) or you can deploy our [Configure Dock Dockutil](https://github.com/kandji-inc/support/tree/main/Scripts/configure-dock-dockutil) script from our GitHub repository. ### Download and Install iMazing Profile Editor Download [iMazing Profile Editor](https://imazing.com/profile-editor/download) from their website, or the Mac App Store. If downloaded directly, open the iMazingProfileEditorMac.dmg and drag iMazing Profile Editor.app to your Applications folder. ### Create Your Dock Profile Once you have iMazing Profile Editor open, follow these steps. Select the **General** domain on the left side and configure the basic profile settings: * Set **Name** to whatever you would like the profile name to be * Set **Identifier** to a unique string * Set **Organization** to your Organization's name * Set **Payload Description** to describe the profile's purpose Set Payload Scope to **System**. In the upper right-hand search box, search for **Dock**, and **Add Configuration Payload**. Configure the appropriate options inside of the Dock payload. Dock payload configuration options Navigate to the Menu Bar and click File > **Save**, then select a save location and **Save** your profile. If deploying via Iru Endpoint, there is no need to sign the profile. Iru Endpoint will sign it when it is deployed. ### Add Your Custom Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Upload Your Custom Dock Profile to Iru Endpoint Give your profile a descriptive name. Select a [**Blueprint**](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint) from the Blueprint Assignment dropdown. Set your Device family to **Mac**. Drag and drop your dock profile to upload it. Save your custom profile. The devices enrolled in the selected Blueprints will display the customized Dock after their next check in with Iru Endpoint. # Configure EAP (Extensible Authentication Protocol) Types Source: https://docs.iru.com/en/endpoint/library/deployment-guides/windows/configure-eap-extensible-authentication-protocol-types Configure EAP authentication types for 802.1X on Windows devices using Iru Endpoint. Set up TLS, TTLS, PEAP, and EAP-FAST for Wi-Fi network profiles. This guide applies to Windows devices Numerous options are available for authenticating to Wi-Fi networks, especially if your infrastructure supports more than one authentication method. Each method has unique settings you need to configure. This article covers the most common EAP configuration options available in the [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) for Windows. Your network infrastructure must support the selected EAP type and be configured correctly to allow authentication. If you do not know how your network is configured, work with your network administrators to confirm how they want network clients to authenticate. When you select Enterprise Wi-Fi in Iru Endpoint, Identity certificate and Certificate trust settings always appear in the UI, regardless of which EAP type you select. These fields are not required, and in some EAP types they do not apply. If your EAP type does not use certificates, you can leave these fields blank. ## Configure EAP-TLS EAP-TLS uses Transport Layer Security and an **identity certificate** to authenticate the device to the network. You must provide an identity certificate to use EAP-TLS. Select **TLS** under **Accepted EAP Types**. Under **Credential source**, choose how the client should locate the identity certificate. * Most deployments use **Certificate Store**. Enable **Simple certificate selection** so Windows automatically selects the correct certificate during authentication. If disabled, users may be prompted to choose from available certificates. Configure the validation options based on how your RADIUS/certificate infrastructure is deployed: * **Perform server validation** (recommended for production) * **Disable user prompt for server validation** * **Accept server name** If your environment uses EKU filtering, configure: * **Client authentication EKU** * **Any purpose EKU** * **All purpose EKU** ## Configure EAP-TTLS Tunneled Transport Layer Security (TTLS) uses a TLS tunnel to encrypt another authentication protocol. It **typically does not require an identity certificate**, and most deployments authenticate using a username and password (or device credentials depending on infrastructure). Select **TTLS** under **Accepted EAP Types**. If your infrastructure supports identity privacy, enable **Enable identity privacy**. When enabled, the client sends an anonymous outer identity during the initial exchange and only reveals the real identity inside the encrypted tunnel. Configure: * **Perform server validation** * **Disable user prompt for server validation** * **Accept server name** Under **Inner authentication**, select the authentication protocol that will be used inside the TLS tunnel (as required by your RADIUS configuration). Identity certificate settings may appear in the UI but are not typically used for TTLS unless your infrastructure explicitly requires a certificate. ## Configure EAP-PEAP Protected Extensible Authentication Protocol (PEAP) uses a TLS tunnel to protect credentials exchanged using an inner authentication method. Like TTLS, PEAP **typically does not require an identity certificate**, and most commonly uses username/password authentication inside the tunnel. Select **PEAP** under **Accepted EAP Types**. Depending on your environment, configure: * **Enable fast reconnect** (improves roaming performance) * **Require cryptobinding** (recommended when supported; helps protect against some tunneling attacks) * **Enable NAP quarantine checks** (legacy; usually disabled in modern deployments) Configure **Allow user to accept untrusted server certificates**. * If enabled, users may be prompted when the server CA is not trusted. * If disabled, the connection will fail automatically if the server cannot be validated. Configure: * **Perform server validation** * **Disable user prompt for server validation** * **Accept server name** Enable **Enable identity privacy** if your deployment supports anonymous outer identities. Select an **Inner authentication** method based on your RADIUS requirements. PEAP typically does not use an identity certificate, even though the identity certificate fields may appear. ## Configure EAP-TEAP Tunneled EAP (TEAP) is a modern tunneled EAP method that supports **multiple inner authentication mechanisms** and stronger extensibility than PEAP/TTLS. Many TEAP deployments authenticate using username/password, certificates, or a combination. Select **TEAP** under **Accepted EAP Types**. Configure **Auto-trust servers accepted by the user**. If enabled, when a user manually accepts a server certificate and the connection succeeds, additional roots pushed by the server can be added to the trusted CA list. Configure: * **Perform server validation** * **Disable user prompt for server validation** * **Accept server name** Enable **Enable identity privacy** if supported by your infrastructure. TEAP can use multiple inner methods. Configure: * **Primary inner authentication** * **Secondary inner authentication** (optional) Some TEAP deployments may use identity certificates, depending on your authentication strategy. If your TEAP deployment does not use certificates, you can leave certificate fields blank. ## Configure EAP-SIM EAP-SIM uses a **SIM card** for authentication. It is commonly used in carrier or enterprise environments that use SIM-based identity for access control. Select **SIM** under **Accepted EAP Types**. Configure **Require strong cipher keys** to require stronger encryption keys (three RANDs). If this is not configured, either two or three RANDs may be allowed depending on server behavior. Configure **Hide permanent subscriber identity (IMSI)** to prevent revealing the IMSI when a pseudonym identity exists from previous authentications. * **Provider name** (limits authentication to SIMs matching this provider) * **Realm configuration** (controls the realm used when sending identity to the server) ## Configure EAP-AKA EAP-AKA uses **USIM-based authentication**, commonly used in mobile carrier and SIM-enabled enterprise deployments. Select **AKA** under **Accepted EAP Types**. Configure **Hide permanent subscriber identity (IMSI)** based on whether you want the IMSI protected when pseudonyms exist. * **Provider name** * **Realm configuration** ## Configure EAP-AKA' EAP-AKA' is an enhanced version of EAP-AKA with improvements to identity binding and key derivation. It is used in some modern SIM-based deployments. Select **AKA'** under **Accepted EAP Types**. Configure **Validate network name from server** to control whether the client verifies the network name it expects against what is advertised by the server. Configure **Enable fast reauthentication** to allow shorter, faster AKA' exchanges when possible. If disabled or not configured, every connection will use full authentication. Configure IMSI protection settings if required by your environment. * **Provider name** * **Realm configuration** ## Recommendations & Best Practices * **Use server validation whenever possible**. Disabling validation or allowing untrusted server certificates increases exposure to credential interception and man-in-the-middle risks. * **Enable identity privacy** when available, especially in TTLS/PEAP/TEAP environments. * **Only use EAP-SIM / AKA / AKA'** when your organization supports SIM/USIM-based identity authentication. These are uncommon in standard enterprise Wi-Fi deployments. * If you are unsure which EAP type to use, consult your Wi-Fi/RADIUS team to confirm what methods are enabled on your infrastructure. # Application Blocking User Experience Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/application-blocking-user-experience See what users experience when application blocking is active on their device. Understand alert dialogs, blocked app behavior, and enforcement messages. This article covers the user experience on Mac computers, Windows devices, and Android devices This article describes what end users see when an application is blocked by Iru Endpoint on **macOS**, **Windows**, or **Android** devices. If you reached this page through a notification, it is because your organization blocked the app you attempted to open. Contact your Iru Endpoint Administrator or IT department for more details. Depending on how the block is configured, the notification window may vary in content. ## Platform-Specific Experiences ### Application Blocking Experience A user attempts to open an application that is blocked. The application is immediately closed. Iru Endpoint displays a block dialog with: * The configured **Message** * Optionally, a **Button Title** (e.g. *Learn More*) * Optionally, the **Button URL**, which opens in the user's default browser if clicked If the user clicks the **Learn More** (or equivalent) button, the browser opens to the URL configured in the Library Item. If no button title or URL is configured, the button will not appear in the dialog. ### Example Block Dialog The macOS block dialog provides clear messaging to users about why an application has been blocked and includes options for additional information if configured by the administrator. ### Application Blocking Experience A user attempts to launch an application that is blocked. The application fails to launch. Windows will enforce the block at the system level. A Windows system message will appear indicating that the app is blocked. ### System-Level Enforcement Windows enforces application blocking at the operating system level, providing native system messages to inform users that the application cannot be launched. ### Application Blocking Experience A user attempts to install or launch a blocked app in the personal profile. If the app is already installed, Iru Endpoint automatically **uninstalls** it from the personal profile. The user will typically see Android's native behavior (such as "App not installed" or a missing icon), but no custom Iru Endpoint dialog. On Android, the block experience is silent. No custom modal or message is presented to the user. ### Silent Enforcement Android application blocking operates silently, removing blocked applications from the personal profile without displaying custom dialogs to users. ## Configuration Options You can configure application blocking through the [**App Blocking** Library Item](/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item) with the following options: * **Blocked Applications**: Specify which applications to block * **Custom Messages**: Configure user-facing messages (macOS only) * **Button Configuration**: Add custom buttons with URLs (macOS only) * **Enforcement Level**: Choose between different blocking methods ## Best Practices Before deploying application blocking policies to production devices, test them on designated test devices to ensure they work as expected. Inform users about application blocking policies through your organization's communication channels to set proper expectations. When blocking applications, consider providing approved alternatives or explaining why certain applications are restricted. Regularly review blocked applications and user feedback to ensure policies remain appropriate and effective. # Configure an AirPrint Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-an-airprint-library-item Set up an AirPrint Library Item in Iru Endpoint for network printing on Apple devices. Add printer IP addresses, resource paths, and port settings. This Library Item is available for Apple devices AirPrint profiles let you display AirPrint printers available in a user's Add Printer list when connected to the same local network. AirPrint printers are not automatically added to a device. If you'd prefer a printer be added directly to the Mac, use the [Custom Printer](/en/endpoint/library/library-items-profiles/custom-printers-overview) Library Item. ### Add an AirPrint Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your profile a **Name.** Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). ### Configure an AirPrint Library Item Fill out the **AirPrint Configuration** fields with your printer information. Optionally, click Add Printer and repeat these steps to configure another AirPrint printer in the same profile. Click **Save**. # Configure Android Apps with Google Play Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-android-apps-with-google-play-library-item Configure Android apps from managed Google Play in Iru Endpoint. Select apps, set managed configurations, and assign to Blueprints for deployment. This Library Item is available for Android devices Deploy Google Play applications to company-owned work profile Android devices using the Google Play apps Library Item. This opens the Google Play iframe, letting you add apps to the Iru Endpoint Library. Once added, Google Play apps can be assigned to an Assignment Map and deployed to managed Android devices. The Google Play iframe will not load if the Android Enterprise integration is not configured. Ensure you have completed the [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) before using this Library Item. ### Create & Deploy a Google Play App Add a Google Play app to the Iru Endpoint Library from the managed Google Play iframe, then open it for configuration. Google Play apps can only be deployed to the **work profile**. Navigate to the Iru Endpoint Library. Select **Add Library Item** in the upper-right corner. Select **Google Play apps** on the left-side navigation bar. Search Google Play for your application. Click on the application to load the app details view. Click **Select** to add the application to the Iru Endpoint Library. Select **View Library Item** to view application configuration options. You can also select **Continue Adding** to remain in the Google Play iframe and search for additional apps. Select **Edit** in the lower-right corner to configure the application. ### Configure Google Play app settings After you select **Edit**, set a label and Blueprint assignment, then configure **Installation**, **Options**, **Permissions**, and **Configurations**. Which settings appear can depend on what the app supports in Google Play. Click **Save** when you finish. Enter a **Label** to distinguish this Library Item from other instances of the same app. The label is for admins only and is not shown to end users. Under **Assignment Maps**, click **+ Assign** to assign the Library Item to one or more **Blueprints**. You can use Assignment Maps for conditional logic if needed. Specify how the Google Play app is installed: * **Install and continuously enforce**: Force the app install and prevent user removal. * **Install on-demand from Managed Google Play**: Allow end users to install the app manually from Managed Google Play. In **Options**, under **Automatic updates**, choose how the app updates: * **Low priority**: Update automatically when the device is idle, charging, and connected to an unmetered network. * **High priority**: Update as soon as possible with no constraints. * **Delayed**: Postpone automatic updates by 90 days. End users can still update the app on demand. Still in **Options**, select **Allow as credential manager** to allow this app to act as a credential manager (such as a password manager or passkey provider) in the work profile, even when the [Android Restrictions](/en/endpoint/library/library-items-profiles/configure-the-android-restrictions-library-item) Library Item blocks it. Google Play app Library Item Options showing Allow as credential manager selected Set how the app handles runtime permission requests: * **Set default permission policy**: Choose the default response for permission requests from this app: **Prompt**, **Grant**, or **Deny**. * **Manage specific permissions**: Set a response for individual permissions. Requires Android API level 24 or higher. Select **+ Add permissions**, choose permissions in the picker (search or **Select all**), then click **Done**. For each permission, choose **Prompt**, **Grant**, or **Deny**. Available permissions come from Google Play and depend on the app. If the app supports managed configurations, set them under **Configurations**: * **Select configurations**: Choose supported configuration keys, then set values for each. * **Enter JSON configuration**: Paste or edit the raw JSON configuration. You can use [Global Variables](/en/endpoint/library/library-items-profiles/global-variables) for configuration values. Variables resolve based on the enrolled user or device. If the app does not support managed configurations, Iru shows that in the **Configurations** section and no keys are available. Click **Save** to deploy the Library Item to assigned devices. # Configure the AirPlay Security Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-airplay-security-library-item Configure the AirPlay Security Library Item in Iru Endpoint to control AirPlay access on Apple devices. Set passwords and restrict AirPlay destinations. This Library Item is available for Apple devices ### What is AirPlay? AirPlay is Apple's wireless protocol for streaming and sharing media like videos, photos, and music from Apple devices such as iPhone, iPad, and Mac to compatible devices like Apple TV, smart TVs, and speakers. It supports both audio and video streaming and allows screen mirroring to display your device's screen on a larger display. In organizations, using an AirPlay Security profile ensures that streaming and mirroring content remains both safe and user-friendly. With AirPlay Security, you can manage who can connect to an Apple TV via AirPlay and tailor the authentication requirement to suit organizational needs. ### How does AirPlay Work? AirPlay uses AES encryption to keep data safe as it travels between devices. Using an AirPlay Security Library Item in Iru Endpoint, you can limit AirPlay connections to devices on the same network and choose to set up a passcode or password for extra security. ### Add an AirPlay Security Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new AirPlay Security Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Choose an **Access Policy** option. * **Allow connections from all devices:** This option will let any nearby device attempt to use AirPlay with the Apple TV, as long as it's in range. * **Require devices to be on the same network as Apple TV:** This option requires devices to be on the same network as the Apple TV to AirPlay content. Select a **Security Policy** option. * **Require a passcode every time:** This option will require the connecting device to enter a passcode that's shown on an enrolled Apple TV at every connection. * **Require a passcode once per device:** Require the connecting device to enter a passcode only at the device's *first* connection to each enrolled Apple TV. * **Specify a password:** This option lets you set a static password to connect to the Apple TV. Note that this password will *not* be displayed on the Apple TV when an AirPlay connection is initiated. Click **Save**. # Configure the Android Restrictions Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-android-restrictions-library-item Set up the Android Restrictions Library Item in Iru Endpoint to control work profile, personal profile, and device restrictions on company-owned Android devices. This Library Item is available for Android devices **Restrictions** limit user access to device features, apps, and system behavior. Use the **Android Restrictions Library Item** to apply those limits on **company-owned work profile** Android devices through Blueprints. Enforcement uses the Android Management API. For Apple devices, see [Configure the Apple Restrictions Library Item](/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item). ### Add an Android Restrictions Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the Iru Endpoint Library. Select **Add Library Item** in the upper-right corner. Select **Android Restrictions** and click **Add and configure** in the lower-right corner. Configure the **Android Restrictions** settings. Click **Save**. ### Android Restrictions Reference These controls mirror what Iru exposes from the Android Management API. Pick the ones that match your policy. Specify how personal apps can access work profile contacts, including contact searches and incoming calls. * **Allow**: Personal apps can use work contacts unless you list specific apps to block. * **Deny**: Personal apps cannot use work contacts unless you list specific apps to allow. * **Allow for system apps only**: System apps can use work contacts; you maintain a list of any other apps that may use them. Click **Add exception**. In the picker, use **Search the Play Store** in the embedded view (click **Select** for each app, repeat as needed), or open the **Add package name** tab, enter **App name** and **Package name** (for example Google Chrome and `com.android.chrome`), click **Add** for each row, then click **Done**. You can also click **+ Add app** on the restriction to add another row to the table. The line above the table is **Except deny for** if **Allow** is selected, **Except allow for** if **Deny** is selected, or **and** if **Allow for system apps only** is selected. Each row lists **App name** and **Package name**. Specify how data from one profile can be shared with apps in the other profile. This only applies to simple data sharing via app intents, such as what appears in the Android Sharesheet. Copy and paste between profiles is a separate control. Use **Disallow cross profile copy & paste** for the clipboard. * **Allow**: Apps can share data between the work profile and the personal profile. * **Deny**: Apps cannot share data between profiles. * **Deny work to personal**: Apps cannot share data from the work profile to the personal profile. Controls whether text can be copied and pasted between the work profile and the personal profile. * **Unchecked**: Text can be copied and pasted both ways between profiles. * **Checked**: Text copied from the personal profile cannot be pasted into the work profile, and text copied from the work profile cannot be pasted into the personal profile. Disables camera access for the profile or device scopes you enable in the table. Honor any **Android 12+** (or similar) requirement shown next to the control. Restricts screen capture for the scopes you select. Use the **Work profile** and **Personal profile** checkboxes. Only these three combinations are valid: | Work profile | Personal profile | Result | | ------------ | ---------------- | ------------------------------------------------------------------------- | | Unchecked | Unchecked | Screen capture is allowed in both profiles | | Checked | Unchecked | Disallow screen capture in the work profile only | | Checked | Checked | Disallow screen capture in both the work profile and the personal profile | Blocks creation of a private space. An existing private space may be removed when this restriction is applied. When enabled, set **Max days** for how long the work profile can remain paused. While the work profile is paused, the device may defer commands and policy updates. Specify if work profile applications are allowed to add widgets to the device home screen. Note, this does not prevent adding work app shortcuts to the device home screen. Controls whether work profile apps can expose app functions, and whether personal profile apps can call those functions. Use the **Work profile** and **Personal profile** checkboxes. Only these three combinations are valid: | Work profile | Personal profile | Result | | ------------ | ---------------- | --------------------------------------------------------------------- | | Unchecked | Unchecked | Allow work app functions, and allow personal apps to call them | | Unchecked | Checked | Allow work app functions, and prevent personal apps from calling them | | Checked | Checked | Disallow work app functions | Blocks installing apps from unknown sources for the scopes you select. Use the **Work profile** and **Personal profile** checkboxes. Only these three combinations are valid: | Work profile | Personal profile | Result | | ------------ | ---------------- | ----------------------------------------------------------------------------------------------- | | Unchecked | Unchecked | Installing apps from unknown sources is allowed in both profiles | | Checked | Unchecked | Disallow installing apps from unknown sources in the work profile only | | Checked | Checked | Disallow installing apps from unknown sources in both the work profile and the personal profile | Typically applies at **Device** scope. Applies to the **work profile**. Chooses the default response to runtime permission requests for work apps: * **Prompt**: Ask the end user to allow or deny each permission request. * **Grant**: Automatically allow permission requests. * **Deny**: Automatically deny permission requests. Sets the default for credential manager apps (password managers and passkey providers) in the **work profile**. Requires Android 14 or later. * **Block all** (default): No credential managers are available in the work profile unless you allow a specific app. This matches the [Android Management API](https://developers.google.com/android/management/reference/rest/v1/enterprises.policies#credentialproviderpolicydefault) default. * **Allow system app credential managers**: Pre-loaded OEM default credential managers (for example Google Password Manager or Samsung Pass) are available. Third-party credential managers stay blocked unless you allow them individually. To allow a specific third-party credential manager, open that app's [Google Play app Library Item](/en/endpoint/library/library-items-profiles/configure-android-apps-with-google-play-library-item) and, in the **Options** section, select the **Allow as credential manager** checkbox. That setting applies even when the default is **Block all**. Google Play app Library Item Options showing Allow as credential manager selected Select the **Require sign-in with managed Google Account** checkbox to require a managed Google Account on company-owned devices with a work profile. The managed Google Account must exist within the Google admin portal associated with Iru's Android Enterprise integration. Under **Require**, choose one of the following: * **Any managed Google Account**: The end user can sign in with any managed Google Account from your organization's managed Google domain. * **A specific managed Google Account**: The end user must sign in with a specific account. Enter a managed Google Account email, or type `$` to use a [global variable](/en/endpoint/library/library-items-profiles/global-variables) such as `$EMAIL`. Use a lowercase email address. This policy is enforced after enrollment completes. If the device does not have a required managed Google Account, the device prompts the end user to sign in and replace the anonymous managed Google Play account. Under **If the device is not compliant with this requirement**, you can set: * **Block the entire device** or **Block the work profile** a set number of days after non-compliance. Set days to `0` to block immediately. * **Erase the entire device** a set number of days after non-compliance. **Configuration options** depend on Android version and hardware. The Iru web app shows what you can set for each Library Item. ### Considerations Some restrictions apply to the full device; others only to the **work profile** or **personal profile**. Iru shows the scope next to each control. For **Disallow screen capture** and **Disallow apps from unknown sources**, use both unchecked, **Work profile** only, or both profiles. **Personal profile** alone is not valid. Developer Mode is disabled by default on managed Android devices. To allow it, deselect **Disallow Android Developer Mode** in this Library Item. Company-owned work profile only. The account must exist in the Google admin portal for your Android Enterprise integration. Without compliance actions, devices are only prompted. Android 14+ and work profile only. **Block all** matches the API default. Allow a third-party provider with **Allow as credential manager** on its Google Play app Library Item. You only get controls the Android Management API exposes. Apple and Android policies do not always map one-to-one across platforms. Test on representative devices and Android versions before a wide rollout. OEMs can interpret the same policy slightly differently. ### Deploy to Devices Assign the **Android Restrictions** Library Item to a Blueprint and click **Save** to deploy to your Android devices. # Configure the App Blocking Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item Block specific applications from running on managed macOS, Windows, and Android devices by configuring App Blocking Library Item lists and enforcement rules. This Library Item is available for Mac computers, Windows devices, and Android devices The **App Blocking** Library Item lets you block applications from running on **macOS**, **Windows**, and **Android** devices. When a user attempts to open a blocked application, it will be prevented from launching. On macOS, the app will immediately close and display a block message. On Windows, blocking is powered by **AppLocker**. With **Android work profile** enrollment, App Blocking applies to the **personal profile** only: Android removes blocked package names from that profile if they are installed. The managed **work profile** is handled separately. Deploy and update work apps through **managed Google Play**, not through App Blocking. To block apps on **iOS** or **iPadOS** devices, use an [Apple Restrictions Library Item](/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item) instead. As of January 8, 2025, App Blocking is configured using the **App Blocking** Library Item. This replaces the previous Application Blocking Parameter for **macOS**. Blueprints that already include the Parameter can still be edited, but the Parameter cannot be added to Blueprints that do not already have it. ## Create an App Blocking Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **App Blocking**. Give the Library Item a **Name**. Under **Install on**, select one or more platforms (**Apple**, **Windows**, **Android**). Assign the Library Item to one or more **Blueprints**. Iru Endpoint web application showing App Blocking Library Item Install on and Blueprint assignment In the Library Item, blocking is split into **Apple only settings**, **Windows only settings**, and **Android only settings** sections, so you configure each platform in its own area. ## Platform-Specific Configuration ### Mac Settings On **macOS**, App Blocking evaluates running applications against the identifiers you configure. When a launch matches a block rule, the app stops immediately and the user sees the block message (and optional **Learn More** link) from the Library Item. Expand **Apple only settings**, then open the nested **Mac only settings** section to configure process identifiers, match types, and optional block notifications. Configure the processes, paths, developer IDs or bundle IDs you'd like to block. Select the desired **Match type**: * **Contains:** Matches that contain the string. * **Exact:** Matches the exact string provided. * **Regex:** Matches based on regular expression using [Swift regex](https://developer.apple.com/documentation/swift/regex) syntax. Iru Endpoint web application showing App Blocking Apple only settings with Mac only settings expanded, block rules, and notification fields Use regex with caution. Test the implementation before you deploy it broadly. Optionally, customize the message, button title, and button URL users will be presented with when an application is blocked. Click **Save**. ### Blocking an Application from Device Record (macOS) Adding an item to the block list can also be performed from an individual **macOS** device record. These updates can either be added to an existing App Blocking Library Item or you can create a new one. Log in to Iru Endpoint and open a **device record** with the application you wish to block installed. Click the **Apps** **tab** and locate the **application** in question. Click the **More (...)** button to the right of the application and click "**Block Application**". Select the **Add rule** **to the following Library Item(s)** drop-down and select a Library Item or type to create new one. Select the desired **Blueprint** that should receive the Blocking Rule, and **customize the identifiers** as needed. Click **Create**. ### Example: Find a macOS App Bundle ID To find the bundle ID of a macOS app, you can use the **codesign** command in Terminal, replacing `/path/to/yourapp.app` with the path to your desired application: ```bash theme={null} codesign -dr - /path/to/yourapp.app ``` The output of this command will include information about the app, including the Team ID, Bundle ID, and Code Requirement which can be helpful when creating [PPPC Profiles](/en/endpoint/library/library-items-profiles/configure-the-privacy-preferences-policy-control-pppc-library-item). The Bundle ID will usually be at the end of the output, after the word **identifier**. In the example output below, the Bundle ID for Keynote is **com.apple.iWork.Keynote**. ```text theme={null} identifier=com.apple.iWork.Keynote ``` ### User Experience * On Mac, users attempting to open a blocked app will see the configured block message. * If you configure a **Learn More** button, users can click it to be directed to your specified URL. You can read more about this in our [User Experience with Application Blocking](/en/endpoint/library/library-items-profiles/application-blocking-user-experience) article. ### Windows Settings On **Windows**, App Blocking uses **AppLocker** to enforce your rules. When an executable matches a block rule, it cannot start; behavior follows AppLocker for the rule types you configure. Under **Windows only settings**, you can configure application blocks using AppLocker. * **Block all unsigned apps** Prevents all unsigned applications from running. You can add exceptions if necessary. * **Configure apps to block** Add specific apps to block by name, file path, or publisher. * **App name**: Friendly name for reference. * **Block**: Choose which file types to block: * EXEs * Scripts * MSIs * Store apps * All types * **Block method**: Define how Iru Endpoint should evaluate the rule (publisher, path, or SHA256 file hash). For detailed information about AppLocker, refer to Microsoft's [AppLocker documentation](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/applocker/applocker-overview). ### Gather File Details for Block Rules When you add rules under **Configure apps to block**, the **Publisher**, **Path**, and **SHA256 file hash** block methods need values that match what AppLocker expects. The most reliable approach is to run the PowerShell cmdlet on a reference computer where the application is already installed, using the full path to the executable you intend to block. Open PowerShell and run: ```powershell get-applocker-file-information.ps1 theme={null} Get-AppLockerFileInformation -Path "C:\Full\Path\To\application.exe" | Format-List ``` Replace the path in quotes with the full path to the file you want to inspect. The command returns the **Path** (often expressed with environment variables such as `%PROGRAMFILES%`), **Publisher**, **Hash** (SHA256), and **AppX** (`True` or `False` for Microsoft Store style packages). For example, to inspect a fictional app installed at `C:\Program Files\FooDev\Foo\Application\foo.exe`: ```powershell get-applocker-file-information-foo.ps1 theme={null} Get-AppLockerFileInformation -Path "C:\Program Files\FooDev\Foo\Application\foo.exe" | Format-List ``` Example output: ```text applocker-file-information-foo.txt lines theme={null} Path : %PROGRAMFILES%\FOODEV\FOO\APPLICATION\FOO.EXE Publisher : O=FOO DEV, L=MIAMI, S=FLORIDA, C=US\FOO\FOO.EXE,1.2.3.4 Hash : SHA256 0x637694332FEA4D87154635D02D7EE525F734D2B20AA1DB686B357A2511C2D4CE AppX : False ``` ### Block Applications Using the Publisher Block Method To build a **Publisher** rule in the App Blocking Library Item, copy the **Publisher** value from the cmdlet output, then trim it so AppLocker matches the certificate’s subject and location fields only (everything before the first backslash). 1. Run `Get-AppLockerFileInformation` with the full path to the executable, piped to `Format-List`, as in [Gather File Details for Block Rules](#gather-file-details-for-block-rules). 2. Locate the **Publisher** line in the output. Copy the string from the start through the character **before** the first backslash (`\`). 3. In Iru Endpoint, open your App Blocking Library Item. 4. Expand **Windows only settings** and enable **Configure apps to block**. 5. Add or edit a rule, set **Block method** to **Publisher**, and paste the trimmed value into **Publisher**. For the sample **Publisher** value above: ```text theme={null} O=FOO DEV, L=MIAMI, S=FLORIDA, C=US\FOO\FOO.EXE,1.2.3.4 ``` use only the portion before the first backslash: ```text theme={null} O=FOO DEV, L=MIAMI, S=FLORIDA, C=US ``` Enter that trimmed string in the rule’s **Publisher** field (for example, a rule that blocks **All types** when **Publisher** matches that value). A **Publisher** rule blocks every application that presents the same publisher information, not only the executable you inspected. For example, blocking one product from publisher **Foo Dev** can also block another product from the same publisher, such as a companion sync client, if it shares that publisher string. ### User Experience * On Windows, blocked apps will fail to launch, following AppLocker behavior. ### Android Settings Under **Android only settings**, you can block applications by package name. * **Blocked app name**: Optional display name for reference. * **Package Name**: The required unique identifier of the Android app. If the app is already installed in the **personal profile**, Android removes it when the policy applies. Android Enterprise allows certain **personal usage** controls on [company-owned devices with a work profile](https://developers.google.com/android/management/provision-device#company-owned_devices_for_work_and_personal_use), including blocking listed apps in the **personal profile** while most policies stay scoped to the **work profile** ([personal usage policies](https://developers.google.com/android/management/policies/work-profile#personal_usage_policies)). The App Blocking Library Item uses that pattern: it targets the personal profile, not the work profile. Work apps are installed, updated, and removed through **managed Google Play**. To find an Android app's package name (for example, `com.android.chrome` for Google Chrome): * Search the web for `[app name] package name` * Use the Google Play Store URL for the app (the package name is the `id` query parameter) * Check app details on the device record **Apps** tab in Iru Endpoint * Run `adb shell pm list packages` on a connected Android device ### User Experience * On Android, blocked apps are removed from the **personal profile** when installed there; the **work profile** is unchanged by App Blocking. ## Considerations * **Cross-platform:** The App Blocking Library Item works across macOS, Windows, and Android. Choose which platforms to target under **Install on**. * **Import from Parameter:** On **macOS**, you can import settings from the legacy Application Blocking Parameter in a Blueprint into the App Blocking Library Item. * **Multiple Library Items:** You can assign more than one App Blocking Library Item to the same Blueprint; all block rules are combined. * **Assignment maps:** You can add multiple App Blocking Library Items to an Assignment Map; all App Blocking rules are combined when evaluated. * **Parameter vs Library Item:** When both exist in a Blueprint, Iru Endpoint uses the Library Item settings. * **Activity:** Blocked actions are logged in both the device and Blueprint activity streams. ## Best Practices Test application blocking rules on a small group of devices before deploying to your entire fleet. Maintain documentation of which applications are blocked and why for audit and troubleshooting purposes. Inform users about application blocking policies to set proper expectations. Regularly review blocking activity logs to ensure policies are working as intended. ## Troubleshooting **Possible causes:** * Block configuration not yet deployed to device * Application not in the blocked applications list * Device not enrolled or agent not installed **Solutions:** * Verify the App Blocking Library Item is assigned to the device's Blueprint * Check that the application is correctly identified in the blocked list * Ensure device is properly enrolled and agent is running **Possible causes:** * No custom message configured * Agent not installed or not running * Application not properly identified **Solutions:** * Configure a custom message in the App Blocking Library Item * Verify Iru Agent is installed and running on the device * Check application identification in the blocked applications list **Possible causes:** * AppLocker service not running * Group Policy not applied * Device not domain-joined (for some features) * **Publisher**, **Path**, or **SHA256 file hash** values do not match what AppLocker expects for the executable **Solutions:** * Check that AppLocker service is running * Verify Group Policy is applied correctly * Ensure device meets AppLocker requirements * For each block rule, confirm the **Publisher**, **Path**, or **SHA256 file hash** you configured matches the executable and what AppLocker expects; use [Gather File Details for Block Rules](#gather-file-details-for-block-rules) to validate values **Possible causes:** * App not in personal profile * Device not properly enrolled * Package name incorrect **Solutions:** * Verify the app is installed in the personal profile * Check device enrollment status * Confirm the package name is correct ## Security Considerations Regularly review blocked applications to ensure they remain appropriate for your security policies. Establish a process for managing exceptions to blocking rules when business needs require it. Monitor blocking activity logs to detect potential security issues or policy violations. Educate users about application blocking policies and approved alternatives. # Configure the App Lock Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-app-lock-library-item Configure the App Lock Library Item in Iru Endpoint to restrict iOS and iPadOS devices to a single app. Set allowed features and autonomy options. This Library Item is available for iOS devices, iPadOS devices, and Apple TV ### What is App Lock? App Lock restricts an Apple device to a single app, enhancing security and focus by preventing access to other apps and system functions. This feature is particularly useful in environments where devices need to operate under strict usage guidelines, such as in educational settings, kiosks, or retail displays. When App Lock is active, the defined app reopens immediately after the device is restarted, ensuring continuous operation in the selected app. Configuration involves selecting the app to lock the device to, and disabling various features such as touch input, volume buttons, and motion detection to prevent users from exiting the app or modifying the device's state. App Lock works on iOS, iPadOS, and tvOS. ### Add an App Lock Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new App Lock Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Configure the app identifier to which you'd like to lock the device. A list of third-party bundle identifiers is maintained at [AppSearch.co](http://appsearch.co/). Specify which physical switches and Accessibility features should be enabled when the device uses the App Lock configuration. Specify which user-enabled options should be allowed when using the App Lock configuration. # Configure the BitLocker Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-bitlocker-library-item Set up the BitLocker Library Item in Iru Endpoint to encrypt Windows device drives. Configure encryption methods, recovery options, and escrow keys. This Library Item is available for Windows devices The **BitLocker** Library Item lets you configure and enforce BitLocker encryption settings on Windows devices. BitLocker provides full-disk encryption to protect data at rest, so sensitive information can't be accessed if a device is lost or stolen. Some configuration options require a Microsoft Entra ID–joined device. Settings are divided into **General**, **System (OS) drives**, **Fixed (internal) drives**, and **Removable (external) drives**. For more details on BitLocker configuration and requirements, see Microsoft's [BitLocker documentation](https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview). ## Create a BitLocker Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **BitLocker**. Give the Library Item a **Name**. Assign it to one or more **Blueprints**. ## Settings ### General * **Require BitLocker encryption** Enforces encryption on the device. * **Prompt user to enable BitLocker** * When enabled, users see a prompt to turn on BitLocker. Requires an Entra ID–joined device. * **Configure identification fields** Allows you to define identification metadata for BitLocker. ### System (OS) Drives * **System drive encryption type** Defines the encryption method used by BitLocker. * **Allow BitLocker without a compatible TPM** If enabled, requires a startup password or USB drive for authentication on systems without TPM. * **Startup authentication policy** Controls whether BitLocker requires additional authentication (e.g., PIN, USB key) at startup. * **Permit enhanced PINs** Allows enhanced PINs with uppercase, lowercase, numbers, symbols, and spaces. * **Allow standard users to change BitLocker volume PINs** Lets standard users (users without administrator rights on the device) change BitLocker PINs if they know the existing PIN. * **Allow devices compliant with InstantGo or HSTI to opt out of pre-boot PIN** Exempts compliant devices from requiring pre-boot authentication. * **Required minimum PIN length** Sets minimum TPM startup PIN length (4–20 digits, default is 6). * **Configure system drive recovery options** Determines how recovery information is handled when startup keys are missing. * **Customize recovery screen** Optionally customize the recovery message or URL displayed during recovery. ### Fixed (Internal) Drives * **Require BitLocker for write access to fixed (internal) drives** When enabled, fixed drives without BitLocker protection are mounted as read-only. * **Configure fixed (internal) drive recovery options** Defines recovery behavior when credentials are unavailable. ### Removable (External) Drives * **Allow users to apply BitLocker protection on removable drives** Permits users to run the BitLocker setup wizard for removable drives. * **Allow users to suspend and decrypt BitLocker on removable data drives** Lets users pause or remove BitLocker protection for maintenance. * **Require BitLocker for write access to removable (external) drives** When enabled, removable drives without BitLocker are mounted as read-only. ## Considerations * Enabling strict policies (such as requiring TPM or write access restrictions) may block users from accessing drives until BitLocker is properly enabled. * Use recovery configuration options to ensure that you can regain access if users forget PINs or lose recovery keys. * Testing in a small pilot group before broad deployment is recommended. ### Recovery Key Storage Recovery keys can be stored in different locations depending on the device's configuration and join state: When recovery keys are backed up to Active Directory or Entra, you can retrieve them and assist users who are locked out. This requires that the device be **domain-joined** (for AD) or **Entra-joined**. Using a centralized directory service (Active Directory or Entra ID) is strongly recommended for enterprise environments so that you can provide recovery assistance. Recovery keys can also be backed up to a personal Microsoft account (such as Outlook.com or Hotmail). In this case, only the end user can access the recovery key; administrators cannot retrieve it. Keys saved to USB can be used by the end user to recover their own device, but administrators cannot access these keys centrally. ## Best Practices Test BitLocker policies on a small group of devices before rolling out to your entire fleet. Set up appropriate recovery key storage options based on your organization's needs and security requirements. Clearly document BitLocker policies and recovery procedures for your IT team and end users. Regularly check that devices are properly encrypted and compliant with your BitLocker policies. ## Troubleshooting **Possible causes:** * Device not Entra ID–joined (for some features) * TPM not available or not enabled * Insufficient disk space **Solutions:** * Verify device join status * Check TPM availability in Device Manager * Ensure adequate free disk space **Possible causes:** * Recovery key not backed up to directory service * User account issues * Network connectivity problems **Solutions:** * Verify recovery key backup configuration * Check user account status * Ensure network connectivity for directory services **Possible causes:** * Encryption process still in progress * Hardware limitations * Software conflicts **Solutions:** * Wait for encryption to complete * Check device hardware specifications * Review installed software for conflicts For recovery key management, refer to Microsoft's [BitLocker recovery guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/recovery-overview). # Configure the Certificate Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-certificate-library-item Set up the Certificate Library Item in Iru Endpoint to deploy trusted certificates to Apple and Windows devices for authentication and secure connections. This Library Item is available for Apple and Windows devices You can upload certificates and deploy them to your Apple and Windows devices using the **Certificate Library Item**. This is useful when you're configuring services that need a valid certificate trust chain or apps that support certificate-based authentication. If your organization uses Microsoft Active Directory Certificate Services (AD CS), complete the tenant-side [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) and [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration) so issuing CAs are available in Iru Endpoint. Use this Library Item to deploy root and intermediate trust chains from uploaded files. To request certificates **from** AD CS, add the **AD CS certificate** type in this same Library Item and follow [**AD CS Certificates**](#ad-cs-certificates) below when that type appears for your tenant. #### Create a Certificate Profile To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your Library Item a descriptive **title**. Assign the Certificate Library Item to a [Blueprint](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). ### Apple Certificate Configuration Select the certificate type you are deploying. Supported types include: * **PKCS #1-formatted certificates** (`.cer`, `.crt`, `.der`) * Contain a certificate without a corresponding private key. * **PKCS #12-formatted certificates** (`.p12`, `.pfx`) * Contain both a certificate and corresponding private key. #### PKCS #1-formatted Certificates To deploy a PKCS #1-formatted certificate, use the steps below: From the **Certificate type** drop-down, select **PKCS #1-formatted certificate**. Under **Certificate**, upload your `.cer`, `.crt`, or `.der` file. You can also drag the file onto the upload box. Enter a **Certificate name**. This is the display name of the certificate that will appear in System Settings on macOS. Click **Save** to finish configuration. PKCS #1 certificates contain only the certificate itself and do not include a private key. If your workflow requires both a certificate and private key, use a PKCS #12-formatted certificate instead. #### PKCS #12-formatted Certificates When you select **PKCS #12-formatted certificate**, follow these steps to configure it for your environment. **Certificate password -** This option appears when you select the **PKCS #12-formatted certificate type**. Enter the password used to decrypt the certificate identity. **Certificate -** Click to upload your certificate or certificate identity file. You can also drag it onto the Certificate box. **Certificate name -** Give the certificate a name that will appear on the configuration profile. **Allow apps to access the private key -** This option appears when you select the **PKCS #12-formatted certificate** type. By selecting it, all apps will automatically be able to use the certificate identity. This is useful when you're setting up apps or services that require certificate-based authentication. If you deselect this option, users with administrator privileges will need to use the Keychain app to allow the use of the certificate identity. **Prevent the private key data from being extracted from the keychain -** This option appears when you select the **PKCS #12-formatted certificate** type. This prevents the private key from being exported from the macOS keychain and ensures the identity stays on the Mac where it was deployed. Click **Save** when finished. #### AD CS Certificates If the AD CS certificate type is available in your tenant, use the steps below to configure a certificate request from Active Directory Certificate Services. To deploy AD CS certificates, the [AD CS integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) must already be set up and configured. Enter a **Certificate name**. This appears on the configuration profile in System Settings. Enter a **Certificate subject** used to identify the device within the certificate authority. You can use a static value or a global variable such as `$SERIAL_NUMBER`. Add any **Subject Alternative Names (SANs)** required for the certificate request. To support strong certificate mapping requirements from Windows update [KB5014754](https://support.microsoft.com/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16), add this URI SAN value: `$ADCS_STRONG_MAPPING_ID`. Enter the **Template name** for the AD CS computer certificate template used to generate AD CS certificates, then select an **AD CS server** from the dropdown. AD CS servers are added during [AD CS integration configuration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration). Select a **Key size**. Optionally select **Allow apps to access the private key** and **Prevent the private key data from being extracted from the keychain**. Click **Save**. #### Troubleshooting ##### Certificates Marked as Untrusted When you deploy a device certificate, include the complete certificate trust chain: * The **device certificate** * Any **intermediate certificates** * The **root certificate** Certificate trust chains work hierarchically, starting with a trusted root certificate, passing through intermediates, and ending with the device certificate. Each certificate vouches for the next, creating a verifiable path back to a trusted source. If any part of the chain is missing, devices may mark the certificate as untrusted. This can lead to connection issues or warnings. Make sure you upload and deploy the full chain. ### Windows Certificate Configuration Select the certificate type you are deploying. Supported types include: * **PKCS #1-formatted certificates** (`.cer`, `.crt`, `.der`) * Contain a certificate without a corresponding private key. * **PKCS #12-formatted certificates** (`.p12`, `.pfx`) * Contain both a certificate and corresponding private key. #### PKCS #1-formatted Certificates To deploy a PKCS #1-formatted certificate, use the steps below: From the **Certificate type** drop-down, select **PKCS #1-formatted certificate**. Under **Certificate**, upload your `.cer`, `.crt`, or `.der` file. You can also drag the file onto the upload box. Under **Certificate store**, select where the certificate will be installed. Click **Save** to finish configuration. PKCS #1 certificates contain only the certificate itself and do not include a private key. If your workflow requires both a certificate and private key, use a PKCS #12-formatted certificate instead. #### PKCS #12-formatted Certificates When you select **PKCS #12-formatted certificate**, follow these steps to configure it for your environment. **Certificate password -** This option appears when you select the **PKCS #12-formatted certificate type**. Enter the password used to decrypt the certificate identity. **Certificate -** Click to upload your certificate or certificate identity file. You can also drag it onto the Certificate box. **Key location**: Select where the certificate's key will be stored in Windows. **Allow private key to be exported**: Choose whether the private key can be exported from Windows after deployment. Click **Save** when finished. #### Troubleshooting ##### Certificates Marked as Untrusted When you deploy a device certificate, include the complete certificate trust chain: * The **device certificate** * Any **intermediate certificates** * The **root certificate** Certificate trust chains work hierarchically, starting with a trusted root certificate, passing through intermediates, and ending with the device certificate. Each certificate vouches for the next, creating a verifiable path back to a trusted source. If any part of the chain is missing, devices may mark the certificate as untrusted. This can lead to connection issues or warnings. Make sure you upload and deploy the full chain. # Configure the Mac Custom App Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-custom-apps-library-item Upload and deploy custom applications to Mac computers using the Custom App Library Item. Support PKG, DMG, and ZIP formats with pre and post-install scripts. This Library Item is available for Mac computers The **Mac Custom App** Library Item lets you deploy custom applications (PKG, DMG, ZIP) to Mac computers. For details on installers, execution options, scripts, and troubleshooting, see the [Custom Apps Overview](/en/endpoint/library/library-items-profiles/custom-apps-overview). ## Create a Mac Custom App Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **Mac Custom App**. Give the Library Item a **Name** and assign it to one or more **Blueprints**. Set **Execution Frequency** to install once per device, audit and enforce, or install on demand from Self Service. For more, see [Execution Frequency](/en/endpoint/library/library-items-profiles/custom-apps-overview#execution-frequency) in the overview. Choose **Package Type** (Installer Package, Disk image, or ZIP file). See [Installers](/en/endpoint/library/library-items-profiles/custom-apps-overview#installers) in the overview for details. Attach a .pkg, .dmg, or .zip file (maximum 5 GB). If you use a .zip file, you can set an unzip location; if you use a .dmg, the image must contain only a .app file. See [Installers](/en/endpoint/library/library-items-profiles/custom-apps-overview#installers) in the overview for details. Optionally add **Pre-install** and **Post-install** scripts. See [Pre- and Post-Install Scripts](/en/endpoint/library/library-items-profiles/custom-apps-overview#pre-and-post-install-scripts) in the overview for details. Optionally check **Restart after successful install**. See [Restart](/en/endpoint/library/library-items-profiles/custom-apps-overview#restart) in the overview. Under **Advanced Settings** > **Liftoff Settings**, optionally select **Hide in Liftoff** and enter a **Friendly name**. See [Liftoff Settings](/en/endpoint/library/library-items-profiles/custom-apps-overview#liftoff-settings) in the overview. Click **Save**. The new Mac Custom App will now appear in your Library and be ready to be added to a Blueprint. ### Configure an Assignment Map to Deploy a Mac Custom App Navigate to **Blueprints** in the left-hand navigation bar. Select the **Assignment Map** you'd like to add the Mac Custom App to. Click **Edit Assignments** in the upper right corner. Drag your Mac Custom App from the left side of the Assignment Map to your desired node on the map. Click **Save**. ### Related Articles Deploy custom applications to Mac and Windows devices Step-by-step setup for Windows Custom Apps (MSI, EXE) # Configure the Default Apps Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-default-apps-library-item Set default applications for iOS and iPadOS devices using the Default Apps Library Item. Configure default mail, browser, and other app associations. This Library Item is available for iOS devices and iPadOS devices This Library Item requires iOS 26 or iPadOS 26. ### What is the Default Apps Library Item? The Default Apps Library Item lets you configure default applications for web browsing, messaging, and calling on iOS and iPadOS devices. This Library Item provides centralized control over which applications users see as defaults when opening links, sending messages, or making calls. You can optionally restrict users from changing these default applications once they're set. This feature is available for iPhone and iPad devices running iOS 26+ and iPadOS 26+. ### How Default Apps Work This Library Item uses Apple's MDM Settings command to configure default applications and uses the Restrictions profile to prevent users from changing these settings. Once deployed, it sets your chosen applications as defaults for their respective categories. Users can manually change default applications by going to **Settings** > **Apps** > **Default Apps** on their iPhone or iPad, unless you've enabled the restriction option. ### Prerequisites Ensure you have the following before configuring the Default Apps Library Item: * Devices running iOS 26+ or iPadOS 26+ * Device supervision (required only if preventing users from changing defaults) * Apps installed on devices before they are configured as defaults * Apps must have proper developer entitlements to be set as defaults ### Configure the Default Apps Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Configure the three settings for default browser, messaging app, and calling app. These settings default to **not configured**. Select the **dropdown** to view available applications. Choose from previously-added **App Store app Library Items** or stock applications (Safari, Messages, Phone/FaceTime). You can also search for specific apps instead of scrolling through the list. If desired, check the boxes to **Restrict the user from changing the default**. Click **Save**. This option is enabled by default when a category is configured and prevents users from changing the default application selection. ### Library Item Options * **Setting**: Choose the default web browser application * **Options**: Previously-added App Store app Library Items or Safari * **Restriction**: Enable to prevent users from changing the default browser * **Setting**: Choose the default messaging application * **Options**: Previously-added App Store app Library Items or Messages * **Restriction**: Enable to prevent users from changing the default messaging app * Icons within each app record indicate individual platform support * Sourced from the **Install on** field in the specific App Store app Library Item * Ensure app compatibility with all platforms in the **Install on** field ### User Experience Once deployed, users will see your configured applications as defaults when: * Opening web links * Sending messages * Making calls Users can manually change these defaults by going to **Settings** > **Apps** > **Default Apps** on their device, unless you've enabled the restriction option. ### Considerations When configuring the Default Apps Library Item, keep the following requirements and limitations in mind: #### App Entitlement Requirements Apple requires specific app entitlements for third-party apps to be configured as defaults. Currently, there is no programmatic way to determine if an app is eligible to be set as default. **To verify app eligibility:** Deploy the app to a test device and check **Settings > Apps > Default Apps** to confirm the app appears as an available option. #### Installation Requirements * **Apps must be pre-installed:** The apps selected in the Default Apps Library Item must already be installed on the device for the Library Item to function properly. * **Installation failures:** If a selected app is not installed when the Default Apps Library Item is deployed, the Library Item will fail. * **Command priority:** The Library Item has a lower command priority than App Store apps to help mitigate race conditions during installation. #### Platform Compatibility When selecting a default app, ensure the app is compatible with all platforms specified in the **Install on** field. **Compatibility conflicts:** If the selected default app is not compatible with all specified platforms, a blocking error will be presented. **Example:** If configured with **Install on = iPhone, iPad** but the default app is only compatible with iPhone, you will need to either: * Remove iPad from the **Install on** field, or * Select a different app that supports both platforms # Configure the Disk Management Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-disk-management-library-item Configure the Disk Management Library Item in Iru Endpoint to manage volume settings and storage policies on Mac computers including APFS volumes. This Library Item is available for Mac computers ### What is Disk Management? Disk Management allows you to set mount restrictions for external and network drives. You can enable or disable the use of external and network storage entirely or only allow the use of read-only media. This Library Item is compatible with macOS 15 Sequoia and later. ### Add and Configure the Disk Management Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Disk Management Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Disk Management allows you to set the volume access level to one of the following: Select your desired access level for **External volumes**. * **Allowed** - The system can mount external storage that is read-write or read-only. * **Read Only** - The system can only mount read-only external storage. Note that external storage that is read-write will not be mounted read-only. * **Disallowed** - The system can't mount any external storage. Select your desired access level for **Network volumes**. * **Allowed** - The system can mount network storage that is read-write or read-only. * **Read Only** - The system can only mount read-only network storage. Note that network storage that is read-write will not be mounted read-only. * **Disallowed** - The system can't mount any network storage. Click **Save**. # Configure the Ethernet Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item Set up the Ethernet Library Item in Iru Endpoint to configure 802.1X authentication for wired network connections on Apple and Windows devices. This Library Item is available for Apple devices ### What is 802.1X Authentication? 802.1X is a standard for controlling access to a network. It ensures that only authorized devices can connect, making your network more secure. This protocol is used in both wired (Ethernet) and wireless networks. ### How 802.1X Authentication Works There are three main parts involved in 802.1X authentication: * **Supplicant** - This is the device (like your user's Mac) that wants to join the network. It provides credentials to the authenticator. * **Authenticator** - This is a network device, such as a switch or access point, that controls access to the network. It checks the credentials and decides whether to allow the device to connect. * **Authentication Server** - Usually a RADIUS server, it verifies the credentials provided by the supplicant and tells the authenticator whether to grant access. Iru uses MDM controls to configure your Mac computers with the required credentials to provide to the authenticator and authentication servers. Please work with your network team internally to determine your network requirements before configuring and deploying this Library Item. ### Add an Ethernet Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Ethernet Library Item a **Name**. **Assign** to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). ### Configure Authentication Settings #### Use as Login Window Configuration Using this configuration requires integration with a directory service. See [this Apple support article](https://support.apple.com/en-us/102001) for more information. This setting uses credentials entered at the login window to authenticate to the network using 802.1X protocols. This is particularly useful in environments where user credentials are required as a network authentication method. When you enable this setting, Mac computers will authenticate to the network using the credentials provided at the login screen, meaning they will not have network connectivity before login. #### Accepted EAP Types Select the **Accepted EAP Types** your network supports. You may select more than one and must set all the settings necessary for the selected EAP types. For more information on configuring specific EAP types, refer to our [Configuring EAP (Extensible Authentication Protocol) Types](/en/endpoint/library/deployment-guides/apple/configure-eap-extensible-authentication-protocol-types) support article. Many older encryption protocols are no longer considered secure. Use the most up-to-date authentication and encryption supported by your network. Ethernet Library Item authentication settings with Accepted EAP Types ### Configure an Identity Certificate You can configure an identity certificate using AD CS, SCEP, or by uploading a PKCS #12 file. For instructions on configuring identity certificates, see our [Using Identity Certificates for 802.1X Authentication](/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication) support article. When using AD CS, first set up the [AD CS integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) and add your certificate authority servers in [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration). #### Configure SCEP When using SCEP for identity certificates, ensure that SCEP is deployed inside the Ethernet Library Item, not as a separate SCEP Library Item. Ethernet Library Item identity certificate configured with SCEP ### Configure Certificate Trust Settings Specifying trusted certificates in the Ethernet Library Item is not recommended. If certificates are renewed or changed, you must redeploy the entire Ethernet profile, potentially causing devices to disconnect from the network. Root and intermediate certificates should be deployed as separate Certificate Library Items, and all of the necessary certificate servers need to be listed in the **Specify server certificate names** section. Install the trusted certificate chain for your RADIUS server(s) using a separate Certificates Library item. Then, specify the names of those certificates in the Ethernet Library item under **Specify server certificate names**. For more information, see Apple's guide, [Connect Apple devices to 802.1X networks](https://support.apple.com/guide/deployment/connect-to-8021x-networks-depabc994b84/web). Most enterprise environments require that devices trust the 802.1X authentication server(s), typically a Remote Access Dial-In User Server (RADIUS). The **Certificate trust** settings allow you to configure which certificates presented by the server devices will trust. If a device does not trust the authentication server(s), the user will be prompted to trust it. Select **Specify trusted certificates** if you want to provide certificates for the configured devices to trust. Then upload the certificates in .cer or .crt format. Select **Specify server certificate names** if you want to provide DNS names of certificates devices should trust. Then enter their DNS names. Wildcards are accepted. Select **Allow trust exceptions** if you want to ask the user whether to trust the authentication server if the presented certificate fails validation. This option is deprecated in newer versions of macOS and iOS. ### Configure Proxy Settings Configure devices to use a network proxy by configuring the settings in the **Proxy** section. To configure network proxy settings, toggle the **Proxy** section to **Managed**. To configure devices to use a Proxy Auto-Configuration (PAC) file, select **Automatic** for **Proxy type**. * Specify the **Proxy PAC URL** where devices can find the PAC file. * If you want devices to attempt to connect directly to destinations when the PAC file is not available, select **Proxy PAC fallback allowed**. To configure devices to use a specific proxy, choose **Manual** for **Proxy type**. * Provide the **Proxy server and port**. * If the proxy requires authentication, provide the **Proxy username** and **Proxy password**. # Configure the Home Screen Layout Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-home-screen-layout-library-item Configure the Home Screen Layout Library Item in Iru Endpoint to arrange app icons on supervised iOS and iPadOS devices. Set pages, folders, and dock apps. This Library Item is available for iOS devices and iPadOS devices The Home Screen Layout Library Item lets you determine the placement of apps on the iPad and iPhone devices in your fleet. When combined with the Wallpaper and Apple Restrictions Library Items, you can create a consistent experience for your users. This is particularly useful for shared devices. This Library Item requires supervision. ### Add a Home Screen Layout Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Set a **title** for this Library Item. Select the **device families** you want the Library Item to apply to. Select the desired **[Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints)**. ### Customize the Home Screen Layout Library Item Turn on customization for iPad or iPhone by toggling the **radio buttons** on the right side. The list of the apps on the left is populated from your Library, and contains your App Store Apps (the ones that are synced from Apps and Books in Apple Business or Apple School Manager) and a list of Apple pre-installed System apps (like Mail, Calendar and Settings). If desired, you can filter by **Blueprint** and **Library Item type** to help you create a layout that matches the apps scoped to your devices. Drag **apps** from the list on the left over to the **device page** on the right. You can select multiple apps at a time by clicking on them, then dragging your selection over. Add as many of your **apps** as will fit. An iPad can have 30 apps per page, arranged in a 5x6 grid (or 6x5 in landscape). An iPhone has a 4x6 grid, for a total of 24 apps. You can add **apps** to the **Dock** by dragging them to the Dock portion of the home screen layout at the bottom. A maximum of 4 apps can be added to the iPhone Dock, and 12 can be added to the iPad Dock. You can add new **pages** and manage up to 11 pages. Devices do not allow empty pages, so you can only add a new page after you have added at least one app to the current page. On iPad, you can toggle the **control** at the upper-right to switch between portrait and landscape device orientation. The apps will flow to match the view. You can add **folders** to your layout if desired. To do so, begin by selecting the **items** you want to add to the folder. Click on the **Actions** button in the upper-right corner of the Preview. Select **"Create Folder"**. Name the **folder** as desired. Close out of the **Folder modal**. ### Accessibility You can use the following keyboard shortcuts while building your Home Screen Layout Library Item: * Upon selecting an app, pressing the **Enter** or **Space** key will initiate the drag-and-drop process. * The **arrow keys** can be used to drag the app around the Preview. * Pressing **Enter** or **Space** again will drop the app at the desired location. * Clicking on multiple apps or using **Tab** and **Shift + Tab** to navigate to next/previous apps, followed by pressing **S** or **Shift + Enter** or **Shift + Space**, will add the app to the selection. ### Other Considerations To match the on-device experience, some apps and folders will appear in the Preview and cannot be removed. * On iPad, the App Library is added to the Dock on the Preview. It cannot be removed or moved anywhere else. * On iPhone, the Phone app is added to the home screen on the Preview. It can be moved to another location, but cannot be removed. * On both iPad and iPhone, the Settings app is added to the Preview. It can be moved to another location, but cannot be removed. To ensure the on-device layout matches what you defined, this Library Item automatically deploys an Allowed Apps Restriction payload that contains the apps in the layout you selected, hiding any other apps that may be present or installed on the device in the future. Both the `com.apple.webapp` and `com.apple.sidecar` bundle IDs are automatically deployed in this payload to ensure any webclips included in your Home Screen Layout configuration are visible and that Apple SideCar and Continuity features remain functional. In addition, the `com.apple.CoreCDPUI.localSecretPrompt` bundle ID is deployed to ensure users can log in to their Google or iCloud accounts. You shouldn't deploy a separate Allowed Apps List with the Apple Restrictions Library Item. They will conflict, and although the device attempts to resolve these conflicts, this will still lead to a layout you don't expect. Once the Library is saved, devices will receive the payload shortly. You'll notice the device's layout changing quickly, hiding all apps that weren't in the layout you defined. App Store Apps that are downloading or installing will be visible temporarily. The same goes for System Apps that automatically download after a device is erased and reset, like Books, Notes and others: once installed they are promptly hidden. Apple’s Settings app cannot be hidden with any MDM payload, per Apple platform restrictions. It remains visible on all devices to ensure that users that need them can configure Accessibility settings. Similarly, on iPhone the Phone app will remain accessible no matter what, to ensure anyone with the device can call emergency services. For more details about the Home screen layout payload, see [Apple's documentation](https://support.apple.com/guide/deployment/dep6d9bdb6e8). # Configure the In-House App Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-in-house-app-library-item Deploy enterprise in-house iOS and iPadOS apps using the In-House App Library Item in Iru Endpoint. Upload IPA files and manage app distribution. This guide applies to iOS devices and iPadOS devices ### In-House Apps In-House apps are proprietary applications designed for internal use within an organization. They are particularly useful when you need to keep your Custom Apps private and avoid the Apple App Store's review process. These apps are typically distributed directly to devices within your organization, bypassing public distribution channels. For more information about in-house apps, please see [Apple's documentation](https://support.apple.com/guide/deployment/distribute-proprietary-in-house-apps-depce7cefc4d/web). ### How It Works In-house apps allow organizations to deploy Custom Apps across their fleet of Apple devices. Using Iru Endpoint, you can create an In-House App Library Item to manage these deployments. When you upload your app's .ipa file to Iru Endpoint, the file is processed, parsing details like the app icon, bundle ID, and version information. Iru Endpoint then uses those details to automatically generate the required manifest file and deploy the app. ### Requirements * The uploaded file must be in .ipa format * The .ipa file size must not exceed 4GB * The uploaded file bundle version must be a semantic, integer-based version * When updating an in-house app, the newly uploaded file bundle ID must match the existing bundle ID * When updating an in-house app, the newly uploaded file bundle version must be higher than the previous version The In-House App Library Item cannot be duplicated. ### Add and Configure an In-House App Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new In-House App Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Under **Install Details**, upload your in-house app's .ipa file. Once your app is uploaded, it will be checked for file type, version, and bundle ID validity. In-House App upload interface showing file validation process with file type, version, and bundle ID checks ### AppConfig for In-House Apps The In-House App Library Item supports managed app configuration (AppConfig) for iOS, iPadOS, tvOS, and visionOS. You can paste an XML dictionary of key-value pairs so the app is configured over-the-air when it deploys. Edits to the app configuration automatically deploy to all assigned devices. In the Library, open the In-House App you want to configure. Locate the **Set app configuration** option and enable it. Paste your AppConfig XML dictionary of key-value pairs. Click **Save**. The configuration deploys with the app and updates when you change it. For more on AppConfig format and examples, see [Using AppConfig](/en/endpoint/library/library-items-profiles/using-appconfig). ### Updating In-House Apps When you're ready to deploy a newer version of an in-house app, there are two recommended approaches: #### Update the Existing In-House App in the Library * Upload the new version to the current In-House App Library Item. This will replace the old file and automatically send new installation commands to all devices assigned to that Library Item. * The new version must have the same Bundle ID as the previous one, and the version number should be higher than the current version. #### Create a New Library Item for the New Version * If you’d prefer to roll out the new version to a specific group of devices while keeping others on the current version, you can create a new In-House App Library Item. * Using Assignment Maps is recommended for this option. * Keep in mind that Blueprints or Assignment Map nodes can only include one in-house app per Bundle ID (the unique identifier Apple requires for each app). However, you can use the same Bundle ID across different Assignment Map nodes. Remember, the rightmost node always takes priority. * To keep things organized, name the Library Item with the app’s version number so you can easily distinguish between different versions of the same app. ### App Icon Parsing Considerations * When uploading an .ipa file to an In-House App Library Item, Iru Endpoint parses the metadata from the **Info.plist** file generated by Xcode. This file includes crucial info like metadata and icon images. The way Xcode builds these apps can vary based on your developer’s configuration. * To ensure Iru Endpoint can extract the correct app icon for display in either the In-House Apps Library or the Home Screen Layout Library Item, the icon image files must be **.png** files, and their filenames must be directly referenced in the **Info.plist** file. For example, in the **Accuhive.ipa** test app, the **Info.plist** file might look something like this under the **CFBundleIcons** key: ```xml Info.plist lines theme={null} CFBundleIcons CFBundlePrimaryIcon CFBundleIconFiles AppIcon60x60 CFBundleIconName AppIcon ``` In this case, Iru uses the **CFBundleIconFiles** key to locate and extract the app icon for display within the Library Item. In-House App Library Item showing app icon extracted from CFBundleIconFiles in Info.plist If the **Info.plist** file doesn’t reference an icon file, Iru won’t be able to display an icon in the Library Item. However, this only impacts Iru’s display. When the app is installed on a device, it will use the icon built into the app itself. ### Other Considerations * In-House Apps can be managed using the [Iru API](/en/endpoint/api/iru-api-overview). For more information, see our [API documentation](https://api-docs.kandji.io/#7468c0a8-7369-45cf-8f4b-0ef5725efc46). * Acceptable .ipa app version formats include integer-based X.Y.Z or X.Y. Other formats, such as X or those containing letters or symbols, are not permitted. * Once saved, your app will appear with its version and bundle ID information, making it easy to identify which app and version are ready for deployment. The details at the top of the Library Item will update to reflect this information. * Blueprints or Assignment Map Nodes can only include one In-House App per Bundle ID (the unique identifier Apple requires for each app on a device). However, you can use the same In-House App bundle ID across different nodes. As with all Assignment Map nodes, the rightmost nodes take precedence. # Configure the Liftoff Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item Configure the Liftoff Library Item in Iru Endpoint to guide users through Mac setup. Customize onboarding steps, required apps, and completion criteria. This Library Item is available for Mac computers ## What is Liftoff? Liftoff is Iru Endpoint's first-run setup experience for Mac. After enrollment, it appears on the Mac and shows the user progress while Library Items from the Blueprint install, before they start using the Mac. ## How Liftoff Works The **Install screen** is a list of Library Items from the Blueprint. As the Mac's first agent check-in runs, each item goes from pending to completed. Liftoff does not change how the check-in works. These Library Item types appear in the list: * Custom Scripts * Custom Printers * Custom Apps * Auto Apps If you use Automated Device Enrollment (ADE) and want specific Library Items to install during Setup Assistant **before** Liftoff, configure [**Install Library Items during Setup Assistant**](/en/endpoint/enrollment/apple/configuring-apple-enrollment#install-library-items-during-setup-assistant) in the Automated Device Enrollment Library Item. ### Liftoff Settings for Library Items For Custom Apps, Custom Scripts, and Custom Printers, **Liftoff Settings** on the Library Item includes: * **Hide in Liftoff**: If selected, the Library Item still processes during Liftoff but is not shown to the end user. While it processes, Liftoff shows **Processing additional required configurations before proceeding…** at the bottom of the screen. This setting does not affect ordering. * **Friendly name** (optional): If specified, Liftoff shows this name to the end user instead of the Library Item **Name**. The Iru Agent still orders those Library Items by **Name** during check-in. Set **Liftoff Settings** on: * [Mac Custom App](/en/endpoint/library/library-items-profiles/custom-apps-overview#liftoff-settings): **Advanced Settings** > **Liftoff Settings** * [Custom Scripts](/en/endpoint/library/library-items-profiles/custom-scripts-overview#liftoff-settings): **Liftoff Settings** * [Custom Printers](/en/endpoint/library/library-items-profiles/custom-printers-overview#liftoff-settings): **Liftoff Settings** Auto Apps do not include Liftoff Settings. ## Create a Liftoff Library Item Custom Apps or Custom Scripts that wait on user input can potentially be blocked from view and cause Liftoff to hang until the agent check-in times out. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. You can duplicate a Liftoff Library Item. Like Automated Device Enrollment, you can still only assign a single Liftoff Library Item per Blueprint. Liftoff does not support Assignment Rules. Place it in the **All Devices** node at the beginning of the Assignment Map to use it in that Blueprint. For more information about duplication, see [Library Item Duplication](/en/endpoint/library/library-items-profiles/library-overview#library-item-duplication) in Library Overview. Give your Liftoff configuration a **Name**. Assign the Liftoff configuration to your desired **Blueprint**. Liftoff Library Item showing Name and Blueprint assignment Select your **Enrollment trigger**. The available options include: * **All enrollments**: Liftoff will be presented regardless of enrollment type * **Automated Device Enrollment only**: Liftoff will only be presented to devices enrolled via Automated Device Enrollment * **Manual enrollment only**: Liftoff will only be presented to devices enrolled via Manual device enrollment Upload a **Logo**, a graphic that will appear in the upper-left corner of Liftoff. This is optional. The default image is for light mode. * If you also wish to include an icon for dark mode, select **Add Dark mode logo** after uploading your light mode logo. This icon will be used instead of the main logo when the user enables Dark Mode. Select a **Display mode**. We recommend using Window mode for initial testing for easy troubleshooting. Your display mode options are: * **Full screen**: Liftoff will be presented in Full screen mode and will prevent the use of the Mac until the initial agent check-in is completed. You can use the exit password to exit Liftoff early * **Window**: Liftoff will be presented in windowed mode. This will not prevent the use of the Mac, but Liftoff will be locked to the forefront. You can use the exit password to exit Liftoff early An **Exit password** is automatically generated. Click the eye icon to the right of the field to reveal the current password. Learn how to use the exit password in [Exit Password](#exit-password). Users can exit Liftoff by pressing **Command-Shift-K-J-D**. To replace the existing exit password, click **Generate new password** and then click **Save**. A replaced exit password is not logged. Liftoff General settings including Enrollment trigger, Logo, Display mode, and Exit password **Customize** the Install screen header and subheader; see the **Customize the Install Screen** section below. Switch between **Light Mode** and **Dark Mode** previews to see how the Install screen will appear. Liftoff Install screen with Customize and Light Mode preview **Customize** the Help screen header and body; see the **Customize the Help Screen** section below. Switch between **Light Mode** and **Dark Mode** previews to see how the Help screen will appear. Liftoff Help screen with Customize and Light Mode preview You can optionally turn off the **Complete** screen. If the Complete screen is not enabled, Liftoff will exit after completion. See the **Customize the Complete Screen** section below. Switch between **Light Mode** and **Dark Mode** previews to see how the Complete screen will appear. Liftoff Complete screen with Customize and Light Mode preview Click **Save** when you are satisfied with your Liftoff configuration. ### Customizing Liftoff #### Customize the Install Screen The Install screen's header and subheader can be customized. As you update the text on the right side of the window, the preview on the left is automatically updated to provide a preview of how it will be displayed for your users. Specify a **Header** for the Install screen. Specify a **Subheader** for the Install screen. You can restore the default text provided by clicking **Restore defaults**. Customize Install screen with Header, Subheader, Restore defaults, and Done Click **Done** when you are finished with your customizations. The preview in the web app will update, reflecting your changes. #### Customize the Help Screen The Help screen's header and subheader can be customized. Note that as you update the text on the right side of the window, the preview on the left is automatically updated to provide a preview of how it will be displayed for your users. Specify a **Header** for the Help screen. Specify a **Body** for the Help screen. You can restore the default text provided by clicking **Restore defaults**. Customize Help screen with Header, Body, Restore defaults, and Done Click **Done** when you are finished with your customizations. The preview in the web app will update, reflecting your changes. #### Customize the Complete Screen The Complete screen's header and subheader can be customized. Note that as you update the text on the right side of the window, the preview on the left is automatically updated to provide a preview of how it will be displayed for your users. Specify a **Header** for the Complete screen. Specify a **Subheader** for the Complete screen. Click and drag the **drag-and-drop** icon to reorganize the links. Click the **trash** icon to delete a link. Customize Complete screen showing Header, Subheader, and Links Click **Add link** to add an additional link; you can have a maximum of four. Upload a **custom icon** for your link. Specify a **Title** for the link (required). Specify a **Subtitle** for the link (required). Specify the **Button text** for the link (required). Specify a **Button URL** for the link, which will be launched when the user clicks the button (required). Button URLs support the following URL schemes: * **http\://** or **https\://** * Opens in the default browser, which is Safari unless the user has selected a different one. * **mailto://** * Opens in the default mail app, which is Mail unless the user has selected a different one. * On iOS and iPadOS, if the user hasn't yet configured a mail account, tapping a mailto:// bookmark results in an error. * **file://** (only supported on macOS) For more information about file paths in macOS, please refer to Apple's [documentation](https://support.apple.com/lv-lv/guide/terminal/apd3cf6fe02-3ec8-48f1-951f-866e52955fc8/mac). * Opens a file from a specified path. * Using three consecutive slashes, such as file:///path/to/file when defining file paths is recommended. If you need to restore the provided defaults, click **Restore defaults**. Customize Complete screen link settings for Mac Basics including Icon, Title, Subtitle, Button text, and Button URL Click **Done** when you are done with your customizations. #### Exit Password Liftoff has an exit password that can be used when Liftoff is in Full Screen or Window mode. In either case, the exit password can be used in the following scenarios: * The exit password can be used to unlock Full-screen mode, which allows for troubleshooting if Library Items are not installed as intended. This is only applicable when using full-screen mode. * The exit password can be used to quit the app through the menu bar before the agent run completes; this additionally unloads the launch agent. * This can be done after using the exit password to release Liftoff from Full Screen or Window mode. Window mode initially does not allow an early exit or show the Quit option in the menu bar. * To open the Exit Password prompt, press these keys simultaneously: **Command-Shift-K-J-D**. Liftoff Enter the exit password dialog to unlock full screen access ### Liftoff Logic Flow #### Evaluation of Liftoff Library Item * If there's no Liftoff configuration in the Blueprint, the Iru Agent will note that Liftoff is not eligible and won't try to retrieve the configuration again. * If a Liftoff configuration is present in the Blueprint, the details will be fetched. #### Enrollment Triggers * **Automated Device Enrollment Only** or **Manual Device Enrollment Only**: The agent will check the Mac's enrollment type. If it doesn't match the criteria, the agent will record that Liftoff is not eligible and won't try to retrieve the configuration again. * **All Enrollments:** The agent will skip evaluating the enrollment type. #### Eligibility Check * If the enrollment criteria are met, the agent will evaluate the duration of the Mac’s enrollment. * If the Mac has been enrolled for more than 1 hour, the agent will record that Liftoff is not eligible and won't try to retrieve the configuration again. * If all criteria are satisfied, the macOS agent will load the LaunchAgent to start Liftoff and initiate an initial check-in. #### Running Parameters with Liftoff * If there's no Liftoff configuration in the Blueprint, the Iru Agent will run all Parameters and then all Library Items in the Blueprint. * If a Liftoff configuration is present in the Blueprint, the Iru Agent will run all Library Items first, followed by all Parameters in the Blueprint. ### Other Considerations When using Liftoff with macOS Tahoe, ensure the **OS Showcase screen** is skipped in both your Automated Device Enrollment (ADE) configuration and Setup Assistant Library Item to prevent configuration interruptions. #### Device Localization When a user configures their macOS device to use one of the supported languages as its primary language, Liftoff displays localized text for non-customizable strings. No admin configuration is required to enable this capability. The following languages are supported: * Chinese (Simplified) * French / French (Canada) * German * Italian * Japanese * Portuguese * Portuguese (Brazil) * Spanish #### Required Restarts If single or multiple Library Items require a restart (such as a Custom App or Custom Script with the "Require restart" option enabled), all restart requests will be collated and held until the end of the Liftoff run. When a Library Item installed through Liftoff requires a restart, the restart timer will always be 5 minutes instead of the typical 30-minute countdown. #### Managed OS Managed OS settings will not be applied during Liftoff. Instead, after Liftoff has completed, the device will begin to cache the update in the background. Once the update is ready to install [the user will be alerted](/en/endpoint/devices/macos-managed-os-user-experience). For Automated Device enrollments, you can also [Require a Minimum OS](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment#require-minimum-os-version) for eligible devices. # Configure the Lock Screen Message Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-lock-screen-message-library-item Set a custom lock screen message on iOS and iPadOS devices using the Lock Screen Message Library Item. Display asset tags, contact info, or return instructions. This Library Item is available for iOS devices and iPadOS devices ### What is a Lock Screen Message? A lock screen message is customizable text on an iPhone or iPad lock screen. You can show organizational details, a reminder, or contact information if the device is lost. The Lock Screen Message Library Item sets that text on enrolled devices, for example a company identifier or an "If found, contact..." note. ### Add a Lock Screen Message Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Lock Screen Message Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). ### Customize the Lock Screen Message Library Item In the **Lock Screen Message** field, enter the text that will appear on the Lock Screen of iPhone and iPad (and on the login screen of Shared iPad). Click **Save**. ### Using Global Variables in the Lock Screen Message The Lock Screen Message Library Item supports the use of global variables. To use a global variable, type `$` and the list of available variables will appear in the dropdown list. # Configure the Login & Background Items Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-login-and-background-items-library-item Manage login items and background processes on Mac using the Login and Background Items Library Item. Approve or block items that launch at startup. This Library Item is available for Mac computers ### What are Login & Background Items? Login and background items refer to applications, processes, or scripts that are set to automatically start when a user logs in or when the system boots up. These items can enhance user experience by providing immediate access to frequently used applications or ensuring certain services are always running. Beginning with macOS Ventura, an end user receives alerts when an app has added a new login or background item and is provided with a way to disable it in **System Settings > General > Login Items**. To learn more about using MDM to manage background tasks in macOS, see [Apple's Platform Deployment guide](https://support.apple.com/guide/deployment/use-mdm-to-manage-background-tasks-on-mac-depdca572563/1/web/1.0). ### How managed Login & Background Items work You can use configuration profiles that define managed login and background items. These profiles ensure that essential software and services are available immediately after login and can't be disabled by end users, even those with local administrator credentials, enhancing security and improving the user experience. Managed Login and Background items rely on identifiers to allow specified background items. #### Identifier Types For **Bundle Identifier Prefix** and **Label Prefix**, use the "com.example" format, and be sure not to include a trailing period. Also, do not include other special characters such as "\*". When asked for the identifier type, you can select one of five options: **Bundle Identifier** * This option maps to a bundle identifier of an app that has adopted Apple's [SMAppService API](https://developer.apple.com/documentation/servicemanagement/smappservice). Check with the software vendor to determine if this option can be used. **Bundle Identifier Prefix** * This option lets you configure one rule for multiple apps sharing a bundle identifier prefix for apps that have adopted Apple's [SMAppService API](https://developer.apple.com/documentation/servicemanagement/smappservice). Check with the software vendor to determine if this option can be used. **Label** * This is used to identify launch agents and launch daemons. To find the label, inspect the property list (plist) files in `/Library/LaunchAgents`, `/Library/LaunchDaemons`, and those same folders in any user's home directory. You can also use the `sudo launchctl list` command to find labels of actively loaded or running items. **Label Prefix** * This is similar to the bundle identifier prefix but for labels. For example, if you have several custom launch daemons running on your systems, all with labels like com.myexamplecompany, you could specify that prefix to allow all of your items to load. **Team Identifier** * Most commercial app vendors sign their software with the same Apple Developer Team ID. Check their documentation for additional details. #### Choosing an Identifier Type Iru suggests using the Team ID option whenever you can, as it's the most secure choice. While bundle identifiers and labels can be mimicked by other software, code-signing identities linked to Apple Developer Team Identifiers are a core part of macOS security, making them much harder to fake. When you use the Team ID, apps that add themselves or that users add to Login Items can't be toggled in System Settings. Instead, you can use the app’s own settings, or right-click on the Dock icon and select “Open at Login” from the “Options” menu to turn the feature on or off. ### Add a Login & Background Items Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Login & Background Items Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Click **Add Background Item.** In the Modal that appears, enter the following details: * The identifier **Type** (more details below) * The **Identifier** itself * An optional **Comment** (this is not used by macOS, but is for your reference) Click **Save.** Optionally, repeat the previous steps to add additional background items. Click **Save** again. # Configure the Login Window Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-login-window-library-item Configure the Login Window Library Item in Iru Endpoint to customize Mac login screen behavior, display options, and authentication requirements. This Library Item is available for Mac computers The Login Window profile lets you customize options for the login window and lock screen, including Login Window & Lock Screen messages, available buttons, and user account visibility. ### Creating a Login Window Profile To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your profile a **name** such as Login Window. Select the desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select applicable options and **Save** your profile. ### Optional Details #### Lock Message The lock message option lets you set a custom message at the bottom of the login window. Global Profile Variables such as \$ASSET\_TAG can be used here. #### Disable Automatic Login After FileVault Disk Unlock This option disables the [FileVault](/en/endpoint/library/deployment-guides/apple/configure-filevault) Auto Login feature; enabling this option will require the end user to authenticate a second time at the Login Window after authenticating at the FileVault pre-boot authentication window. This option can be incredibly useful for environments that use smart cards or Yubico PAM authentication and want to ensure the user also authenticates with a smart card. #### Logged-In Users - Hide "Lock Screen" option in the Apple menu Enabling this option will prevent users from locking the Mac screen. This option can be critical in multi-user macOS environments, as once a screen is locked by a user, it can only be unlocked by that user unless a restart is forced. ### Auto Login for macOS 14 and Later Iru Endpoint supports allowing the configuration of auto login in the Login Window Library Item for devices running macOS 14 Sonoma and later. To configure auto login for a local user, enter the username and password in the **Auto Login** section of the Library Item. This user must already exist on the Mac, or the profile installation will fail. FileVault must also be disabled for Auto Login to function. # Configure the Microsoft Defender Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-microsoft-defender-library-item Set up the Microsoft Defender Library Item in Iru Endpoint for Windows devices. Configure real-time protection, scan schedules, and threat response actions. This Library Item is available for Windows devices The **Microsoft Defender** Library Item lets you configure and enforce settings for Microsoft Defender on Windows devices. This profile helps you manage antivirus, antispyware, and threat protection policies, along with configuration options for scanning, monitoring, network protection, updates, and exclusions. This ensures consistent endpoint protection across your organization. For detailed information on functionality, settings, and deployment considerations, see Microsoft's official [Microsoft Defender for Endpoint documentation](https://learn.microsoft.com/en-us/defender-endpoint/). ## Create a Microsoft Defender Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **Microsoft Defender**. Give the Library Item a **Name**. Assign it to one or more **Blueprints**. ## Settings The following settings are available for Microsoft Defender. * **Allow archive scanning** Scans for malicious software and unwanted software in archive files such as `.ZIP` or `.CAB`. * **Allow behavior monitoring** Enables behavior monitoring. * **Allow cloud protection** Joins Microsoft MAPS to send information about malicious or potentially unwanted software. * **Allow email scanning** Enables email scanning to parse mailboxes and attachments. * **Allow full scan on mapped network drives** Enables scanning of mapped network drives. * **Allow full scan on removable drive scanning** Controls whether removable drives (e.g., USB) are included in scans. * **Allow intrusion prevention system** Allow or disallow Intrusion Prevention functionality. * **Allow IO AV protection** Enables scanning for all downloaded files and attachments. * **Allow on access protection** Enables monitoring for file and program activity. * **Allow realtime monitoring** Allow or disallow Defender real-time monitoring functionality. * **Allow scanning network files** Allow scanning of network files. * **Allow script scanning** Allow or disallow Defender script scanning functionality. * **Allow user UI access** Controls whether the Defender UI is visible to users. * **Attack surface reduction only exclusions** Exclude files and paths from Attack Surface Reduction (ASR) rules. * **Configure Average CPU load factor** Configure maximum CPU utilization during a scan. * **Check for signatures before running scan** Manage whether a check for new security intelligence occurs before running scans. * **Specify days to retain cleaned malware** Define the number of days items remain in Quarantine before removal. * **Disable catchup full scan** Configure catch-up scans for missed scheduled full scans. * **Disable catchup quick scan** Configure catch-up scans for missed scheduled quick scans. * **Enable controlled folder access** Enable or disable controlled folder access for untrusted applications. * **Enable low CPU priority** Enable low CPU priority for scheduled scans. * **Enable network protection** Enable or disable Exploit Guard network protection. * **Excluded extensions** Specify file extensions to ignore during a scan. One extension per line. * **Excluded paths** Specify file paths to ignore during a scan. One directory path per line. * **Excluded processes** Specify processes to ignore during a scan. One process per line. * **PUA protection** Enable or disable detection for potentially unwanted applications. * **Scan parameter** Specify the scan type for scheduled scans. * **Schedule quick scan time** Specify the time of day to perform a daily quick scan. * **Schedule scan day** Specify the day(s) of the week for scheduled scans. * **Schedule scan time** Specify the time of day for scheduled scans. * **Threat severity default action (Low, Medium, High, Severe)** Customize which automatic remediation action will be taken for each threat alert level. * **Engine updates channel** Specify when devices receive Defender engine updates. * **Platform updates channel** Specify when devices receive Defender platform updates. * **Security intelligence updates channel** Specify when devices receive security intelligence updates. * **Security intelligence update day** Specify the day of the week for security intelligence updates. * **Security intelligence update time** Specify the time of day for security intelligence updates. * **Signature update file shares sources** Configure UNC file share sources for security intelligence updates. * **Signature update interval** Specify the interval in hours for security intelligence updates. * **Allow metered connection updates** Allow managed devices to update through metered connections. * **Archive max depth** Specify maximum folder depth to extract from archive files. * **Archive max size** Specify maximum archive file size to scan. * **CPU throttling** Apply CPU usage limits to scans. * **Days until aggressive catchup quick scan** Configure how many days can pass before an aggressive catch-up scan is triggered. * **Disable cache maintenance** Configure whether cache maintenance is performed. * **Disable core ECS integration** Turn off ECS integration for Defender core service. * **Disable core service telemetry** Stop Defender core service telemetry collection. * **Disable CPU throttle on idle scans** Configure whether CPU is throttled for idle-time scans. * **Disable gradual release** Disable staged rollout of Defender updates. * **Disable local admin merge** Prevent local admins from overriding policy with preference settings. * **Enable file hash computation** Enable or disable computation of file hashes for scanned files. * **Enable performance mode** Configure Defender performance mode. * **Excluded IP addresses for wdnisdrv packet inspection** Exclude IP addresses from packet inspection. One IP per line. * **Hide exclusions from local users** Control whether exclusions are visible to local users. * **Intel TDT integration level** Configure Intel TDT integration level. * **OOBE: Enable RTP and signature updates** Configure whether real-time protection and updates are enabled during Out of Box Experience. * **Passive remediation** Configure automatic remediation for Sense scans. * **Scan excluded files and directories during quick scans** Configure whether excluded items are included in quick scans. * **Randomize schedule task times** Randomize the start time of scheduled scans by 0–23 hours. * **Scan only if idle** Run scheduled scans only if the system is idle. * **Enable Device Control** Control the Device Control feature. * **Allow network protection down level** Configure whether network protection can be set on down-level Windows. * **Allow switch to async inspection** Configure whether to use asynchronous inspection. * **Disable UDP processing for Network Protection** Disable UDP inspection. * **Disable DNS over TCP parsing** Disable DNS over TCP parsing. * **Disable DNS parsing** Disable DNS parsing. * **Disable FTP parsing** Disable FTP parsing. * **Disable HTTP parsing** Disable HTTP parsing. * **Disable inbound connection filtering** Disable inbound connection filtering. * **Disable network protection performance telemetry** Disable network protection telemetry. * **Disable QUIC parsing** Disable QUIC parsing. * **Disable RDP parsing** Disable RDP parsing. * **Disable SMTP parsing** Disable SMTP parsing. * **Disable SSH parsing** Disable SSH parsing. * **Disable TLS parsing** Disable TLS parsing. * **Convert warn to block** Configure whether network protection blocks traffic instead of displaying a warning. * **Enable UDP receive offload** Enable UDP receive offload. * **Enable UDP segmentation offload** Enable UDP segmentation offload. * **Network Protection reputation mode** Set reputation mode engine for Network Protection. * **Brute Force protection mode** Detect and block brute-force attempts to forcibly sign in and initiate sessions. * **Remote encryption protection mode** Detect and block attempts to replace local files with encrypted versions from another device. * **Allow datagram processing on Windows server** Control Datagram inspection on Windows Server. * **Allow network protection on Windows server** Configure whether Network Protection can be set on Windows Server. * **Real time scan direction** Configure monitoring for incoming and outgoing files on servers. ## Deployment Notes Review exclusions carefully to avoid reducing security coverage. Review information on how to configure exclusions in the [Microsoft Defender documentation](https://learn.microsoft.com/en-us/defender-endpoint/configure-extension-file-exclusions-microsoft-defender-antivirus). Coordinate Defender policy settings with any third-party endpoint protection to prevent conflicts. Test configurations in a pilot group before broad deployment. # Configure the Passcode Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-passcode-library-item Set up the Passcode Library Item in Iru Endpoint to enforce password and passcode requirements on Apple, Windows, and Android managed devices. This Library Item is available for Apple, Windows, and Android devices The **Passcode** Library Item in Iru Endpoint lets you define password and passcode requirements for managed devices. By enforcing these requirements, you can strengthen security, maintain compliance, and ensure consistent password hygiene across your fleet. You can deploy Passcode profiles to **Apple**, **Windows**, and **Android** devices. Each platform includes both shared and platform-specific configuration options. When using Passport, you must remove the Passcode Library Item from any Blueprint containing Passport to avoid conflicts. Your IdP should handle password requirements. [Learn more](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#passcode). ## Platform Support Matrix | Feature | macOS | iOS | tvOS | visionOS | Windows | Android | | ---------------------------------------------- | ----- | --- | ---- | -------- | ------- | ------- | | Require Passcode | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Disallow Simple Passcode | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Require Alphanumeric Passcode | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Minimum Passcode Length | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Minimum Complex Characters | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Max Passcode Age | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Passcode History / Repetition | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | Require after Sleep / Screen Saver / Lock | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Start Screen Saver After Timer | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | | Maximum failed attempts before account lockout | ✅ | ❌ | ❌ | ❌ | ✅ | ✅ | | Account lockout duration | ✅ | ❌ | ❌ | ❌ | ✅ | ❌ | | Force password reset | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | | Maximum available Auto-Lock delay | ❌ | ✅ | ✅ | ✅ | ❌ | ❌ | | Maximum Failed Attempts before Erasing Device | ❌ | ✅ | ✅ | ✅ | ❌ | ✅ | ## Create a Passcode Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **Passcode**. Give the Library Item a **Name**. Select the platforms where the profile should be installed under **Install on**. Assign it to one or more **Blueprints**. ## Shared Settings These settings are available across platforms: * **Require passcode** Requires a passcode on the device. * **Disallow simple passcode** Prevents simple sequences (e.g., `123`, `CBA`) or repeating characters (e.g., `111`, `AAA`). * **Minimum passcode length** Defines the minimum number of characters in the passcode. On Windows, this applies to Windows Hello and traditional account passwords. For more on Windows Hello for Business, see [Microsoft's Windows Hello for Business overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/). * **Maximum passcode age** Number of days a passcode can remain unchanged before a new one is required. * **Passcode history** Prevents reuse of previously used passcodes. * **Maximum failed attempts before lockout or erasing device** The allowed number of failed passcode attempts before all data on the device will be erased, or on Mac, the account is locked. **Windows**: Setting this key for Windows will result in a device erasure if the threshold is exceeded. Use Account lockout duration below instead to enforce lockouts without device erasure. **Non-Mac**: Non-Mac devices will immediately be erased after the number of failed passcode attempts is reached. ## Platform-Specific Settings ### Apple-Specific Settings These settings apply only to Apple devices. Platform support is noted in parentheses. * **Require alphanumeric passcode** (All Apple platforms) Requires letters as well as numbers. * **Require passcode after screen lock** (All Apple platforms) Defines the time before a passcode is required after screen lock. * **Minimum complex characters** (All Apple platforms) Defines the number of required special characters such as `%`, `$`, or `#`. * **Start screen saver after** (macOS only) Defines the idle time before the screen saver starts. * **Account lockout duration** (macOS only) Determines how long an account remains locked after failed attempts. * **Force password reset** (macOS only) Prompts the user to reset their password at next login. * **Maximum available auto-lock delay** (iOS, iPadOS, tvOS, visionOS) Defines the maximum period of time available in the Auto-Lock setting. ### Windows-Specific Settings These settings apply only to Windows devices: * **Require alphanumeric passcode** Require the passcode to contain letters, and not just numbers. On Windows, this applies to Windows Hello and traditional account passwords, same as **Minimum passcode length** in Shared Settings. For more on Windows Hello for Business, see [Microsoft's Windows Hello for Business overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/). * **Configure max inactivity time** Sets the maximum number of idle minutes allowed before Windows forces the device to the PIN/password lock screen. A device reboot may be required before this setting takes effect. * **Account lockout threshold** This security setting determines the number of failed logon attempts that causes a user account to be locked out. A locked-out account can't be used until it's reset by an administrator or until the lockout duration for the account has expired. * **Prevent administrator lockout** Exempts the builtin administrator account from the account lockout policy. * **Minimum password length audit** Determines the minimum password length for which password length audit warning events are issued. Only enable and configure this setting when trying to determine the potential effect of increasing the minimum password length setting. * **Prevent enabling lock screen camera** Disables the lock screen camera toggle switch in PC Settings and prevents a camera from being invoked on the lock screen. ### Android Device Passcode Settings These settings apply to the device-level passcode on Android devices: * **Require alphanumeric passcode** Requires letters, numbers, and optionally complex characters. * **Passcode timeout** Defines how long a device can remain unlocked with strong authentication (e.g., fingerprint, face) before requiring the passcode again. * **Block on non-compliance** Blocks the entire device after the defined number of days. Setting this to `0` blocks immediately. * **Erase entire device** Erases the device after the defined number of days in non-compliance. **Android Considerations**: "Require alphanumeric passcode" is mutually exclusive with "Disallow simple passcode." The Android Management API does not support restricting repeating / ascending / descending characters with alphanumeric passcodes. ### Android Work Profile Passcode Settings These settings apply specifically to the work profile passcode on Android company-owned work profile devices: * **Require alphanumeric passcode** Requires letters, numbers, and optionally complex characters for work profile access. * **Passcode timeout** Defines how long the work profile can remain unlocked with strong authentication before requiring the passcode again. * **Block on non-compliance** Blocks the work profile after the defined number of days. Setting this to `0` blocks immediately. * **Erase entire device** Erases the device after the defined number of days in non-compliance. **Work Profile Considerations**: * The work profile passcode requirements cannot be less strict than the device passcode requirements * If both Device Passcode and Work Profile Passcode are configured, Android applies the most restrictive block/erase setting * Users will be prompted for the work profile passcode when accessing work applications ## Important Considerations ### Max Passcode Age (macOS) With auto-generated user accounts, such as Auto Admin accounts and accounts created with the `Create a User Account` parameter, the creation date defaults to `12/31/1969`. A passcode reset will be forced during the first login attempt if **Max Passcode Age** is enabled. ### Force Password Reset (macOS) If you enable **Force Password Reset**, users will be prompted to change their password at their next login. This occurs regardless of whether the existing password meets current complexity requirements. The reset is enforced only once, but you can re-enable the option in the future if needed. Consider alerting users before deploying this option to avoid disruption. ### Enrolling Existing Devices When adding new devices to Iru, users' passwords may never have changed. This could conflict with **Max Passcode Age**. Consider delaying deployment or providing advance notice to users. ## Creating Android Work Profile Passcode Policies For Android company-owned work profile devices, you can configure a separate passcode policy specifically for the work profile. To create a work profile passcode policy: Navigate to the **Library** Select **Add Library Item** Search for and select **Android Work Profile Passcode** The *Android Work Profile Passcode* Library Item applies passcode policies only to the work profile. Users will be prompted for this passcode when accessing work applications. To reset or set a new work profile passcode, see [Reset Android Work Profile Passcode](/en/endpoint/devices/device-actions/reset-android-work-profile-passcode). **Deployment**: You can simultaneously deploy both the *Passcode* and the *Android Work Profile Passcode* Library Items to the same device, configuring separate policies for device and work profile access. ## Best Practices Test passcode policies on a small group of devices before rolling out to your entire fleet. Inform users about new passcode requirements and provide guidance on creating strong passwords. Balance security requirements with user convenience to avoid excessive lockouts. Regularly check that devices are compliant with passcode policies. ## Troubleshooting **Possible causes:** * Existing passwords don't meet new complexity requirements * Max passcode age forcing immediate password changes * Account lockout threshold too low **Solutions:** * Provide advance notice before deploying new policies * Consider a grace period for password changes * Adjust lockout thresholds if appropriate **Possible causes:** * Device not enrolled or agent not running * Policy not assigned to device's Blueprint * Platform-specific limitations **Solutions:** * Verify device enrollment and agent status * Check Blueprint assignments * Review platform-specific documentation **Possible causes:** * Conflicting device and work profile policies * Work profile not properly configured * Device compliance issues **Solutions:** * Review both device and work profile passcode settings * Ensure work profile is properly set up * Check device compliance status ## Security Recommendations Implement strong passcode requirements while considering user experience and productivity. Encourage regular password updates and provide tools to help users create strong passwords. Monitor passcode compliance and failed attempt logs for security insights. Provide user education on password security best practices and company policies. # Configure Platform SSO with Entra ID Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-platform-sso-with-microsoft-entra-id-library-item Set up the Platform SSO Library Item in Iru Endpoint for Microsoft Entra ID integration. Enable macOS login with Entra credentials and token-based SSO. Platform SSO is available for Mac computers ### What is Platform SSO? Platform SSO is a capability that allows users to sign in to their Mac devices using a hardware-bound key, smart card, or their IdP password. This feature enhances the Microsoft Enterprise SSO plug-in for Apple devices, providing single sign-on for Microsoft Entra ID accounts on macOS. For more information, see [Microsoft's macOS Platform Single Sign-on overview](https://learn.microsoft.com/en-us/entra/identity/devices/macos-psso). ### Add and Configure the Company Portal Auto App To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Set your **Installation Method** to Continuously Enforce. Specify your **Version Enforcement** settings. Click the **Save** button. ### Add and Configure a Login Window Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Enter a **Name** for your Login Window Library Item. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Under **User Visibility**, select **Display username and password fields**. Click the **Save** button. ### Add and Configure a Single Sign-on Extension Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Enter a **Name** for the new Library Item. Select **Mac** as the **Install on** platform. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Platform SSO with Microsoft Entra ID Library Item configuration interface Under **Extension type**, select **Redirect**. For **Extension identifier**, enter the following: ```text theme={null} com.microsoft.CompanyPortalMac.ssoextension ``` Enter the following in **Team identifier**: ```text theme={null} UBF8T346G9 ``` Paste the following URLs into the **URLs** fields. ```text theme={null} https://login.microsoftonline.com ``` ```text theme={null} https://login.microsoft.com ``` ```text theme={null} https://sts.windows.net ``` Single Sign-on Extension Library Item extension details showing Extension type, Extension identifier, Team identifier, and URLs If you use sovereign cloud domains, include the following additional URLs. ```text theme={null} https://login.partner.microsoftonline.cn ``` ```text theme={null} https://login.chinacloudapi.cn ``` ```text theme={null} https://login.microsoftonline.us ``` ```text theme={null} https://login-us.microsoftonline.com ``` Single Sign-on Extension Library Item showing optional sovereign cloud URL fields Toggle the switch for **Platform SSO**. Select your **Authentication Method**. For information on which method to use for your organization, refer to [Microsoft's support article](https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#step-1---decide-the-authentication-method). Optionally, enter your **Registration token** when your identity provider requires one. The Mac uses this value for Platform SSO registration with your identity provider, including silent registration when your identity provider and SSO extension support it. Platform SSO authentication method and Registration token fields in the Single Sign-on Extension Library Item Enable additional optional settings for macOS 15 and later as needed. Platform SSO optional settings for macOS 15 and later Set default permissions for **Existing Users**. Set default permissions for **New Users**. Platform SSO Existing Users and New Users permission settings Select the checkbox for **Shared Device Keys**. Enable **Allow authorization (with identity provider account)**. This will allow users to interact with system authorization prompts using their Microsoft Entra ID credentials. If you want to automatically create local accounts for users, enable **Allow creation of new users at login**. To create a local account, the device must be connected to the internet at the login screen with FileVault unlocked, and Iru must have a valid Bootstrap token for that device. Platform SSO Shared Device Keys, Allow authorization, and Allow creation of new users at login If checked, the device UDID and serial number will be included in Platform SSO attestations. Available in macOS 15.4 and later. Enter an **Account display name**. Specify the number of seconds after which to **Require full login**. In **Token mapping**, enter the following for **AccountName**: ```text theme={null} preferred_username ``` Enter the following for **FullName**: ```text theme={null} name ``` Platform SSO Account display name, Require full login, and Token mapping fields If desired, configure **Admin Groups**, **Additional Groups**, and **User Groups.** Microsoft [currently only supports](https://learn.microsoft.com/en-us/mem/intune/configuration/platform-sso-macos#more-platform-sso-settings-you-can-configure) using static Standard and Admin values for new and existing users. * **Admin groups** are groups from Microsoft Entra ID that should have administrator access on the device. These groups are used to grant elevated permissions to specific users * **Additional groups** are custom groups you'd like to create in the device's local directory. These groups can be used to organize users and apply specific settings or permissions * **User groups** are particularly useful, allowing you to map specific macOS system rights to custom groups created in the local directory. For example, you can use user groups to grant 'sudo' access or manage printer permissions Click the **Save** button. ### Enable Registration During Setup Assistant (macOS 26 and later) Starting in macOS 26, Platform SSO can run during Setup Assistant so the Mac can register with your identity provider earlier in the enrollment flow. This section lets you configure registration during setup, first-user creation, profile picture sync behavior, and Authenticated Guest Mode for shared-device workflows. When you deploy Platform SSO with Automated Device Enrollment, do not set **Primary account type** to **Skip primary account creation** in the **Mac** section of your [Automated Device Enrollment Library Item](/en/endpoint/enrollment/apple/configuring-apple-enrollment). Setup Assistant is where the user sets the local account password. If you skip primary account creation, that step does not run, the password is never set, and enrollment can stall. Mac computers with Apple silicon and some other models store account credentials in the [Secure Enclave](https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web). See Apple's documentation for which devices include a Secure Enclave. Skipping primary account creation is for **Passport** workflows, not Platform SSO. See [Primary account creation](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#primary-account-creation) if you use Passport instead. In the **Library**, open the existing **Single Sign-on Extension** Library Item you created earlier, click **Edit**, then go to the **Mac macOS 26 and later** section. Select **Yes** for **Enable registration during Setup Assistant** so Platform SSO registration runs while Setup Assistant is still in progress. For **Create first user during Setup Assistant**, select **Yes** when the Mac should create its first local account during Setup Assistant using Platform SSO. If your organization provisions the first account differently, adjust this setting to match that workflow. Configure **Synchronize profile picture** based on whether the Mac should request the user’s login profile picture from the SSO extension during this setup flow. Configure **Enable Authenticated Guest Mode** when you deploy shared Mac computers where users sign in temporarily with IdP credentials and want Authenticated Guest Mode behavior. For standard single-user Mac computers, leave this behavior off. Under **New user authentication methods**, select the authentication methods available for newly created accounts. Click the **Save** button. In your **Automated Device Enrollment** Library Item, turn on **Install Library Items during Setup Assistant** for **Mac**. Add the **Company Portal Auto App**, **Login Window**, and **Single Sign-on Extension** Library Items you configured in this guide so they install during enrollment setup. See [Install Library Items during Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#install-library-items-during-setup-assistant) for the full details. If a device is stuck on **Configuring**, see [Manually release devices held in Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#manually-release-devices-held-in-setup-assistant). Automated Device Enrollment Mac section with Library Items selected for Install Library Items during Setup Assistant # Configure the PPPC Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-privacy-preferences-policy-control-pppc-library-item Set up the PPPC Library Item in Iru Endpoint to manage app privacy permissions. Control access to camera, microphone, screen recording, and system files. This Library Item is available for Mac computers ### What is PPPC? Privacy Preferences Policy Control (PPPC) in macOS helps you manage app permissions and protect user data. With a PPPC profile, you can pre-approve apps' access to system services like the camera, microphone, and file systems. This eliminates manual user approval and simplifies your deployment process. ### How PPPC and TCC Controls Work Starting with macOS Mojave (10.14), [Apple's PPPC payload](https://support.apple.com/guide/deployment/privacy-preferences-policy-control-payload-dep38df53c2a/web) lets you configure Transparency, Consent, and Control (TCC) settings for safeguarding user information. PPPC profiles let you pre-approve or deny app access to system services like the camera, microphone, and file systems. You create these profiles using XML files that specify each app's permissions, bundle IDs, and code requirements. Once created, you deploy these profiles via MDM to apply the settings to enrolled Mac computers. Due to Apple's privacy requirements, Camera, Microphone, and Screen Recording access will always require user interaction to approve. ### Determining Which Apps Need a Privacy Profile To determine if your app needs additional privacy permissions, follow these steps. Note that preference panes may vary between different macOS versions. #### For macOS 13 Ventura or later Install your app on a test device or a macOS virtual machine. Launch the app and pay attention to any UI dialogues that appear, such as those requesting access to accessibility features or the Downloads folder. Navigate to System Settings and select **Privacy & Security**. Select an option on the right-hand side, like **Accessibility**. If your app is listed here, it indicates that the app requires this PPPC permission. Right-click on the app listed and select **Show in Finder.** Finder will launch with the app in question selected. You can drag and drop the application into Terminal to get its full path, which will be used in the next step. #### For macOS versions prior to macOS 13 Ventura Install your app on a test device or a macOS virtual machine. Launch the app and pay attention to any UI dialogues that appear, such as those requesting access to accessibility features or the Downloads folder. Navigate to System Settings and select **Security & Privacy** Select the **Privacy** tab. Select an option on the right-hand side, like **Accessibility**. If your app is listed here, it indicates that the app requires this PPPC permission. Right-click on the app listed and select **Show in Finder.** Finder will launch with the app in question selected. You can drag and drop the application into Terminal to get its full path, which will be used in the next step. #### Determine the Identifier and Code Requirement To create a PPPC profile, you need the application's code requirement and identifier. You can collect this information using Terminal on a Mac with the application installed. Launch Terminal on a macOS device on which the application is installed. Run the following command, replacing */Applications/zoom.us.app* with the path to your application. ```bash theme={null} codesign -dr - "/Applications/zoom.us.app" ``` When the output results appear, copy all text after the **=>** characters; do not copy any trailing or leading spaces. This output is the **Code Requirement**. The portion between the quotes, e.g. "us.zoom.xos", is the **Identifier**. ### Configuring a Privacy Profile using Iru With your application information collected, you can create a Privacy profile in the Iru web app. Privacy settings deployed via MDM will not appear in the graphical user interface in System Settings. To add this Library Item to your Iru Endpoint Library, follow the steps in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your profile a descriptive **Name**. Select your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). If your output includes an identifier in the first part of the code requirement, leave the Identifier type set to **Bundle ID**. Otherwise, select **Path**. Paste in the **identifier** found in the first part of the code requirement. * If you selected **Path** above, input the path for the profile. Paste in the full code requirement that you copied from Terminal. Make sure there are no leading or trailing spaces in the code requirement, as unnecessary characters can prevent the profile from deploying. Optionally, check the **Statically validate the code requirement** box. This option is only used if the process invalidates its dynamic code signature. Select an option from the **App or Service** dropdown. * This selection depends on the application's requirements. For more information, see the [Determine Which Apps Need a Privacy Profile](/en/endpoint/library/library-items-profiles/configure-the-privacy-preferences-policy-control-pppc-library-item#determining-which-apps-need-a-privacy-profile) section of this guide. If needed, you can add additional app access to a PPPC profile by selecting **Add app access**. Select **Save** in the bottom right corner. # Configure the Recovery Password Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-recovery-password-library-item Set up the Recovery Password Library Item in Iru Endpoint for managed Mac computers. Configure firmware recovery passwords and escrow recovery credentials. This Library Item is available for Mac computers The Recovery Password Library Item allows you to configure and apply recovery passwords to Mac computers with Apple silicon and EFI firmware passwords to Intel-based Mac computers, all from within the same library item. Iru Endpoint supports automatically generating per-device passwords with optional configurable time-based rotation, or you can set a manual static password. You can also provide existing known firmware passwords for Intel-based Mac computers to update them using Iru Endpoint automatically. ### Create a Recovery Password Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. ### Configure the Recovery Password Library Item **Name** your Library Item, and choose an **icon** if desired. Select your desired [**Blueprints**](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). **Choose** whether to have Iru Endpoint automatically generate device-specific passwords or to specify a static password manually. If you have Iru Endpoint automatically generate device-specific passwords, choose whether Iru Endpoint should automatically rotate the password and specify how often. If you have firmware passwords already deployed to Intel-based Mac computers, enable the **Legacy Firmware passwords** option so Iru Endpoint can update them. Add a **Legacy password** already deployed to Intel-based Mac computers Optionally add up to 19 more legacy passwords (20 total) for Iru Endpoint to use when updating them. Click **Save**. Iru Endpoint cannot update existing deployed firmware passwords on Intel-based Mac computers unless the currently in-use password(s) are provided to Iru Endpoint in the Legacy Firmware passwords section. ### Device Experience * **Mac computers with Apple silicon**: The recovery password is applied and no user interaction is required. * **Intel-based Mac computers**: Users are prompted by the Iru Agent to restart within 30 minutes after a legacy firmware password is applied, whether for the first time or when being rotated. As with the [FileVault Library Item](/en/endpoint/library/deployment-guides/apple/configure-filevault), this counter can **not** be deferred. ### View Recovery Password for a Device After the recovery password has been set, this option becomes available when the device's next daily check-in completes. Open the **Device Action Menu**. Click **View Recovery Lock password**. When removing the Recovery Password Library Item, the recovery password will still show on the device record, even though there won’t be a visible password. This will be removed from the device record at the next daily check-in. ### Additional Considerations #### Blueprint Changes When you move a device between Blueprints, Iru Endpoint automatically updates the recovery password to match the new Blueprint's settings. For instance, if you move a device from a Blueprint with randomized passwords to one with a fixed password, the device will switch to the fixed password automatically. #### Removing Recovery Passwords If you remove the Recovery Password Library Item from a Blueprint or move a device to a Blueprint that doesn't have one, Iru Endpoint will attempt to remove the recovery password from the device. #### Device Unenrollment When you delete a device record (which unenrolls it from Iru), macOS automatically removes any applied recovery password. However, legacy firmware passwords remain on the device and must be removed manually. #### Password Format When using an automatically generated recovery password to unlock a device, enter it exactly as displayed, including all capital letters and hyphens. #### Erase Device Commands on Intel Macs with T2 Chip Intel-based Mac computers with the Apple T2 Security Chip have special behavior when receiving an Erase Device command. If a legacy firmware password is still present, the device will perform a complete erase and require macOS reinstallation instead of the standard Erase All Content and Settings (EACS). To avoid this and preserve the EACS behavior, move the device to a Blueprint without a Recovery Password Library Item before sending the Erase Device command. This step isn't required for Mac computers with Apple silicon. # Configure the Apple Restrictions Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item Set up the Apple Restrictions Library Item in Iru Endpoint to control device features, app access, content ratings, and privacy settings on managed Apple devices. This Library Item is available for Apple devices **Restrictions** limit user access to device features, apps, and system behavior. Use the **Apple Restrictions Library Item** to apply those limits on iPhone, iPad, Mac, Apple TV, and Vision through Blueprints. Many Apple restrictions require a **supervised** device. For company-owned Android work profile devices, see [Configure the Android Restrictions Library Item](/en/endpoint/library/library-items-profiles/configure-the-android-restrictions-library-item). ### Add an Apple Restrictions Library Item Configure device restrictions for iPhone, iPad, Mac, Apple TV, and Vision using the **Apple Restrictions Library Item**. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. When you choose **Add Library Item**, select **Apple Restrictions** to create an **Apple Restrictions Library Item**. Give the **Apple Restrictions Library Item** a **Name**. In the **Install on** field, select the device types you want to target (iPhone, iPad, Mac, Apple TV, or Vision). Assign to your desired Blueprints. Configure the restriction settings you need. Click **Save**. ### Apple Restrictions Reference This reference groups Apple restrictions by category as shown in the Iru Endpoint web app. Each restriction includes platform tags and availability text as provided by Apple. * **Disallow installing apps and updates**: Users are prevented from installing or updating apps using the App Store or host apps (iTunes, Configurator). Also prevents installation and use of marketplace apps and marketplace-hosted apps in the European Union. The App Store is disabled, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 4 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow installing apps and updates from the device**: Users are prevented from installing or updating apps using the App Store. The App Store is disabled, and its icon is removed from the Home screen. Host apps (iTunes, Configurator) are still allowed to be used to install and update apps. Requires a supervised device. Available in iOS 9 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow marketplace apps and marketplace-hosted apps**: Disallow installing marketplace apps and marketplace-hosted apps in the European Union. Requires a supervised device. Available in iOS 17.4 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow modifying the default browser app**: Prevents a user from modifying the default browser app. Available in iOS 18.2 and later and iPadOS 18.2 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow modifying the default calling app**: Prevents a user from modifying the default calling app. Available in iOS 18.4 and later and iPadOS 18.4 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow modifying the default messaging app**: Prevents a user from modifying the default messaging app. Available in iOS 18.4 and later and iPadOS 18.4 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow app installation directly from websites**: Disallow installing apps directly from websites in the European Union. Requires a supervised device. Available in iOS 17.5 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow in-app purchases**: In-app purchasing is prohibited. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Disallow automatically downloading apps**: Automatic downloading of apps purchased on other devices using the same iCloud account is prohibited. This setting doesn't affect updates to existing apps. Requires a supervised device. Available in iOS 9 and later, and visionOS 27 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow removing apps**: Users are unable to remove apps from the device, including marketplace apps and marketplace-hosted apps in the European Union. Requires a supervised device. Available in iOS 4.2.1 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow removing system apps**: Users are unable to remove system apps from the device. Requires a supervised device. Available in iOS 11 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow use of FaceTime**: The FaceTime app is disabled, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 4 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow use of Messages**: On iPhone, the Messages app allows SMS text messaging, but not iMessage. On iPad, the Messages app is disabled, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 5 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of News**: The News app is disabled, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 9 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of Podcasts**: The Podcasts app is disabled, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 8 and later. * *Platforms:* iPad, iPhone, Supervised * **Enforce app ratings**: Manage the maximum level of app content allowed on the device. Apps that do not meet ratings compliance in the App Store will be unavailable for download. On iPhones and iPads (but not Macs), existing apps on the device that are out of compliance will be disabled and removed from the Home screen. Available in iOS 4 and later, macOS 10.15 and later, and tvOS 11.3 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV * **Disallow App Clips**: Prevents a user from adding any App Clips, and removes any existing App Clips on the device. Available in iOS 14.0 and later. * *Platforms:* iPad, iPhone, Supervised * **Delay App Software Updates**: Delays user visibility of non-OS Software Updates. Requires a supervised device. Available in macOS 11 and later. * *Platforms:* Mac, Supervised * Deprecated as of macOS 27. Use the [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item) instead. * **Disallow apps to be locked**: Disallow apps to be locked in iOS and iPadOS 18 and later. Requires a supervised device. Note: Applying this restriction will also prevent apps from being able to be hidden. * *Platforms:* iPad, iPhone, Supervised * **Disallow apps to be hidden**: Disallow apps to be hidden in iOS and iPadOS 18 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow Rosetta usage awareness**: Turns off Rosetta usage awareness, which prevents a pop-up dialog being displayed to the user indicating that Rosetta will be removed in a future version of macOS. Requires a supervised device. Available in macOS 26.4 and later. * *Platforms:* Mac, Supervised * **Manage App Block List**: Choose to block specific apps from being used, or specify that only listed apps are allowed. Restricted apps are disabled and hidden from the Home screen. This also applies to use of marketplace apps and marketplace-hosted apps in the European Union. Requires a supervised device. Available in iOS 9.3 and later, tvOS 11.0 and later, and visionOS 27 and later. * *Platforms:* iPad, iPhone, Apple TV, Vision, Supervised * **Autonomous Single App Mode**: Allow listed apps to autonomously enter Single App Mode. Requires a supervised device. Available in iOS 7 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow passcode modification**: Prevents the user from adding, changing, or removing device passcodes (iPhone and iPad) or user account passcodes (Mac). iPhone and iPad devices must be supervised. Available in iOS 9 and later, macOS 10.13 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow adding or removing Face ID / Touch ID data**: Prevents the user from modifying Touch ID or Face ID. Requires a supervised device. Available in iOS 8.3 and later, macOS 14 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow using Face ID / Touch ID for device unlock**: Prevents Touch ID or Face ID from unlocking a device. Available in iOS 7 and later, visionOS 2.0 and later, and macOS 10.12.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow using Apple Watch for device unlock**: Prevents Apple Watch from being used to automatically unlock a Mac or iPhone. Available in macOS 10.12 and later. * *Platforms:* Mac, iPhone * **Enforce Fingerprint Timeout**: The number of hours after which the fingerprint unlock will require a password to authenticate. Available in macOS 12 and later. * *Platforms:* Mac * **Disallow voice dialing while device is locked**: Disables voice dialing if the device is locked with a passcode. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Disallow Control Center on lock screen**: Prevents the Control Center from appearing on the lock screen. Available in iOS 7 and later. * *Platforms:* iPad, iPhone * **Disallow Notifications Center on lock screen**: Prevents displaying notifications on the lock screen. Available in iOS 7 and later. * *Platforms:* iPad, iPhone * **Disallow Today view on lock screen**: Hides the Today view in the notification center on the lock screen. Available in iOS 7 and later. Also available for user enrollment. * *Platforms:* iPad, iPhone * **Disallow Wallet notifications on lock screen**: Prevents Wallet notifications on the lock screen. Available in iOS 6 and later. * *Platforms:* iPad, iPhone * **Allow USB accessories while device is locked**: Allows the device to always connect to USB accessories while locked. On macOS, allows new USB accessories to connect without authorization. Requires a supervised device. Available in iOS 11.4.1 and later, and macOS 13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Enable captive Wi-Fi portal for login and unlock**: If enabled, the Mac allows use of the captive Wi-Fi portal at login or unlock. Requires a supervised device. Available in macOS 27 and later. * *Platforms:* Mac, Supervised * **Enable Wi-Fi network selection for login and unlock**: If enabled, the Mac allows the user to select Wi-Fi networks at login or unlock. Requires a supervised device. Available in macOS 27 and later. * *Platforms:* Mac, Supervised * **Disallow changing account settings**: Users are prevented from adding, removing, or modifying accounts (mail, contacts, calendars). Requires a supervised device. Available in iOS 7 and later, visionOS 2.0 and later, and macOS 14 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow AutoFill Passwords**: Disables the AutoFill Passwords feature, and the user isn't prompted to use saved passwords in apps, including Safari. This restriction also disables Automatic Strong Passwords, and strong passwords are no longer suggested to users. iPhone and iPad devices must be supervised. Available in iOS 12 and later, visionOS 2.0 and later, and macOS 10.14 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Require authentication before using AutoFill Passwords**: Users must authenticate before passwords or credit card information can be autofilled in apps, including Safari. Only supported on devices with Face ID or Touch ID. Requires a supervised device. Available in iOS 11 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow Password Sharing**: Users are prevented from sharing passwords with the AirDrop Passwords feature. iPhone and iPad devices must be supervised. Available in iOS 12 and later, visionOS 2.0 and later, and macOS 10.14 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow proximity based password sharing requests**: Prevents devices from requesting passwords from nearby devices. iPhone and iPad devices must be supervised. Available in iOS 12 and later, macOS 10.14 and later, and tvOS 12 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV, Supervised * **Disallow Proximity Setup for New Devices**: Disables the prompt to set up new devices that are nearby. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow opening documents from managed sources in unmanaged destinations**: Documents in managed apps and accounts only open in other managed apps and accounts. Available in iOS 7 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Disallow opening documents from unmanaged sources in managed destinations**: Documents in unmanaged apps and accounts only open in other unmanaged apps and accounts. Available in iOS 7 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Allow managed apps to write contacts to unmanaged contacts accounts**: Managed apps can write contacts to unmanaged contacts accounts. Available in iOS 12 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Allow unmanaged apps to read contacts from managed contacts accounts**: Unmanaged apps can read from managed contacts accounts. Available in iOS 12 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Disallow iCloud Address Book**: Disables iCloud Address Book services. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Bookmarks**: Disables iCloud Bookmark sync. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Calendar**: Disables iCloud Calendar services. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Mail**: Disables iCloud Mail services. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Notes**: Disables iCloud Notes services. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Reminders**: Disables iCloud Reminders services. Available in macOS 10.12 and later. * *Platforms:* Mac * **Disallow iCloud Drive**: Disables document and app data syncing to iCloud. iPhone and iPad devices must be supervised. Available in iOS 5 and later, visionOS 2.0 and later, and macOS 10.11 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow iCloud Desktop & Documents**: Disables syncing Desktop and Documents folders to iCloud. Available in macOS 10.12.4 and later. * *Platforms:* Mac * **Disallow iCloud Keychain**: Disables syncing the Keychain to iCloud. iPhone and iPad devices must be supervised. Available in iOS 7 and later, visionOS 2.0 and later, and macOS 10.12 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow iCloud Photo Library**: Disables the iCloud Photo Library. Available in iOS 9 and later, macOS 10.12 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow iCloud Photo Stream**: Disables the iCloud Photo Stream. Available in iOS 5 and later. * *Platforms:* iPad, iPhone * **Disallow iCloud Shared Photo Stream**: Disables the iCloud Shared Photo Stream. Available in iOS 6 and later. * *Platforms:* iPad, iPhone * **Disallow device backup to iCloud**: Disables backing up the device to iCloud. Requires a supervised device. Available in iOS 5, visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow managed app data storage in iCloud**: Prevents managed apps from using iCloud sync. Available in iOS 8 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Disallow Handoff**: Disables activity continuation. Available in iOS 8, macOS 10.15 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow iCloud Private Relay**: Prevents the user from turning on iCloud Private Relay. Available in iOS 15, iPadOS 15, visionOS 2.0, macOS 12, and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow iPhone Widgets on Mac**: Prevents syncing of iPhone widgets on a Mac with iCloud. Requires a supervised device. Available in iOS 17 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Freeform Document Syncing**: Prevents a user from syncing Freeform documents with iCloud. Available in macOS 14 and later. * *Platforms:* Mac * **Force Wi-Fi power on**: Prevents Wi-Fi from being turned off in Settings or Control Center, even by entering or leaving Airplane Mode. It does not prevent selecting which Wi-Fi network to use. Requires a supervised device. Available in iOS 13.0 and later. * *Platforms:* iPad, iPhone, Supervised * **Only allow managed Wi-Fi networks**: Devices can only join Wi-Fi networks configured by a configuration profile. Requires a supervised device. Available in iOS 10.3 and later, visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow modifying Bluetooth settings**: Prevents the user from changing Bluetooth settings. Requires a supervised device. Available in iOS 11 and later, and macOS 13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow adding VPN configurations**: Prevents the creation of VPN configurations. Requires a supervised device. Available in iOS 11 and later, visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow NFC**: Disables Near Field Communication (NFC) on the device. Available in iOS 14.2 and later. * *Platforms:* iPhone, Supervised * **Disallow modifying cellular plan settings**: Prevents users from changing settings related to their cellular plan. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow modifying cellular data app settings**: Prevents users from changing settings for app cellular data usage. Requires a supervised device. Available in iOS 7 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow modifying Personal Hotspot settings**: Users are prevented from making modifications to the Personal Hotspot setting. Requires a supervised device. Available in iOS 12.2 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow global background fetch activity when roaming**: Disables background fetch activity for apps when roaming. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Disallow modifying eSIM settings**: Users are prevented from making modifications to the eSIM setting. Requires a supervised device. Available in iOS 12.1 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow eSIM outgoing transfers**: Prevent the transfer of an eSIM from the device on which the restriction is installed to a different device. Requires a supervised device. Available in iOS and iPadOS 18 and later. * *Platforms:* iPad, iPhone, Supervised * **Force preserve eSIM on erase**: Preserves eSIM when a device is erased due to too many failed password attempts or Erase All Content and Settings. The eSIM is not preserved if Find My initiates the erase. Requires a supervised device. Available in iOS and iPadOS 17.2 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Live Voicemail**: Disallow the use of Live Voicemail. Requires a supervised device. Available in iOS 17.2 and later. * *Platforms:* iPhone, Supervised * **Disallow RCS messaging**: Disallow the use of RCS messaging in Messages. Available in iOS and iPadOS 18.1 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow call recording**: Disallow call recording. Available in iOS 18.1 and later. Requires a supervised device. * *Platforms:* iPhone, Supervised * **Deny ICCIDs for iMessage & FaceTime**: Prevents use of iMessage and FaceTime for listed ICCIDs. The list must contain no more than 4 ICCIDs. Available in iOS 26 and later and iPadOS 26 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Deny ICCIDs for RCS**: Prevents the use of RCS for listed ICCIDs. The list must contain no more than 4 ICCIDs. Available in iOS 26 and later, and iPadOS 26 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised * **Disallow AirDrop**: Disables AirDrop file sharing. iPhone and iPad devices must be supervised. Available in iOS 7, visionOS 2.0 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow sharing managed documents using AirDrop**: Forces managed apps to treat AirDrop as an unmanaged destination. Available in iOS 9 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Disallow incoming AirPlay requests**: Disables incoming AirPlay requests. Requires a supervised device. Available in tvOS 10.2 and later, and macOS 12.3 and later. * *Platforms:* Mac, Apple TV, Supervised * **Require password for incoming AirPlay requests**: Forces all devices sending AirPlay requests to the device to use a pairing password. Available in iOS 7.1 and later. * *Platforms:* iPad, iPhone * **Require password for outgoing AirPlay requests**: Forces all devices receiving AirPlay requests from the device to use a pairing password. Available in iOS 7.1 and later. * *Platforms:* iPad, iPhone * **Disallow AirPrint**: Disables AirPrint printing. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow storage of AirPrint credentials in Keychain**: Disables Keychain storage of usernames and passwords for AirPrint. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow discovery of AirPrint printers using iBeacons**: Disables iBeacon discovery of AirPrint printers, which prevents spurious AirPrint Bluetooth beacons from phishing for network traffic. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow AirPrint to destinations with untrusted certificates**: Requires trusted certificates for TLS printing communication. Requires a supervised device. Available in iOS 11 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow pairing with Apple Watch**: Disables pairing with an Apple Watch. Any currently paired Apple Watch is unpaired and the watch's content is erased. Requires a supervised device. Available in iOS 9 and later. * *Platforms:* iPad, iPhone, Supervised * **Enforce Apple Watch wrist detection**: Forces a paired Apple Watch to use Wrist Detection to lock it when the user takes it off. Available in iOS 8.2 and later. * *Platforms:* iPad, iPhone * **Disallow sending diagnostics and usage data to Apple**: Prevents the device from automatically submitting diagnostic reports to Apple. Available in iOS 6 and later, visionOS 2.0 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow modifying diagnostics settings**: Disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. Requires a supervised device. Available in iOS 9.3.2 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow network drive access in Files app**: Prevents connecting to network drives in the Files app. Requires a supervised device. Available in iOS 13.0 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow USB drive access in Files app**: Prevents connecting to any connected USB devices in the Files app. Requires a supervised device. Available in iOS 13.0 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Find My Devices**: Disables Find My Device in the Find My app. iPhone and iPad devices must be supervised. Available in iOS 13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow Find My Friends**: Disables Find My Friends in the Find My app. iPhone and iPad devices must be supervised. Available in iOS 13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow modifying Find My Friends settings**: Disables changes to Find My Friends. Requires a supervised device. Available in iOS 7 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of Game Center**: Disables Game Center, and its icon is removed from the Home screen. iPhone and iPad devices must be supervised. Available in iOS 6 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow adding Game Center friends**: Prohibits adding friends to Game Center. iPhone and iPad devices must be supervised. Available in iOS 4.2.1 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow multiplayer gaming**: Prohibits multiplayer gaming. iPhone and iPad devices must be supervised. Available in iOS 4.1 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow auto correction**: Disables keyboard autocorrection. Requires a supervised device. Available in iOS 8.1.3 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow spell check**: Disables keyboard spell-check. Requires a supervised device. Available in iOS 8.1.3 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow predictive keyboard**: Disables predictive keyboards. Requires a supervised device. Available in iOS 8.1.3 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow definition lookup**: Disables definition lookup. iPhone and iPad devices must be supervised. Available in iOS 8.1.3 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow dictation input**: Disallows dictation input. iPhone and iPad devices must be supervised. Available in iOS 10.3 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow keyboard shortcuts**: Disables keyboard shortcuts. Requires a supervised device. Available in iOS 9 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Continuous Path keyboard**: Disables QuickPath keyboard. Requires a supervised device. Available in iOS 13 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of Apple Books**: Disables Apple Books. iPhone and iPad devices must be supervised. Available in iOS 6 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow explicit sexual content in Apple Books**: Users can't download Apple Books media that is tagged as erotica. Available in iOS 6 and later, macOS 10.15 and later, and tvOS 11.3 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV * **Disallow backup of enterprise books**: Disables backup of Enterprise books. Available in iOS 8 and later. * *Platforms:* iPad, iPhone * **Disallow notes and highlights sync of enterprise books**: Disables sync of Enterprise books, notes, and highlights. Available in iOS 8 and later. * *Platforms:* iPad, iPhone * **Disallow use of Apple Music**: Disables the Music service, and the Music app reverts to classic mode. iPhone and iPad devices must be supervised. Available in iOS 9.3 and later, and macOS 10.12 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow use of Apple Music Radio**: Disables Apple Music Radio. Requires a supervised device. Available in iOS 9.3 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of iTunes Store**: Disables the iTunes Music Store, and its icon is removed from the Home screen. Users cannot preview, purchase, or download content. Requires a supervised device. Available in iOS 4 and later. * *Platforms:* iPad, iPhone, Supervised * **Require iTunes Store password for all purchases**: Forces the user to enter their iTunes password for each transaction. Available in iOS 6 and later. * *Platforms:* iPad, iPhone * **Disallow playback of explicit music, podcasts, and iTunes U media**: Hides explicit music or video content purchased from the iTunes Store. Explicit content is marked as such by content providers, such as record labels, when sold through the iTunes Store. iPhone and iPad devices must be supervised. Available in iOS 4 and later, macOS 10.15 and later, and tvOS 11.3 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV, Supervised * **Disallow iTunes file sharing services**: Disables iTunes file sharing services. Available in macOS 10.13 and later. * *Platforms:* Mac * **Manage Movie rating restrictions**: Enforce the maximum level of movie content allowed on the device. Available in iOS 4 and later, macOS 10.15 and later, and tvOS 11.3 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV * **Manage TV Show rating restrictions**: Enforce the maximum level of TV content allowed on the device. Available in iOS 4 and later, macOS 10.15 and later, and tvOS 11.3 and later. * *Platforms:* Mac, iPad, iPhone, Apple TV * **Defer software updates**: Delays user visibility of software updates. In macOS, seed build updates are allowed, without delay. iPhone and iPad devices must be supervised. Available in iOS 11.3 and later, macOS 10.13 and later, and tvOS 12.2 and later. Learn more about Software Updates and their deferral limits. **Defer software updates** is deprecated as of iOS 27, iPadOS 27, tvOS 27, and macOS 27. Use the [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item) instead. See [Delay and Enforce OS Updates](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates). * *Platforms:* Mac, iPad, iPhone, Apple TV, Supervised * **Disallow Background Security Improvement installation**: Prevents installation of Apple Background Security Improvements (formerly known as Rapid Security responses). Devices must be supervised. Available in iOS 16.0 and later, iPadOS 16.0 and later and macOS 13 and later. **Disallow Background Security Improvement installation** is deprecated as of iOS 27, iPadOS 27, and macOS 27. Use the [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item) instead. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow Background Security Improvement removal**: Prevents removal of Apple Background Security Improvements (formerly known as Rapid Security responses). Devices must be supervised. Available in iOS 16.0 and later, iPadOS 16.0 and later and macOS 13 and later. **Disallow Background Security Improvement removal** is deprecated as of iOS 27, iPadOS 27, and macOS 27. Use the [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item) instead. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow use of Safari**: Disables the Safari web browser app, and its icon is removed from the Home screen. This setting also prevents users from opening web clips. Requires a supervised device. Available in iOS 4 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Safari AutoFill**: Disables Safari Autofill. iPhone and iPad devices must be supervised. Available in iOS 4 and later, visionOS 2.0 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Safari pop-ups**: Disables pop-up windows in Safari. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Force Safari fraud warnings**: Enables fraud warnings in Safari. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Disallow Safari Javascript**: Disables the use of Javascript in Safari. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Manage Safari cookies**: Enforce cookie settings for Safari. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Allow deprecated TLS versions in Safari**: Allow the use of deprecated TLS versions 1.0/1.1 in Safari. Available in iOS 12.4 and later, and macOS 10.15.4 and later. * *Platforms:* Mac, iPad, iPhone * **Disallow Safari history clearing**: Prevents a user from clearing browsing history in Safari. Available in iOS 26 and later, iPadOS 26 and later, macOS 26 and later, and visionOS 26 and later. Requires a supervised device. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Safari private browsing**: Prevents a user from enabling private browsing in Safari. Available in iOS 26 and later, iPadOS 26 and later, macOS 26 and later, and visionOS 26 and later. Requires a supervised device. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow use of Siri**: Disables Siri. Available in iOS 5 and later, and macOS 10.15 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow use of Siri while device is locked**: Disables Siri when the device is locked. This restriction is ignored if the device doesn't have a passcode set. Available in iOS 5.1 and later. * *Platforms:* iPad, iPhone * **Disallow user-generated content in Siri**: Prevents Siri from querying user-generated content from the web. Requires a supervised device. Available in iOS 7 and later. * *Platforms:* iPad, iPhone, Supervised * **Enable Siri profanity filter**: Forces the use of the profanity filter with Siri. iPhone and iPad devices must be supervised. Available in iOS 11 and later, and macOS 10.14 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Force on device translation**: Prevent the device from connecting to the Siri servers for translations. Available in iOS 15, iPadOS 15, and later. * *Platforms:* iPad, iPhone * **Force on device dictation**: Prevent the device from connecting to the Siri servers for dictation. Available in iOS 14.5, iPadOS 14.5 and later, visionOS 2.0 and later, and Mac computers with Apple silicon running macOS 14 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Automatically reject untrusted HTTPS certificates**: Automatically rejects untrusted HTTPS certificates without prompting the user. Available in iOS 5 and later, visionOS 1.1 and later. * *Platforms:* iPad, iPhone, Vision * **Disallow manual installation of configuration profiles and certificates**: Prohibits the user from installing configuration profiles and certificates interactively. Requires a supervised device. Available in iOS 6 and later, macOS 13 and later, and visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow OTA PKI updates**: Disables over-the-air PKI updates. Setting this restriction to false doesn't disable CRL and OCSP checks. Available in iOS 7 and later. * *Platforms:* iPad, iPhone * **Disallow "Trust Enterprise Developer" option**: Remove the Trust Enterprise Developer button in Settings > General > Profiles & Device Management, preventing apps from being provisioned by universal provisioning profiles. This restriction applies to free developer accounts. It doesn't apply to enterprise app developers who are trusted because their apps were pushed through APNs. It also doesn't revoke previously granted trust. Available in iOS 9 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision * **Force automatic date and time**: Enables the Set Automatically feature in Date & Time, and this can't be disabled by the user. The device's time zone is updated only when the device can determine its location using a cellular connection or Wi-Fi with location services enabled. Requires a supervised device. Available in iOS 12 and later, visionOS 2.0 and later, and tvOS 12.2 and later. * *Platforms:* iPad, iPhone, Apple TV, Vision, Supervised * **Force encrypted backups**: Requires that all backups be encrypted. Available in iOS 4 and later. * *Platforms:* iPad, iPhone * **Force limited ad tracking**: Limits ad tracking on Apple's ad platform. Additionally, it disables app tracking and the Allow Apps To Request To Track setting. Available in iOS 7 and later, and up through macOS 11. * *Platforms:* Mac, iPad, iPhone * **Disallow Apple personalized advertisements**: Limits Apple personalized advertising. Available in iOS 14, visionOS 2.0 and later, and macOS 12 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow Mail Privacy Protection**: Disables Mail Privacy Protection on the device. Requires a supervised device. Available in iOS 15.2 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow use of camera**: Disables the camera, and its icon is removed from the Home screen. Users are unable to take photographs. iPhone and iPad devices must be supervised. Available in iOS 4, visionOS 27, and macOS 10.11 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow modifying device name**: Warning: This restriction, which prevents the device name from being changed, has been moved to the Device Name Library Item. * *Platforms:* Mac, iPad, iPhone, Apple TV, Vision, Supervised * **Disallow Erase All Content and Settings**: Disable Erase All Content and Settings. Requires a supervised device. Available in iOS 8, macOS 12, visionOS 2.0, and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow modifying notification settings**: Prevents changing notification settings. Requires a supervised device. Available in iOS 9.3 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow use of Screen Time**: In iOS 12 or later, disables the “Enable Screen Time” option in the Screen Time UI in Settings and disables Screen Time if already enabled. Prior to iOS 12, this disables the “Enable Restrictions” option in the Restrictions UI in Settings. Requires a supervised device. Available in iOS 8 and later, and visionOS 2.0 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow screenshots and screen recording**: Disables saving a screenshot of the display and capturing a screen recording. Available in iOS 4 and later, macOS 10.14.4 and later, visionOS 2.0 and later. * *Platforms:* Mac, iPad, iPhone, Vision * **Disallow Spotlight internet search results**: Disables Spotlight Internet search results. Available in iOS 8 and later, and macOS 10.11 and later. * *Platforms:* Mac, iPad, iPhone * **Disallow modifying Wallpaper**: Prevents wallpaper from being changed. iPhone and iPad devices must be supervised. Available in iOS 9 and later, and macOS 10.13 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow guest user**: Disallow the ability to log in as a Guest user on iPad devices configured as Shared iPad. Available in iOS 13.4 and later. * *Platforms:* iPad * **Disallow auto dim**: Prevents auto dim on iPads with OLED displays. Available in iOS and iPadOS 17.4 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Remote app pairing**: Disables pairing Apple TV for use with the Remote app or Control Center widget. Requires a supervised device. Available in tvOS 10.2 and later. * *Platforms:* Apple TV, Supervised * **Disallow pairing with non-Configurator hosts**: Disables host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Requires a supervised device. Available in iOS 7 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow device sleeping**: Prevents device from sleeping. Requires a supervised device. Available in tvOS 13 and later. * *Platforms:* Apple TV, Supervised * **Allow boot to recovery by unpaired device**: Allows devices to be booted into recovery by an unpaired device. Requires a supervised device. Available in iOS 14.5 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Apple TV automatic screensaver**: Disables the Apple TV from automatically starting the screensaver after inactivity. Available in tvOS 15.4 and later. * *Platforms:* Apple TV * **Disallow use of Content Caching service**: Disables content caching. Available in macOS 10.13 and later. * *Platforms:* Mac * **Disallow Universal Control**: Disables Universal Control, which allows the Mac's trackpad and keyboard to control additional Mac or iPad devices nearby. Available in macOS 13 and later. * *Platforms:* Mac * **Disallow startup disk modification**: Prevents the user from selecting a different startup disk. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Time Machine backup**: Prevents the user from setting up and using Time Machine. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow local user creation**: Prevents a user with the role of administrator from creating new users in Users & Groups in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Bypass screen capture alerts**: Prevents user notifications for content capture technologies in macOS 15.1 and later. * *Platforms:* Mac, Supervised * **Disallow File Sharing modification**: Prevents a user from changing the state of the File Sharing service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Printer Sharing modification**: Prevents a user from changing the state of the Printer Sharing service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Remote Management modification**: Prevents a user from changing the state of the Remote Management service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Remote Apple Events modification**: Prevents a user from changing the state of the Remote Apple Events service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Internet Sharing modification**: Prevents a user from changing the state of the Internet Sharing service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Bluetooth Sharing modification**: Prevents a user from changing the state of the Bluetooth Sharing service in System Settings. Available in macOS 14 and later. * *Platforms:* Mac * **Disallow Media Sharing modification**: Prevents a user from changing the state of the Media Sharing service in System Settings. Available in macOS 15.1 and later. * *Platforms:* Mac, Supervised * **Disallow iPhone Mirroring**: Prevents the use of iPhone Mirroring. When used on macOS, this prevents the Mac from mirroring any iPhone. When used on iOS, this prevents the iPhone from mirroring to any Mac. Requires a supervised device. Available in iOS 18 and later and macOS 15 and later. * *Platforms:* Mac, iPhone, Supervised * **Disallow remote screen control via FaceTime**: Prevents the ability for a remote FaceTime session to request control of the device. Requires a supervised device. Available in iOS and iPadOS 18 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Apple Intelligence reports**: When checked, disallows Apple Intelligence reports. Requires a supervised device. Available in iOS and iPadOS 18.4 and later, macOS 15.4 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow external intelligence integrations**: Prevents the use of external, cloud-based intelligence services with Siri. Cannot be used with Shared iPad. Available in iOS 18.2 and later and macOS 15.2 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow external intelligence integrations sign-in**: Forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction will cause them to be signed out. Cannot be used with Shared iPad. Available in iOS 18.2 and later and macOS 15.2 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Allowed external intelligence workspace IDs**: When provided, only accounts in the specified workspace in the external intelligence system, such as ChatGPT, can sign in on the device. In ChatGPT, this ID can be found in the admin panel for your enterprise workspace. Requires a supervised device. Available in iOS and iPadOS 18.3 and macOS 15.3 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Genmoji**: Prohibits creating new Genmoji. Requires a supervised device. Available in iOS and iPadOS 18 and later, and macOS 15 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Image Playground**: Prohibits the use of image generation. Requires a supervised device. Available in iOS and iPadOS 18 and later, and macOS 15 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Image Wand**: Prevent the use of Image Wand. Requires a supervised device. Available in iOS and iPadOS 18 and later, and visionOS 2.4 and later. * *Platforms:* iPad, iPhone, Vision, Supervised * **Disallow Personalized Handwriting Results**: Prevents generating text in the user's handwriting. Requires a supervised device. Available in iOS and iPadOS 18 and later. * *Platforms:* iPad, iPhone, Supervised * **Disallow Mail smart replies**: When checked, disallows smart replies in Mail. Requires a supervised device. Available in iOS and iPadOS 18.4 and later, macOS 15.4 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Mail summaries**: Disallow the use of the summarize button in Mail. Requires a supervised device. Available in macOS 15.1 and later, and iOS and iPadOS 18.1 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow transcription in Notes**: Prevents transcription in Notes. Available in iOS 18.2 and later, iPadOS 18.2 and later, macOS 15.2 and later, and visionOS 2.4 and later. Requires a supervised device. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow Notes transcription summary**: When checked, disallows transcription summaries in Notes. Requires a supervised device. Available in iOS and iPadOS 18.3 and macOS 15.3 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Supervised * **Disallow summarizing content in Safari**: When checked, disallows summarizing content in Safari. Requires a supervised device. Available in iOS and iPadOS 18.4 and later, macOS 15.4 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow writing tools**: Prevent the user from using Apple Intelligence writing tools. Requires a supervised device. Available in iOS and iPadOS 18 and later, and macOS 15 and later, and visionOS 2.4 and later. * *Platforms:* Mac, iPad, iPhone, Vision, Supervised * **Disallow visual intelligence summarization**: Disables visual intelligence summarization. Available in iOS 18.3 and later, iPadOS 18.3 and later, and visionOS 2.4 and later. Requires a supervised device. * *Platforms:* iPad, iPhone, Supervised ### Important Considerations Many Apple restrictions only apply on **supervised** devices. Enroll those devices with Automated Device Enrollment or Apple Configurator. Support varies by device type and OS. Confirm a restriction exists for your targets before you depend on it. Tighter restrictions can block legitimate work; looser ones may leave gaps. Set policies to match your risk and how people use devices. Try changes on test hardware first. Undoing some restrictions may require re-enrolling the device. # Configure the Safari Extensions Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-safari-extensions-library-item Manage Safari browser extensions on iOS and iPadOS devices using the Safari Extensions Library Item. Allow, block, or require specific extensions. This Library Item is available for iOS devices and iPadOS devices ### What are Safari Extensions? Safari extensions in iOS and iPadOS 18 are designed to enhance the Safari browser by allowing users to customize their browsing experience. These extensions can help with tasks such as blocking ads, managing passwords, and enhancing privacy. With Iru, you can manage whether Safari extensions are allowed or restricted across your mobile device fleet. You can also determine which domains are permitted or blocked for extension installations. This Library Item requires supervision. ### Add and Configure the Safari Extensions Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Safari Extensions Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select the global **State** of Safari Extensions. Select the global **State** of Safari Extensions in Private Browsing. Optionally, configure allowed **Domains**. Wildcarded domains, such as \*.kandji.io are supported. Optionally, configure denied **Domains**. Wildcarded domains, such as \*.kandji.io are supported. To customize settings for individual extensions, click the **Add configuration for a specific extension** button and specify the desired settings for each extension. Specify the **Bundle ID** of the extension you want to configure. Specify the **Team ID** of the extension. Select the **State**. Select the **State in Private Browsing**. Optionally, configure allowed **Domains**. Wildcarded domains, such as \*.kandji.io are supported. Optionally, configure denied **Domains**. Wildcarded domains, such as \*.kandji.io are supported. Click **Save.** ### Considerations * Global and specific Safari Extension configurations can be combined. For example, you can set all extensions to be off by default and then selectively enable specific ones, or vice versa. * When configuring specific extensions, the app containing the extension must be installed separately via an Apps and Books Library Item. * Please contact the software developer to find an extension's Bundle ID and Team ID. For more information on Safari extensions, see [Apple's Developer Documentation](https://developer.apple.com/safari/extensions/). # Configure the SCEP Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-scep-library-item Set up the SCEP Library Item in Iru Endpoint to issue device certificates from a SCEP server. Configure certificate templates for Apple and Windows devices. This Library Item is available for Apple and Windows devices The **Simple Certificate Enrollment Protocol (SCEP)** profile lets you securely issue certificates to your devices from a SCEP server and Certificate Authority (CA). You can use these certificates for services like 802.1x, VPN, and authentication. Iru's SCEP Profile feature automatically distributes and re-distributes certificates to **Apple** and **Windows** devices. Certificates are delivered at the machine level, not per user. You can only use static challenges with the SCEP Library Item. ## Create a SCEP Profile Library Item Log in to your Iru tenant before you start. To add this Library Item to your Iru Endpoint Library, follow the steps in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **SCEP**. Give your SCEP Library Item a descriptive name. Choose which platforms should get the profile under **Install on**. Pick the [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) you want to use. Enter the base URL for your SCEP server. Optionally, add a display **Name**, **Challenge**, and **Fingerprint**. Set the **Subject** (optional) and **Subject Alternative Name Type**. Set your **Key Size** and **Key Usage**. Optionally, add retry, access, export, expiration, and redistribution settings. ## General Settings * **URL** The base URL for your SCEP server (like `scep.example.org`). * **Name** (optional) A label to distinguish this CA when you use multiple certificates. * **Challenge** A pre-shared secret string for automatic enrollment. On **Windows**, only certain characters are allowed. See **SCEP Challenge characters** under Windows-Specific Options. * **Fingerprint** The certificate authority fingerprint as a hex string. ### Subject Configuration * **Subject** Distinguished name in X.500 format. You can use [global variables](/en/endpoint/library/library-items-profiles/global-variables) like: * `CN=$SERIAL_NUMBER` * **Subject Alternative Names (SAN)** Add alternative identifiers, including [global variables](/en/endpoint/library/library-items-profiles/global-variables), like: * `RFC 822 Name` = `$DEVICE_NAME` ## Key Settings * **Key size** Pick your key size (1024, 2048, or 4096 bits). * **Key usage** Options: * Signing * Encryption * Both signing and encryption ## Additional Options * **Retries** How many times to retry if the server sends a *PENDING* response. * **Automatic profile redistribution** When enabled, Iru checks certificate expiration dates and automatically re-issues new certificates when they're about to expire. Renewal only starts when the certificate is within the redistribution window, which must be at least 5 days before expiration. This prevents certificates from being renewed too early, like right after they're issued. * When renewing, Iru appends the `$PROFILE_UUID` variable to the Subject. ## Platform-Specific Options ### Apple-Specific Options * **Retry delay** How long to wait (in seconds) between retries. * **Allow all apps to access the private key** Gives all apps access to the private key in the keychain. * **Prevent private key extraction** Prevents exporting the private key from the keychain (macOS 10.15+). You should enable this for better security. * **Certificate expiration notification** Sends notifications when certificates are about to expire on macOS. When **Automatic profile redistribution** is enabled for Apple devices, specify a user global variable in the Subject Alternative Names (SAN) if user information is required in the certificate. This is necessary because the Wi-Fi Library Item ID is added to the Common Name in the certificate's subject to track certificate renewal. ### Windows-Specific Options * **Hash algorithm** Pick the algorithm (like SHA-256). * **Retry wait time in minutes** How long to wait between retries on *PENDING* responses. Maximum retries on Windows is 30. * **Extended key usage** Add extra usages like *Client authentication*. * **Key protection** Choose where to store the private key. You should enable **Prevent the private key data from being extracted** for better security. * **Valid period** Set how long certificates stay valid. The validity period needs at least a 5-day renewal window. For example, if your certificate is valid for 10 days, you can set automatic redistribution to start 5 days before expiration. You can't set a shorter window (like 7 days on a 10-day certificate) because that would try to renew too soon after issuing. * **SCEP Challenge characters** On Windows, the **Challenge** field accepts only letters (A-Z and a-z), digits (0-9), space, and `' ( ) + , - . / : = ?`. These characters are **not** allowed: ``` @ # $ % & * _ ; < > " [ ] { } | \ ^ ~ ` ``` Non-ASCII and Unicode characters are also not allowed. If enrollment fails, check the challenge for disallowed characters before you change server or network settings. ## Important Considerations ### Profile Redistribution Automatic profile redistribution renews certificates before they expire, so you avoid downtime and keep authentication working smoothly. ### Preventing Key Extraction Enabling **Prevent the private key data from being extracted** prevents end users from exporting the private key. You should enable this for better security. ## Best Practices Set certificate validity periods and renewal windows to keep services running without interruption. Use strong, unique challenge secrets for each SCEP configuration to prevent unauthorized enrollment. Check certificate enrollment and renewal status regularly so you can catch and fix issues quickly. Test SCEP configurations on a few devices first - this helps you catch issues before they affect your whole fleet. ## Troubleshooting **Possible causes:** * The **Challenge** value includes a character Windows does not allow (for example `_`) * The challenge includes non-ASCII or Unicode characters **Solutions:** * Compare your **Challenge** to the allowed character list under **SCEP Challenge characters** in Windows-Specific Options * Remove or replace disallowed characters, then save the Library Item. We have seen enrollment fail when a challenge contained an underscore until the challenge was updated to use only allowed characters * Allow devices to check in or sync so the updated profile applies **Possible causes:** * Incorrect SCEP server URL * Invalid challenge secret * Network connectivity issues * Certificate authority fingerprint mismatch **Solutions:** * Verify SCEP server URL and accessibility * Confirm challenge secret matches server configuration * Check network connectivity and firewall rules * Validate certificate authority fingerprint **Possible causes:** * Renewal window too short * SCEP server not responding * Certificate validity period conflicts **Solutions:** * Ensure renewal window is at least 5 days before expiration * Check SCEP server availability and logs * Verify certificate validity period configuration **Possible causes:** * Key protection settings too restrictive * Keychain access permissions * Application-specific key access requirements **Solutions:** * Review key protection and access settings * Check keychain permissions for applications * Configure appropriate key access for required applications ## Security Considerations You should use strong, unique challenge secrets and rotate them regularly to prevent unauthorized enrollment. Enable private key extraction prevention to keep your certificates secure. Monitor certificate enrollment and renewal activities to spot security issues. Set key access permissions based on what your applications need. # Configure the Setup Assistant Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-setup-assistant-library-item Configure the Setup Assistant Library Item in Iru Endpoint to customize which screens appear during initial device setup on Apple and Windows devices. This Library Item is available for Mac computers, iOS devices, and iPadOS devices ### What is Setup Assistant? Setup Assistant is a built-in feature in macOS, iOS, and iPadOS that helps users configure their devices out of the box. It's typically encountered when setting up a new device or after a factory reset; on Mac computers, it also appears when creating new local user accounts and after some OS upgrades. ### How Managing Setup Assistant Works You can use a Setup Assistant Library Item to simplify the setup process for end users. This lets you skip certain setup steps, making it easier for users to get started. The Setup Assistant Library Item is compatible with iOS and iPadOS 14 and later, and macOS 15 and later. ### Add and Configure the Setup Assistant Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Setup Assistant Library Item a **Name** Select which Device Families this Library Item will **Install on**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select the screens you'd like to skip for **Mac**. Select the screens you'd like to skip for **iPhone**. Select the screens you'd like to skip for **iPad**. Click **Save**. # Configure the Single Sign-On Extension Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-single-sign-on-extension-library-item Set up the SSO Extension Library Item in Iru Endpoint to enable single sign-on across apps and websites on Mac, iPhone, and iPad devices. This Library Item is available for Apple devices ### What is a Single Sign-On Extension? A Single Sign-On (SSO) extension is a type of application for macOS, iOS, iPadOS, and visionOS that uses Apple's Extensible Enterprise Single Sign-on framework. These applications, or *extensions,* let identity providers (IdPs) build applications that keep a user signed in across native macOS applications and browsers. This allows you to sign in once to the extension and be authenticated across macOS, iOS, iPadOS, and visionOS. SSO extensions can also allow for synchronizing a user's local macOS password with their IdP password. When deploying Okta Device Trust, this Single Sign-On Extension is not required separately because the functionality of the SSO Extension is included as part of the Okta Device Trust deployment. ### How Can I Deploy a Single Sign-On Extension? * For iOS, iPadOS, and visionOS extensions, you must first deploy the app containing the SSO extension via Apps and Books from Apple Business or Apple School Manager. * For macOS extensions, you must first deploy the app containing the SSO extension via Apps and Books from Apple Business or Apple School Manager or via a Custom App in Iru. * After deploying the extension, you will then configure and deploy a Single Sign-On profile to the devices. ### Configure a Single Sign-On Extension Profile To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Single Sign-On Extension Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). #### Redirect Single Sign-On Extension Profile **Extension Type**: This option refers to the type of SSO extension. Choose **Redirect** from the drop-down menu. **Extension Identifier**: In this option, you specify the Bundle ID of the SSO extension. The Bundle ID can be found by inspecting the app's *info.plist* file. **Team Identifier:** The team identifier of the app extension that performs single sign-on. Required if the extension will be assigned to Mac computers. **URLs**: This option allows you to specify the URL prefix on behalf of which the SSO extension will authenticate. **Denied Bundle Identifiers:** Specify bundle identifiers of apps that shouldn't use SSO provided by this extension. Applies to iOS and iPadOS 15 and later, and macOS 12 and later. **Set additional extension configuration:** Optionally specify any additional configuration data required by the extension. #### Credential Single Sign-On Extension Profile **Extension type**: This option refers to the type of SSO extension. Choose **Credential** from the drop-down menu. **Extension Identifier**: In this option, you specify the Bundle ID of the SSO extension. The Bundle ID can be found by inspecting the app's *info.plist* file. **Team Identifier:** The team identifier of the app extension that performs single sign-on. Required if the extension will be assigned to Mac computers. **Realm**: This option will be displayed only if the credential type is **Credential.** Typically, this is in reference to a Kerberos realm when leveraging the Kerberos extension. **Hosts**: This option allows you to specify which host can be authenticated through the SSO extension. An example would be an ADFS instance. **Denied Bundle Identifiers:** Specify bundle identifiers of apps that shouldn't use SSO provided by this extension. Applies to iOS and iPadOS 15 and later, and macOS 12 and later. **Set additional extension configuration:** Optionally specify any additional configuration data required by the extension. #### Configure a Single Sign-On Extension Profile for Apple's Kerberos Extension **Extension type**: This option refers to the type of SSO extension. Choose **Kerberos** from the drop-down menu. **Realm:** Set the Realm to the capitalized form of your Active Directory domain name (i.e. accuhive.io becomes ACCUHIVE.IO) **Hosts:** This can be left empty. If you have enterprise applications leveraging ADFS, and ADFS is configured to accept Kerberos authentication, you can add the host to your ADFS server here. (i.e. adfs.accuhive.io) Under the **Password Options** section, you can configure all of the available Kerberos extension options (such as syncing the local user password). ### What is Platform SSO? Platform SSO allows Single Sign-On Extensions to extend their functionality to the macOS login window. This lets users unlock their Mac using an IdP password and enables just-in-time creation of local accounts on a shared Mac using credentials from your organization's Identity Provider (IdP). The local account password is automatically kept in sync, so the cloud password and local passwords match. Permissions and local group memberships can be managed, and this also extends to IdP users who don't have a local account, so those credentials can be used at authorization prompts. Platform SSO requires macOS 14 Sonoma or later, and in addition to the Platform SSO profile payload deployed by Iru, a properly configured Single-Sign On Extension App from your Identity Provider. ### Configure Platform SSO If you selected Kerberos as the **extension type**, the Platform SSO section will be unavailable, as they are not complementary technologies. The Platform SSO section is inactive by default. Toggle the radio button to expand and configure it: Select the authentication method. The SSO Extension must support this authentication method. Optionally, enter your **Registration token** when your identity provider requires one. The Mac uses this value for Platform SSO registration with your identity provider, including silent registration when your identity provider and SSO extension support it. Select the permissions group that existing local user accounts should have at login: Standard, administrator, or groups that will be specified in later steps. Select the permissions group that new accounts created at the login window should have. If you would like to allow account creation at the login window, which is helpful for shared devices, configure shared device key usage: Select **Use shared device keys.** **Allow authorization (with identity provider account)** will let users interact with system authorization prompts using their IdP credentials. If you want to have local accounts created automatically for users, select **Allow creation of new users at login window**. Local account creation requires the device to be online, at login window with FileVault unlocked and for Iru to have a valid Bootstrap token for the device. #### Login Options & Groups Next, you'll configure a few more login options: * The account display name will typically be your organization's name or something your users will recognize as it appears in notifications and authentication requests. * A full login can be required after a certain amount of time. The default is 18 hours (64800 seconds), and the minimum value is 1 hour (3600 seconds). * The attribute mapping to use when creating new users or for authorization. Finally, you can configure authorization groups which will let users or IT staff have specific permissions on the device. There are three different types of groups: * **Admin groups** are groups from your IdP that should have administrator access on the device. * **Additional groups** are ones you would like to see created in the device's local directory. * **User groups** are most useful: They let you map specific macOS systems rights to arbitrary groups that will be created in the local directory. For example, to grant 'sudo' or printer management access. #### Enable Registration During Setup Assistant (macOS 26 and later) Starting in macOS 26, Platform SSO can run during Setup Assistant so the Mac can register with your identity provider earlier in the enrollment flow. This section lets you configure registration during setup, first-user creation, profile picture sync behavior, and Authenticated Guest Mode for shared-device workflows. In the **Platform SSO** section of this Library Item, go to **Mac macOS 26 and later**. Select **Yes** for **Enable registration during Setup Assistant** so Platform SSO registration runs while Setup Assistant is still in progress. For **Create first user during Setup Assistant**, select **Yes** when the Mac should create its first local account during Setup Assistant using Platform SSO. If your organization provisions the first account differently, adjust this setting to match that workflow. Configure **Synchronize profile picture** based on whether the Mac should request the user’s login profile picture from the SSO extension during this setup flow. Configure **Enable Authenticated Guest Mode** when you deploy shared Macs where users sign in temporarily with IdP credentials and want Authenticated Guest Mode behavior. For standard single-user Macs, leave this behavior off. Under **New user authentication methods**, select the authentication methods available for newly created accounts. Click the **Save** button. Platform SSO with Automated Device Enrollment requires your **Single Sign-on Extension** Library Item and the **Auto App** Library Item for your identity provider’s SSO extension application to install during Setup Assistant. In your **Automated Device Enrollment** Library Item, turn on **Install Library Items during Setup Assistant** for **Mac**, then add those Library Items plus any others your IdP requires for this flow (for example a **Login Window** Library Item). See [Install Library Items during Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#install-library-items-during-setup-assistant) for the full details. If a device is stuck on **Configuring**, see [Manually release devices held in Setup Assistant](/en/endpoint/enrollment/apple/configuring-apple-enrollment#manually-release-devices-held-in-setup-assistant). For Microsoft Entra ID-specific Library Items and values, see [Configure Platform SSO with Entra ID](/en/endpoint/library/library-items-profiles/configure-the-platform-sso-with-microsoft-entra-id-library-item). # Configure the SSH Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-ssh-library-item Configure the SSH Library Item in Iru Endpoint to manage secure shell access on Mac computers. Enable or disable remote login and set allowed users. This Library Item is available for Mac computers ### What is SSH? SSH, or Secure Shell, is a network protocol that lets you securely access and manage a remote computer over an encrypted connection. It's commonly used by Mac admins to issue remote commands, access important files, and run applications on computers in their fleet. ### How does SSH work? macOS comes with a built-in SSH client accessible through Terminal. It also includes an SSH server, which is disabled by default, but can be enabled to allow remote access to your Mac. SSH uses cryptographic techniques to secure the connection between the client and server. This includes symmetric encryption, asymmetric encryption, and hashing to ensure data integrity and confidentiality during transmission. Using Iru, you can configure SSH according to your organization's security tolerances under the General section within the SSH Library item. The /etc/ssh/ssh\_config and /etc/ssh/sshd\_config config files may return to their default values upon any update or major upgrade. However, the Iru Agent will automatically remediate and set the corresponding values defined in the SSH Library item. ### Add an SSH Library Item Use the guidance below to meet NIST or STIG requirements for SSH in your Mac fleet. For organizations aiming to meet CIS Level 1 requirements without using a CIS Level 1 Blueprint, disabling the SSH server on macOS is recommended. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new SSH Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select **SSH server availability**. * Click **On**. Select **Challenge-response authentication**. * Click **On**. Select **Root login**. * Click **Off**. Select **SSH login banner**. * Click **On**. * Enter a custom **Banner text** per your organization's security policy. You can also use the default text. Select **Login attempt grace period**. * Ensure that the login attempt timeout is set to **30** seconds. Select **Session timeout**. * Ensure that the session timeout is set to **900** seconds. Select **Maximum alive count**. * Ensure that the alive count is set to **0** messages. Select **Remove non-FIPS Ciphers**. Select **Remove non-FIPS Message Authentication Codes**. Select **Use secure key exchange algorithms**. Click **Save**. # Configure the Wallpaper Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-wallpaper-library-item Set custom wallpapers on managed iOS and iPadOS devices using the Wallpaper Library Item. Deploy lock screen and home screen images to supervised devices. This Library Item is available for iOS devices and iPadOS devices The Wallpaper Library Item has two main functions: it lets you deploy a custom wallpaper to iPhone and iPad devices and restrict users from modifying the wallpaper. Once you, as an admin, determine that a standard wallpaper should be deployed, the user won't be allowed to opt out or change it. You'll also see a preview of the result on a device to help you quickly achieve your desired result. This Library Item requires supervision. The Wallpaper Library Item cannot be duplicated. ### Select Device Families By default, this Library Item will apply to both iPhone and iPad, but you can change this in the **Install on** field at the top of the Library Item. By selecting the device families you wish to manage, you control the availability of the related sections. ### Upload Wallpaper and Check Fit The Settings area contains platform-specific sections, with a file upload UI conveniently contained within device bezels, one each for the device's Lock Screen and Home Screen. Drag and drop your wallpaper image onto one of the device bezels, or use the **Select file** link to upload it. The image is displayed inside the device bezel to give you a close approximation of the on-device result. A link below the device lets you easily copy this image to the Home or Lock Screen. In addition, typical onscreen elements, including date and time, network status, and standard apps, help you determine if your wallpaper's key elements are positioned for good visibility. iOS and iPadOS automatically zoom wallpaper images to make them fit the screen. If your image looks odd or clipped in Iru, it will likely look the same on a device. Try modifying your image's dimensions before proceeding further. For iPad, there is a screen orientation control at the top right to preview wallpaper in both portrait and landscape. For iPhone, the recommended resolution is 2796 x 1290 pixels (19.5:9 aspect ratio). For iPad, the recommended resolution is 2732 x 2732 pixels with the main content centered within a 2048 x 1536 pixel area (4:3 aspect ratio). You can upload PNG, JPG, JPEG, BMP, or TIFF files, as long as they are no larger than 5 MB. Results on versions older than iOS and iPadOS 17 will not match the preview if your image exceeds the recommended resolution. # Configure the Web Clip Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-web-clip-library-item Create web clips on managed devices using the Web Clip Library Item in Iru Endpoint. Add home screen shortcuts to websites for quick one-tap access. This Library Item is available for iOS devices and iPadOS devices ### What is a Web Clip? A web clip is a shortcut or visual bookmark that provides quick access to a specific web page directly from a device's home screen. Unlike traditional bookmarks, Web Clips appear as icons on the home screen of iOS and iPadOS devices resembling apps. This feature allows users to open web links without launching a browser each time, making it particularly useful for accessing frequently visited sites or web applications. ### How do Web Clips Work? Web clips function by linking directly to a specified URL. When tapped, they open the linked page in the default browser or in full-screen mode if configured. This functionality is not limited to standard URLs; Web Clips can also support various URI schemes, such as `mailto:`, `sms:`, or even JavaScript commands like `javascript:`, but their compatibility depends on the apps and configurations you have enabled on your device fleet. This versatility lets web clips perform actions beyond merely opening web pages, such as initiating emails or text messages. To enhance user experience, web clips can be customized with specific icons and names. They can also be configured to open in full-screen mode, which hides the browser's UI controls, providing an app-like experience. This is especially useful when deploying Web Clips in environments where browser access needs to be restricted. ### Add & Configure the Web Clip Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new web clip Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Enter a user-facing **Label** for your web clip. Enter the **URL** the web clip should point to. Upload an **Icon**. For best results, use a PNG file that is 144x144 to 400x400 pixels and less than 1MB in size. Optionally, allow the web clip to be **Removable**. If desired, force the web clip to open in **Full screen**. To allow a full-screen web clip to navigate to an external website without showing Safari UI, check the **Always hide UI controls** checkbox. ### Considerations * Web clips require Safari to function. If you're using a [Home Screen Layout Library Item](/en/endpoint/library/library-items-profiles/configure-the-home-screen-layout-library-item), you can either add Safari to your Home Screen Layout, allowing users to access the full browser, or enable the 'Fullscreen' option in each web clip's settings. * To keep the Safari interface out of sight and ensure users stay focused on the content, select the "Fullscreen" option. * If using a web clip and need to navigate to other web resources while still keeping browser controls hidden, make sure to check "Always hide UI controls." * Web clips can only be deployed to iPad devices with a single user. # Configure the Wi-Fi Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item Set up the Wi-Fi Library Item in Iru Endpoint to deploy wireless network configurations. Configure SSID, security type, proxy, and 802.1X authentication. This Library Item is available for Apple and Windows devices The **Wi-Fi** Library Item lets you configure managed devices to automatically connect to wireless networks. You can define SSIDs, authentication methods, certificates, and proxy settings to ensure secure, consistent connectivity across your fleet. You can deploy Wi-Fi profiles to **Apple** and **Windows** devices. While most options are shared, some settings are specific to certain platforms. ## Create a Wi-Fi Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **Wi-Fi**. Enter a **Name** for the Library Item. Select one or more platforms under **Install on**. Assign the profile to one or more **Blueprints**. ## General Settings Specify the **Service Set Identifier (SSID)**, also known as the network's name. If you want devices to automatically join this network when it is available, select **Auto join network**. If you do not select Auto join network, devices will know how to connect to the network, but the user will have to choose to do so. If the network is hidden (it does not broadcast its SSID), select Hidden network. Hidden networks are not standards-compliant and are not recommended. If you wish to turn off MAC address randomization, select **Disable MAC address randomization**. Available for iOS 14+ and later versions. To use IPv6 on this network, select **IPv6**. If you do not want to use Apple's Captive Network Assistant on this network, select **Disable captive network detection**. Specify the **Service Set Identifier (SSID)**, also known as the network's name. If you want devices to automatically join this network when it is available, select **Auto join network**. If you do not select Auto join network, devices will know how to connect to the network, but the user will have to choose to do so. If the network is hidden (it does not broadcast its SSID), select Hidden network. Hidden networks are not standards-compliant and are not recommended. If you wish to turn off MAC address randomization, select **Disable MAC address randomization**. ## Authentication ### None Use the None authentication type when no password is necessary to join the network. If a network with the specified SSID is available and does not require authentication, the device will attempt to join it. * No password is required. * Devices automatically connect if the SSID is available. It is highly recommended **NOT** to use this authentication type as anyone can join the network without authenticating. ### Pre-Shared Key (PSK) PSK authentication is commonly used in home and small business environments. Anyone who has the network's shared password can join it. Choose from: **WEP**, **WPA Personal**, **WPA2 Personal**, **WPA3 Personal**, or **Any Personal**. Any Personal will work with any of the methods above, and it is useful when some locations use WPA2, and others use WPA3. Enter the **Password** for the network. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. ### Enterprise (802.1X EAP) Enterprise authentication uses 802.1X to provide more secure authentication options when connecting to Wi-Fi networks. Enterprise authentication types include: * **Dynamic WEP** * **WPA Enterprise** * **WPA2 Enterprise** * **WPA3 Enterprise** When an enterprise type is selected, additional settings appear depending on the chosen **EAP type** (e.g., EAP-TLS, PEAP, TTLS). You can configure: * Identity certificates (AD CS, SCEP, or PKCS #12) * Trusted server certificates * User authentication (username/password, smartcard, or certificates) Certificate options are only available if you select one of the WPA Enterprise options in the Authentication type dropdown. Configure Wi-Fi using the following options: For **Authentication type**, choose Dynamic WEP, WPA Enterprise, WPA2 Enterprise, or WPA3 Enterprise. On macOS, if you wish to authenticate to the network as the user that logs in at the login window, select Use as a Login Window configuration. Otherwise, the configuration is considered a System configuration, and Mac systems will be able to authenticate to the network when a user has not logged in. You can also use this option in conjunction with EAP-TLS so a certificate identity is used to authenticate the system before login, but then login window credentials are used to authenticate the user. Select the **Accepted EAP Types** your network supports. You may select more than one and will need to set all the settings necessary for the selected EAP types. For more information on configuring specific EAP types, refer to [Configure Enterprise Wi-Fi authentication protocols](/en/endpoint/library/deployment-guides/apple/configure-eap-extensible-authentication-protocol-types). Using this configuration requires integration with a directory service. See [this Apple support article](https://support.apple.com/en-us/102001) for more information. ### Configure an Identity Certificate You can configure an identity certificate using AD CS, SCEP, or by uploading a PKCS #12 file. For instructions on configuring identity certificates, see our [Using Identity Certificates for 802.1X Authentication](/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication) support article. If you are using AD CS, complete [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) and [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration) first. On Windows, the authentication type must be something other than **None**. ### Pre-Shared Key (PSK) PSK authentication is commonly used in home and small business environments. Anyone who has the network's shared password can join it. Windows supports **WPA Personal** and **WPA2 Personal**. Enter the **Password** for the network. If you do not enter a password, the device prompts the user to enter a password when connecting to the network. ### Enterprise (802.1X EAP) Enterprise authentication uses 802.1X to provide more secure authentication options when connecting to Wi-Fi networks. Windows supports: * **WPA Enterprise** * **WPA2 Enterprise** When an enterprise type is selected, additional settings appear depending on the chosen **EAP type** (e.g., EAP-TLS, PEAP, TTLS). You can configure: * Identity certificates (AD CS, SCEP, or PKCS #12) * Trusted server certificates * User authentication (username/password, smartcard, or certificates) Certificate options are only available if you select one of the WPA Enterprise options in the Authentication type dropdown. For **Authentication type**, choose WPA Enterprise or WPA2 Enterprise. Select the **Accepted EAP Types** your network supports. You may select more than one and will need to set all the settings necessary for the selected EAP types. For more information on configuring specific EAP types, refer to [Configure Enterprise Wi-Fi authentication protocols](/en/endpoint/library/deployment-guides/windows/configure-eap-extensible-authentication-protocol-types). ### Configure an Identity Certificate You can configure an identity certificate using AD CS, SCEP, or by uploading a PKCS #12 file. For instructions on configuring identity certificates, see our [Using Identity Certificates for 802.1X Authentication](/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication) support article. If you are using AD CS, complete [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview) and [AD CS Integration: Configure the Integration](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-configure-the-integration) first. ## Proxy Proxy settings are available for Apple devices only Configure devices to use a network proxy by configuring the settings in the **Proxy** section. To configure network proxy settings, toggle the **Proxy** section to **Managed**. **Automatic**: Provide a Proxy Auto-Configuration (PAC) URL. If you want devices to attempt to connect directly to destinations when the PAC file is not available, select **Proxy PAC fallback allowed**. **Manual**: Enter proxy **server**, **port**, and (if required) **username** and **password**. ## Fast Lane Marking Fast Lane marking is available for Apple devices only Use Fast Lane on networks and devices that support Quality of Service (QoS) marking to prioritize traffic from apps on connected devices as voice, video, or real-time data. To learn more about Fast Lane, refer to [iOS Compatibility with Cisco QoS Fastlane & Adaptive 802.11r.](https://support.apple.com/en-us/HT207308) Fast Lane is not supported by all networks or devices and is primarily available on Apple devices. To turn off Fast Lane, choose **Disable Fast Lane for all apps**. To turn on Fast Lane, choose **Allow specific apps**. Fast Lane applies to network traffic from specific apps. Click **Add application** to add apps to the allow list. To add apps from your Iru Library, enter the app's name under **Search by name**. Select the apps you want to allow to use Fast Lane. You may also specify apps by Bundle ID. Click **Add Bundle ID**. Provide the **App Name** and **Bundle ID** and click **Add**. You can add multiple Bundle IDs. Click **Done**. ## Certificate Trust Settings Specifying trusted certificates in the Wi-Fi Library Item is not recommended. If certificates are renewed or changed, you will need to redeploy the entire Wi-Fi profile, potentially causing devices to disconnect from the Wi-Fi network. Instead, install the trusted certificate chain for your RADIUS server(s) using a separate Certificates Library item. Then specify the name of those certificates in the Wi-Fi Library item under **Specify server certificate names**. See [Apple Platform Deployment](https://support.apple.com/guide/deployment/connect-to-8021x-networks-depabc994b84/web) for more information. Most enterprise Wi-Fi environments require that devices trust the 802.1X authentication server(s), typically a Remote Access Dial-In User Server (RADIUS). The **Certificate trust** settings allow you to configure which certificates presented by the server devices will trust. If a device does not trust the authentication server(s), the user will be prompted to trust it. Select **Specify trusted certificates** if you want to provide certificates for the configured devices to trust. Then upload the certificates in .cer or .crt format. Select **Specify server certificate names** if you want to provide DNS names of certificates devices should trust. Then enter their DNS names. Wildcards are accepted. # Configure the Windows Custom App Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-windows-custom-app-library-item Deploy custom Windows applications using the Windows Custom App Library Item. Upload MSI or EXE installers, configure install commands, and set detection rules. The Windows Custom App Library Item is available for Windows devices The **Windows Custom App** Library Item lets you deploy Windows applications (MSI, EXE) to Windows devices. For details on installers, installation options, detection logic, commands, and troubleshooting, see the [Custom Apps Overview](/en/endpoint/library/library-items-profiles/custom-apps-overview#windows). For what end users see when pending **Auto App** or **Windows Custom App** updates are available, including the Iru system tray **Updates** list and [when a running app must close first](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#when-an-app-must-close), see [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray). ## Create a Windows Custom App Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Use the **Search** field to find **Windows Custom App** by name, type, or label, then select it. Assign the Library Item to one or more **Blueprints**. You can use Assignment Maps within Blueprints for conditional logic if needed. Choose **Install once per device** or **Install and continuously enforce**. See [Installation options](/en/endpoint/library/library-items-profiles/custom-apps-overview#installation-options-2) in the overview. Set **Enforcement deadline** and, if you use **By enforcement deadline**, **Enforcement after version is saved** and **Enforcement deadline time**. See [Enforcement timeframe](/en/endpoint/library/library-items-profiles/custom-apps-overview#enforcement-timeframe) in the overview. Enter **Publisher**, **Name**, and **Version**. Optionally add an **App icon** (.png). For more, see [Application details](/en/endpoint/library/library-items-profiles/custom-apps-overview#application-details) in the overview. Upload a .zip file containing the installer (MSI or EXE) and any supporting files (maximum 5 GB). Details are in [Installers](/en/endpoint/library/library-items-profiles/custom-apps-overview#installers-2). Add at least one rule under **Detection logic rules**. See [Detection logic](/en/endpoint/library/library-items-profiles/custom-apps-overview#detection-logic) in the overview. Optional. Add executable names as described in [Executables for open app detection](/en/endpoint/library/library-items-profiles/custom-apps-overview#executables-for-open-app-detection) in the overview. In **Architecture**, choose **x64** or **arm64**. See [Architecture](/en/endpoint/library/library-items-profiles/custom-apps-overview#architecture) in the overview. In **Install command line parameters**, enter the full silent install command line. You can reference files in the zip with relative paths or run a PowerShell script from inside the zip. See [Commands](/en/endpoint/library/library-items-profiles/custom-apps-overview#commands) in the overview. If a path contains spaces, wrap it in double quotes, for example `"my installer.exe"`. In **Uninstall command line parameters**, enter the full silent uninstall command line. See [Commands](/en/endpoint/library/library-items-profiles/custom-apps-overview#commands) in the overview. Use the same quoting rule as for the install command when paths contain spaces. Click **Save**. The new Windows Custom App will now appear in your Library and be ready to be added to a Blueprint. ### Configure an Assignment Map to Deploy a Windows Custom App Navigate to **Blueprints** in the left-hand navigation bar. Select the **Assignment Map** you'd like to add the Windows Custom App to. Click **Edit Assignments** in the upper right corner. Drag your Windows Custom App from the left side of the Assignment Map to your desired node on the map. Click **Save**. ### Related Articles Deploy custom applications to Mac and Windows devices Step-by-step setup for Mac Custom Apps (PKG, DMG, ZIP) # Configure the Windows Firewall Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-windows-firewall-library-item Set up the Windows Firewall Library Item in Iru Endpoint. Configure firewall rules, enable or disable profiles, and enforce network protection settings. This Library Item is available for Windows devices The **Windows Firewall** Library Item lets you configure and enforce firewall settings for Windows devices. With this profile, you can manage global firewall behavior, define security association rules, and enforce profile-specific policies across public, private, and domain networks. By using this Library Item, you ensure that Windows endpoints in your organization adhere to consistent firewall configurations, reducing the risk of misconfigurations or unmanaged local rules. For detailed technical background on each firewall setting, refer to Microsoft's official [Windows Firewall documentation](https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/windows-firewall-with-advanced-security). ## Create a Windows Firewall Profile Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. In the **Library**, select **Add Library Item**. Search for and select **Windows Firewall**. Give the Library Item a **Name**. Assign the profile to one or more **Blueprints**. You can use Assignment Maps within Blueprints for conditional logic if needed. ## Global Settings These options apply globally across all firewall profiles: * **Disable stateful FTP transfers** If enabled, disables stateful File Transfer Protocol (FTP) filtering. * **Enable packet queue** Configures scaling for encrypted and clear-text forwarding paths in IPsec tunnels. Ensures packet order is preserved. Default is off. * **IPSec Exemptions** Defines exemptions for IPsec traffic. * **Security association idle time** Sets the idle time (in seconds) before unused security associations are deleted. Default is `300`. ## Profile Settings Profile settings can be applied separately for **Public**, **Private**, and **Domain** network profiles. Toggle management for each profile at the top of the section. ### Core Firewall Settings * **Shielded** Blocks all inbound traffic, regardless of rules. Use with caution. * **Default inbound action** Specifies action (allow or block) for inbound traffic. * **Default outbound action** Specifies action (allow or block) for outbound traffic. ### Policy Management * **Allow local IPsec policy merge** Determines whether local connection security rules are enforced. * **Allow local policy merge** Determines whether local firewall rules are enforced. * **Merge user authorized global ports** Determines whether user-defined global port rules are enforced. * **Merge user authorized app firewall rules** Determines whether user-defined app firewall rules are enforced. ### Advanced Options * **Disable inbound notifications** Suppresses notifications when apps are blocked from listening. * **Disable stealth mode** If enabled, disables stealth (which drops unsolicited traffic). * **Disable unicast responses to multicast/broadcast** Blocks unicast responses to multicast or broadcast requests. ### Logging Configuration * **Log dropped packets** Records all dropped packets. * **Log ignored rules** Records when rules are ignored, depending on implementation. * **Log success connections** Records successful inbound connections. * **Log file path** Defines where firewall logs are written (e.g., `%programdata%\kandji\agent\logs`). * **Log max file size** Maximum size (in KB) for the log file. Default is `1024`. ## Network Profile Configuration The Domain profile applies when the device is connected to a domain network. This is typically the most permissive profile for corporate environments. **Recommended settings:** * Default inbound action: Block * Default outbound action: Allow * Allow local policy merge: Enabled * Logging: Enabled for monitoring The Private profile applies to trusted networks like home or office networks. **Recommended settings:** * Default inbound action: Block * Default outbound action: Allow * Allow local policy merge: Enabled * Logging: Enabled for security monitoring The Public profile applies to untrusted networks like public Wi-Fi. This should be the most restrictive profile. **Recommended settings:** * Default inbound action: Block * Default outbound action: Allow * Shielded: Consider enabling for maximum security * Logging: Enabled for security monitoring ## Considerations * Settings marked "Not configured" do not override the local device configuration. * When blocking all inbound traffic with Shielded, verify that required management and update services remain accessible. * Use logging options to validate firewall behavior before rolling out strict rules fleet-wide. ## Best Practices Test firewall configurations on a small group of devices before deploying to your entire fleet. Enable appropriate logging to monitor firewall behavior and troubleshoot issues. Document any required firewall exceptions for business applications and services. Regularly review firewall logs and policies to ensure they remain appropriate for your organization's needs. ## Troubleshooting **Possible causes:** * Firewall blocking required ports or applications * Incorrect profile settings * Missing firewall rules **Solutions:** * Check firewall logs for blocked connections * Verify the correct network profile is active * Add appropriate firewall rules for the application **Possible causes:** * Firewall blocking management ports * Shielded mode enabled * Incorrect profile configuration **Solutions:** * Ensure management ports are allowed * Disable Shielded mode if necessary * Verify domain profile settings for managed devices **Possible causes:** * Logging not enabled * Insufficient disk space * Incorrect log file path **Solutions:** * Enable appropriate logging options * Check available disk space * Verify log file path is accessible ## Security Recommendations Use different firewall profiles to implement network segmentation based on trust levels. Enable logging to monitor network traffic and detect potential security issues. Regularly review and update firewall policies to address new threats and business requirements. Test firewall configurations in a controlled environment before production deployment. # Configure the Windows Update Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/configure-the-windows-update-library-item Configure the Windows Update Library Item in Iru Endpoint. Manage update rings, deferral periods, active hours, and the end-user update experience. This Library Item is available for Windows devices The **Windows Update** Library Item lets you manage Windows Update settings and the end-user update experience on Windows devices. Control how and when updates are offered, set active hours to avoid disruptive restarts, and limit what users can do from the Windows Update UI. For detailed technical background on each setting, refer to Microsoft's official [Update Policy CSP documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update). ## Create a Windows Update Library Item To add this Library Item to your Iru Endpoint Library, follow the steps in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select **Windows Update**. Give the Library Item a **Name**. Assign the profile to one or more **Blueprints**. You can use Assignment Maps within Blueprints for conditional logic if needed. ## Settings The following settings are available for Windows Update. ### Manage Updates Offered from Windows Update #### Allow Optional Content Controls whether devices receive optional updates and gradual rollouts (controlled feature rollouts, or CFRs) in addition to required updates. Options: * Don't receive optional updates * Automatically receive optional updates (including CFRs) * Automatically receive optional updates only * Users can select optional updates ### Manage End-User Experience #### Allow Auto Update Controls how updates are installed: notify only, auto install, or auto install and restart. Options: * Notify the user before downloading the update * Auto install and then notify the user to schedule a restart * Auto install and restart (default) * Auto install and restart at a scheduled time * Allow the local administrator to choose the setting * Turn off automatic updates #### Active Hours Start Start of the active hours window (hour 0–23). Windows avoids restarting the device for updates during this time. #### Active Hours End End of the active hours window (hour 0–23). Restarts can occur after this hour. #### Set Disable Pause UX Access Controls whether users can pause updates from the Windows Update UI. Options: **Users can pause updates**, or **Remove the pause option from the device UI**. Choose the latter to prevent users from stalling updates. #### Manage Preview Builds Controls whether the device can receive Windows Insider Preview builds. Options: * Disable Preview builds * Disable Preview builds once the next release is public * Enable Preview builds * Preview builds are left to user selection #### Update Notification Level Controls which update notifications users see: default, hide all except restart warnings, or hide all including restart warnings. Options: * Use the default Windows Update notifications * Disable restart notifications for updates (excludes restart warnings) * Disable all notifications for updates (includes restart warnings) ## Advanced Settings These settings appear in an expandable section of the Library Item. They are not configured by default and are for admins who need more control over update behavior. * **Allow non-Microsoft signed update** Lets the device accept updates signed by someone other than Microsoft when using an intranet update service (for example, WSUS for third-party patches). * **Automatic maintenance wake up** Allows Automatic Maintenance to wake the device for its daily scheduled maintenance if needed. * **Disable WUfB safeguards** Windows Update for Business (WUfB). When enabled, devices skip Microsoft safeguard holds that block upgrades when known compatibility issues exist. Use only for validation; it can lead to poor upgrade experiences. * **Exclude WU drivers in quality update** Excludes driver updates from Windows quality updates. Use if you manage drivers separately. * **Active hours max range** Maximum number of hours (8–18) that users can set for their active hours window, starting from the active hours start time. * **Allow auto Windows Update download over metered network** Allows Windows Update to download updates over metered (for example, cellular) connections. May incur data charges. * **Allow MU update service** Controls whether the device scans for app and other Microsoft product updates via Microsoft Update. * **Allow temporary enterprise feature control** When allowed, features delivered in monthly quality updates (servicing) are turned on before the next feature update. When disabled, those features stay off until the feature update that includes them. * **Configure feature update uninstall period** Number of days (2–60) that users can uninstall a feature update after it is installed. * **No update notifications during active hours** Reduces or turns off Windows Update notifications during active hours (optionally excluding restart warnings). Notifications can still appear after the deadline if configured. * **Scheduled install day** Day of the week (or every day) when updates are installed. Only applies when **Allow auto update** is set to **Auto install and restart at a scheduled time** or **Allow the local administrator to choose the setting**. Options: Every day, Sunday, Monday, Tuesday, Wednesday, Thursday, Friday, Saturday. * **Scheduled install every week** When enabled, updates are scheduled every week. Only applies when **Allow auto update** is set to **Auto install and restart at a scheduled time** or **Allow the local administrator to choose the setting**. * **Scheduled install first week** Schedule install during the first week of the month (days 1–7). Use with **Scheduled install day** for a specific weekday (for example, first Tuesday). * **Scheduled install second week** Schedule install during the second week of the month (days 8–14). Use with **Scheduled install day** for a specific weekday. * **Scheduled install third week** Schedule install during the third week of the month (days 15–21). Use with **Scheduled install day** for a specific weekday. * **Scheduled install fourth week** Schedule install during the fourth week of the month (days 22–31). Use with **Scheduled install day** for a specific weekday. * **Scheduled install time** Hour of the day (0–23) when scheduled updates install. There is about a 30-minute window. Only applies when **Allow auto update** is set to **Auto install and restart at a scheduled time** or **Allow the local administrator to choose the setting**. * **Set disable UX WU access** When enabled, users cannot scan, download, or install updates from the Windows Update settings UI. * **Set EDU restart** Allows the device to automatically restart outside active hours to finish updates. Intended for Education (EDU) scenarios. * **Allow update service** When using an intranet update service, this controls whether the device can still use Microsoft Update, WSUS, or Microsoft Store. Disabling can break Store and other public services. * **Detection frequency** How many hours Windows waits before checking for updates, plus a 0–4 hour random offset. Only applies when using a WSUS server. Range: 1–22 hours. * **Do not enforce enterprise TLS cert pinning for update detection** When enabled, the Windows Update client does not enforce TLS certificate pinning for update detection. Microsoft recommends keeping TLS pinning enabled for WSUS environments. * **Fill empty content URLs** Lets Windows Update Agent determine download URLs when metadata does not include them. Use when working with an alternate download server or ISV cache that does not populate all content URLs. * **Set policy driven update source for driver updates** Chooses whether driver updates come from Windows Update or your WSUS server. Requires **Update service URL** to be set. * **Set policy driven update source for feature updates** Chooses whether feature updates come from Windows Update or your WSUS server. Requires **Update service URL** to be set. * **Set policy driven update source for other updates** Chooses whether other updates come from Windows Update or your WSUS server. Requires **Update service URL** to be set. * **Set policy driven update source for quality updates** Chooses whether quality updates come from Windows Update or your WSUS server. Requires **Update service URL** to be set. * **Set proxy behavior for update detection** Allows using the user proxy as a fallback when detecting updates with an HTTP WSUS server. Using the user proxy can reduce security; prefer system proxy when possible. * **Update service URL** URL of your WSUS server so devices check for updates there instead of Microsoft Update (for example, `https://server:8531` or `http://server:8530`). Per-type update source settings require this field to be configured before they take effect. * **Update service URL alternate** Alternate intranet server for update detection, download, or statistics reporting. Use this to specify a secondary download server or redirect reporting traffic separately from the main WSUS server. ## Considerations When settings are left as "Not configured," they do not override the local device configuration. This is how Not configured interacts with existing device config. When you disable access to the Windows Update UI (**Set disable UX WU access**), users cannot manually check for updates. Ensure your update policies apply to all relevant devices before you enable this. Set active hours to match your organization's work schedule so restarts do not disrupt users during the day. For per-type source settings (feature, quality, driver, other), **Update service URL** must be configured before they take effect. Disabling **Allow update service** can break Microsoft Store and other public Microsoft services. Verify those services remain accessible before disabling. **Detection frequency** only applies when a WSUS server is in use; it has no effect in cloud-only Windows Update configurations. When using **Set proxy behavior for update detection**, enabling the user proxy fallback reduces security. Prefer system proxy unless your environment requires otherwise. For update detection, enabling **Do not enforce enterprise TLS cert pinning for update detection** turns off TLS pinning and reduces the security of update scanning. Disabling pinning has security impact. Enable only if required by your WSUS infrastructure. ## Best Practices The main settings have Iru-recommended defaults. Start with those, then adjust for your organization. Set **Active hours start** and **Active hours end** to match your users' workday so restarts do not occur during work hours. Set **Set disable pause UX access** to **Remove the pause option from the device UI** so users cannot stall updates from the Windows Update UI. Test your configuration on a small group of devices before rolling out to the full fleet. A pilot group helps you catch unexpected restart behavior. ## Troubleshooting When updates are not installing on schedule, check the schedule, active hours, and **Allow auto update**. **Possible causes:** * Allow auto update is not set to the intended option * Scheduled install time or day misconfigured * Active hours configured too broadly (for example, close to the maximum allowed range) **Solutions:** * Verify that Allow auto update is set to your intended option * Check that the scheduled install time and day are configured correctly * Ensure active hours are configured to a realistic workday window and respect the **Active hours max range** setting **Possible causes:** * **Set disable pause UX access** is not enabled or is set to allow pausing **Solutions:** * Set **Set disable pause UX access** to **Remove the pause option from the device UI** Restarts during business hours often relate to active hours and time zone. **Possible causes:** * Active hours start and end do not cover the full workday * Incorrect time zone or configuration **Solutions:** * Review your **Active hours start** and **Active hours end** settings * Make sure the range covers the full workday for your users **Possible causes:** * **Manage preview builds** is set to allow preview builds or left to user selection **Solutions:** * Set **Manage preview builds** to **Disable Preview builds** to prevent devices from receiving Windows Insider builds When devices do not receive updates from the WSUS server, verify the following. Common causes include **Update service URL** and reachability. **Possible causes:** * **Update service URL** not configured or not reachable from devices **Solutions:** * Verify that **Update service URL** is configured and reachable from your devices. Per-type source settings will not take effect without a valid Update service URL. When Microsoft Store or other public Microsoft services are broken or inaccessible, check the following. **Possible causes:** * **Allow update service** is disabled **Solutions:** * Check whether **Allow update service** is disabled. Disabling it can block access to Microsoft Store and other public Microsoft services. When updates are not detected on the expected schedule, review the following. This often involves **Detection frequency** and the random offset. **Possible causes:** * **Detection frequency** misconfigured or not accounting for random offset **Solutions:** * Review **Detection frequency**. Windows adds a 0–4 hour random offset to the configured interval. If detection frequency is not configured, the CSP default is 22 hours. When update scanning fails with TLS errors (for example, with WSUS), check the following. Common causes include WSUS certificate and TLS pinning. **Possible causes:** * WSUS server certificate conflicts with TLS pinning **Solutions:** * If your WSUS server uses a certificate that conflicts with TLS pinning, enable **Do not enforce enterprise TLS cert pinning for update detection** after confirming the certificate configuration on the WSUS server. When download URLs are missing or broken (for example, with an alternate download server or ISV cache), try the following. **Possible causes:** * Alternate download server or ISV cache not populating content URLs in metadata **Solutions:** * If you use an alternate download server or ISV cache, enable **Fill empty content URLs** so Windows Update Agent can resolve download paths when they are absent from update metadata. ## Related Articles Curate, create, and manage Library Items and add them to Blueprints Configure Microsoft Defender antivirus and threat protection on Windows Configure and enforce firewall settings for Windows devices Configure BitLocker encryption on Windows devices Set up Windows device enrollment Configure managed OS updates for Mac computers # Create a PPPC Library Item Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/create-a-privacy-preferences-policy-control-pppc-library-item Create a new PPPC profile in Iru Endpoint to pre-approve app access to camera, microphone, screen recording, and other macOS privacy-protected resources. This Library Item is available for Mac computers ### What is PPPC? Privacy Preferences Policy Control (PPPC) in macOS helps administrators manage app permissions and protect user data. Using a PPPC profile, you can pre-approve apps' access to system services like the camera, microphone, and file systems, eliminating the need for manual user approval and simplifying your deployment process. ### How PPPC and TCC Controls Work Due to Apple's privacy requirements, Camera, Microphone, and Screen Recording access will always require user interaction to approve. Apple's PPPC payload allows you to configure Transparency, Consent, and Control (TCC) settings, which are crucial for safeguarding user information. PPPC profiles let you pre-approve or deny app access to system services like the camera, microphone, and file systems. You create these profiles using XML files that specify each app's permissions, bundle IDs, and code requirements. Once created, you deploy these profiles via MDM to apply the settings to enrolled macOS devices. For more information about PPPC payloads and their capabilities, see [Apple's Privacy Preferences Policy Control documentation](https://support.apple.com/en-gb/guide/deployment/dep38df53c2a/web). ### Considerations Once you've configured permissions through a PPPC profile, they're managed by the system and won't show up in System Settings. Users can't change these settings on their own, and there's no way to bypass macOS's PPPC protections. ### Determining Which Apps Need a Privacy Profile To determine if your app needs additional privacy permissions, follow these steps: Install your app on a test device or a macOS virtual machine. Launch the app and pay attention to any UI dialogues that appear, such as those requesting access to accessibility features or the Downloads folder. Navigate to System Settings and click on **Privacy & Security**. Select an option on the right-hand side, like **Accessibility**. If your app is listed here, it indicates that the app requires this PPPC permission. Right-click on the app listed and select **Show in Finder**. Finder will launch with the app in question selected. You can drag and drop the application into Terminal to get its full path, which will be used in the next step. ### Determine the Identifier and Code Requirement To create a PPPC profile, you need to know the application's code requirement and identifier. This information can easily be collected using Terminal on a Mac with the application installed. Launch Terminal on a macOS device on which the application is installed. Run the following command, replacing `/Applications/zoom.us.app` with the path to your application: ```bash theme={null} codesign -dr - "/Applications/zoom.us.app" ``` When the output results appear, copy all text after the **=>** characters; do not copy any trailing or leading spaces. This output is the **Code Requirement**. The portion between the quotes, e.g. "us.zoom.xos", is the **Identifier**. ### Configuring a Privacy Profile using Iru Privacy settings deployed via MDM will not appear in the graphical user interface in System Settings. With your application information collected, you can create a Privacy profile in the Iru Web App. Follow the steps in [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library) to create a Privacy Library Item. Select your desired Blueprints. If your output includes an identifier in the first part of the code requirement, leave the Identifier type set to **Bundle ID**; otherwise, select **Path**. Paste in the **identifier** found in the first part of the code requirement. If you selected **Path** above, input the path for the profile. Paste in the full code requirement that you copied from Terminal. Ensure that there are no leading or trailing spaces in the code requirement; unnecessary characters can prevent the profile from deploying. Optionally, check the **Statically validate the code requirement** box. This option is used only if the process invalidates its dynamic code signature. Select an option from the **App or Service** dropdown. This selection depends on the application's requirements. For more information, refer to the Determine Which Apps Need a Privacy Profile section of this guide. If needed, you can add additional app access to a PPPC profile by clicking **Add app access**. Click **Save** in the bottom right corner. ### Verifying Your PPPC Profile To verify that your PPPC profile is working correctly: Open **System Information** on the target Mac computer. Select **Profiles** from the left-hand column. Locate your profile containing the PPPC payload. Click the disclosure triangle next to the profile name. Look for the `com.apple.TCC.configuration-profile-policy` entry. This confirms that the profile is actively managing TCC permissions on the device. ### Troubleshooting Double-check that the code requirement was copied correctly with no leading or trailing spaces. Re-run the `codesign -dr -` command to verify the code requirement matches what's in your profile. Verify you selected the correct identifier type (Bundle ID or Path) and that the identifier matches exactly what was returned from the codesign command. Confirm the application is included in the approved applications list in your PPPC profile. Verify the correct service permissions are configured for the application. For example, if an app needs screen recording access, ensure "Screen Recording" is selected in the App or Service dropdown. If you're still seeing permission prompts, use this command in Terminal to identify which app or binary is requesting access: ```bash theme={null} log stream --debug --predicate 'subsystem == "com.apple.TCC" AND eventMessage BEGINSWITH "AttributionChain"' ``` This shows real-time TCC permission requests and can help identify the exact app or binary that needs to be added to your PPPC profile. In System Settings > Privacy & Security, sliders for certain permissions may appear grayed out even when the app has the necessary permissions. This is a visual quirk and doesn't necessarily indicate a problem. Test the application's functionality to confirm it's working properly. Confirm the PPPC profile is installed and active on the device by checking System Information > Profiles. Ensure the code requirement doesn't have any leading or trailing spaces. Even a single space can prevent the profile from working correctly. If an app was updated, the code requirement may have changed. Re-run the codesign command to get the updated code requirement and update your PPPC profile accordingly. If you're using the "Statically validate the code requirement" option, ensure it's only enabled when the process invalidates its dynamic code signature. Most apps don't need this option enabled. # Custom Apps Overview Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/custom-apps-overview Overview of custom apps in Iru Endpoint for Mac and Windows. Learn about supported package formats, install scripts, deployment options, and versioning. Custom App Library Items are available for Mac computers and Windows devices Iru Endpoint lets you upload and deploy custom applications to your enrolled devices. Use the **Mac Custom App** Library Item for Mac computers or the **Windows Custom App** Library Item for Windows devices. Both let you choose whether to install once per device or continuously enforce the app, and both support a maximum upload size of **5 GB**. ### What Are Custom Apps? Custom Apps are installer-based Library Items that you upload and configure in the Library. You assign them to Blueprints to deploy to Mac or Windows devices. Options include install once per device, continuous enforcement, or (on Mac) offering the app in Self Service. ### By Platform Select your platform below for installer types, configuration options, and step-by-step guidance. The **Mac Custom App** Library Item lets you deploy custom applications (PKG, DMG, ZIP) to Mac computers. Upload installers, configure audit and install options (including pre- and post-install scripts), and assign the Library Item to Blueprints. You can offer apps via Self Service or enforce them automatically at check-in. The sections below cover supported installer types, execution options, scripts, Self Service, and troubleshooting. ### Installers Iru Endpoint supports several different installer types for Mac: * **.PKG**: Iru Endpoint supports compressed PKG and MPKG files. * **.ZIP**: With ZIP files, you can specify where the contents should be decompressed. * **.DMG**: DMG files are extracted to the /Applications folder. If your DMG contains a PKG, extract the PKG first and upload that instead. Iru Endpoint's maximum file upload size is 5 GB. ### Installation Options #### Execution Frequency Depending on the app you want to deploy, you can specify whether Iru Endpoint should install it once or continuously monitor and ensure it's installed. * **Install once per device**: Iru Endpoint installs the Custom App once. If the app is removed from the Mac, it won't be reinstalled automatically. Use this for software patches that shouldn't run continuously. * If a pre-install script fails, the Iru Agent won't attempt to install the Custom App, and it will run this Custom App Library Item again on the next check-in. * If a post-install script fails, the Iru Agent will run this Custom App Library Item again on the next check-in, regardless of whether the Custom App was successfully installed. * **Audit and enforce**: Iru Endpoint runs the audit script and ensures it passes (exits 0) at each check-in, including before the first install. If the audit script exits anything other than 0, Iru Endpoint reinstalls the application automatically. * **Install on demand from Self Service**: The item is only offered as an optional install from Self Service. After execution, the **Install** button becomes **Reinstall**. #### Audit Script Considerations Audit scripts give you control over what qualifies as a pass. Does the app need to be in a specific location? Have a particular checksum? Be on a certain version? You can check all of these with an audit script. Example: This audit script checks for the presence of an app; if it's not present, the script prompts Iru to reinstall it. ```bash audit-app-presence.sh icon="terminal" lines theme={null} #!/bin/bash APPPATH="/Applications/zoom.us.app" if [ -e "$APPPATH" ]; then exit 0 else exit 1 fi ``` To enforce a specific version of an installed app, use the [Minimum Enforced Version script](https://github.com/kandji-inc/support/blob/main/Scripts/audit-enforce-scripts/minimum_enforced_version.zsh) available on our [Iru Support GitHub](https://github.com/kandji-inc/support/). #### Pre- and Post-Install Scripts Pre- and post-install scripts let you customize the install process for Custom Apps. Use a pre-install script to remove another app that's being replaced. A post-install script can configure the Custom App that was just installed. #### Self Service Considerations There are important considerations when using Custom Apps with Self Service. * When a Custom App's enforcement option is set to **Install and continuously enforce** or **Install once per device**, you can still show this item in Self Service. This is useful if users need to reinstall the software. * When a Custom App's **Enforcement** option is set to **Install on demand from Self Service**, the app won't be installed until the user installs it from Self Service. * When installing via Self Service, the latest version of the app is installed. * Iru Endpoint automatically takes over management of non-App Store licensed apps if set to **Install on demand from Self Service** (as long as the bundle ID matches the Apps and Books version). Your global or per-app update settings are respected. #### Restart Some applications require a reboot after installation to operate correctly. Iru Endpoint can trigger the restart to ensure proper functionality. Check the **Restart after successful install** box to have Iru Endpoint restart the computer after the Custom App is installed. Users will be given a 30-minute countdown before the restart occurs. #### Liftoff Settings At the bottom of the Library Item, under **Advanced Settings** > **Liftoff Settings**, customize how this Library Item behaves when used with [Iru Liftoff](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item): * **Hide in Liftoff**: If selected, this Library Item still processes during Liftoff but is not shown to the end user. While it processes, Liftoff shows **Processing additional required configurations before proceeding…** at the bottom of the screen. This setting does not affect ordering. * **Friendly name** (optional): If specified, Liftoff shows this name instead of the Library Item **Name**. The Iru Agent still orders Library Items by **Name** during check-in. #### Status The status tab in a Custom App Library Item shows which Mac devices are waiting for the app to be installed, which ones have successful installations, and which ones are in **Error** status after installation problems. **Error** status generates an alert; see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. ### Step-by-Step Instructions For step-by-step instructions, see [Configure the Mac Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-custom-apps-library-item). ### Troubleshooting If the zip file contains a package and you see a Gatekeeper notification warning on a Mac during the custom app install process, run this command from a Terminal session on the package to clear the quarantine bit before zipping and uploading the install file to Iru. ```bash clear-quarantine.sh icon="terminal" theme={null} xattr -dr com.apple.quarantine "/path/to/package.pkg" ``` The **Windows Custom App** Library Item lets you deploy and manage Windows applications (MSI, EXE) on Windows devices. Upload a zipped installer, configure install and uninstall commands, define detection logic, and assign the Library Item to Blueprints. The zipped installer can contain single files or directories of files. Enforcement begins within 15 minutes for online devices. All installers run in System context. The sections below cover installers, enforcement and detection settings, commands, architecture, security, and troubleshooting. For what end users see when pending **Auto App** or **Windows Custom App** updates are available, including the Iru system tray **Updates** list and [when a running app must close first](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#when-an-app-must-close), see [User Experience with Windows Apps](/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps#app-updates-in-the-iru-system-tray). ### Installers Upload a **.zip** file containing the installer (MSI or EXE) and any supporting files or folders. The installer is downloaded to the device and expanded locally before the install command runs, so the install does not depend on network availability at execution time. Uploads are resumable; if a network interruption occurs, the upload picks up where it left off. Iru Endpoint's maximum file upload size is 5 GB. ### Installation Options Controls how Iru enforces the app on targeted devices. * **Install once per device**: Iru installs the app on devices that do not already have it. Once installed, Iru does not reinstall the app if a user removes it manually. * **Install and continuously enforce** (default): Iru installs the app and reinstalls it if it is removed or detected as absent at subsequent check-ins. ### Enforcement Timeframe Controls whether this version of the app is enforced immediately or after a grace period. Set **Enforcement deadline** to one of the following: * **Immediately** (default): The app is enforced as soon as possible after assignment. New installations begin within 15 minutes for online devices. * **By enforcement deadline**: The app will try to install by the enforcement deadline if the app is not open. At the deadline, installation becomes required on devices that have not yet installed it. When **By enforcement deadline** is selected, two additional fields appear: * **Enforcement after version is saved**: How long after the Library Item is saved before enforcement begins. Default: **2 weeks**. * **Enforcement deadline time**: The time of day when enforcement takes effect on the deadline date. Default: **12:00 PM (Noon)**. ### Application Details * **Publisher**: The organization or individual that produced the application. * **Name**: The display name for the application. Shown in the Library and in device status views. * **Version**: A version string for this release of the app. Free-form text; not validated against semantic versioning. * **App icon**: Upload a `.png` image to represent the app in the Library. Drag the file into the upload area or select **choose file**. * **Upload app**: Upload a `.zip` file containing the installer and any supporting files or folders. Drag the file into the upload area or select **choose file**. * The zip must contain the installer (MSI, EXE) along with any files your install command references. * Structure the zip so that relative paths in your install command resolve correctly once the contents are expanded on the device. ### Detection Logic Detection logic tells Iru whether the application is present on a device. At least one detection method is required. Iru runs detection when the agent checks in to determine whether the app needs to be installed or is already present. Select a detection type from the **Detection logic rules** dropdown. Options appear top to bottom as **MSI**, **File**, **Folder**, then **Registry**. #### MSI Detects whether a specific MSI package is installed by its Product Code. * **MSI product code**: The package Product Code as a braced GUID, `{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}`. The Web App validates the format. Find the code from MSI properties or documentation for the product. * **Check MSI product version**: When **No**, only the Product Code is evaluated. When **Yes**, also compare the installed product version using an operator **equals** or **is greater than or equal to** and the version string you enter. #### File Detects using a file at a path you specify. * **Path to file**: Full path to the file, including the file name (for example, `C:\Program Files\YourApp\YourApp.exe`). * **Detection method**: Choose how the file is evaluated: * **File exists**: Passes if the file is found at the specified path. * **File does not exist**: Passes if the file is not found. Use for uninstall detection. * **Version**: Passes if the file's version meets the comparison. Set the operator to **equals** or **is greater than or equal to**, then enter the version string. * **Size in MB**: Passes if the file size in megabytes meets the comparison. Set the operator to **equals** or **is greater than or equal to**, then enter the size. #### Folder Detects using a folder at a path you specify. * **Path to folder**: Full directory path where the folder is expected (for example, `C:\Program Files\YourApp`). * **Detection method**: * **Folder exists**: Passes if the folder is found at the specified path. * **Folder does not exist**: Passes if the folder is not found. #### Registry Detects the app based on a registry key or value. * **Key path**: Required. Full registry path to check (for example, `HKLM\SOFTWARE\YourApp`). Paths are not case-sensitive. * **Value**: Optional registry value name within the key. * **Detection method**: * **Key exists**: Passes if the key exists. If you supplied a **Value**, the value must exist under that key. * **String comparison**: Passes if the value at the key matches the string you supply. ### Executables for Open App Detection * Enter one executable name per field (for example, `yourapp.exe`). Iru checks these processes when install or uninstall runs so users can be prompted to close them. * Use **Add** for more rows and remove rows with the delete control when needed. * Up to 100 executables can be entered. ### Commands The Web App labels these **Install command line parameters** and **Uninstall command line parameters**. Enter silent install and silent uninstall command lines. **Install command** The full command line used to install the application silently. For MSI packages, a standard silent install looks like: ```powershell icon="terminal" theme={null} msiexec /i yourapp.msi /qn ``` If your installer includes supporting files or folders inside the zip, reference them using relative paths. For example: ```powershell icon="terminal" theme={null} msiexec /i lance.msi TRANSFORMS=".\mytransforms\transform.mst" /qn ``` You can run a PowerShell script from inside the zip instead of calling msiexec directly. The script must run the installer silently. ```powershell icon="terminal" theme={null} .\installapp.ps1 ``` **Uninstall command** The full command line used to remove the application. For MSI packages: ```powershell icon="terminal" theme={null} msiexec /x {ProductCode} /qn ``` If the path to the installer, uninstaller, or script in your install or uninstall command contains spaces, enclose that path in double quotes (for example, `"my installer.exe"`). ### Architecture In **Architecture**, choose **x64** or **arm64** for the installer. When MSI metadata is available, Iru attempts to auto-detect the correct value. Confirm or override the selection before saving. ### Enforcement Behavior * Enforcement begins within **15 minutes** of assignment for online devices. For new installs, this means the download process starts within that window; installation time depends on file size and device performance. * If an install or uninstall fails, Iru retries every 15 minutes. * The installer is not re-downloaded on retry unless the file on the server has changed. * Removing the Library Item or removing the Blueprint assignment does **not** uninstall the app from devices. The app remains on the device; enforcement simply stops. When install or uninstall failures generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. ### Security * **Hash verification**: Iru verifies the SHA-256 hash of the installer before executing the install command. If the hash does not match, installation fails immediately. * **Encrypted delivery**: Installer files are delivered over HTTPS. Only devices that are targeted by the Library Item can download the installer. ### Considerations * Removing a Library Item or removing a Blueprint assignment does not uninstall the app. Apps remain on the device and are no longer enforced. * The installer zip is expanded on the device before execution. Make sure relative paths in your install command match the folder structure inside your zip. * If multiple apps are targeted to a device simultaneously, enforcement is queued. The 15-minute SLO applies to the first app in the queue beginning to download. ### Best Practices For MSI-based installers, Product Code identifies the installed package regardless of install path. Run your install and uninstall commands manually on a test device before uploading to Iru. Silent flags that work on one installer type may not work on another; validate before deploying to the fleet. If your install command references supporting files using relative paths, make sure the zip folder structure matches those paths exactly. A mismatch causes the install to fail. Assign the Library Item to a small Blueprint containing test devices before expanding to your full fleet. Verify installation, detection, and reporting all behave as expected. Overly broad detection rules (for example, checking for a folder that multiple apps share) can lead to false positives. Use the most specific method available for detection. ### Step-by-Step Instructions For step-by-step instructions, see [Configure the Windows Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-windows-custom-app-library-item). ### Troubleshooting **Possible causes:** * Library Item not assigned to the device's Blueprint * Target devices have not checked in recently **Solutions:** * Verify the Library Item is assigned to the correct Blueprint and that the target devices have checked in within the last 15 minutes * Check the per-device status view for exit codes or error messages Review the exit code in the per-device status view. Common MSI exit codes include: * **1603**: Generic failure, often caused by the app already running, insufficient disk space, or a permissions issue. * **1618**: Another installation is already in progress. The agent will retry. * **1638**: A newer version of the app is already installed. Review your detection logic and upgrade path. **Possible causes:** * Detection rule does not match the actual installed state * Incorrect Product Code, path, or registry value **Solutions:** * For MSI packages, verify the Product Code is correct * For file or registry detection, confirm the path and value exactly as they appear after installation ### Related Articles Step-by-step setup for Mac Custom Apps (PKG, DMG, ZIP) Step-by-step setup for Windows Custom Apps (MSI, EXE) Curate, create, and manage Library Items and add them to Blueprints Configure Library Items for Self Service (macOS) Configure how Iru Endpoint surfaces alerts when Custom Apps or other Library Items report issues # Custom Printers Overview Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/custom-printers-overview Deploy custom printer configurations to Mac computers using Iru Endpoint. Add network printers, set default options, and manage driver installation. Custom Printers are available for Mac computers ### Getting Started Before you create your Custom Printer library item, you'll need two things: The driver installer package associated with that printer. The file path to the PPD (PostScript Printer Description) file installed by the package. Typically the correct PPD can be identified by the model name appearing in the filename. After you've collected these two things, you'll then need to gather the following information: * The display name of the printer (for example, Marketing Printer) * The CUPS (Common Unix Printing System) name of the printer (for example, marketing\_printer) * The location description (for example, 2nd Floor) * The printer URI (for example, lpd://192.168.0.43/queue\_name or ipp\://hostname.local/queue\_name) ### Creating a Custom Printer Library Item #### Add a Custom Printer Item: To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. #### Configure the Custom Printer Item: Give your Custom Printer a name and optionally upload a custom icon for it. Assign your Custom Printer to a [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Choose an option from the Installation pop-up menu: * **Install printer once per device**: This installation option will install the printer and associated driver once per device. Flushing the item status for a device will trigger a reinstall. * **Install printer and continuously enforce**: This installation option will install the printer and associated driver and continually enforce the installation by checking for the presence of the printer's configuration at every check-in. * **Install on demand from Self Service**: This installation option will install the printer only if the user triggers the install through Self Service. Optionally configure Self Service options. [Learn more about Self Service options](/en/endpoint/settings/self-service/self-service-library-items). In the Display Name field, enter the display name that the user will see within printer preferences. In the Printer Name field, enter the CUPS printer name. You should remove any special characters and replace spaces with underscore characters. Dashes are not allowed in CUPS queue names. In the Location field, enter the location. This will be visible to the user in the location field of their printer preferences. In the Device URI field, enter the device URI. This is usually the print protocol (ipp\:// or lpd:// or dnssd://) followed by the hostname or IP address of the printer. If you are sending print jobs to a print server, you will typically see the queue name appended to the hostname (for example, lpd://print-server.local/queue\_name). Choose a PPD path, use the Apple-provided generic driver, AirPrint, or upload a custom PPD. * When uploading a custom PPD, the PPD file name must match the Printer Name. * You can retrieve a PPD file from a Mac with the printer already configured from the /etc/cups/ppd folder. Optionally choose to provide a printer driver PKG file. This PKG will be installed as part of the printer installation. The installer file must be a PKG. If you do choose the **Install provided software package** option, upload the PKG. Under **Liftoff Settings**, optionally select **Hide in Liftoff** and enter a **Friendly name**. See [Liftoff Settings](#liftoff-settings). Click **Save**. After the Iru Agent installs a custom printer, macOS may take a few minutes to update the printer configuration file. When printer installation or enforcement issues generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. ### Liftoff Settings At the bottom of the Library Item, under **Liftoff Settings**, customize how this Library Item behaves when used with [Iru Liftoff](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item): * **Hide in Liftoff**: If selected, this Library Item still processes during Liftoff but is not shown to the end user. While it processes, Liftoff shows **Processing additional required configurations before proceeding…** at the bottom of the screen. This setting does not affect ordering. * **Friendly name** (optional): If specified, Liftoff shows this name instead of the Library Item **Name**. This is separate from **Display Name**, which appears in printer preferences. The Iru Agent still orders Library Items by **Name** during check-in. ### Related Articles Curate, create, and manage Library Items and add them to Blueprints Create and configure device Blueprints for policy management Configure Library Items for Self Service (macOS) Configure how Iru Endpoint surfaces alerts when Custom Printers or other Library Items report issues # Custom Profiles Overview Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/custom-profiles-overview Deploy custom Apple configuration profiles using Iru Endpoint. Upload mobileconfig files for advanced settings not covered by built-in Library Items. Custom Profiles are available for Apple devices ### What are Custom Profiles? Custom profiles, which end in a .mobileconfig extension, are XML files that contain settings and authorization information for Apple devices. These profiles are based on Apple's Mobile Device Management (MDM) framework and are used to configure and manage device settings securely and wirelessly. When issues with Custom Profiles generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Iru Endpoint supports Custom Profiles deployed to the System Channel. You do not need to sign custom profiles before uploading them to Iru. ### Creating a Custom Profile built with iMazing Profile Editor Download iMazing Profile Editor from the Mac App Store or [their website](https://imazing.com/profile-editor/download). Follow [iMazing's Getting Started Guide](https://imazing.com/guides/getting-started-with-imazing-profile-editor) to add your desired configuration payloads and compose them as desired. Ensure that your profile contains a name and identifier configured in the General payload and at least one other system domain configured. Save your configuration profile as a .mobileconfig file, and upload it to Iru in a Custom Profile Library Item. ### Creating a Custom Profile from a GitHub Repository Navigate to the file you wish to use in your desired GitHub repository. Click on the **Download raw file** button in the upper-right corner. Right-click on your newly downloaded .mobileconfig file, and select **Open with...** Select to open with a text editor of your choice, such as BBEdit or Visual Studio Code. Make any required changes to the XML and save your changes. Upload the .mobileconfig file into your Custom Profile Library Item. ### Related Articles Curate, create, and manage Library Items and add them to Blueprints Create and configure device Blueprints for policy management Configure how Iru Endpoint surfaces alerts when Custom Profiles or other Library Items report issues # Custom Scripts Overview Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/custom-scripts-overview Deploy custom scripts to managed Mac and Windows devices using Iru Endpoint. Run shell, Python, PowerShell, or batch scripts on enrollment or on schedule. Custom Scripts are available for Mac computers and Windows devices ### What is a Custom Script? Custom scripts in Iru Endpoint automate tasks and configure settings on managed devices. Think of them as a set of instructions that can be deployed and executed on enrolled devices using the Iru Agent. With custom scripts, you can configure device settings, install or update software applications, run maintenance tasks, and enforce security policies. You can also use custom scripts to collect device information, like hardware inventory or system logs. A collection of prebuilt and regularly maintained scripts is available in our [GitHub repository](https://www.github.com/kandji-inc/support/tree/main/Scripts). Iru Endpoint's Custom Script Library Item can deploy scripts in various languages. However, our support team is best equipped to help troubleshoot scripts written in shell, bash, zshell, or Python. Support can also assist with AppleScript, provided it is invoked by one of the supported languages. ### How Custom Scripts Work The Iru Agent runs custom scripts on enrolled Mac computers. Your custom script can specify any shell or interpreter on the Mac computer. If a shell or interpreter is not specified, the default shell (/bin/sh) is used. Custom scripts are always executed as the root user. #### Execution Frequency Depending on the script you want to deploy, you can specify whether it will be run once at every check-in, once per day, or on-demand from Self Service. For **Install once per device**, Iru reruns the audit script at each check-in until the Library Item reaches **Pass** for that device. If a remediation script is enabled and succeeds, the Library Item can show **Remediated**, but Iru still reruns the audit script on later check-ins until it reaches **Pass**. The script will be run at each check-in (\~ every 15 minutes). The script will be run every 24 hours based on the previous run time. The script will never be run automatically and will only be offered as an optional item from Self Service. After executing the item, the **Run** button will be relabelled **Run again**. The Custom Script Library Item can also be offered via Self Service in the first 3 scenarios above. #### Exit Codes and Outputs If the audit script exits with code **0**, that run has **Pass** status. If the audit script exits with any non-zero exit code, that run has **Error** status. When a run has **Error** status, Iru generates an alert. See our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Stdout and Stderr are recorded in the script's audit information, which can be found on the device status page or custom script status page. #### Remediation A remediation script allows the main **Audit Script** to be used as a true audit script to check for system configuration or application state. If the audit script exits with any non-zero exit code, that run has **Error** status; Iru then runs the remediation script. If the remediation script exits with code **0**, the Library Item status for that device is **Remediated**. If the remediation script exits with a non-zero exit code, the Library Item status for that device is **Error**, and Iru generates an alert. See our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. #### Restart Options The restart option allows you to force a restart after a successful script execution. When selecting this option, the user will receive a restart timer from the Iru Agent menu bar application. This timer will be a 5-minute restart timer if the item was initiated from Self Service or a 30-minute restart timer if initiated in another way such as during a check-in. The restart option will behave differently based on the use of a remediation script: * If a [**Remediation** script](#remediation) is being used, when the **Remediation** script exits 0, this will trigger the restart countdown. * If a **Remediation** script *is not* being used, when the **Audit** script exits 0, this will trigger the restart countdown. #### Liftoff Settings At the bottom of the Library Item, under **Liftoff Settings**, customize how this Library Item behaves when used with [Iru Liftoff](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item): * **Hide in Liftoff**: If selected, this Library Item still processes during Liftoff but is not shown to the end user. While it processes, Liftoff shows **Processing additional required configurations before proceeding…** at the bottom of the screen. This setting does not affect ordering. * **Friendly name** (optional): If specified, Liftoff shows this name instead of the Library Item **Name**. The Iru Agent still orders Library Items by **Name** during check-in. ### Add a Custom Script Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Custom Script Library Item a **Name**. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Select an **Execution Frequency**. Optionally, make the script available in **Self Service**. Paste your script into the **Audit Script** field. Optionally, configure and paste a **Remediation Script**. If desired, check the box to **Restart after a successful execution**. Under **Liftoff Settings**, optionally select **Hide in Liftoff** and enter a **Friendly name**. See [Liftoff Settings](#liftoff-settings). Click **Save**. ### Related Articles Curate, create, and manage Library Items and add them to Blueprints Create and configure device Blueprints for policy management Deploy Homebrew to Mac computers using a custom script Learn how to use global variables in Iru Endpoint to dynamically insert device and user information into profiles, scripts, and configuration settings. Configure how Iru Endpoint surfaces alerts when Custom Scripts or other Library Items report issues ### Windows Custom Script The **Windows custom script** Library Item allows you to run PowerShell scripts on managed Windows devices. You can use this item to audit device state, enforce configuration through remediation, or perform administrative tasks not covered by built-in Windows profiles. Windows custom scripts support an audit and remediation model, enabling detection of non-compliant states and automatically correcting them. ### Create a Windows Custom Scripts Library Item Navigate to **Library**. Select **Add Library Item**. Search for and select **Windows Custom Script**. Enter a descriptive **Name**. Confirm the status is set to **Active**. Assign the Library Item to one or more **Blueprints**. ### Script Details The **Script details** section defines settings for audit and remediation scripts. #### Audit Script The **Audit script** determines whether the device is in the desired state. You can provide the audit script using one of the following options: * **Upload signed script** * Upload a signed PowerShell `.ps1` file. * **Manually enter script** * Paste or edit PowerShell code directly into the editor. The audit script should exit with a non-zero exit code when the device is not compliant. A zero exit code indicates compliance. #### Command Line Parameters (Optional) The **Command line parameters** field allows you to pass arguments to the audit and remediation scripts at runtime. * Use standard PowerShell parameter syntax. * Parameters are appended when the script executes. Example: `-Mode Full -ConfigPath "C:\Config.json"` This is useful for making scripts reusable without hardcoding values. #### Remediation Script (Optional) Select **Add remediation script** to configure a remediation action. * The remediation script runs only when the audit script reports non-compliance. * You can upload a signed script or manually enter remediation logic. * Use remediation scripts to correct configuration drift or enforce settings. The remediation script should exit successfully after the issue is resolved. #### Execute In Use **Execute in** to select the PowerShell environment used to run the scripts: * **64 bit** * **32 bit** **64 bit** runs the script in the standard 64-bit PowerShell environment and is recommended for most Windows devices. Use 32 bit only if the script or its dependencies require WOW64 compatibility. ### Assignment and Execution After saving the Library Item: 1. Click **Save**. 2. Assign it to one or more **Blueprints** using **+ Assign**. Scripts will execute once per device. ### Best Practices * Sign PowerShell scripts before uploading whenever possible. * Separate detection logic (audit) from enforcement logic (remediation). * Test scripts on non-production devices before wide deployment. ### Related Articles Official PowerShell docs from Microsoft PowerShell exception handling Configure how Iru Endpoint surfaces alerts when Windows Custom Scripts or other Library Items report issues # FileVault User Experience Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/filevault-user-experience See what users experience when FileVault is enabled on their Mac. Understand the encryption prompt, recovery key escrow, and restart behavior during setup. This article covers the user experience on Mac computers FileVault is an encryption tool Apple offers for Mac computers that ensures all your data is private and secure. This article will help you understand what prompts related to FileVault you might see on your device. ### FileVault Key Regeneration Any Mac that enrolls into Iru that previously had FileVault enabled will automatically prompt you to regenerate your FileVault Key so it can be escrowed. FileVault key regeneration prompt on Mac during enrollment ### Authenticate You will be prompted to authenticate with your FileVault Credentials, as shown below. Authentication and user interaction are required due to how FileVault works. FileVault authentication prompt asking for credentials The list of usernames is automatically populated with all FileVault Enabled users. If the currently logged-in user is FileVault enabled, that username is chosen by default. Otherwise, the next available FileVault user is selected. If no FileVault-enabled username is entered, an error will be displayed. Please reach out to your administrator for assistance if you receive an error. **Key Regeneration**: Once you have successfully authenticated, the FileVault Key will be regenerated and may display the key depending on your administrator's settings, as shown below. FileVault recovery key displayed after successful regeneration **Accessibility View**: If your admin has chosen to display the FileVault recovery key as part of the regeneration process, you can click on the Recovery Key to display it in a large accessible format. # Global Variables Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/global-variables Use global variables in Iru Endpoint custom scripts and profiles to dynamically insert device-specific values like serial number, user email, and hostname. Global variables work for all device types ### What are Global Variables? Global variables (or environment variables) are dynamic values that influence how processes and applications behave. These variables store essential information like system paths, user details, and configuration settings, which can be accessed and used by various programs and scripts. Iru's global variables feature lets you automatically input unique device details into most profile text fields within profiles, including [Custom Profiles](/en/endpoint/library/library-items-profiles/custom-profiles-overview) and other Library Items, or [App Config](/en/endpoint/library/library-items-profiles/using-appconfig). ### How to Use Global Variables in Iru Endpoint Global variables can be used inside most text fields within Profiles (Custom Profiles or Library Items) and the **Provision Local Administrator Account** section's Full Name and Short Name fields in the [Automated Device Enrollment Library](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) item. Global variables work for all device types. Variables can also be used multiple times in the same field. If a device variable that is used on a profile is updated, that profile will be re-installed on the device with the updated variable. For use in custom scripts, we have examples of a [Custom Profile](https://github.com/kandji-inc/support/blob/main/Global%20Variables/Global%20Variables.mobileconfig) that populates those values locally, and a [Custom Script](https://github.com/kandji-inc/support/blob/main/Global%20Variables/GlobalVariablesExample.sh) which reads those values back into the web app on our [GitHub repo](https://github.com/kandji-inc/support). Ensure that you do not use the Zsh shell when referencing these variables in scripts as some variables will not render correctly. ### Available Global Variables | Variable | Description | | ------------------- | -------------------------------------------------------------------------------------------------- | | `$SERIAL_NUMBER` | Inserts the **Serial Number** of the device the profile installs on. | | `$DEVICE_NAME` | Inserts the **Device Name** of the device the profile installs on. | | `$ASSET_TAG` | Inserts the **Asset Tag** of the device the profile installs on. | | `$DEVICE_ID` | Inserts the **Device ID** of the device the profile installs on. | | `$UDID` | Inserts the **Unique Device Identifier** of the device the profile installs on. | | `$PROFILE_UUID` | Inserts the **Universally Unique Identifier** of the profile. | | `$EMAIL` | Inserts the **Email Address** of the Assigned User for the device. | | `$FULL_NAME` | Inserts the **Full Name** of the Assigned User for the device. | | `$EMAIL_PREFIX` | Inserts the **Email Prefix** of the Assigned User for the device. (Everything before the @ symbol) | | `$USERNAME` | Inserts the **Username** of the Assigned User in Iru. | | `$USERNAME_PREFIX` | Inserts the **Username Prefix** of the Assigned User in Iru. (Everything before the @ symbol) | | `$DEPARTMENT` | Inserts the **Department** of the Assigned User for the device. | | `$JOB_TITLE` | Inserts the **Job Title** of the user that is defined in the identity provider. | | `$BLUEPRINT_ID` | Inserts the **Blueprint ID** of the Blueprint the device is assigned to. | | `$BLUEPRINT_NAME` | Inserts the **Blueprint Name** of the Blueprint the device is assigned to. | | `$MODEL_NAME` | Inserts the **Model Name** of the device the profile installs on. | | `$MODEL_IDENTIFIER` | Inserts the **Model Identifier** of the device the profile installs on. | | Variable | Description | | ---------------------- | -------------------------------------------------------------------------------- | | `$MEID` | Inserts the **MEID** of the device the profile installs on. | | `$ICCID_SLOT_1` | Inserts the **ICCID for SIM slot 1** of the device the profile installs on. | | `$ICCID_SLOT_2` | Inserts the **ICCID for SIM slot 2** of the device the profile installs on. | | `$IMEI_SLOT_1` | Inserts the **IMEI for SIM slot 1** of the device the profile installs on. | | `$IMEI_SLOT_2` | Inserts the **IMEI for SIM slot 2** of the device the profile installs on. | | `$PHONE_NUMBER_SLOT_1` | Inserts the **Phone Number for SIM slot 1** of the profile. | | `$PHONE_NUMBER_SLOT_2` | Inserts the **Phone Number for SIM slot 2** of the Assigned User for the device. | | Variable | Description | | --------------- | ------------------------------------------------------------------- | | `$MODEL_NUMBER` | Inserts the **Model Number** of the device the profile installs on. | # Legacy System Extensions Alerts Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/legacy-system-extensions-alerts Understand legacy system extension deprecation alerts in Iru Endpoint. Identify affected kernel extensions and plan migration to modern system extensions. This article covers legacy system extensions on Mac computers ### Changes in macOS Catalina Version 10.15.4 Starting with **macOS 10.15.4**, Apple has begun alerting end users if their Mac has a Kernel Extension that uses deprecated KPIs (Kernel Programming Interfaces). Apple has begun referring to deprecated Kernel Extensions as "**Legacy System Extensions**" in certain macOS interfaces and support documentation. An example of this alert can be seen below. ### Prevent this Alert To prevent your users from seeing this notification you'll need to **allow any relevant Kernel Extension** via Iru. Determine the Kernel Extension(s) causing the alerts and gather a list of all the developer names being presented to your end users. Determine the Kernel Extension developer's Team ID (and optionally KEXT bundle ID). The following Iru Endpoint support article will walk you through collecting this information from a Mac receiving the alert, as well as how to create the required KEXT approval profile in Iru. We also highly encourage you to work with any Software Vendors that are impacted by this change and request that they move their Kernel Extension to a System Extension equivalent. ### What is a Kernel Extension? Essentially, KEXTs (Kernel Extensions) are bundles of code that let developers extend the capabilities of the kernel. These Kernel Extensions use Programming Interfaces, known as KPIs (Kernel Programming Interfaces). Because the kernel is in charge of everything on the system, and because all KEXTs are given kernel privileges, these extensions are very powerful. Due to this high level of privilege, these extensions can cause what is known as "Kernel Panics"; errors that occur in the macOS Kernel that are unrecoverable and require a system reboot. ### What is a System Extension? Like KEXTs, System Extensions extend the functionality of the operating system. However, unlike KEXTs, System Extensions run in userland (Userspace), outside of the Kernel, thus free from many of the restrictions developers had to face while coding in the Kernel (many of which we'll discuss in the next section). This significant departure from KEXT development dramatically improves the reliability of macOS and nearly eliminates the chance of an unrecoverable error. System Extensions introduced in macOS Catalina replace certain types of Kernel Extensions and KPIs. Kernel Extensions that use one or more of the following KPIs that have System Extension equivalents will cause the aforementioned alert. | **KPI** | **System Extension Replacement** | | ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | KAUTH | [EndpointSecurity](https://developer.apple.com/documentation/endpointsecurity) | | Network Filter | [NetworkExtension](https://developer.apple.com/documentation/networkextension) | | IOHIDFamily | [HIDDriverKit](https://developer.apple.com/documentation/hiddriverkit) | | IOUSBFamily | [USBDriverKit](https://developer.apple.com/documentation/usbdriverkit) | | USB Networking | [NetworkingDriverKit](https://developer.apple.com/documentation/networkingdriverkit) | | USB Serial | [USBSerialDriverKit](https://developer.apple.com/documentation/serialdriverkit) | | USB Vendor Specific IPC | [USBDriverKit](https://developer.apple.com/documentation/usbdriverkit) / [IOUSBHost](https://developer.apple.com/documentation/iousbhost) / [DriverKit](https://developer.apple.com/documentation/driverkit) | **About Legacy System Extensions** [https://support.apple.com/en-us/HT210999](https://support.apple.com/en-us/HT210999) **Additional information on deprecated Kernel Extensions** [https://developer.apple.com/support/kernel-extensions/](https://developer.apple.com/support/kernel-extensions/) **Additional information on System Extensions** [https://developer.apple.com/system-extensions/](https://developer.apple.com/system-extensions/) # Library Item Status Activity Timeline Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/library-item-status-activity-timeline View the status and activity timeline of deployed Library Items in Iru Endpoint. Track installation progress, errors, and version history per device. Library Item status monitoring works for all device types ### Status Indicators The following visual indicators can be found throughout the Iru Web App: * A **green** icon indicates success for that Library Item on the device * A **red** icon indicates **Error** status for that Library Item run on the device. **Error** status generates an alert in Iru Endpoint; see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details * A **grey** icon indicates that the status is pending the next check-in * A **blue** icon indicates a remediation has occurred (**Remediated**). This transient status should turn green upon the next Agent check-in To review the status of individual Library Items, navigate to **Library** in the left-hand navigation bar. A preview of the statuses of each Library Item and the number of devices in each status will appear underneath each Library Item tile. ### Status Details and Activity Timeline You can view additional details about the status of each Library Item, including their Last Audit, Last Install, and associated errors. For Mac Auto Apps with [phased rollout](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#phased-rollout) enabled, the **Status** tab also shows when each device becomes eligible for an updated version. Select the **Status** tab. The status will be indicated in the right-hand column. Click the disclosure triangle to expand a detailed view of a specific device's last install status. From this view, you can also [flush the installation attempt](/en/endpoint/library/library-items-profiles/using-the-flush-action). #### Additional Details for Profile-Based Library Items Profile-based Library Items include additional details that can be helpful for auditing and troubleshooting. * **ProfileUUID** - A string that corresponds to the unique Iru Library Item identifier * **PayloadIdentifier** - A string that corresponds to the reverse-DNS style identifier used in the installed profile payload * **PayloadUUID** - A string that corresponds to the globally unique identifier used in the installed profile payload ### Related Articles Configure how Iru Endpoint surfaces alerts when Library Items report **Error** status Clear a failed install and retry after you resolve the underlying issue Curate, create, and manage Library Items and add them to Blueprints # Library Overview Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/library-overview Overview of the Iru Endpoint Library for managing apps, profiles, scripts, and configurations. Curate Library Items and assign them to device Blueprints. The Library works for all device types The Library inside your Iru Endpoint tenant is where you can curate, create, and select items that can be added to any Blueprint. ### Library Interface Overview In the Library, use **Library Sections** in the sidebar to show all Library Items or only items in a section (for example **All**, **Auto Apps**, **App Store apps**, or **Custom scripts**). For a full list of sections and what each one includes, see [Library Sections](#library-sections) at the end of this article. Library with Library Sections sidebar showing All and section names Use the **Search** field to find items by name, type, or label. Library search field for name, type, or label Use the drop-down menus (**Type**, **Device**, **Install status**, **Install type**, **Blueprint**, **State**) to narrow the list. Library toolbar with filter drop-down menus Click the sort control (up and down arrows) and choose how items are ordered: **Library Item name (A-Z)**, **Library Item name (Z-A)**, **Newest Created**, **Oldest Created**, or **Recently Updated**. Library sort menu with name and date ordering options Click the **Sync App Store Apps** icon to pull any recent changes to Apps and Books. Library with Sync App Store Apps control highlighted Click **Add Library Item** at the top right of the Library to add a new Library Item. Library with Add Library Item button ### Library Item Labels A **Label** helps you tell one Library Item apart from another in the Iru Endpoint Web App when you use the same **Auto App**, **App Store App**, or **Managed OS** more than once (for example two copies with different Blueprint assignments or enforcement). Open the Library Item you want to label. To locate it in the Library, use **Library Interface Overview** above or [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library). Click **Edit**. Enter a **Label** for the Library Item. Click **Save**. Library Item edit view showing the Label field and Save button For labels when you add the same **Auto App**, **App Store App**, or **Managed OS** more than once, see [Understanding Auto App Settings for macOS](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos), [Understanding Auto App Settings for Windows](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-windows), [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms), and [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books) for App Store App Library Items. ### Library Item Notes You can add notes to any Library Item to keep your team informed about changes, the intent of a configuration, or other context. Notes are visible to anyone with access to the Library Item in the Iru Endpoint Web App and help maintain consistency when multiple admins manage the same items. Open the Library Item you want to add a note for. Click the **Notes** tab. Click **+ Create note**. Library Item Notes tab with Create note Enter your note in the editor. You can use the formatting options at the top of the prompt as needed. Library Item note editor with formatting toolbar Click **Save** to store the note. To edit an existing note, click the ellipsis next to the note and choose **Edit**. Library Item note menu with Edit selected To delete a note, click the ellipsis next to the note and choose **Delete note**. Library Item note menu with Delete note selected ### Glimpses The Library Item page displays glimpses to the left of the assigned Blueprint information in each Library Item card. Glimpses help provide insight into how you’ve configured the availability and enforcement options for a Library Item. Indicates that the Library Item is set to install and continuously enforce. Indicates that the Library Item is offered in Self Service. Indicates that the Library Item is set to install once per device. Indicates that the Library Item is set to update if it is already installed, but will not install the application on its own. ### Library Item Duplication Most Library Items can be easily duplicated to create a new item with the same configurations and assets, such as installer packages and scripts. However, this does not apply to Wallpaper, Device Name, In-House App, Microsoft Authenticator, and Okta Verify. You can duplicate from the **Library** list or from an open **Library Item**. #### From the Library Navigate to the **Library** page in the Iru Endpoint Web App. Find the Library Item you want to duplicate in the list, then click the **ellipsis** next to its name. Click **Duplicate**. Library list with ellipsis menu open and Duplicate selected for a Library Item Click **Yes, duplicate** to confirm duplication. Edit the **Title**, [**Label**](#library-item-labels), and **Blueprint** Assignment as appropriate. If the title is editable, (COPY) will be appended to it by default. Otherwise, it will be added to the [**Label**](#library-item-labels). #### From the Library Item Navigate to the **Library** page in the Iru Endpoint Web App. Open the Library Item you want to duplicate. Click the **ellipsis** in the Library Item header. Click **Duplicate**. Library Item detail view with ellipsis menu open and Duplicate selected Click **Yes, duplicate** to confirm duplication. Edit the **Title**, [**Label**](#library-item-labels), and **Blueprint** Assignment as appropriate. If the title is editable, (COPY) will be appended to it by default. Otherwise, it will be added to the [**Label**](#library-item-labels). The **Activity** timeline for each Library Item shows duplication events. The source Library Item will have an entry that says "**Library Item Duplicated**" with details including which Library Item it was duplicated *to.* The first "Library Item Created" activity entry for the duplicate Library Item will have details containing which Library Item it was duplicated *from.* ### Assigning Duplicated Self-Conflicting Library Items to One Blueprint If duplicates of a specific **Auto App**, **App Store App**, or **Managed OS** Library Item need to be assigned to the same Blueprint, there are several prerequisites that need to be fulfilled. #### Prerequisites * The duplicated Library Item needs a [Label](#library-item-labels) to make it unique. * The Blueprint must use the **Advanced View** for the Assignment Maps. For more information about the Advanced View, please see the Advanced View section of the [Creating a Blueprint](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint#advanced-view). #### Self-Conflicting Library Item icon When two **Auto App**, **App Store App**, or **Managed OS** Library Items for the same app or managed OS configuration are assigned on the same Blueprint, they are **self-conflicting** with each other. Each affected Library Item tile shows the **Self-Conflicting Library Item icon** in the Blueprint **Assignment Map** view (stacked cards with a slash). Hover the icon to read how assignment is resolved for that item. Blueprint Assignment Map with Library Item tiles showing the Self-Conflicting Library Item icon and tooltip The hover text follows this pattern. In the product, *type name* is replaced with the name of that Library Item type (for example, **Auto App**, **App Store App**, or **Managed OS**). For how those types are organized in the Library UI, see [Library Sections](#library-sections). **App Store App** tooltips also include that app's display name. > Only one *type name* Library Item may be assigned per device for the same app or managed OS configuration. Devices which qualify for more than one will receive whichever is scoped to them last (farthest right) on the map. #### Create Assignment Logic You add a branch in the Blueprint Assignment Map so the duplicate is used only under the conditions you define, such as a second **1Password 8** Auto App Library Item for **New Hire** devices while the original stays on the main path, or a second **Managed OS** Library Item scoped to a different device group. Go to **Blueprints** and open the Blueprint you want to configure. Select **Edit assignments**. Add a **conditional block** and define the conditionals (for example, **Tags contain one of** **New Hire**). See [Using Conditional Logic in Blueprints](/en/endpoint/blueprints/assignment-maps/using-conditional-logic-in-blueprints) for detail. Drag the duplicated Library Item from the Library Item Bank onto the branch that matches those conditions, and drag the original **Auto App**, **App Store App**, or **Managed OS** Library Item onto the **else** path or your default branch so each device group gets the correct build. Dragging a Library Item from the Library Item Bank onto a branch in the Blueprint Assignment Map Click **Save**. Assignment Map with conditional logic assigning a duplicated 1Password 8 Auto App using a New Hire tag #### Add to Existing Assignment Map Logic When conditional blocks are already configured on the Assignment Map, add the duplicated Library Item to the appropriate block so it does not target the same devices as the original. Follow these steps: Edit the duplicated **Auto App**, **App Store App**, or **Managed OS** Library Item you would like to assign. Click **Assign** and choose the appropriate Assignment Map. Drag the duplicated Library Item from the Library Item Bank onto a block where it would not be assigned to the same devices as the original Library Item. Dragging a duplicated Library Item onto a different block in the Assignment Map Click **Done**. Assignment Map with Done after adding a duplicated Library Item to a block Click **Save**. ### Library Sections Iru Endpoint lets you block specific applications from being opened on enrolled macOS, Windows, and Android devices using the App Blocking Library Item. Refer to [Configure the App Blocking Library Item](/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item) to learn more. Apps from the App Store are available to be added to Iru Endpoint. When you add licenses to Iru Endpoint from within Apple Business or Apple School Manager, that app will show as available in this section. You can see which device type the app is made for at the bottom of the app, or you can filter by device type at the top of the Library page. You can also click **Sync App Store Apps** next to the Add Library Item button near the top right of the page to pull the latest App Store assignments from the portal. When deployment or licensing issues generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Refer to [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books) to learn more about Apple Business or Apple School Manager Apps and Books support within Iru Endpoint. Auto Apps are pre-packaged, hosted, and automatically patched according to your chosen enforcement policy. All Iru Endpoint Auto Apps that you've added to your Library are displayed in the Auto Apps section. For more information, see our [Auto App Overview](/en/endpoint/library/auto-apps/auto-apps-overview) and our [List of Available Auto Apps](https://www.iru.com/library-items). Bookmarks Library Items hold bookmarks (links) for resources that are made available in Self Service. Refer to [Self Service: Bookmarks](/en/endpoint/settings/self-service/self-service-bookmarks) to learn more. All Custom Apps that you've uploaded to Iru Endpoint will be located in your Library. On Mac, custom apps can be added through an installer package (PKG or MPKG), disk image (DMG), or ZIP file; on Windows, use a zip containing an MSI or EXE installer. Refer to [Custom Apps Overview](/en/endpoint/library/library-items-profiles/custom-apps-overview) to learn more. For step-by-step setup, see [Configure the Mac Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-custom-apps-library-item) or [Configure the Windows Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-windows-custom-app-library-item). When install or audit failures generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Custom Printers are available in your Library. Install and set up printers and printer drivers using the Iru Agent. Choose to have the agent continuously enforce printers to verify their settings. Unmatched settings will be remediated automatically. When printer installation or enforcement issues generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Refer to [Custom Printers](/en/endpoint/library/library-items-profiles/custom-printers-overview) to learn more. You can have Custom Scripts in your Library. Run any type of script supported by macOS. Choose to run once per device or continuously, and add an optional remediation script that can be run when needed. If you do not specify a shell or interpreter, scripts will run in the standard shell (/bin/sh). When audit or remediation failures generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Refer to [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview) to learn more. Endpoint Detection & Response (EDR) functionality is available for Mac devices assigned to Blueprints containing EDR. You can view identified threats in the Iru Endpoint Web App on the **Detections** page (under **Endpoint** in the left-hand navigation) and on the device record page. Refer to [Overview of Endpoint Detection and Response (EDR)](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview), [Configuring the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item), and [Configuring the Accessory & Storage Access Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-accessory-and-storage-access-library-item) to learn more. Items in this section configure the behavior of [Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment), [Liftoff](/en/endpoint/library/library-items-profiles/configure-the-liftoff-library-item), and [Passport](/en/endpoint/library/passport/configure-the-passport-library-item), allowing you to customize enrollment, setup, and login behaviors. The **Google Play apps** section lists Android applications you add through the Google Play Library Item and assign to work profile devices. The integration uses a Google Play iframe in Iru Endpoint; [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) must be complete before it will load. Refer to [Configure Android Apps with Google Play Library Item](/en/endpoint/library/library-items-profiles/configure-android-apps-with-google-play-library-item) to learn more. Refer to [Configuring the In-House App Library](/en/endpoint/library/library-items-profiles/configure-the-in-house-app-library-item) to learn more. Managed OS Library Items let you manage operating system versions across your fleet. You can add the same Managed OS more than once and use [**labels**](#library-item-labels) to tell copies apart in the Iru Endpoint Web App. Refer to [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos), [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms), and [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos) to learn more. The **Profiles** section groups configuration profile Library Items for Apple devices, including [Custom Profiles](/en/endpoint/library/library-items-profiles/custom-profiles-overview) you build or upload as `.mobileconfig` files, plus other MDM configuration items that ship as profile-style Library Items in Iru Endpoint. When profile installation or validation issues generate alerts in Iru Endpoint, see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. Refer to [Custom Profiles Overview](/en/endpoint/library/library-items-profiles/custom-profiles-overview) to learn more. For individual configuration types, see the Library Item articles under **Library** in the docs navigation. For Custom Apps, Custom Scripts, and Custom Printers, you can upload an icon next to the title. PNG, JPG, and ICNS are the recommended file types when using this feature. ### Related Articles Configure how Iru Endpoint surfaces alerts when Library Items report issues across categories Create and configure device Blueprints for policy management # System extensions on macOS with Iru Endpoint Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/system-extensions-overview-and-guide Learn about macOS system extensions and how to manage them with Iru Endpoint. Understand network extensions, endpoint security, and driver extensions. This Library Item is available for Mac computers ### What Is a System Extension? System extensions are the modern replacement for kernel extensions (kexts) in macOS Catalina and later. With system extensions, Apple provides new frameworks for developers to perform tasks previously reserved for kexts. The primary benefit of system extensions is that they run in user space rather than kernel space, which means they can't compromise the built-in security or stability of macOS. Although kexts still work in macOS Catalina, Apple has deprecated certain types, and developers should migrate their kexts to system extensions as equivalent frameworks become available. Currently, there are three new system extension frameworks available to replace kexts: * **DriverKit**: Create drivers for USB, Serial, NIC, and HID devices that users can install in macOS Catalina or newer. [Learn more about DriverKit.](https://developer.apple.com/documentation/driverkit) * **Network Extensions**: Distribute network extension apps such as content filters, DNS proxies, and VPN clients as system extensions in macOS Catalina or newer. [Learn more about NetworkExtension.](https://developer.apple.com/documentation/networkextension) * **Endpoint Security**: Monitor and block system events using the EndpointSecurity API to conform with security policies and protect from malicious activity in macOS Catalina or newer. [Learn more about Endpoint Security](https://developer.apple.com/documentation/endpointsecurity) Kexts that operate outside of these new frameworks (such as virtualization software) must continue to use kexts until Apple offers equivalent system extension frameworks. System extensions can also be allowed using a separate configuration profile. If you're using an application that still uses a kernel extension, we recommend reaching out to your software vendors to encourage them to migrate to system extensions. #### Additional Information [Kernel Extensions Overview](https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/KernelProgramming/Extend/Extend.html#//apple_ref/doc/uid/TP30000905-CH220) - Apple Developer Documentation Archive [System Extensions](https://developer.apple.com/system-extensions/) - Apple Developer ### What Is a Kernel Extension? Kernel extensions, sometimes referred to as kexts, allow developers to load code dynamically into the macOS kernel. They provide access to internal kernel interfaces that enable complex apps to function properly. Examples include virtualization applications and hypervisors such as Parallels or VMware Fusion. ### The Difference Between Kernel Extensions and System Extensions If you're unsure whether a piece of software uses a system extension or a kext, there are a few ways to find out: * Contact the software manufacturer * After installing your software, run the command below to list all active system extensions. If no system extensions are listed, the software likely uses a legacy kext ```bash systemextensionsctl-list.sh theme={null} systemextensionsctl list ``` Here's an example of the output you might see if no system extensions are installed: ```bash terminal-output.txt lines theme={null} Iru Endpoint Support@TestMac1 ~ % systemextensionsctl list 0 extension(s) ``` Here's an example of the output you might see if a system extension is installed: ```bash systemextensionsctl-with-extensions.txt lines theme={null} Iru Endpoint Support@TestMac1 ~ % systemextensionsctl list 1 extension(s) --- com.apple.system_extension.endpoint_security enabled active teamID bundleID (version) name [state] * * 9PTGMPNXZ2 com.symantec.mes.systemextension (10.0.0/10.0.0) Symantec [activated enabled] ``` ### Create a System Extension Profile Follow these steps to create a system extension profile in Iru Endpoint that will pre-approve an application's system extension(s). To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give your new profile a descriptive name, such as *System Extension Allowance*. Select the designed [Blueprints](/en/endpoint/blueprints/assignment-maps). Optional: If you deselect **Allow users to approve system extensions**, this will prevent all users on the Mac, including local administrators, from approving additional system extensions not approved via a profile. Selecting this option will also disapprove any system extensions a user has previously approved. Input the **Team ID**; this is the identifier in the third column of the Terminal output generated by the *systemextensionsctl list* command discussed above. Optionally provide a **Name** to associate with the Team ID. Under the **System Extensions** portion, you may optionally change the default value of **Approve all system extensions**. Leaving this option at its default setting will preapprove any System Extension from the specified Team ID. You can optionally set this option to one of the following: * **Allow specific system extensions**: Allows you to specify the exact bundle ID of the specific system extension you want to approve; use the bundle ID generated by the *systemextensionsctl list* command described above. You can also optionally configure one or more of these specific extensions to be able to be removed automatically by admin tooling, such as Iru Endpoint or a vendor-provided package. * **Allow specific system extension types**: Allows you to specify system extension types from a developer, such as endpoint security extensions, driver extensions, or network extensions, that you want to be preapproved. For our Symantec example, we would approve the **Endpoint security extensions** type, as this matches the extension type generated by the *systemextensionsctl list* command described above. Optionally, you can select the **Add Team ID** button to allow additional system extensions in a single profile. Click **Save**. # User Experience with Windows Apps Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/user-experience-with-windows-apps What to expect when Auto Apps and Windows Custom Apps install or update on Windows: the Iru system tray Updates list, close-app prompts, background retries, and enforcement countdowns. This guide applies to Windows devices When **Iru Agent** installs or updates a company **Auto App** or **Windows Custom App** on your PC, most of the work runs in the background. The **Iru system tray app** next to the clock is where you see pending updates, start installs on your schedule, and respond when a running app blocks an update you chose to run. ### App updates in the Iru system tray When updates have not finished installing, those apps appear in the **Updates** section of the Iru system tray app. The list includes only apps with outstanding updates. Apps that already updated successfully do not appear. Each row shows: * App name and the version available * Time remaining before the update is enforced automatically (**Auto-install in N days**) * An **Update** button to start that install * Status indicators as the install progresses When nothing is pending, the tray shows a green checkmark and **No app updates are required at this time.** #### Update one app Click **Update** next to an app to start that install. If the app is open, you see the [close-app dialog](#when-an-app-must-close) and can close the app to proceed or **Cancel** to return to the list. **Cancel** does not remove the app from the tray; it stays listed until the update completes. Only one install runs at a time. If you click **Update** on several apps, they queue in the order you clicked and install one after another. #### Update all apps Click **Update All** to queue every pending update and install them one at a time from the top of the list (alphabetical order). The button is disabled when every pending app is already queued. If more than one queued app is open when its turn arrives, you see the close-app dialog for each app that is still running. #### Background updates and tray reminders **Iru Agent** also tries to install pending updates silently about every **15 minutes**. If the app is not open, the update installs without a prompt. If the app is open during a background attempt, no dialog appears. The agent retries on the next cycle. The close-app dialog appears only when you click **Update** or **Update All** in the tray, not during those automatic background attempts. While updates are still pending, the tray opens on its own about every **8 hours** to show the update list. In that automatic view you see pending updates only. The **Self Service** entry appears when you open the tray yourself. If **Iru Agent** installs an update silently while the tray is closed, that app no longer appears the next time you open the tray. **Iru Agent** runs one app installer at a time, whether you start the install from the tray or it runs in the background. That prevents installer conflicts. ### When an app must close If a running app blocks an install or update **you started from the tray**, a prompt appears in the center of your screen. The Iru system tray app stays open next to the clock. The prompt names the app, explains why it has to close, and offers: * **Continue:** The listed app closes right away and the install or update completes. * **Cancel:** Stops this install attempt and returns you to the tray list. **Iru Agent** retries silently about every **15 minutes** in the background. The app remains in the **Updates** list until the update succeeds. Save your work before you choose **Continue**, so you don't lose anything unsaved. #### What the prompt looks like The card header on the left starts with the Iru logomark **Iru**. Under that you'll see the app icon, a short line about which app must close before things can continue, and **Continue** and **Cancel** along the bottom, the same choices described above. Example Iru prompt on Windows asking you to close a running app so an install or update can finish, with Continue and Cancel ### Enforcement deadline Your IT team can set an **enforcement deadline**: the date and time by which the app must be installed or updated. The tray shows how many days remain before each app auto-installs (**Auto-install in N days**). When the enforcement deadline arrives, the [enforcement countdown](#during-the-countdown) takes over, not the tray close-app dialog you see when you click **Update** while an app is open. At the deadline, **Iru Agent** shows a **5-minute countdown** on your screen. Windows enforcement countdown with Update now and delay options before a required app install or update #### During the Countdown You can: * **Update now:** Close the app immediately and let the install finish. * **Delay for 1 hour:** Postpone the countdown. **Iru Agent** still retries in the background about every 15 minutes. If the app is still open an hour later, the countdown comes back. #### Delay Limit Across those delays you can postpone for up to **24 hours** in total. Once you've used that time, you get one last countdown with no way to delay further. Pick **Update now** to close the app and finish right away. If the timer runs out with no response, the app closes on its own and the install runs. ### What to Do * Use the tray **Updates** list to install pending **Auto App** or **Windows Custom App** updates before the enforcement deadline when it fits your schedule. * Save your work before **Continue**, **Update now**, or the countdown ends. * If you need more room on the clock, use **Delay for 1 hour**. Just keep the **24-hour** limit in mind. After that, the install goes through whether you answer the prompt or not. * If something looks wrong or you aren't sure what to do, contact your **IT team**. ### Related Articles How Auto App installs and updates work on Windows and macOS How Windows Custom Apps are packaged, enforced, and detected Admin configuration for Windows Custom App deployments What to expect when you enroll your Windows device through the enrollment portal # Using AppConfig Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/using-appconfig Configure managed app settings using AppConfig in Iru Endpoint. Deploy key-value pairs and XML configurations to supported iOS and Android applications. AppConfig is available for iOS devices, iPadOS devices, Apple TV, and visionOS devices ### What is AppConfig? [AppConfig](https://www.appconfig.org/), developed by a dedicated community, provides tools and best practices that use native capabilities in mobile operating systems. You can pre-configure **App Store Apps** (Apps and Books from Apple Business or Apple School Manager) and **In-House Apps** deployed via Iru Endpoint on iOS, iPadOS, tvOS, or visionOS. ### How does AppConfig Work? AppConfig uses XML dictionaries to automate the configuration of essential app settings such as URL/port settings, group codes, email addresses, and license keys. This eliminates the need for end-user intervention during the initial setup, simplifying the deployment process. By centralizing configuration management, AppConfig lets you consistently apply settings across multiple environments and devices without requiring an additional Library Item. ### Configuring AppConfig for an iOS, iPadOS, tvOS, or visionOS App AppConfig can be set for both App Store Apps and [In-House Apps](/en/endpoint/library/library-items-profiles/configure-the-in-house-app-library-item). The steps below apply to either type; for In-House Apps, select your In-House App Library Item instead of an App Store App. Log in to your Iru Endpoint tenant and navigate to the **Library**. Select an **App Store App** or **In-House App** that supports AppConfig. Scroll to the bottom of the Library Item, and check the **Set app configuration** checkbox. Paste in your **AppConfig** dictionary. Click **Save**. ### Example Uses for AppConfig Configure the Kiosk Pro app to automatically open a default kiosk URL and set other application restrictions: ```xml kiosk-pro-config.xml lines theme={null} settingsShowingOption 2 settingsPassCode 1234 autonomousSingleAppMode 0 kp_passCodeToExitAutonomousSingleAppMode 1234 homePage .io showStatusBar showAddressBar ``` Configure the Okta Mobile app to enforce mobile device trust: ```xml okta-mobile-config.xml lines theme={null} managementHint Okta generated token goes here ``` If you have specific questions about creating an AppConfig for your application, please contact the developer or [Iru Support](/en/iru/iru-support/access-to-iru-support) for assistance. # Using the Flush Action Source: https://docs.iru.com/en/endpoint/library/library-items-profiles/using-the-flush-action Use the flush action in Iru Endpoint to clear a Library Item's installation status and force a re-evaluation. Retry failed deployments on Apple devices. The Flush Action applies to Apple devices When a Library Item installation fails, the next behavior depends on that Library Item's configuration. Some Library Items retry automatically, while others stop and require manual action. A failed run is shown as **Error** status for that Library Item on the device, and **Error** status generates an alert; see our [Global Alerts](/en/endpoint/devices/global-alerts) support article for details. There are several reasons a Library Item installation could fail. Use **Flush** after you've identified and resolved the cause of the failure, and when the item is no longer retrying automatically. For retry behavior, refer to the documentation for the specific Library Item. This is designed to avoid endless attempts at downloading and installing profiles on all devices. Before attempting to deploy the Library Item again, you will need to identify the cause for the error received and rectify the issue. Once you are ready for another attempt, perform the Flushing Action for the Library Item on the device. Once the previous error is "flushed," Iru will attempt the installation again. ### Flushing an Install Attempt Navigate to **Library** in the left-hand navigation bar. Select the **Library Item** in question. Click on the **Status** tab to see a list of all devices the Library Item is assigned to. Click the **Flush** button on the right of the device(s) you wish to re-attempt the install. # Configure Managed OS for iOS, iPadOS, and tvOS Source: https://docs.iru.com/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos Configure the iOS, iPadOS, and tvOS Managed OS Library Item in Iru Endpoint with rolling enforcement, phased rollout, and version options. This guide applies to iOS devices, iPadOS devices, and Apple TV This Library Item requires supervision. Keeping the operating systems of a fleet of Apple devices up to date can be a lot of work if done interactively. Managed OS allows you to automate this work on your supervised devices without the need to send multiple MDM commands and prompts to users manually. Enable Managed OS for iOS, iPadOS, and tvOS, and Iru Endpoint will take care of the rest. ### About Managed OS for iOS, iPadOS, and tvOS Managed OS for iOS, iPadOS, and tvOS deploys and enforces OS updates across your fleet of supervised Apple mobile and TV devices. On iOS 17, iPadOS 17, and tvOS 17 and later, updates are delivered via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os). Iru handles: * **Update detection**: Iru monitors for available OS updates from Apple * **Download and caching**: Updates are automatically downloaded and cached on devices * **User notification**: Users are notified of pending updates with enforcement deadlines * **Automatic installation**: Updates are installed according to your configured schedule * **Compliance monitoring**: Iru tracks which devices have successfully updated For how **Rolling enforcement** calculates the floor, how **Enforce a specific version** differs from **Manually enforce a minimum version**, [phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout), notifications, and [first-time fleet enforcement recommendations](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#recommendations), see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms). ### Enabling Managed OS in your Library Deploying and enforcing an OS version is as easy as adding a Managed OS Library Item to your Library and assigning it to a Blueprint. Follow the steps below. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. #### Enabling Multiple Managed OS Library Items Iru Endpoint supports adding the same Managed OS to your Library multiple times. This is useful when it's desired to configure differing settings for different Blueprints. For example, you can have Managed OS update devices automatically 1 week after Apple releases an update in one Blueprint, while having it do the same up to 3 months after the release in another. Labels are used to differentiate multiple copies of the same Managed OS (see the steps below). For how to set a **Label** on any Library Item, see [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview. ### Configuring Managed OS Enter a **Label** to help differentiate this instance of Managed OS from others in your Library. These labels are not visible to end users, but are displayed throughout the Iru Endpoint Web App. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. **Assign** to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Under **Updates**, select an option for Version Enforcement. Available options include the following: Managed OS Version Enforcement options #### Do not manage updates This option will not manage OS updates. #### Rolling enforcement Select **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release** and **at** a time for enforcement. Optionally, set **Delay enforcement by** to a number of days (up to 90). This delays when Iru sends the target-version declaration without changing the enforcement date. Use it to temporarily hold back the newest available version while still using **Rolling enforcement**. To hide the new version from users for the same period, set a matching deferral in a [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item). If **Delay enforcement by** is shorter than that deferral, Managed OS still overrides the deferral once its declaration is sent. For full behavior, see [Rolling enforcement](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#rolling-enforcement) in **Understanding Managed OS for Apple Platforms**. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). After any **Delay enforcement by** period ends (or immediately if delay is not set), declaration issuance for a new Apple release is spread across that window. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for iOS, iPadOS, and tvOS Rolling enforcement Within and at settings #### Manually enforce a minimum version Specify the **Minimum Version** a device should be running and the **Enforcement Deadline** date by which users must update. No updates will be enforced if a device is already running an OS version greater than the specified minimum. You will also select an **Enforcement Time**. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). Declaration issuance is staggered from Library Item save (on first create, or when OS version settings or date/time change) and again when Apple releases a new version. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for iOS, iPadOS, and tvOS Manually enforce a minimum version settings #### Enforce a specific version Uses the same version selection dropdown and enforcement scheduling fields as **Manually enforce a minimum version**—select a **Specific version**, an **Enforcement Deadline** (**on**), and an **Enforcement Time** (**at**). Unlike **Manually enforce a minimum version**, this option enforces that exact OS version rather than a minimum floor. To enforce an Apple beta build, select **This is a beta version**, choose a **Seed Token** synced from Apple to Iru, then enter the beta version and build. Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) as separate declarations. If you use Managed OS for beta enrollment and version enforcement, set **Beta program enrollment** in any Software Update Library Item on the same Blueprint to **Not configured**. For opt-in beta enrollment or enrollment without a required version, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment). The **Seed Token** list can be long and difficult to navigate. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). When you save after creating the item, or after changing OS version settings or the enforcement date or time, declaration issuance is spread across that window from Library Item save. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for iOS, iPadOS, and tvOS Enforce a specific version settings For how each Version Enforcement option behaves after you save—including floors, [phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout), and user notifications—see [Version Enforcement option behavior](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#version-enforcement) in **Understanding Managed OS for Apple Platforms**. The Library Item **Status** tab shows when each device becomes eligible under phased rollout. Under **Background Security Improvements Enforcement**, choose whether to automatically enforce these updates when Apple makes them available. Options: * **None**: Background Security Improvements will not be enforced. * **Automatically enforce**: Choose the enforcement timeframe and local time for enforcement. Select an **Enforcement timeframe for Background Security Improvements.** Select an **Enforcement Time**, the time of day Background Security Improvements are enforced in the device's local time zone. Click **Save** in the bottom right corner. Background Security Improvements apply only to devices on the latest OS version; users must be on the latest OS before these updates can be enforced. Background Security Improvements use [Declarative Device Management](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) for enforcement. **Automatically enforce** under Background Security Improvements is separate from **Rolling enforcement** under **Updates** → Version Enforcement. ### Passcode Considerations At the enforcement deadline, on iOS and iPadOS devices with a passcode, the security architecture of iOS and iPadOS requires users to be prompted for the update and to enter their passcodes. On tvOS, and on iOS and iPadOS devices without passcodes, updates will be cached by Iru Endpoint and the update will be applied without user intervention at the enforcement deadline. For more details, see [User Experience with Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos). ### Related Articles Understand how Managed OS enforcement works on Apple devices What to expect when Managed OS updates run on your device About Apple DDM and Managed OS in Iru Endpoint Compare different OS update management strategies Configure OS update delays and enforcement policies # Configure Managed OS for macOS Source: https://docs.iru.com/en/endpoint/library/managed-os/configure-managed-os-for-macos Configure the macOS Managed OS Library Item in Iru Endpoint with rolling enforcement, phased rollout, version options, and upgrades. This guide applies to Mac computers Deploying and enforcing a macOS version is as easy as adding Managed OS for macOS to your Library and assigning it to an Assignment Map. To configure it, follow the steps below. ### About Managed OS for macOS Managed OS for macOS deploys and enforces macOS updates across your fleet of Mac computers via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os). You can offer major macOS upgrades **on-demand from Self Service** or have them enforced automatically. When you configure Managed OS, Iru declares the required macOS version and deadline; macOS handles download, caching, notifications, and installation. Iru handles: * **Update detection**: Iru monitors for available macOS updates from Apple * **Download and caching**: Updates are automatically downloaded and cached on devices * **User notification**: Users are notified of pending updates with enforcement deadlines * **Automatic installation**: Updates are installed according to your configured schedule * **Compliance monitoring**: Iru tracks which devices have successfully updated For how **Rolling enforcement** calculates the floor, how **Enforce a specific version** differs from **Manually enforce a minimum version**, [phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout), notifications, and [first-time fleet enforcement recommendations](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#recommendations), see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms). ### Enabling Managed OS for macOS in your Library To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. #### Enabling Multiple Managed OS Library Items When using Iru Endpoint, you can add the same Managed OS version to your Library multiple times. This is helpful when configuring different settings for various Blueprints or creating distinct update settings for nodes in an Assignment Map. To differentiate between these copies, you can use labels. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. ### Configuring Managed OS for macOS Managed OS for macOS is not compatible with blocking the Software Update System Settings pane via any method, and doing so can produce unexpected behavior. Add a **Label** to easily identify this instance of Managed OS for macOS in your Library. While these labels won't be visible to end users, they will appear throughout the Iru Endpoint Web App. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview for steps. Assign to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Under **Upgrades**, configure the way upgrade installations of this major version of macOS should be enforced: * **Upgrade automatically** forces the device to the latest version of this OS either immediately upon Library Item assignment, or on a specified date and time. Optionally turn on **Available in Self Service** so users can install before the deadline. * **Upgrade on demand from Self Service** lets users upgrade through Self Service or Software Update with no enforced deadline. Differentiate Blueprints by making additional copies of the same Managed OS for macOS. When **Upgrade automatically** is scheduled with a date and time, set those under **Upgrades**. Update enforcement under **Updates** uses its own schedule, so the same Library Item can enforce minor updates and major upgrades on different timelines. Devices on an older major macOS version are no longer treated as out of date for updates and forced to upgrade as soon as the Library Item is scoped. Which macOS version a Mac receives when it updates depends on your Version Enforcement option under **Updates** (see **Configure Version Enforcement** below). **Rolling enforcement** and **Manually enforce a minimum version** install the latest Iru-approved update for the selected major version; **Enforce a specific version** enforces the macOS version you select. Under **Updates**, select an option for Version Enforcement. Available options include the following: Managed OS for macOS Version Enforcement options #### Do not manage updates This option will not manage macOS updates. It cannot be selected if you've chosen to **Upgrade automatically**, as **Upgrades** also determines the schedule and conditions for upgrading. #### Rolling enforcement Select **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release** and **at** a time for enforcement. Optionally, set **Delay enforcement by** to a number of days (up to 90). This delays when Iru sends the target-version declaration without changing the enforcement date. Use it to temporarily hold back the newest available version while still using **Rolling enforcement**. To hide the new version from users for the same period, set a matching deferral in a [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item). If **Delay enforcement by** is shorter than that deferral, Managed OS still overrides the deferral once its declaration is sent. For full behavior, see [Rolling enforcement](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#rolling-enforcement) in **Understanding Managed OS for Apple Platforms**. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). After any **Delay enforcement by** period ends (or immediately if delay is not set), declaration issuance for a new Apple release is spread across that window. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for macOS Rolling enforcement Within and at settings #### Manually enforce a minimum version Specify the minimum macOS version a Mac should be running and the **Enforcement Deadline** date by which users must update. No updates will be enforced if a Mac is already running a macOS version greater than the specified minimum. You will also select an **Enforcement Time**. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). Declaration issuance is staggered from Library Item save (on first create, or when OS version settings or date/time change) and again when Apple releases a new version. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for macOS Manually enforce a minimum version settings #### Enforce a specific version Uses the same version selection dropdown and enforcement scheduling fields as **Manually enforce a minimum version**—select a **Specific version**, an **Enforcement Deadline** (**on**), and an **Enforcement Time** (**at**). Unlike **Manually enforce a minimum version**, this option enforces that exact macOS version rather than a minimum floor. To enforce an Apple beta build, select **This is a beta version**, choose a **Seed Token** synced from Apple to Iru, then enter the beta version and build. Iru applies two declarations to the device in order: **Software Update Settings** (to enroll the device in the beta program), then **Software Update Enforcement** (to the specified version). For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as `27.0`) and the current AppleSeed beta build. If you use Managed OS for beta enrollment and version enforcement, set **Beta program enrollment** in any Software Update Library Item on the same Blueprint to **Not configured**. For opt-in beta enrollment or enrollment without a required version, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment). The **Seed Token** list can be long and difficult to navigate. Optionally select the **Enable phased rollout** checkbox, then enter the number of hours in the **Rollout window** field (24–168). When you save after creating the item, or after changing OS version settings or the enforcement date or time, declaration issuance is spread across that window from Library Item save. See [Phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout). Managed OS for macOS Enforce a specific version settings For how each Version Enforcement option behaves after you save—including floors, [phased rollout](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#phased-rollout), and user notifications—see [Version Enforcement option behavior](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#version-enforcement) in **Understanding Managed OS for Apple Platforms**. The Library Item **Status** tab shows when each device becomes eligible under phased rollout. Under **Background Security Improvements Enforcement**, choose whether to automatically enforce these updates when Apple makes them available. Options: * **None**: Background Security Improvements will not be enforced. * **Automatically enforce**: Choose the enforcement timeframe and local time for enforcement. Select an **Enforcement timeframe for Background Security Improvements.** Select an **Enforcement Time**, the time of day Background Security Improvements are enforced in the device's local time zone. Click **Save** in the bottom right corner. Background Security Improvements apply only to Mac computers on the latest macOS version; users must be on the latest macOS before these updates can be enforced. Background Security Improvements use [Declarative Device Management](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) for enforcement. ### Related Articles Understand how Managed OS works with DDM and macOS when troubleshooting updates Understand how Managed OS enforcement works on Apple devices Understand compatibility and installation mechanisms for Managed OS on macOS About Apple DDM and Managed OS in Iru Endpoint What to expect when using Managed OS on Mac computers Compare different OS update management strategies Configure OS update delays and enforcement policies Manage Windows Update settings and the end-user update experience on Windows devices # Declarative Device Management and Managed OS Source: https://docs.iru.com/en/endpoint/library/managed-os/declarative-device-management-and-managed-os Learn how Apple Declarative Device Management (DDM) works with Managed OS in Iru Endpoint. Understand status reports, declarations, and update behavior. This guide applies to Apple devices ### About Declarative Device Management Declarative Device Management (DDM) is Apple's next-generation device management framework that provides a more efficient and reliable way to manage devices. Unlike traditional MDM, which uses a push-based approach, DDM allows devices to pull their configuration from the MDM server, making them more autonomous and self-managing. Iru Endpoint was [first to market](https://the-sequence.com/kandji-support-declarative-device-management) to support actively managing supervised devices with DDM in 2022, and since that launch, has continued to expand the usage of DDM throughout the product. ### How It Works DDM enhances Managed OS functionality by providing more reliable update delivery and enforcement. When DDM is enabled, devices can: * **Pull updates autonomously**: Devices check for updates independently * **Handle offline scenarios**: Updates can be cached and applied when connectivity is restored * **Provide better reliability**: Reduced dependency on constant server communication * **Improve user experience**: Fewer interruptions during updates ### DDM and Managed OS Iru Endpoint uses DDM for Managed OS for macOS, iOS 17, iPadOS 17, and tvOS 17 and later. DDM is used to manage software updates automatically; there is no additional configuration needed in Managed OS Library Items. When DDM is used, Iru Endpoint applies declarations to scoped devices that specify the required OS version and enforcement deadline. For beta enforcement, Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version). From that point forward, the respective operating system handles all end user notifications and the actual enforcement process. ### Admin Experience #### Library Item Configuration Managed OS Library Items for macOS Sonoma, iOS 17, and iPadOS 17 separate the enforcement time zone option into its own section. This option now applies only to *upgrades* from older operating systems. When DDM is in use, update enforcement always uses the device's local time zone. Iru Endpoint cannot change this behavior as it is set by the operating systems. #### MDM Commands Only a single MDM command for **DeclarativeManagement** is visible in the device's activity stream when new OS versions are released or enforcement timelines are changed. Individual AvailableOSUpdates and OSUpdateStatus commands are no longer run throughout the update lifecycle as they don't provide any information to Iru Endpoint when DDM is in use. #### Library Item Status macOS, iOS, iPadOS, and tvOS send updates proactively to Iru Endpoint about the status of OS updates. The operating systems, not Iru Endpoint, control the contents and granularity of these status updates. Iru Endpoint simply displays the updates as they are received. Iru Endpoint then maps various reported statuses to standard Library Item statuses, such as Downloading, Cached, Installing, Pass, and Error. ### User Experience Please visit the [User Experience with Managed OS for macOS](/en/endpoint/devices/macos-managed-os-user-experience) and [User Experience with Managed OS for iOS, iPadOS and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos) articles for more information. ### Deferrals Users cannot defer enforced updates beyond their enforcement deadline an hour at a time; this is because the operating systems do not allow it. This means updates could happen during critical business tasks if users continuously ignore notifications and don't update their devices (though all notifications in the last 24hrs of enforcement ignore Do Not Disturb). Iru Endpoint cannot control this, but does recommend considering this important change when setting enforcement times in Managed OS. Also be sure to consider that all updates are enforced in device local time. ### Troubleshooting Check System Settings on macOS or Settings on iOS or iPadOS for the applied declaration. If it has the correct enforcement settings but users are not being notified properly, or updates are failing to install, please contact [Apple support](https://support.apple.com/guide/deployment/applecare-support-dep6971a1932/web) or send feedback to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web). If devices are not receiving the correct declarations at all, or you have a general question about Managed OS, including how to configure it, please [contact Iru support](/en/iru/iru-support/access-to-iru-support). ### Frequently Asked Questions Using DDM to manage software updates on [Iru-supported Apple devices](/en/iru/requirements/device-requirements) is the most reliable way to do so. It also brings a number of benefits like enforcement of updates in a device's local time zone, and notifications that are able to bypass Do Not Disturb in the last 24hrs leading up to enforcement. macOS: Open System Settings > General > Device Management > Double click on "MDM Profile" > Scroll down to "Device Declarations". Once a declaration hits a device, users will be notified immediately that an update is scheduled. Depending on your configuration, this notification could happen weeks or months ahead of the enforcement date. iOS: Open **Settings > General > VPN & Device Management > MDM Profile > Configurations** Yes. Iru Endpoint supports Managed OS for [all supported operating systems](/en/iru/requirements/device-requirements). When an update is already cached, and you want to push back the enforcement date, the enforcement date and time will be re-evaluated as soon as possible with the next MDM check-in. Feedback about the end user experience when updates are managed with DDM, including the contents of notifications, their frequency, deferrals, or any other customizations should be sent to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web). Check System Settings on macOS or Settings on iOS or iPadOS for the applied declaration. If it has the correct enforcement settings but users are not being notified properly, or updates are failing to install, please contact [Apple support](https://support.apple.com/guide/deployment/applecare-support-dep6971a1932/web) or send feedback to Apple through [AppleSeed for IT](https://support.apple.com/guide/deployment/join-appleseed-for-it-depe9ec59a81/web). If devices are not receiving the correct declarations at all, or you have a general question about Managed OS, including how to configure it, please [contact Iru support](/en/iru/iru-support/access-to-iru-support). ### Related Articles Configure managed OS updates for Mac computers Understand how Managed OS enforcement works on Apple devices Configure managed OS updates for iOS, iPadOS, and tvOS devices Compare different OS update management strategies # Managed OS macOS compatibility and install methods Source: https://docs.iru.com/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms macOS Managed OS update types, DDM delivery, and deployment considerations including Rolling enforcement planning and Software Update Library Item conflicts. This guide applies to Mac computers Managed OS is a feature in Iru Endpoint that lets you specify a minimum macOS version a supervised Mac must run and enforce updates when that minimum is not met. The experience is similar to [Auto Apps](/en/endpoint/library/auto-apps/auto-apps-overview). ### How Updates Are Delivered Managed OS uses [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) to deliver and enforce macOS updates. The operating system handles downloading, caching, user notifications, and installation. You can offer **major macOS upgrades via Self Service** (install on-demand from Self Service) or have them enforced automatically. For more on how DDM and Managed OS work together, see [Declarative Device Management and Managed OS](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os). Update types you can manage include: * **Minor and patch updates** (e.g., 14.2.1 → 14.3) * **Major version upgrades** (e.g., macOS 14 → 15) * **Background Security Improvements**: Lightweight security updates from Apple (Safari, WebKit, system libraries) delivered between full OS updates. Iru checks hardware compatibility before enforcing **Enforce a specific version**, **Manually enforce a minimum version**, and **Rolling enforcement** targets. Devices that cannot run the required version are not forced to install an incompatible update. Managed OS does not support downgrading macOS. ### Deployment Considerations Managed OS for macOS is not compatible with blocking the Software Update System Settings pane via any method; doing so can produce unexpected behavior. If you use **Rolling enforcement**, the enforcement schedule is based on Apple’s release date. Optional **Delay enforcement by** (up to 90 days) delays when the target-version declaration is sent without changing that enforcement date. For [first-time fleet enforcement recommendations](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms#recommendations), how **Rolling enforcement** can require immediate updates when Apple has not released an update within your **Within** window, and how **Delay enforcement by** works with Software Update deferrals, see [Understanding Managed OS for Apple Platforms](/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms). To avoid conflicts with pre-downloading and caching, if you use Managed OS, turn off automatic download of updates in any Software Update Library Items used in the same Blueprint. ### Related Articles Configure managed OS updates for Mac computers Understand how Managed OS enforcement works on Apple devices What to expect when Managed OS updates run on your device Understand how Managed OS works with DDM and macOS when troubleshooting updates About Apple DDM and Managed OS in Iru Endpoint # Managed OS for Windows Source: https://docs.iru.com/en/endpoint/library/managed-os/managed-os-for-windows Configure the Managed OS Library Item for Windows 11 in Iru Endpoint. Set feature and quality update deferrals, deadlines, grace periods, and version enforcement. This Library Item is available for Windows devices Managed OS Library Items let you define which major Windows 11 feature version devices must be on and set deadlines for installation and restart. Iru Endpoint provides one Library Item per supported Windows 11 release (for example, **Windows 11, Version 24H2** or **Windows 11, Version 25H2**). Assigning a Managed OS Library Item pins devices to that version. Devices will not advance beyond it while the Library Item is assigned, and monthly quality updates within that version continue normally. Managed OS controls version destination and enforcement timing. For settings that affect the Windows Update end-user experience (notifications, active hours, and optional content), use the [Configure the Windows Update Library Item](/en/endpoint/library/library-items-profiles/configure-the-windows-update-library-item). For detailed technical background on each setting, refer to Microsoft's official [Update Policy CSP documentation](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update). ### Create a Managed OS Library Item To add this Library Item to your Iru Endpoint Library, follow the steps in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Navigate to the **Library** and select **Add Library Item**. Search for and select the Windows 11 version you want to enforce, such as **Windows 11, Version 25H2**. Give the Library Item a **Name** that identifies its purpose in your environment. Assign the Library Item to one or more **Blueprints**. Only Windows devices in those Blueprints receive the Managed OS settings. You can use Assignment Maps within Blueprints for conditional logic if needed. Set your deferral, deadline, grace period, and pause settings for both feature and quality updates. See [Settings](#settings) below. Click **Save** in the bottom right corner. Only one Managed OS Library Item can be assigned to a device at a time. If a device already has one assigned, Iru Endpoint prompts you to confirm before replacing it. ### Settings Managed OS settings are organized into two sections on the **Settings** tab: **Feature updates** and **Quality updates**. Feature updates are major Windows 11 version upgrades (for example, moving from 24H2 to 25H2). These settings control when that version becomes available to devices, when installation is required, and how restarts are handled. **Defer feature updates for** Delays how many days after Microsoft releases a feature update before devices are offered the update. Range: 0 to 365 days. Default: 0 days. **Deadline for feature update install** Number of days after the end of the deferral period before the feature update must be installed and the device can be forced to restart. Range: 0 to 14 days. Default: 7 days. **Grace period for restart** Minimum number of days after the feature update is installed before an automatic restart is forced. Range: 0 to 3 days. Default: 2 days. **Pause start date** Sets a specific date to begin pausing feature updates. While a pause is active, the feature update is not offered to devices. Leave empty if you do not need to pause updates. Quality updates are the monthly cumulative updates released within a feature version. These settings mirror the feature update controls and apply independently based on each device's current feature version. **Defer quality updates for** Delays how many days after Microsoft releases a quality update before devices are offered it. Range: 0 to 30 days. Default: 7 days. **Deadline for quality update install** Number of days after the end of the deferral period before the quality update must be installed and the device can be forced to restart. Range: 0 to 30 days. Default: 7 days. **Grace period for restart** Minimum number of days after the quality update is installed before an automatic restart is forced. Range: 0 to 7 days. Default: 2 days. **Pause start date** Sets a specific date to begin pausing quality updates. While a pause is active, quality updates are not offered to devices for up to 35 days from the pause start date. Leave empty if you do not need to pause updates. ### Status The **Status** tab shows the standard Library Item statuses for each assigned device. | **Status** | **Meaning** | | ---------- | ----------------------------------------------------------------------------------------------- | | Pass | The Managed OS settings were successfully applied to the device. | | Pending | The Managed OS settings have been assigned but the device has not yet received or applied them. | | Error | An error occurred while applying the Managed OS settings to the device. | These statuses reflect whether the Managed OS settings were successfully delivered to the device, not whether the device has finished installing the required update. A device can show **Pass** on the **Status** tab while still in the process of downloading or installing an update. ### Considerations Only one Managed OS Library Item can be assigned to a Blueprint at a time. If you assign a new version to a Blueprint that already has a Managed OS Library Item assigned, Iru Endpoint prompts you to confirm the replacement. The previous Library Item is removed from the Blueprint when you confirm. A Managed OS Library Item acts as a ceiling on the feature version. Devices will not advance beyond the targeted version while the Library Item is assigned. Monthly quality updates within that version continue unaffected. Deferral and pause control when an update becomes available to devices. Deadline and grace period control how soon installation and restart are enforced once the update is available. Pausing an update stops it from being offered, but does not reset the deferral timeline once the pause ends. If you set the grace period to a value greater than 0, the device will not force a restart at the deadline until the grace period ends. Setting the grace period to 0 allows the device to restart at the deadline without waiting. ### Best Practices Create multiple Library Items with different deferral periods to allow the update to roll out over time, reducing risk and enabling patching issues to be caught before rolling out to additional devices. Set a deferral to 0 days for the initial ring so those devices get updates immediately when released. A deferral of 7 to 30 days gives you time to validate updates on a small group of devices before they roll out to the full fleet. Configuring a deadline ensures devices install required updates within a predictable window, reducing exposure to unpatched vulnerabilities. Use the pause start date during major business events or when a release has known issues. Pausing stops the update from being offered without changing your deferral configuration. Managed OS controls version enforcement. Assign a **Windows Update** Library Item to the same Blueprint to also manage active hours, notifications, and end-user update experience settings. ### Troubleshooting **Possible causes:** * The device encountered an issue receiving the Managed OS settings via MDM. * A conflicting policy from another source is preventing the settings from applying. **Solutions:** * Check the device record for recent activity and error details. * Confirm no other MDM profiles or policies are setting conflicting Windows Update CSP values on the device. **Possible causes:** * The pause start date is set in the future and has not taken effect yet. * The device has not checked in since the pause was configured. **Solutions:** * Confirm the pause start date is set to today's date or earlier. * Trigger a device check-in or wait for the next scheduled check-in. ### Related Articles Learn how Library Items work and how to assign them to Blueprints Configure end-user update experience settings, active hours, and optional content for Windows devices Configure managed OS updates for Mac computers Use Assignment Maps to target Library Items to specific groups of devices within a Blueprint # Understanding Issues with Managed OS for macOS Source: https://docs.iru.com/en/endpoint/library/managed-os/understanding-issues-with-managed-os-for-macos Troubleshoot Managed OS issues on macOS including failed updates, DDM conflicts, and stuck installations. Diagnose common problems and their solutions. This guide applies to Mac computers ### About Issues with Managed OS for macOS Understanding how Managed OS works can make it easier to troubleshoot when something doesn’t go as expected. Managed OS for macOS uses [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) on all supported macOS versions. Iru Endpoint declares the required macOS version and enforcement deadline to the device. The operating system then handles the downloading, caching, user notifications, and installation. ### How It Works When you configure Managed OS for macOS in Iru Endpoint, you set a minimum version and deadline. Iru sends that as a declaration to the device. The operating system then: * Checks for available updates from Apple * Downloads and caches updates * Notifies the user according to your deadline * Enforces installation at the scheduled time Iru Endpoint displays the status that macOS reports (such as Downloading, Cached, Installing) so you can track progress in the Iru Endpoint Web App. For more on how DDM works and what you’ll see in the admin and user experience, see [Declarative Device Management and Managed OS](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os). ### Need More Help? [Contact Iru support](/en/iru/iru-support/access-to-iru-support) for additional help with Managed OS. ### Related Articles Configure managed OS updates for Mac computers What to expect when Managed OS updates run on your device About Apple DDM and Managed OS in Iru Endpoint Understand compatibility and installation mechanisms for Managed OS on macOS # Understanding Managed OS for Apple Platforms Source: https://docs.iru.com/en/endpoint/library/managed-os/understanding-managed-os-for-apple-platforms How Managed OS enforcement works in Iru Endpoint across macOS, iOS, iPadOS, and tvOS, including rolling enforcement, phased rollout, and version options. This guide applies to Mac computers, iOS devices, iPadOS devices, and Apple TV ### About Managed OS Managed OS deploys and enforces OS updates across your fleet of Apple devices. Updates are delivered via [Declarative Device Management (DDM)](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) on supported versions. Which OS version a device receives when it updates depends on [Version Enforcement](#version-enforcement): **Rolling enforcement** and **Manually enforce a minimum version** install the latest Iru-approved update; **Enforce a specific version** enforces the OS version you select. For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos). ### Version Enforcement Under **Updates**, choose how OS updates are enforced. **Rolling enforcement** and **Manually enforce a minimum version** set a minimum version floor; **Enforce a specific version** targets an exact OS version by a deadline. | Option | Sets a floor? | OS version installed | Key configuration fields | | -------------------------------------- | ------------------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Do not manage updates** | No | No Managed OS enforcement | N/A | | **Rolling enforcement** | Yes (from Apple's release date) | Latest Iru-approved version | **Within** (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release**, **at**, optional **Delay enforcement by** (up to 90 days), optional **Enable phased rollout** and **Rollout window** | | **Manually enforce a minimum version** | Yes (admin-set minimum) | Latest Iru-approved version | Minimum version, **Enforcement Deadline**, **Enforcement Time**, optional **Enable phased rollout** and **Rollout window** | | **Enforce a specific version** | No (exact target) | Selected **Specific version** | **Specific version**, **Enforcement Deadline**, **Enforcement Time**, optional **Enable phased rollout** and **Rollout window** | #### Shared enforcement behavior * When [DDM](/en/endpoint/library/managed-os/declarative-device-management-and-managed-os) is in use, enforcement uses the device's local time zone. * When a new update is available in Iru Endpoint, it is cached on devices as soon as possible. After the update is cached, users are notified leading up to enforcement. On macOS, the Iru menu app displays rounded days (for example, if an update will be enforced in 7.6 days, 8 days is displayed). * **Rolling enforcement** and **Manually enforce a minimum version** install the latest Iru-approved OS version (shown in the upper-right corner of the Library Item). **Enforce a specific version** enforces the OS version you selected. #### Do not manage updates Iru Endpoint does not enforce an OS version. On macOS, this option cannot be used with **Upgrade automatically** under **Upgrades**, since **Upgrades** sets the major-version upgrade schedule and conditions separately from **Updates**. #### Rolling enforcement New OS updates are enforced automatically after release. You configure: * **Within**: How long after release (1 day, 2 days, 1 week, 2 weeks, 3 weeks, 1 month, 2 months, or 3 months) **of release** * **at**: The time of day the update is enforced * **Delay enforcement by** (optional): How many days (up to 90) to delay sending the target-version declaration. This does not change the enforcement date calculated from **Within** and **at**. Use it to temporarily hold back the newest available version while still using **Rolling enforcement**. The floor is calculated from Apple's release date. Devices receive the latest Iru-approved OS version when they update. To hide a new OS version from users for the same period, set a matching deferral in a [Software Update Library Item](/en/endpoint/devices/device-configurations/apple/delay-and-enforce-os-updates#configure-the-software-update-library-item). For example, if an OS update is released on July 22 and you set **Delay enforcement by** to 5 days and a 5-day Software Update deferral, users do not see that update until July 27. If **Delay enforcement by** is shorter than your Software Update Library Item deferral, Managed OS still sends its declaration before the deferral ends and overrides the deferral for that update. #### Manually enforce a minimum version You set the minimum OS version and an **Enforcement Deadline** (plus **Enforcement Time**). No update is enforced if a device is already above the minimum. Use this for critical security updates or to align the fleet to a version by a date. Devices below the minimum receive the latest Iru-approved OS version when they update. #### Enforce a specific version Uses the same version selection dropdown and enforcement scheduling fields as **Manually enforce a minimum version**: select a **Specific version**, an **Enforcement Deadline**, and an **Enforcement Time**. Unlike **Manually enforce a minimum version**, this option enforces that exact OS version on your deadline rather than treating it as a minimum floor. Use this when you need all devices on a particular version by a fixed date. To enforce an Apple beta build, select **This is a beta version** and choose a **Seed Token** synced from Apple to Iru. Iru applies **Software Update Settings** (beta enrollment) and then **Software Update Enforcement** (to the specified version) as separate declarations. For example, to test a beta upgrade to the next major macOS release, use a macOS Tahoe Managed OS Library Item, select a macOS Golden Gate seed token, and enter the target major version (such as `27.0`) and the current AppleSeed beta build. Managed OS is for beta program enrollment and a specific beta version together. To offer opt-in programs, enforce enrollment without a version, or enroll at ADE before management, see [Testing Apple Beta Releases](/en/endpoint/devices/device-configurations/apple/testing-apple-beta-releases#ways-to-manage-apple-beta-program-enrollment). The **Seed Token** list can be long and difficult to navigate. Iru checks hardware compatibility before enforcing **Enforce a specific version**, **Manually enforce a minimum version**, and **Rolling enforcement** targets. Devices that cannot run the required version are not forced to install an incompatible update. #### Phased rollout Select the **Enable phased rollout** checkbox under **Updates**, then enter the number of hours in the **Rollout window** field (24–168). Iru gradually rolls out the enforced update by staggering when each device receives its enforcement declaration across that window. Enforcement deadlines are unchanged, and OS upgrades and initial installs are unaffected. When each device becomes eligible (the reveal time), that timing appears on the Library Item **Status** tab, similar to [phased rollout for Mac Auto Apps](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#phased-rollout). See [Library Item Status Activity Timeline](/en/endpoint/library/library-items-profiles/library-item-status-activity-timeline). How declarations are staggered depends on the Version Enforcement option: * **Enforce a specific version**: When you create the Library Item, or when you change OS version settings or the enforcement date or time and save, declaration issuance is spread across the **Rollout window** starting from Library Item save. * **Rolling enforcement**: When Apple releases a new version, if **Delay enforcement by** is set, the update remains hidden until that delay ends. After the delay expires (or immediately if delay is not set), declaration issuance is spread across the additional **Rollout window** hours. * **Manually enforce a minimum version**: When you first create the Library Item, or when you change OS version settings or the enforcement date or time and save, distribution is spread across the **Rollout window** from Library Item save. When Apple releases a new version, new declaration issuance is spread across the **Rollout window** for the fleet. #### Background Security Improvements In the same Library Item you can configure **Background Security Improvements** (lightweight security updates from Apple). **Automatically enforce** under Background Security Improvements is separate from **Rolling enforcement** under **Updates** → Version Enforcement. For configuration steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos). ### macOS: Installation Options macOS Managed OS also lets you choose how major macOS upgrades are offered under **Upgrades**: * **Upgrade automatically**: Iru Endpoint forces the device to the latest version of this OS either immediately upon Library Item assignment, or on a specified date and time. Optionally make it **Available in Self Service** so users can install before the deadline. * **Upgrade on demand from Self Service**: Users upgrade through Self Service or Software Update with no enforced deadline. Use different copies of the same Managed OS Library Item with different [labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) to offer this in some Blueprints and automatic upgrades in others. **Updates** and **Upgrades** use separate enforcement schedules in the same Library Item. You can enforce minor macOS updates on one timeline and major upgrades on another. This avoids devices on an older major version appearing out of date and being forced to upgrade as soon as the Library Item is scoped. For UI steps, see [Configure Installation Method](/en/endpoint/library/managed-os/configure-managed-os-for-macos#configuring-managed-os-for-macos) in **Configuring Managed OS for macOS**. Additional macOS considerations: * Managed OS does not support downgrading macOS. * Do not block the Software Update System Settings pane; doing so is not compatible with Managed OS and can produce unexpected behavior. ### iOS, iPadOS, and tvOS: Supervision Managed OS for iOS, iPadOS, and tvOS requires supervision. At the enforcement deadline, on iOS and iPadOS devices with a passcode, users must be prompted for the update and enter their passcode. On tvOS, and on iOS and iPadOS devices without passcodes, updates apply without user intervention at the deadline. For details, see [User Experience with Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/devices/user-experience-with-managed-os-for-ios-ipados-and-tvos). ### Recommendations * **First time enforcing an OS version on your fleet:** Use **Manually enforce a minimum version** and set the **Enforcement Deadline** at least 5 days later so users get advance notifications. For UI steps, see [Configuring Managed OS for macOS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) or [Configuring Managed OS for iOS, iPadOS, and tvOS](/en/endpoint/library/managed-os/configure-managed-os-for-ios-ipados-and-tvos). * **Rolling enforcement and immediate update requirements:** If Apple has not released an update within your selected window (e.g. **Within 2 weeks of release**), all out-of-date devices may immediately be required to update and restart. * **Delay enforcement by and Software Update deferrals:** Use **Delay enforcement by** with a matching Software Update Library Item deferral when you want to hold back the newest version under **Rolling enforcement** and keep it hidden from users. Set both to the same number of days so Managed OS does not override the deferral early. See [OS Update Strategies: OS Deferral Restriction and Managed OS](/en/endpoint/devices/device-configurations/apple/os-update-strategies-os-deferral-restriction-and-managed-os). * **Phased rollout:** Select the **Enable phased rollout** checkbox and enter hours in **Rollout window** when you want declaration issuance staggered across the fleet instead of all at once. Pair it with **Delay enforcement by** under **Rolling enforcement** when a new Apple release should stay hidden until the delay ends, then spread over the **Rollout window**. * **Software Update Library Items:** If you use Managed OS, turn off automatic download of updates in any Software Update Library Items used in the same Blueprint to avoid conflicts with caching. On macOS, see also [Deployment Considerations](/en/endpoint/library/managed-os/managed-os-for-macos-compatibility-and-installation-mechanisms#deployment-considerations) in **Managed OS for macOS Compatibility and Installation Mechanisms**. ### Labels Use **labels** to tell copies of the same Managed OS apart when you add it to your Library more than once. See [Library Item Labels](/en/endpoint/library/library-items-profiles/library-overview#library-item-labels) in Library Overview. ### Related Articles Configure Managed OS updates for Mac computers Configure Managed OS updates for iOS, iPadOS, and tvOS devices Understand compatibility and installation mechanisms for Managed OS on macOS Understand how Managed OS works with DDM and macOS when troubleshooting updates About Apple DDM and Managed OS in Iru Endpoint What to expect when Managed OS updates run on your Mac What to expect when Managed OS updates run on iOS, iPadOS, and tvOS devices # Advanced Passport Troubleshooting Source: https://docs.iru.com/en/endpoint/library/passport/advanced-passport-troubleshooting Troubleshoot advanced Passport issues in Iru Endpoint. Diagnose token refresh failures, IdP sync problems, keychain errors, and login loop scenarios. This guide applies to Mac computers ### Login, Diagnostics, and Network At the Passport login window, always enter the user's full email address in the username field so the session uses your IdP instead of local authentication. For how the login window and visibility settings interact with Passport, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). If a user cannot sign in, open Iru Endpoint Passport Diagnostics with **Command-Shift-K-L** on the Mac. The panel surfaces useful detail, including error messages returned from your IdP. Passport must reach your IdP to validate credentials. When you customize the Passport login window, enable the network manager so users can join Wi-Fi if needed. The control respects AirPort security settings in macOS. Passport shows a Wi-Fi icon at the upper-right of the login window; users can click it to join a password-protected network. Passport does not support captive portals, click-through acceptance pages, or enterprise 802.1X networks that require a separate username and password in that flow. To isolate network issues, try a mobile hotspot or wired Ethernet while testing at the Passport login window. ### Ensure Surname (familyName) in Your IdP Passport requires a **familyName** value in IdP user attributes. Populate **Last name** or the equivalent surname field for every account that signs in with Passport, including service accounts you test with. ### Passport Supported IdPs The current Iru Endpoint Passport supported IdPs are [Google Workspace](/en/endpoint/library/passport/google-workspace/passport-configuration-with-google-workspace), [Microsoft Entra](/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad), [Okta](/en/endpoint/library/passport/okta/passport-configuration-with-okta), and [OneLogin](/en/endpoint/library/passport/onelogin/passport-configuration-with-onelogin). ### Passport Requirements when using Other IdPs [Passport configuration](/en/endpoint/library/passport/configure-the-passport-library-item) requires OIDC and ROPG (Resource Owner Password Grant) workflows to function. Check with your IdP to verify that they support these features. While Iru does offer the option to choose Mac Login or Web Login, set up Passport first using Mac Login, as there can be additional factors when configuring Web Login. You can reference the supported configurations using Google Workspace, Microsoft Entra, Okta, or OneLogin as a resource. * [Passport Configuration with Google Workspace](/en/endpoint/library/passport/google-workspace/passport-configuration-with-google-workspace) * [Passport Configuration with Microsoft Entra (formerly Azure AD)](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) * [Passport Configuration with Okta](/en/endpoint/library/passport/okta/passport-configuration-with-okta) * [Passport Configuration with OneLogin](/en/endpoint/library/passport/onelogin/passport-configuration-with-onelogin) If you're not using one of the identity providers above, you may still be able to configure Passport using the **Other** option. ### Configure Other IdP #### Authentication Configuration * When configuring an IdP other than Google Workspace, Microsoft Entra, Okta, or OneLogin, select the **Other** option from the **Identity provider** drop-down. #### Authentication Mode * If you **do not** use multi-factor authentication (MFA), you need to choose Mac Login. * If you **do** use multi-factor authentication (MFA), you need to choose Web Login. #### Mac Login Enter the **Identity provider URL**. Enter the **Client ID** of the Passport App that you created in your IdP (may also be called App ID) #### Web Login Enter the **Identity Provider URL** Enter the **Client ID** of the Passport App that you created in your IdP (may also be called App ID) When using Web Login, your app must support both PKCE (Proof Key for Code Exchange) authentication and POST authentication. Some IdPs may require configuring two different apps. The **Redirect URI** should be your IdP's default Redirect URI in most cases. ### Troubleshooting There are many factors to consider when troubleshooting Passport issues when selecting the **Other** option for the Passport IdP. This section helps you capture errors, understand them, and adjust configuration. **What you see:** `"error":"Unauthorized","error_description":"Authentication Failed: Invalid user credentials"` **What to do:** * Confirm the username and password with your IdP. * If the GET request to your OIDC well-known `openid-configuration` URL returns **200**, the **Identity provider URL** and **Client ID** in the Passport Library Item are typically reaching the IdP correctly. Your IdP may label the client identifier **Application ID**. **What you see:** `"error":"access_denied","error_description":"End-user does not have access to this application"` **What to do:** * In your IdP, confirm the user or group can access the Passport OIDC application and that sign-on or access rules allow it. * If the GET request to your OIDC well-known `openid-configuration` URL returns **200**, the **Identity provider URL** and **Client ID** in the Passport Library Item are typically reaching the IdP correctly. Your IdP may label the client identifier **Application ID**. **What you see:** Ticket decode failed. Failed to login with possible error: Unknown **What to do:** * Remove the optional **Client secret** from the Passport Library Item, let the device check in, sign out of the local user, and sign in again with Passport. * If the error persists, rule out network issues with a mobile hotspot at the Passport login window. **What you see:** An error occurred fetching user info: No key was found matching "familyName" **What to do:** * Populate **Last name** or the equivalent surname field for the user in your IdP. Passport requires that attribute. If you continue to experience issues with Passport, [reach out to Support](/en/iru/iru-support/support-customer-portal). #### Error Code Lookup Many IdPs will generate their own specific error codes. Check with your IdP to see if they have a lookup page for reading more about the specific error you are receiving from them. An example of this is the [error code form](https://login.microsoftonline.com/error) from Microsoft for looking up Entra errors. ### Related Articles Passport compatibility with macOS and Iru features How to manage passwords with Passport. # Configure the Passport Library Item Source: https://docs.iru.com/en/endpoint/library/passport/configure-the-passport-library-item Configure the Passport Library Item in Iru Endpoint to sync macOS login with your identity provider. Set up IdP authentication, password sync, and SSO. This guide applies to Mac computers ### About Passport Passport is a feature in Iru Endpoint that allows users to log into Mac computers using their organization's Identity Provider (IdP) credentials instead of separate local passwords. Passport connects the IdP to macOS login. Starting **June 15, 2026**, Microsoft Entra ID handles Conditional Access for Passport sign-in differently. * **Mac Login:** See [Entra ID Passport Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login#june-2026-conditional-access-change) to confirm whether your tenant is affected and what to update before that date. * **Web Login:** Updates are required only if you use Web Login and want to exempt Passport from MFA in Conditional Access. See [Entra ID Passport Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login#june-2026-conditional-access-change). Microsoft explains the change in [this documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions). ### How It Works Passport integrates with your Identity Provider (IdP) to authenticate users at the macOS login screen. When users enter their IdP credentials, Passport verifies them against your organization's identity system and creates or updates the local Mac user account accordingly. For more information about how Passport interacts with other Iru Endpoint and macOS features, see [Passport Compatibility with macOS & Iru Endpoint Features](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). ### Set Up Your IdP for Passport Set up your identity provider with Passport before you configure the Library Item in Iru Endpoint. Depending on your IdP and authentication mode, you will need the right values to enter in Iru Endpoint, such as the OIDC well-known configuration URL (issuer metadata URL), the application client ID, and, when your setup requires them, client secrets and redirect URIs. Use the guide that matches your IdP: Secure LDAP and certificate setup for Google Workspace. OIDC application and Passport Library Item setup for Okta. Use this guide when you need MFA with Passport. Use this guide when you do not need MFA with Passport. OIDC applications and Passport Library Item setup for OneLogin. If you use **Other** as the **Identity provider** in Iru Endpoint, use your vendor's documentation to obtain the issuer `.well-known/openid-configuration` URL and the client settings that match **Web Login** or **Mac Login** in your Passport Library Item. ### Create a Passport Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the new Passport Library Item a descriptive **Name** and assign it to your desired [Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints). Continue with **Authentication configuration**, **User provisioning**, **Access**, **Login window**, and **Help window** as described later in this article. When you are finished, select **Save** on the Library Item. ### Authentication Configuration In **Settings**, under **Authentication configuration**, select **Identity provider** and choose your IdP. If you use any **Identity provider** other than **Google Workspace**, skip this step and continue with **Enter Identity provider URL** below. Upload the compressed certificate from your Secure LDAP client in **Authentication configuration**. Skip ahead to [User provisioning](#user-provisioning). In the **Identity provider URL** field, enter the IdP's OIDC well-known configuration endpoint. The expected URL pattern depends on your IdP; use the tab that matches your **Identity provider** selection. If you are unsure of your tenant ID, follow the instructions located [here](https://learn.microsoft.com/en-us/entra/fundamentals/how-to-find-tenant) to find it. ```bash theme={null} https://login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration ``` ```bash theme={null} https://{yourOktaDomain}/.well-known/openid-configuration ``` ```bash theme={null} https://{subdomain}.onelogin.com/oidc/2/.well-known/openid-configuration ``` ```bash theme={null} https://{OIDCDomainURL}/.well-known/openid-configuration ``` In the **Client ID (Password Sync)** field, enter the client ID of the OIDC application configured in the identity provider's platform. Passport configuration interface showing Identity Provider URL and Client ID (Password Sync) fields The two modes work differently at the Mac login window: * **Web Login:** Passport shows a web view of your IdP's sign-in page. Users complete IdP sign-in (including multifactor authentication when your IdP requires it) inside that view. When your organization allows it, they can [sign in locally](/en/endpoint/library/passport/user-experience-with-passport#signing-in-with-only-your-mac-account-local-login). * **Mac Login:** Passport shows the Mac username and password fields only. Users enter their IdP credentials there; Passport checks them against the IdP without running the IdP's full web sign-in flow at the login window. Use **Web Login** if you need Passport to **support MFA** with your IdP at Mac sign-in. Use **Mac Login** if you **do not** need Passport to support MFA that way for your deployment. If FileVault is set to **Disallow automatic FileVault Login** and **Web Login** is selected, users need to authenticate three times in total after the device is powered on or restarted. If you selected **Web Login**, enter the redirect URI in the **Redirect URI** field as described in your IdP configuration article. If your IdP OIDC app uses a client secret, enter it in the **Client secret (optional)** field. That applies to **Mac Login** or **Web Login** when your app is configured with a secret in the IdP (for example, some Web Login apps use a confidential client). If you are unsure, follow your IdP configuration article. If you are using Microsoft Entra ID, the "Client Secret" is the Client Secret Value, not the Client Secret ID. Using the Client Secret ID will result in login errors. ### User Provisioning Configure the user provisioning settings you want to be applied when a user first logs in to the Mac. You can control how account types are assigned and what to do when an account already exists. Passport uses two attributes of a local Mac user account (which you can view using the `dscl` command or the Directory Utility app): * `dsAttrTypeNative:io.kandji.KandjiLogin.LinkedAccount`: contains a unique value specific to the IdP account; this varies and could be a number, email address, or unique identifier * `dsAttrTypeNative:io.kandji.KandjiLogin.LinkedAccountName`: contains a value from the RecordName attribute of the linked user account, for example, an email address Passport also adds an additional value to the RecordName attribute, the email address of the IdP account. When Passport creates a new local user account, Passport creates the local Mac account with the appropriate attributes and values. When Passport links with an existing local user account, Passport adds a value to the existing RecordName attribute, adding the two additional attributes and values to the existing local user account. In **User provisioning**, the **User account type** drop-down offers **Administrator** (default), **Standard**, and **Specify per identity provider group**. When Passport creates new local user accounts, their type follows this setting. * If you select **Administrator** or **Standard**, Passport checks a local account's permissions at the initial Passport login. * If you select **Specify per identity provider group** to configure the new account type based on IdP group membership: * With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user matches an **Identity provider group** row farther down, Passport uses that row's account type instead. * Ensure the group in the **Identity provider group** field in Iru Endpoint matches the group in your IdP * For Microsoft Entra ID, based on Microsoft's recommendations, use the Entra ID group Object ID instead of the group name. * For Google Workspace, the name entered should be the email prefix of the group in Google as opposed to the name of the group. * If a user is designated as an administrator in one group and a standard user in another, that user's account type will be **Administrator**. * When **Specify per identity provider group** is selected, Passport checks the user's group membership every time the user logs in. Passport updates the user's account type if you make a group membership change or a configuration change that would cause a user to: * change from a standard account to an administrator account * change from an administrator account to a standard account (this change forces the user to restart their Mac to demote the user account and ensure that the change is in effect) Select whether the user will be offered the option to link their IdP account with an existing local user. This option will be shown just once. * **Always.** This is the default setting. When a user logs in to the Mac using their IdP credentials, Passport will prompt the user to select an existing local Mac account they want to link to. It is a good option if you are unsure whether or not your users' IdP account names match their Mac account names. When **Always** is selected, you will see two additional options: * **Require linking to an existing local user:** The user will be required to link their IdP account to an existing local user account. * **Exclude local users:** Exclude specific accounts from the list of local users able to be linked during the user's initial login. Enter a short name in **Local user short name** and select **Add user** when you need more than one row. A common use case is preventing the user from being prompted to link an IT admin or service account. * **If a local username matches.** When a user logs in to the Mac using their IdP credentials, Passport will automatically find the Mac account with a matching username and prompt the user to link it. The user will not have the option to link to another account. * **Never.** When a user logs in using their IdP credentials, Passport will create a new user account on the Mac, regardless of existing accounts. ### Access Configure which users can log into the Mac and FileVault's automatic login behavior. Our [Managing Passwords with Passport](/en/endpoint/library/passport/managing-passwords-with-passport) article provides in-depth information regarding password management using Passport. These settings apply only to new or existing Passport users who authenticated against the IdP. Use **Local user access** below to control sign-in for other local users. * **Allow all users to log in** allows all IdP users to log into the Mac at the Passport login window. * **Specify which IdP users can log in** allows only users you specify to log into the Mac at the Passport login window. * **Automatically include user assigned to device record:** Automatically allows the user assigned to the device record in Iru Endpoint to log in. * **Specify additional IdP users:** Allows certain IdP users to log in, even if they aren't assigned to the device record in Iru Endpoint. Choose whether existing local users can sign in, or whether access is limited to local administrators or specific local users. * **Allow all local users to log in** allows all local users to log in to the Mac at the Passport login window. If the Mac is connected to a network and can reach the IdP, Passport will check the user's credentials against the IdP. If the Mac is not connected to a network, the user can log in with their local Mac account credentials. This is the default setting. * **Allow local administrators to log in** allows only local administrator users to log in to the Mac at the Passport login window. * **Specify which local users can log in** allows only users you specify to log into the Mac at the Passport login window. These options control FileVault pass-through authentication (also called automatic FileVault login): whether users can unlock FileVault and reach the desktop without a separate sign-in at the Passport window. * **Allow automatic FileVault login:** Users sign in only at the FileVault login window. They do not see the Passport login window unless they log out. The FileVault login window does not check credentials against an IdP. * **Disallow automatic FileVault login:** This is the default. Users see the Passport login window when they turn on their Mac. They sign in at the FileVault login window and again at the Passport login window. When **Disallow automatic FileVault login** is selected, users authenticate at the FileVault window and again at the Passport login window after each system reboot. Optionally store the user's current password in a dedicated keychain so Passport can handle password changes at the login window without extra prompts where possible. * **Securely store password:** Stores the user's IdP credentials in a dedicated keychain on their Mac to aid in password changes. When the user changes their password with their IdP and then logs in to the Mac, they only need to enter their new credentials; Passport will silently update the Mac password. If a user is already logged in and changes their password with the IdP, Passport will prompt them within 5 minutes to update their local password, and the user will not have to provide their local password; they will only have to enter their IdP password for Passport to change their local password to match their IdP password. The location of this keychain is `/Library/Keychains/iru.keychain`. If you remove that keychain, Passport will automatically create a new keychain in that location and use it without generating an error or notification to the user. * **Web Login Passthrough:** When this option is selected with **Web Login**, users will see an additional password verification screen only the first time they log in. The login process will be completed after a single authentication at the Web Login window on subsequent logins. * **Do not store password:** With this option set, Passport only checks and enforces password synchronization at login. If a user changes their password in between login sessions, their local password will remain out of sync until their next login. ### Customize Login Window You can customize the Passport login window for your users. Click **Customize** to reveal the **Customize login window** drawer with the following options: * **Display logo:** Include your organization's logo on the login window. If the Passport Library Item uses **Web Login**, Passport shows the web view instead of the logo until the user selects **Local Login**, which brings back the logo with the username and password fields. * **Logo:** Use a 128 x 128 pixel PNG with a transparent background. Drag the file into the upload area or select **upload**. JPEG and PNG are accepted. * **Customize Desktop picture:** Turn this on to upload a picture for the login window background. * **Desktop picture:** A 3840 x 2160 pixel JPEG or PNG is recommended. Drag the file into the upload area or select **upload**. * **Network manager:** Include the Wi-Fi network manager in the menu bar so users can connect at the Passport login window when they are not already on a network. * **Allow connecting to unsecured Wi-Fi networks:** When **Network manager** is on, users can use it to join networks that do not require encryption. Captive Portal networks are not supported. **Lock message:** Choose to display or hide a lock message. Options are **Don't display a lock message**, **Display a custom lock message**, and **Inherit system settings**. For a custom message, enter up to 220 characters in the text field. **Policy banner:** Choose to display or hide a policy banner. Options are **Don't display a policy banner**, **Display a plain-text policy banner**, **Display an RTF policy banner**, and **Inherit system settings**. Plain text accepts up to 900 characters. For RTF, use the drop zone or select **upload** to attach a file. Specify which power controls are available from the login window. By default, all three are enabled. * **Shut Down button** * **Restart button** * **Sleep button** * **Customize username label:** Add a custom label that appears in the username field. Up to 83 characters. * **Include password reset URL:** Allow users to reset their passwords from the login window. Enter the full URL, for example a value starting with `https://`. ### Customize Help Window Users select the Help **?** control in the bottom left of the Passport login window. The Help window that opens has three tabs across the top: **Support**, **Device info**, and **About**, matching what you configure here. In the Passport Library Item, click **Customize** to open the **Customize Help window** drawer. * **Header:** Required. Up to 30 characters. This text appears as the main heading on the Support tab, for example **Contact us**. * **Body text (optional):** Up to 250 characters. This text appears under the heading, for example instructions to contact the organization's IT department if login fails. Turn each toggle on or off to control whether that row appears on the Device info tab. By default, all of these options are enabled. * **Serial number** * **IP address** * **Hostname** * **macOS version** * **Model information** Shows the **Passport** name, a **Version** line with the build number, and the Iru copyright notice, similar to a standard macOS About window. ### Testing Passport When testing Passport: * You can use the command `sudo iru library` to force the new Passport Library Item configuration to be applied after making changes. * You can delete a user account associated with Passport using the Users & Groups settings (or Users & Groups preferences). * After you've performed these steps, you can safely log out and then attempt to log in again with new Passport settings using the credentials of a test IdP user account. ### Related Articles How to manage passwords with Passport. Passport compatibility with macOS and Iru features # Passport Configuration with Google Workspace Source: https://docs.iru.com/en/endpoint/library/passport/google-workspace/passport-configuration-with-google-workspace Set up Passport with Google Workspace in Iru Endpoint. Configure OAuth credentials, enable user authentication, and sync macOS passwords with Google. This guide applies to Mac computers ### About Passport with Google Workspace Passport with Google Workspace enables users to log into Mac computers using their Google Workspace credentials. Passport uses your organization's Google identity system at macOS login. ### How It Works Passport integrates with your Google Workspace instance using Secure LDAP to authenticate users at the macOS login screen. When users enter their Google Workspace credentials, Passport verifies them against your Google directory and creates or updates the local Mac user account. ### Prerequisites * Your organization's Google Workspace instance needs to support Secure Lightweight Directory Access Protocol (LDAP). Google has a list of supported licenses for the LDAP service [here](https://support.google.com/a/answer/9100761). * Every Google Workspace user who will sign in with Passport must have a Cloud Identity Premium license assigned in Google Workspace. * You need access to your organization's super administrator account. * If your web browser automatically uncompresses .zip files, temporarily change that setting and download the file again, or compress the uncompressed folder before you upload it to your Passport Library Item. ### Create a Secure LDAP Client and Download the Certificate Passport uses Secure LDAP to communicate with Google to confirm login credentials and gather basic user and group information. When you create a new Secure LDAP client in Google Workspace, you'll download a certificate to secure communications and turn the service on. In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com). In the left sidebar, click **Apps**. In the Apps section, click **LDAP**. If **LDAP** does not appear, your edition may not include Secure LDAP. Business Starter and Business Standard do not offer the Secure LDAP service. If your organization already has one or more Secure LDAP clients, they appear in the list on the **LDAP** page you opened in the previous step. In the upper-right corner, select **ADD CLIENT** to create another client for Passport. Google Workspace LDAP apps page with existing LDAP clients and ADD CLIENT button in the header If your organization does not have any Secure LDAP clients yet, the LDAP apps page shows **ADD LDAP CLIENT**. Select **ADD LDAP CLIENT** to start creating the client for Passport. Google Workspace LDAP apps page with no LDAP clients and ADD LDAP CLIENT button In the **LDAP client name** field, enter a name like **Iru Passport**. In the **Description** field, enter a description like **Passport: keep Mac login passwords in sync with Google Workspace**. Select **CONTINUE**. Google Workspace Add LDAP client form showing LDAP client name, Description, CANCEL, and CONTINUE In the **Verify user credentials** section, select either **Entire domain** (your domain appears in parentheses), or if you want to limit Passport to certain accounts, select **Selected organizational units, groups and excluded groups**. Google Workspace Add LDAP client Step 2 Access permissions with Verify user credentials and Entire domain option In the **Read user information** section, configure the same settings as you did in **Verify user credentials** (for example **Entire domain** or **Selected organizational units** when those options appear). Confirm that the checkbox for **System Attributes** is selected so that Passport can read the default user attributes. Leave **Public Custom Attributes** and **Private Custom Attributes** deselected; Passport will not use custom user attributes. Google Workspace Add LDAP client Read user information with System Attributes checked and Public and Private Custom Attributes unchecked In the **Read group information** section, set the switch to **On** so you can configure Passport to use a user's Google Workspace group information to dynamically convert their local Mac account between standard and administrator privileges when they log in. You can turn this option on later if you don't turn it on now. Review your configuration, then select **ADD LDAP CLIENT**. Google Workspace Add LDAP client Read group information On with BACK and ADD LDAP CLIENT buttons Select **Download certificate**. Select **CONTINUE TO CLIENT DETAILS**. Google Workspace Add LDAP client success with Download certificate and CONTINUE TO CLIENT DETAILS In the **Service status** section, select **OFF** or the disclosure control (chevron) to open the flow where you can turn the LDAP service on. Google Workspace Settings for LDAP client with Service status OFF and Authentication section On the **Service status** page, select **ON for everyone**. Select **SAVE**. Google Workspace Service status with ON for everyone selected and SAVE and CANCEL ### Re-Download Your Secure LDAP Certificate (Optional) After you configure the LDAP client in the previous section, you can always download the certificate that's used to secure the LDAP communication between Passport and Google. There are many other options, including renaming a certificate, generating additional certificates, and deleting a certificate. In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com). In the left sidebar, click **Apps**. In the Apps section, click **LDAP**. In the list of LDAP clients, select the LDAP client you created for use with Passport. Google Workspace LDAP apps list with Passport LDAP client selected Open the **Authentication** section for the client. Google Workspace Settings for LDAP client with Authentication section and certificates summary In **Certificates**, select the download icon for the certificate row. The control’s tooltip reads **Download certificate**. Google Workspace Authentication Certificates with download icon and GENERATE NEW CERTIFICATE ### Collect Group Email Prefixes for User Provisioning If you want Passport to set each user's Mac account type from Google group membership, collect the **Group email** prefix for each group you plan to map. You will use those values under **User provisioning** on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). In Google Admin, open a group you want to use for Passport user provisioning. From **Group email**, copy everything before the **@** symbol. Passport expects that prefix in the Library Item, not the group's display name. Paste the prefix into a secure text document or internal runbook. If you use several groups, note which prefix belongs to which group. Repeat the previous steps for every Google group you plan to reference in Passport. When the Secure LDAP client and certificate are ready, open the [**Iru Endpoint** tab](#iru-endpoint) to upload the certificate and complete the Library Item steps there. ### After Initial Setup #### Certificate Expiration and Renewal Google Workspace Secure LDAP certificates expire. Generate, download, and upload a replacement before the current certificate expires so Passport can keep authenticating users without interruption. Sign in to the Google Admin console, open **Apps** → **LDAP**, then select the LDAP client you use for Passport. Google Workspace LDAP apps list with Passport LDAP client selected Open the **Authentication** section for that client. Google Workspace Authentication with certificate table and expiration date Note the **Expiration date** in the certificate table (and **Earliest Certificate Expires in** on the **Apps** → **LDAP** client list if you use that column) so you can plan renewal ahead of time. In **Certificates**, select **GENERATE NEW CERTIFICATE**. Do not wait until the current certificate has already expired if you can avoid it. Google Workspace Authentication Certificates with GENERATE NEW CERTIFICATE Download the new certificate bundle using the same download icon as in [Re-download Your Secure LDAP certificate](#re-download-your-secure-ldap-certificate-optional) (tooltip **Download certificate**). Google Workspace Authentication Certificates with Download certificate tooltip on download icon In Iru Endpoint, open the [**Iru Endpoint** tab](#iru-endpoint) and use [**Certificate expiration and renewal**](#replace-google-workspace-certificate-in-passport) to remove the old compressed certificate, upload the new bundle, and save. Return to the **Authentication** section for your Passport LDAP client in Google Admin. For the **previous** certificate row, open the row **More** menu (vertical ellipsis) and select **DELETE CERTIFICATE**. Google Workspace Authentication Certificates row menu open with DELETE CERTIFICATE In the **Delete certificate** dialog, read the warning, then select **DELETE** to confirm (or **CANCEL** to go back). Google Workspace Delete certificate dialog with CANCEL and DELETE For the next steps in this workflow, open the [**Iru Endpoint** tab](#iru-endpoint) and follow [**Certificate expiration and renewal**](#replace-google-workspace-certificate-in-passport). If you have not already, use [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) to add the Passport Library Item and set **Name** and **Blueprints**. The steps below are the **Iru Endpoint** configuration specific to Google Workspace Passport. ### Library Item Configuration Provide the certificate that you downloaded from Google Workspace. In the **Settings** section, in the **Authentication configuration** section, click **Identity provider** and select **Google Workspace**. In **Upload certificate from Google Workspace**, drag your **.zip** file into the dashed area, or select **click to upload** to pick the same **.zip** from Google Workspace. Passport Library Item Authentication configuration with Google Workspace selected and Upload certificate from Google Workspace In the **Choose Files to Upload** window, navigate to the folder that contains your compressed certificate file and select the compressed certificate file. Click **Upload**. If you see the **Validating file** message, wait a few moments for the validation to complete. Passport Library Item showing Validating file while the Google Workspace certificate is processed Confirm that the compressed certificate file is displayed. Passport Library Item showing uploaded compressed certificate under Upload certificate from Google Workspace ### User Provisioning If you want Passport to set each user's Mac account type from Google group membership, use the **User provisioning** steps below on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). Use the **Group email** prefixes from **Collect group email prefixes for user provisioning** on the [**Google Workspace** tab](#google-workspace). In the Passport Library Item, click the User account type menu in the User provisioning section and select **Specify per identity provider group**. With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user's IdP group membership returns both Administrator and Standard account types, the user is designated an Administrator. In each **Identity provider group** field, enter the part of **Group email** before the **@** symbol, not the group's display name. Add a row for each additional group as the Library Item shows, matching the prefixes from your document. For each **Identity provider group** row, set the **Account type** as appropriate. Passport Library Item User provisioning with Identity provider group rows and Account type In the Passport Library Item, click **Save**. When **User provisioning** and related saves are complete in the Passport Library Item, switch back to the [**Google Workspace** tab](#google-workspace) if you need to confirm the Secure LDAP client or download the certificate again. ### After Initial Setup #### Certificate Expiration and Renewal Use these steps after you finish [**Certificate expiration and renewal**](#renew-secure-ldap-certificate-google-workspace) on the [**Google Workspace** tab](#google-workspace), when you need Iru Endpoint to trust the new certificate bundle instead of the old one. In Iru Endpoint, open the **Library**, then open your Passport Library Item. Confirm **Identity provider** is set to **Google Workspace** under **Authentication configuration**. In **Upload certificate from Google Workspace**, select the **trash** icon on the existing certificate file row to remove it. Passport Library Item Authentication configuration with Upload certificate from Google Workspace and trash icon on the zip file Upload the **new** compressed certificate file you downloaded from Google Admin (the same file type and flow as in [Library Item configuration](#library-item-configuration) above). Select **Save** on the Passport Library Item. ### Troubleshooting If a user enters the correct Google Workspace email address and password but still cannot sign in with Passport, verify that they meet the [Cloud Identity Premium license requirement](#cloud-identity-premium-license) for Passport. In Google Admin, open **Users**, select the user, then open **Licenses**. Confirm that **Cloud Identity Premium** is assigned to that user and enabled. If it is missing, assign the license, then have the user try again. Passport cannot authenticate users if the Secure LDAP certificate in Google Workspace has expired or is rejected. On the [**Google Workspace** tab](#google-workspace), [Certificate expiration and renewal](#renew-secure-ldap-certificate-google-workspace) walks through generating and downloading a new certificate in Google Admin and removing the old certificate there. On the [**Iru Endpoint** tab](#iru-endpoint), [Certificate expiration and renewal](#replace-google-workspace-certificate-in-passport) covers updating the Passport Library Item. Plan renewal before the expiration date so users do not lose sign-in access. # Managing Passwords with Passport Source: https://docs.iru.com/en/endpoint/library/passport/managing-passwords-with-passport Manage macOS local account passwords with Passport in Iru Endpoint. Understand password sync behavior, change workflows, and expiration handling with your IdP. This guide applies to Mac computers ### About Managing Passwords with Passport Passport password management refers to how Passport handles password synchronization between your Identity Provider and local Mac user accounts. This includes automatic password updates, secure storage, and password reset capabilities. For setup and Library Item configuration, see [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item). ### How It Works Passport can securely store user credentials and automatically synchronize password changes between your Identity Provider (IdP) and the local Mac account. When users change their IdP password, Passport can detect this change and update the local Mac password so the two stay in sync. ### Login, Diagnostics, and Network At the Passport login window, always enter the user's full email address in the username field so the session uses your IdP instead of local authentication. For how the login window and visibility settings interact with Passport, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). If a user cannot sign in or password sync seems wrong, open Iru Endpoint Passport Diagnostics with **Command-Shift-K-L** on the Mac. The panel surfaces useful detail, including error messages returned from your IdP. Passport must reach your IdP to validate credentials and sync passwords. When you customize the Passport login window, enable the network manager so users can join Wi-Fi if needed. The control respects AirPort security settings in macOS. Passport shows a Wi-Fi icon at the upper-right of the login window; users can click it to join a password-protected network. Passport does not support captive portals, click-through acceptance pages, or enterprise 802.1X networks that require a separate username and password in that flow. To isolate network issues, try a mobile hotspot or wired Ethernet while testing at the Passport login window. For more on Wi-Fi at the login window, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#network-wi-fi). ### Ensure Surname (familyName) in Your IdP Passport requires a **familyName** value in IdP user attributes. Populate **Last name** or the equivalent surname field for every account that signs in with Passport, including service accounts you test with. ### Password Configuration #### Recommended Password Sync Configuration To give users the most independent experience and reduce password-related support requests, configure the following in the Passport Library Item. 1. Enable password syncing. In the Passport Library Item, set **Store user password** to **Securely store password** in the Access section so Passport can sync IdP and local passwords automatically. For more on how syncing works, see [Password Syncing with the identity provider](#password-syncing-with-the-identity-provider). 2. Set the password reset URL in the Login Window. In [Customize Login Window](/en/endpoint/library/passport/configure-the-passport-library-item#customize-login-window), configure **Include password reset URL** so users can reset their IdP password from the login window or the Iru Endpoint menu app without contacting support. You can enable either setting on its own, but you will not get both behaviors. With only password syncing, changes sync automatically but users cannot reset their password via the IdP URL. With only the password reset URL, users can reset their IdP password but their local Mac password will not sync. #### Passport & Passcode Conflicts It is highly recommended to remove the Passcode Library Item from any Blueprint containing Passport. Your IdP should handle password requirements; otherwise users may see the error below. [Learn more](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#passcode) in Passport Compatibility. When the Passcode Profile is applying a password requirement that is higher than the requirements defined by the IdP, the following message is displayed to the user at the Passport Login Window: **Message shown to the user** The password you entered doesn't yet meet the passcode policy requirements for this Mac; please contact your IT administrator for help. This Mac has a local passcode policy that applies to passwords that have been changed or created since the policy was put in place. This is common when the Mac passcode policy conflicts with the Identity Provider passcode policy. To resolve this issue, remove the Passcode Library Item from any Blueprints that also contain Passport. ### Password Experience #### Recommended Order for Password Changes For the best result, users should change or reset their password in this order: 1. Change their password with your organization's IdP. 2. If a [Passport Reset URL](/en/endpoint/library/passport/configure-the-passport-library-item#customize-login-window) is configured, users can reset their IdP password from the Iru Endpoint menu app or the Passport Login Window. 3. Let Passport sync the local Mac password to match (Passport will prompt the user or update it automatically). #### Password Reset at the Iru Endpoint Menu App Users can reset their IdP password from the Iru Endpoint menu by clicking the gear icon and choosing the **Reset Password...** option. They are sent to the Passport reset URL set in your Passport Library Item. * **Requirement:** The **Reset Password...** option is shown only when the user is logged in with their full email address. To walk users through the steps, share the [Reset password from the menu bar (while logged in)](/en/endpoint/library/passport/user-experience-with-passport#reset-password-from-the-menu-bar-while-logged-in) section from the User Experience with Passport article. #### Password Reset at the Passport Login Window If the password reset URL is configured in the Passport Library Item, Passport shows a reset link after a user enters an incorrect IdP password three times at the Passport (local) login window. * **Requirement:** **Include password reset URL** must be enabled in [Customize Login Window](/en/endpoint/library/passport/configure-the-passport-library-item#customize-login-window). To walk users through the steps, share the [Reset password at the login screen](/en/endpoint/library/passport/user-experience-with-passport#reset-password-at-the-login-screen) section from the User Experience with Passport article. ### Password Syncing with the Identity Provider The **Store user password** setting in the Passport Library Item, in the [Access](/en/endpoint/library/passport/configure-the-passport-library-item#access) section, controls how Passport syncs IdP and local Mac passwords. The two options behave as follows. #### Securely Store Password Passport stores credentials and can automatically sync the local password with the IdP password. * **Logged out:** If a user changes their IdP password and then signs in at the Passport login window, Passport updates the local password to match automatically. * **Logged in:** If a user changes their IdP password while logged in, Passport prompts them within 5 minutes; the user enters only their IdP password and Passport updates the local password. #### Do Not Store Password Passport does not store the local password. The user must provide it whenever Passport syncs. * **Logged out:** If a user changes their IdP password and then signs in at the Passport login window, Passport asks for their local password before updating it to match. * **Logged in:** If a user changes their IdP password while logged in, Passport prompts within 5 minutes; the user must enter both their local password and their IdP password to update. * **Login with new IdP password but old local password:** If the user signs in with their new IdP password and their local password does not match, Passport prompts for the old local password. With **Do not store password**, the user must enter both passwords. #### Password Syncing with Okta When using Okta with Passport, set **Refresh Token** in your Passport OIDC application as follows: * **Refresh Token disabled (recommended):** Use this when **Store user password** is set to **Securely store password**. If Refresh Token is left enabled, Passport will not prompt users to update their password while they are logged into their Mac. * **Refresh Token enabled:** Use this only when **Store user password** is set to **Do not store password**, to avoid users being repeatedly prompted for their credentials while logged in. For setup and options, see [Passport Configuration with Okta](/en/endpoint/library/passport/okta/passport-configuration-with-okta). For issues, see [Passport Troubleshooting with Okta](/en/endpoint/library/passport/okta/passport-troubleshooting-with-okta). ### Password Changes in System Settings If a user changes their password locally in System Settings, it will go out of sync with Passport. Passport will then prompt the user for their new local password to bring the local password back in sync, which sets the local password to match the IdP. Users should change their password with their IdP so that Passport can sync it with their Mac. To prevent users from changing their password in System Settings, use an [Apple Restrictions Library Item](/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item) and enable **Disallow passcode modification** in the [**Passcode & authentication**](/en/endpoint/library/library-items-profiles/configure-the-restrictions-library-item#passcode-and-biometric-settings) group. With this restriction applied, the option for users to change their password in System Settings will be inactive. ### Password Check Frequency Passport checks the user's password every 5 minutes and every online login from the login window. These checks ensure that the local account password and the user's IdP password are the same. If they aren't, the user is prompted to provide their IdP password. ### Troubleshooting **What you see:** Users do not see a way to reset their IdP password from the Passport login window or the Iru Endpoint menu app. **What to do:** * Follow [Recommended password sync configuration](#recommended-password-sync-configuration): enable password syncing as needed and set **Include password reset URL** in [Customize Login Window](/en/endpoint/library/passport/configure-the-passport-library-item#customize-login-window). * Remember that at the **FileVault login window** (before the disk unlocks), the menu app and Passport reset URL are not available. Use [Password reset at the FileVault login window](#password-reset-at-the-filevault-login-window) when the user is stuck there. **What you see:** The user needs to reset a password while only the FileVault pre-boot screen is shown (after power on or restart, before the normal login screen). **What to do:** * The startup disk is still encrypted and Iru Endpoint and Passport are not running there, so the password reset URL and menu app cannot be used. Unlock with the **FileVault recovery key** and reset the local password using the steps in [If FileVault 2 is Enabled](/en/endpoint/devices/device-actions/reset-a-macos-user-password#if-filevault-2-is-enabled) in [Reset a macOS user password](/en/endpoint/devices/device-actions/reset-a-macos-user-password). * After the user reaches the Passport login window, they can align the IdP password using the reset URL if you configured it. See [Password Reset at the Passport Login Window](#password-reset-at-the-passport-login-window). # Configure Passport Mac Login with Microsoft Entra ID Source: https://docs.iru.com/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login Configure Passport with Microsoft Entra ID for Mac Login in Iru Endpoint. Enable macOS login screen authentication with Entra ID credentials. This guide applies to Mac computers ### About Passport with Microsoft Entra ID Mac Login Passport with Microsoft Entra ID Mac Login signs users in at the Mac login window with their Microsoft Entra ID username and password. For Web Login (Microsoft Entra ID sign-in in the Passport web view, including when you need MFA), use [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login). Starting **June 15, 2026**, Microsoft Entra ID handles Conditional Access for Passport sign-in differently when the enforcement change applies to your tenant. See [Required changes before June 15, 2026](#june-2026-conditional-access-change) to confirm whether you are affected. Microsoft explains the change in [this documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions). If you are setting up Passport for the first time, continue from the beginning of this article. The setup instructions already include these updates. ### How It Works Passport integrates with your Microsoft Entra ID tenant to authenticate users at the macOS login screen using standard username and password fields. When users enter their Entra ID credentials, Passport verifies them against your tenant and creates or updates the local Mac user account. ### Prerequisites * Access to a Microsoft Entra ID admin account that can grant the Passport app the correct permissions. ### Create the App Registration Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a Global Administrator account. Open the portal menu and then select **Identity**. On the **Identity** menu, under **Applications**, select **App registrations**. On the **App registrations** page, on the menu, select **+ New registration**. On the **Register an application** dialog, enter a name for the new application (such as *Iru Passport Mac Login*). Under **Supported account types**, open the drop-down and select **Single tenant only** (the option also shows your tenant name, for example **Single tenant only - *Accuhive***). Passport should be single-tenant in your organization only. See [Register an application in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app). In the **Redirect URI** section, in the **Select a platform** drop-down, choose **Web**. In the URI field, enter the following: `https://localhost.redirect` For more information about redirect URI restrictions, platform types, and best practices, see [Microsoft's redirect URI documentation](https://learn.microsoft.com/en-us/entra/identity-platform/reply-url). Click **Register**. ### Configure Application Details Open a secure text document where the values for this OIDC app can be temporarily stored. You will need these details when you [configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item). On the **Overview** page, copy the **Application (client) ID** to a temporary secure text document. While still on the Overview page, click **Endpoints**. Copy the **OpenID Connect metadata document** (identity provider URL) to your temporary secure text document. On the left, select **Authentication**, then click **Settings**. Set **Allow public client flows** to **Enabled**. Click **Save**. On the left, select **Token configuration**. Click **Add optional claim**. For the Token type, select **ID**. For the Claim, select **preferred\_username**. Click **Add**. While still on the Token configuration page, click **Add groups claim**. Select **All groups**. Entra ID SAML only supports up to 150 security groups. If you have more than 150 security groups, you should not use **All groups**, but rather select specific groups. You can read more in Microsoft's [Configure group claims for applications by using Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-group-claims) article. Click **Add**. Once you complete the token configurations, you will see both optional claims. ### Configure API Permissions Select **API Permissions**. Click **Add a permission**. Click **Microsoft Graph**. Select **Delegated permissions**. Confirm that the **OpenID permissions** section is expanded. If it is not expanded, click the expand icon next to **OpenID permissions**. Select **email**. Select **profile**. In the **Select permissions** field, enter **User.Read**. In the User section, confirm that **User.Read** is already selected. If **User.Read** isn't selected, select it. Click **Add permissions**. While still on the API permissions page, select **Grant admin consent for \[your tenant]**. Select **Yes**. You should see a notification similar to the one below, and you should see a "Granted for \[your tenant] ..." message in the Status column next to each permission. Microsoft Entra ID API permissions showing Granted for tenant status ### Assign Users and Groups By default, when you create a new App registration, the "Assignment required?" attribute is set to "No". However, if your Passport Enterprise app is set to require assignment, follow these steps to assign users so they can use your Passport app. In the Entra ID navigation menu on the left, select **Enterprise Apps**. In the All applications list, select **Iru Passport Mac Login** or whatever name you named the App registration in the previous section. Entra ID Enterprise applications list with Iru Passport Mac Login Under **Manage**, select **Properties**. Optionally, add a logo to your Enterprise App. Inspect the **Assignment required?** setting. If it is set to "No," then you can skip the rest of this section. All users in Entra ID will be able to use the Passport app. Confirm that **Visible to users?** is set to **No**; otherwise, users will see the app in their portal. The Passport app is only useful as a replacement for the macOS login window. Click **Save**. Entra ID Passport Properties with Visible to users set to No If the **Assignment required?** setting is set to "No," you can skip the remaining steps in this section and continue to the next section. If it is set to "Yes," proceed with the following steps to assign users and groups. Under **Manage**, select **Users and Groups**. Entra ID Passport Properties with Assignment required Yes and Users and groups On the menu, select **+ Add user/group**. On the **Add Assignment** dialog, select the link under **Users and groups**. Entra ID Passport Users and groups with no assignments A list of users and security groups is displayed. You can search for a specific user or group or select multiple users and groups that appear in the list. After you have selected your users and groups, select **Select**. If you see the message below, it means that a free tier is being used. You can only add users (not groups) to the Passport Enterprise App. Groups are not available for assignment due to Active Directory plan level Select **Assign** to finish the assignment of users and groups to the app. Entra ID Add Assignment Users and groups picker with Select Confirm that the users and groups you added appear in the **Users and groups** list. Entra ID Add Assignment with users selected and Assign button With this portion of the Entra ID configuration complete, review the remaining sections of this article for your Microsoft Entra ID environment. Entra ID Passport Users and groups with assigned users ### Microsoft Entra ID Conditional Access Considerations [Microsoft Entra ID Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/) is included with Microsoft Entra ID Premium or better. Be sure to turn off both per-user MFA and Security defaults before you turn on Microsoft Entra ID Conditional Access policies. Complete the steps below to register **Passport - CA Policy API**, add its scope to your Passport app, and exclude that app from applicable policies. Skip this section if you do not use Conditional Access. When you finish, add the scope under **Additional scopes (optional)** in [Authentication Mode](#authentication-mode) on the [Iru Endpoint](#iru-endpoint) tab. #### Create the Passport - CA Policy API application Create this application registration so Passport can request a scope beyond baseline scopes. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Select **+ New registration**. Enter **Passport - CA Policy API** as the name, under **Supported account types** select **Single tenant only**, and leave **Redirect URI** empty. Select **Register**. Open **API permissions**. If admin consent is not already granted, select **Grant admin consent for \[your tenant]**. Open **Expose an API** in the left navigation. Select **+ Add a scope**. Review the **Application ID URI**. Entra ID suggests a default value (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a`). The default is fine. Select **Save and continue**. You do not need to copy this URI; copy the scope URI in **Copy the scope URI** below. For **Scope name**, enter `Passport` without spaces or special characters. Leave **Who can consent** at the default. Enter a display name and description in the **Admin consent** fields, then select **Add scope**. Microsoft Entra ID Expose an API scope list showing the Passport scope URI and Enabled state Next to the scope URI in the **Scopes** list (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a/Passport`), select **Copy**. Save it for **Add Additional scopes** in [Authentication Mode](#authentication-mode) on the [Iru Endpoint](#iru-endpoint) tab. #### Add the custom scope to your Passport app registration If you aren't already signed in, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Open the application you use for Passport **Mac Login**. Open **API permissions** and select **+ Add a permission**. Open the **APIs my organization uses** tab and select **Passport - CA Policy API**. Select **Delegated permissions**, select the **Passport** permission, then select **Add permissions**. Select **Grant admin consent for \[your tenant]**. Microsoft Entra ID API permissions for Passport showing Microsoft Graph and Passport - CA Policy API delegated permissions #### Exclude Passport - CA Policy API from All resources policies If you use Conditional Access, exclude **Passport - CA Policy API** from each policy scoped to **All resources**. Policies scoped to **All resources** include sign-ins that use the `openid` scope. Excluding **Passport - CA Policy API** removes the MFA requirement for ROPG, which Passport uses for password verification and synchronization in **Mac Login**. In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Protection** > **Conditional Access** > **Policies**. Select each policy scoped to **All resources**, then open **Target resources**. Open the **Exclude** tab, select **Select resources**, then select **Passport - CA Policy API**. Select **Select**, then **Save**. Microsoft Entra ID Conditional Access policy Exclude tab showing Passport - CA Policy API selected under Select specific resources Repeat these steps for every Conditional Access policy scoped to **All resources**. If **Save** fails, confirm that **Passport - CA Policy API** does not allow public client flows. If the app has a redirect URI configured, remove it and try again. ### User Account Provisioning via Passport If you want Passport to set each user's Mac account type from Entra ID security group membership, collect each group's **Object ID** in the Microsoft Entra admin center using the steps in this section. You will use those values under **User provisioning** on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). For more detail on this mode, see [User provisioning](/en/endpoint/library/passport/configure-the-passport-library-item#user-provisioning) in **Configure the Passport Library Item**. The number of security groups supported by Entra is 150 for SAML assertions. In larger organizations, the number of groups where a user is a member might exceed the limit that Microsoft Entra ID applies before emitting group claims in a token. Exceeding this limit will cause Microsoft Entra ID to omit group claims from the token. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). In the Identity navigation menu on the left, open **Groups** and select **All groups**. Select the group that you want to use. Entra ID All groups list with Mac Computer Admin Users Copy the **Object ID** for that group. Entra ID group Overview with Object ID For each additional Entra ID group you want to use, repeat **Select group** and **Copy Object ID**. Keep the **Object ID** values in a secure document until you enter them on the [**Iru Endpoint** tab](#iru-endpoint). Configure **Authentication mode** and **User provisioning** in the Passport Library Item on the [**Iru Endpoint** tab](#iru-endpoint). If you have not already, use [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) to add the Passport Library Item and basic settings. The steps below are Microsoft Entra ID **Mac Login** fields in the Passport Library Item; use the **Application (client) ID** and OpenID Connect metadata URL from the [Microsoft Entra ID](#microsoft-entra-id) tab. ### Authentication Mode Set **Authentication mode** to **Mac Login** so users sign in with their Microsoft Entra ID username and password at the Mac login window. In the Passport Library Item, set **Identity provider** to **Microsoft Entra ID**. In the **Identity provider URL** field, paste the **OpenID Connect metadata document** URL from the app registration on the [Microsoft Entra ID](#microsoft-entra-id) tab. In the **Client ID (Password Sync)** field, paste the **Application (client) ID** from the app registration on the [Microsoft Entra ID](#microsoft-entra-id) tab. Complete this step only if you completed [Microsoft Entra ID Conditional Access Considerations](#microsoft-entra-id-conditional-access-considerations). If you skipped that section, continue to **Select Mac Login**. Paste the scope URI you copied from **Create the Passport - CA Policy API application** into **Additional scopes (optional)**. This field appears below **Client ID (Password Sync)**. Passport Library Item Additional scopes field showing the Passport - CA Policy API scope URI Under **Authentication mode**, select **Mac Login**. Click **Save** on the Passport Library Item. ### User Provisioning If you want Passport to set each user's Mac account type from Entra ID security group membership, use the steps below under **User provisioning** on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). Collect each group's **Object ID** in Entra ID first. See [User Account Provisioning via Passport](#user-account-provisioning-via-passport) on the [Microsoft Entra ID](#microsoft-entra-id) tab. In the **User provisioning** section, open **User account type** and select **Specify per identity provider group**. With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user's IdP group membership returns both Administrator and Standard account types, the user is designated an Administrator. In each **Identity provider group** field, enter the Entra ID group **Object ID** as a GUID, not the group display name. For each **Identity provider group** row, set the **Account type** as appropriate. Passport Library Item user account type by Entra ID identity provider group Click **Save**. When the Passport Library Item is saved, return to the [Microsoft Entra ID](#microsoft-entra-id) tab if you need to change the app registration, **Passport - CA Policy API** exclusions, or group **Object IDs**. ## Required Changes Before June 15, 2026 On **June 15, 2026**, Microsoft Entra ID starts enforcing Conditional Access more broadly for policies that target **All resources** (formerly **All cloud apps**) and include **resource exclusions**. Sign-ins that request only **baseline scopes**, including `openid`, `profile`, `email`, and `User.Read`, will be subject to those policies. If you are not licensed for Conditional Access, this change does not apply to your organization. It applies only when policies target **All resources** with one or more **resource exclusions** and users sign in through applications that request only baseline scopes. If you do not use that policy layout, you are not affected. Policies that target **All resources** with no resource exclusions are also outside this change. Passport **Mac Login** requests those scopes as a public client. If this change applies to your tenant and you already use **Mac Login**, complete the relevant updates below before **June 15, 2026**. If you skip them, sign-in and password sync can break once enforcement begins. If you are configuring Passport **Mac Login** for the first time using this article, the **Microsoft Entra ID** and **Iru Endpoint** tabs above already include these updates. Read [Enforcement for baseline scopes in Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions) for more detail. ### If you skip these updates If you do not prepare before **June 15, 2026**: * New users might not be able to sign in with Passport. * Password sync and state management can stop working. * Microsoft Entra ID might record extra failed sign-in events. ### If you do not use Conditional Access policies If you do not use Conditional Access, or you want the old behavior across your tenant while you test: Register a single-tenant application in Microsoft Entra ID to serve as the custom target resource for baseline scopes. No additional configuration is required during registration. See **Create an application** in [Customize behavior](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). In each Conditional Access policy where you need to retain legacy behavior, exclude the placeholder application from **Target resources**. See **Exclude the application from the relevant policy** in [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). Open [Baseline scopes settings](https://aka.ms/BaselineScopesSettingsUX), select **Customize behavior**, select the placeholder application, then select **Save**. See **Select the application in the Baseline scopes settings UX** in [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). You do not need to change your Passport Library Item in Iru Endpoint. This Entra ID setting affects every application that requests baseline scopes, not just Passport. ### If you use Conditional Access policies If you use Conditional Access with Passport **Mac Login**, complete the steps below before **June 15, 2026**. #### Create the Passport - CA Policy API application Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Select **+ New registration**. Enter **Passport - CA Policy API** as the name, under **Supported account types** select **Single tenant only**, and leave **Redirect URI** empty. Select **Register**. Open **API permissions**. If admin consent is not already granted, select **Grant admin consent for \[your tenant]**. Open **Expose an API** in the left navigation. Select **+ Add a scope**. Review the **Application ID URI**. Entra ID suggests a default value (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a`). The default is fine. Select **Save and continue**. You do not need to copy this URI; copy the scope URI in **Copy the scope URI** below. For **Scope name**, enter `Passport` without spaces or special characters. Leave **Who can consent** at the default. Enter a display name and description in the **Admin consent** fields, then select **Add scope**. Microsoft Entra ID Expose an API scope list showing the Passport scope URI and Enabled state Next to the scope URI in the **Scopes** list (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a/Passport`), select **Copy**. Save it for [Update your Passport Library Item](#update-passport-library-item). #### Add the custom scope to your Passport app registration If you aren't already signed in, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Open the application you use for Passport **Mac Login**. Open **API permissions** and select **+ Add a permission**. Open the **APIs my organization uses** tab and select **Passport - CA Policy API**. Select **Delegated permissions**, select the **Passport** permission, then select **Add permissions**. Select **Grant admin consent for \[your tenant]**. Microsoft Entra ID API permissions for Passport showing Microsoft Graph and Passport - CA Policy API delegated permissions #### Exclude Passport - CA Policy API from All resources policies Policies scoped to **All resources** include sign-ins that use the `openid` scope. Excluding **Passport - CA Policy API** removes the MFA requirement for ROPG, which Passport uses for password verification and synchronization in **Mac Login**. In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Protection** > **Conditional Access** > **Policies**. Select each policy scoped to **All resources**, then open **Target resources**. Open the **Exclude** tab, select **Select resources**, then select **Passport - CA Policy API**. Select **Select**, then **Save**. Microsoft Entra ID Conditional Access policy Exclude tab showing Passport - CA Policy API selected under Select specific resources Repeat these steps for every Conditional Access policy scoped to **All resources**. If **Save** fails, confirm that **Passport - CA Policy API** does not allow public client flows. If the app has a redirect URI configured, remove it and try again. #### Update your Passport Library Item In Iru Endpoint, open **Library** and edit your Passport Library Item configured for Microsoft Entra ID **Mac Login**. On the [**Iru Endpoint** tab](#iru-endpoint), paste the scope URI from [Create the Passport - CA Policy API application](#create-passport-ca-policy-api-app) into **Additional scopes (optional)**, then select **Save**. Passport Library Item Additional scopes field showing the Passport - CA Policy API scope URI Repeat **Add the scope URI** for every Passport Library Item configured for Microsoft Entra ID **Mac Login**. After you finish these updates, test Passport sign-in on an enrolled Mac. If sign-in fails, see [Passport Troubleshooting with Microsoft Entra ID (formerly Azure AD)](/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad). ## Microsoft Entra ID Troubleshooting If Passport sign-in fails with Entra ID, see [Passport Troubleshooting with Microsoft Entra ID (formerly Azure AD)](/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad). # Configure Passport Web Login with Microsoft Entra ID Source: https://docs.iru.com/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login Configure Passport with Microsoft Entra ID Web Login in Iru Endpoint. Set up browser-based Entra authentication for macOS password synchronization. This guide applies to Mac computers ### About Passport with Microsoft Entra ID Web Login Passport with Microsoft Entra ID Web Login signs users in through a web view of your organization’s Microsoft Entra ID sign-in page, so Conditional Access and MFA can run at login. For Mac Login (username and password at the Mac login window without that web view), use [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login). Starting **June 15, 2026**, Microsoft Entra ID handles Conditional Access for Passport sign-in differently. Existing Passport **Web Login** deployments need updates only in some cases. See [Required changes before June 15, 2026](#june-2026-conditional-access-change). Microsoft explains the change in [this documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions). If you are setting up Passport for the first time, continue from the beginning of this article. The setup instructions already include these updates where they apply. ### How It Works Passport integrates with your Microsoft Entra ID tenant at the macOS login screen. In Web Login mode, users complete Entra ID sign-in (including MFA when required) in that web view before the local Mac session is created or updated. ### Prerequisites * Access to a Microsoft Entra ID admin account that can grant the Passport app the correct permissions. * For MFA settings in Microsoft Entra ID, see [Microsoft's MFA configuration guide](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-mfasettings). ### Create the App Registration Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a Global Administrator account. In the sidebar, under the Entra ID category, select **App registrations**. On App registrations, select **+ New registration** on the menu. Microsoft Entra ID App registrations with New registration for Passport Enter a name for the new application (such as *Iru Passport Web Login*). Under **Supported account types**, open the drop-down and select **Single tenant only** (the option also shows your tenant name, for example **Single tenant only - *Accuhive***). Passport should be single-tenant in your organization only. See [Register an application in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app). In the Redirect URI section, open the **Select a platform** drop-down and choose **Public client/native (mobile & desktop)**. In the URI field, enter `https://localhost`. You will use this redirect URI when you [configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item). ``` https://localhost ``` For more information about redirect URI restrictions, platform types, and best practices, see [Microsoft's redirect URI documentation](https://learn.microsoft.com/en-us/entra/identity-platform/reply-url). Click **Register**. Microsoft Entra ID New registration form showing name, supported account types, and redirect URI for Passport ### Collecting Configuration Details Open a secure text document where the values for this OIDC app can be temporarily stored. You will need these details when you [configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item). #### Overview Pane Copy the application (client) ID from the app’s overview. You will need it for the Passport Library Item. In the left menu, select **Overview** to open that pane. Copy the **Application (client) ID** to your secure document. Microsoft Entra ID Overview pane showing Application (client) ID for Passport #### Endpoints Pane Copy the OpenID Connect metadata URL from Endpoints; this is the identity provider URL Passport uses to discover sign-in and token endpoints. In the top menu, select **Endpoints** to open that pane. Microsoft Entra ID App registration with Endpoints pane for Passport Copy the **OpenID Connect metadata document** (identity provider URL) to your secure document. Click the **X** at the top right to close the Endpoints pane. Microsoft Entra ID Endpoints pane showing copy option and close button for Passport #### Authentication (Preview) pane Enable public client flows so the Mac app can complete the sign-in flow without a client secret. In the left menu, select **Authentication (Preview)** to open that pane. Select the **Settings** tab. Set **Allow public client flows** to **Enabled**. Click **Save**. Microsoft Entra ID Authentication settings showing Allow public client flows enabled for Passport #### Token Configuration Pane Add the required claims so the token includes the username and group membership Passport needs. In the left menu, select **Token configuration** to open that pane. Click **Add optional claim**. For the Token type, select **ID**. For the Claim, select **preferred\_username**. Click **Add**. Microsoft Entra ID Token configuration showing preferred_username optional claim and Add button for Passport Click **Add groups claim**. Select **All groups**. Entra ID SAML only supports up to 150 security groups. If you have more than 150 security groups, you should not use **All groups**, but rather select specific groups. You can read more in Microsoft's [Configure group claims for applications by using Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-fed-group-claims) article. Click **Add**. Microsoft Entra ID Token configuration Add groups claim for Passport Once you complete the token configurations, you will see both optional claims. ### API Permissions Add the Microsoft Graph permissions Passport needs (email, profile, User.Read) and grant admin consent so users can sign in. In the left menu, select **API permissions** to open that pane. Click **Add a permission**. Microsoft Entra ID API permissions pane showing Add a permission for Passport Click **Microsoft Graph**. Microsoft Entra ID Request API permissions showing Microsoft Graph for Passport Select **Delegated permissions**. Confirm that the **OpenID permissions** section is expanded. If it isn't, click the icon next to it to expand it. Select **email** and **profile**. Microsoft Entra ID Request API permissions showing Delegated permissions for Passport In the **Select permissions** search field, enter **User.Read**. In the User section, confirm that **User.Read** is already selected. If it isn't, select it. Click **Add permissions**. Microsoft Entra ID API permissions showing User.Read for Passport Select **Grant admin consent for \[your tenant]**. Select **Yes**. Microsoft Entra ID API permissions Add permissions for Passport Confirm that there is a ** Granted for \[your tenant]** message in the **Status** column for each permission. Microsoft Entra ID API permissions Status column Granted for tenant for Passport ### Assign Users and Groups Configure who can use the Passport app and whether it appears in the user portal. By default, all users in Entra ID can use the app; the steps below cover the Properties settings and assigning users or users and groups when required. In the Entra ID navigation menu on the left, select **Enterprise Apps**. In the All applications list, select **Iru Passport Web Login** or whatever name you gave the App registration in the previous section. Microsoft Entra ID Enterprise apps for Passport In the left menu, under the **Manage** category, select **Properties** to open that pane. Optionally, add a logo to your Enterprise App. Inspect the **Assignment required?** setting: * **No**: You will not need to assign users or users and groups. * **Yes**: You will need to assign users or users and groups. Set **Visible to users?** to **No**. If it is **Yes**, users will see the app in their portal. The Passport app is only useful as a replacement for the macOS login window. Click **Save**. Microsoft Entra ID Properties pane showing Assignment required and Visible to users for Passport If **Assignment required?** is set to **No**, you can go directly to [User Account Provisioning via Passport](#user-account-provisioning-via-passport). If it is set to **Yes**, continue with the steps below. #### Assignment Required If your Passport Enterprise application has **Assignment required?** set to **Yes**, follow the steps below to assign users or users and groups. In the left menu, under the **Manage** category, select **Users and groups** to open that pane. On the menu, select **+ Add user/group**. Microsoft Entra ID Users and groups pane under Manage for Passport On the **Add Assignment** page, under the **Users** or **Users and groups** heading, select the **None selected** link to choose who can use the app. Depending on your Microsoft Entra ID plan, you may only be able to assign users, not groups. In that case, the heading shows **Users** and group assignment is not available. Microsoft Entra ID Add Assignment page showing Users and groups with None selected link for Passport A list of users or users and security groups is displayed. You can search for a specific user or group, or select multiple users or users and groups that appear in the list. After you have selected your users or users and groups, select **Select**. Microsoft Entra ID Select users or users and groups for Passport Select **Assign** to finish the assignment of users or users and groups to the app. Microsoft Entra ID Assign users or groups for Passport Confirm that the users or users and groups you added appear in the **Users and groups** list. Microsoft Entra ID Users and groups list showing assigned users or groups for Passport With this portion of the Entra ID configuration complete, review the remaining sections of this article for your Microsoft Entra ID environment. ### Microsoft Entra ID Conditional Access Considerations [Microsoft Entra ID Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/) is included with Microsoft Entra ID Premium or better. Be sure to turn off both per-user MFA and Security defaults before you turn on Microsoft Entra ID Conditional Access policies. Complete the steps below to register **Passport - CA Policy API**, add its scope to your Passport app, and exclude that app from applicable policies. Skip this section if you do not use Conditional Access. When you finish, add the scope under **Additional scopes (optional)** in [Authentication Mode](#authentication-mode) on the [Iru Endpoint](#iru-endpoint) tab. Passport **Web Login** completes Conditional Access challenges such as MFA in the Passport web view at login. #### Create the Passport - CA Policy API application Create this application registration so Passport can request a scope beyond baseline scopes. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Select **+ New registration**. Enter **Passport - CA Policy API** as the name, under **Supported account types** select **Single tenant only**, and leave **Redirect URI** empty. Select **Register**. Open **API permissions**. If admin consent is not already granted, select **Grant admin consent for \[your tenant]**. Open **Expose an API** in the left navigation. Select **+ Add a scope**. Review the **Application ID URI**. Entra ID suggests a default value (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a`). The default is fine. Select **Save and continue**. You do not need to copy this URI; copy the scope URI in **Copy the scope URI** below. For **Scope name**, enter `Passport` without spaces or special characters. Leave **Who can consent** at the default. Enter a display name and description in the **Admin consent** fields, then select **Add scope**. Microsoft Entra ID Expose an API scope list showing the Passport scope URI and Enabled state Next to the scope URI in the **Scopes** list (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a/Passport`), select **Copy**. Save it for **Add Additional scopes** in [Authentication Mode](#authentication-mode) on the [Iru Endpoint](#iru-endpoint) tab. #### Add the custom scope to your Passport app registration If you aren't already signed in, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Open the application you use for Passport **Web Login**. Open **API permissions** and select **+ Add a permission**. Open the **APIs my organization uses** tab and select **Passport - CA Policy API**. Select **Delegated permissions**, select the **Passport** permission, then select **Add permissions**. Select **Grant admin consent for \[your tenant]**. Microsoft Entra ID API permissions for Passport showing Microsoft Graph and Passport - CA Policy API delegated permissions #### Exclude Passport - CA Policy API from All resources policies Exclude **Passport - CA Policy API** from each policy scoped to **All resources** so password verification and synchronization continue to work. In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Protection** > **Conditional Access** > **Policies**. Select each policy scoped to **All resources**, then open **Target resources**. Open the **Exclude** tab, select **Select resources**, then select **Passport - CA Policy API**. Select **Select**, then **Save**. Microsoft Entra ID Conditional Access policy Exclude tab showing Passport - CA Policy API selected under Select specific resources Repeat these steps for every Conditional Access policy scoped to **All resources**. If **Save** fails, confirm that **Passport - CA Policy API** does not allow public client flows. If the app has a redirect URI configured, remove it and try again. ### User Account Provisioning via Passport If you want Passport to set each user's Mac account type from Entra ID security group membership, collect each group's **Object ID** in the Microsoft Entra admin center using the steps in this section. You will use those values under **User provisioning** on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). For more detail on this mode, see [User provisioning](/en/endpoint/library/passport/configure-the-passport-library-item#user-provisioning) in **Configure the Passport Library Item**. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). In the Identity navigation menu on the left, open **Groups** and select **All groups**. Select the group that you want to use. Microsoft Entra ID Groups for Passport user provisioning Copy the **Object ID** for that group. Microsoft Entra ID Groups list showing Object ID for Passport For each additional Entra ID group you want to use, repeat **Select group** and **Copy Object ID**. Keep the **Object ID** values in a secure document until you enter them on the [**Iru Endpoint** tab](#iru-endpoint). Configure **Authentication mode** and **User provisioning** in the Passport Library Item on the [**Iru Endpoint** tab](#iru-endpoint). If you have not already, use [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) to add the Passport Library Item and basic settings. The steps below are Microsoft Entra ID **Web Login** fields in the Passport Library Item; use the **Application (client) ID** and OpenID Connect metadata URL from the [Microsoft Entra ID](#microsoft-entra-id) tab. ### Authentication Mode Set **Authentication mode** to **Web Login** when users must complete Microsoft Entra ID sign-in (including MFA) in the Passport web view. In the Passport Library Item, set **Identity provider** to **Microsoft Entra ID**. In the **Identity provider URL** field, paste the **OpenID Connect metadata document** URL from the app registration on the [Microsoft Entra ID](#microsoft-entra-id) tab. In the **Client ID (Password Sync)** field, paste the **Application (client) ID** from the app registration on the [Microsoft Entra ID](#microsoft-entra-id) tab. Complete this step only if you completed [Microsoft Entra ID Conditional Access Considerations](#microsoft-entra-id-conditional-access-considerations). If you skipped that section, continue to **Select Web Login**. Paste the scope URI you copied from **Create the Passport - CA Policy API application** into **Additional scopes (optional)**. This field appears below **Client ID (Password Sync)**. Passport Library Item Additional scopes field showing the Passport - CA Policy API scope URI Under **Authentication mode**, select **Web Login**. In the **Redirect URI** field, enter the following. It must match the redirect URI on the app registration from the [Microsoft Entra ID](#microsoft-entra-id) tab: ``` https://localhost ``` Click **Save** on the Passport Library Item. ### User Provisioning If you want Passport to set each user's Mac account type from Entra ID security group membership, use the steps below under **User provisioning** on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). Collect each group's **Object ID** in Entra ID first. See [User Account Provisioning via Passport](#user-account-provisioning-via-passport) on the [Microsoft Entra ID](#microsoft-entra-id) tab. In the **User provisioning** section, open **User account type** and select **Specify per identity provider group**. With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user's IdP group membership returns both Administrator and Standard account types, the user is designated an Administrator. In each **Identity provider group** field, enter the Entra ID group **Object ID** as a GUID, not the group display name. For each **Identity provider group** row, set the **Account type** as appropriate. Passport Library Item User Provisioning showing Identity provider group field for Entra ID Object ID Click **Save**. When the Passport Library Item is saved, return to the [Microsoft Entra ID](#microsoft-entra-id) tab if you need to change the app registration, **Passport - CA Policy API** exclusions, or group **Object IDs**. ## Required Changes Before June 15, 2026 On **June 15, 2026**, Microsoft Entra ID starts enforcing Conditional Access more broadly for policies that target **All resources** (formerly **All cloud apps**) and include **resource exclusions**. Sign-ins that request only **baseline scopes**, including `openid`, `profile`, `email`, and `User.Read`, will be subject to those policies. Passport **Web Login** requests those scopes as a public client. If you already use Passport **Web Login**, you need the steps below only when you want password verification and synchronization to work without MFA being enforced through Conditional Access on policies scoped to **All resources** (you exempt Passport from MFA instead of having users complete MFA during web sign-in). If users complete MFA in the Entra ID web view, you generally do not need the custom scope, [Exclude Passport - CA Policy API from All resources policies](#exclude-passport-ca-policy-api), or the **Additional scopes** Library Item update; your tenant may still need the path under [If you do not use Conditional Access policies](#if-you-do-not-use-conditional-access-policies). If you skip required updates, sign-in and password sync can break once the change reaches your tenant. If you are configuring Passport **Web Login** for the first time using this article, the **Microsoft Entra ID** and **Iru Endpoint** tabs above already include these updates where they apply. Read [Enforcement for baseline scopes in Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions) for more detail. ### If you skip these updates If you do not prepare before **June 15, 2026**: * New users might not be able to sign in with Passport. * Existing users might need to switch to local login after a reboot or logout. * Password sync and state management can stop working. * Microsoft Entra ID might record extra failed sign-in events. ### If you do not use Conditional Access policies If you do not use Conditional Access, or you want the old behavior across your tenant while you test: Register a single-tenant application in Microsoft Entra ID to serve as the custom target resource for baseline scopes. No additional configuration is required during registration. See **Create an application** in [Customize behavior](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). In each Conditional Access policy where you need to retain legacy behavior, exclude the placeholder application from **Target resources**. See **Exclude the application from the relevant policy** in [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). Open [Baseline scopes settings](https://aka.ms/BaselineScopesSettingsUX), select **Customize behavior**, select the placeholder application, then select **Save**. See **Select the application in the Baseline scopes settings UX** in [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions#customize-behavior). You do not need to change your Passport Library Item in Iru Endpoint. This Entra ID setting affects every application that requests baseline scopes, not just Passport. ### If you use Conditional Access policies If you use Conditional Access with Passport **Web Login** and want to exempt Passport from MFA as described above, complete the steps below before **June 15, 2026**. #### Create the Passport - CA Policy API application Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Select **+ New registration**. Enter **Passport - CA Policy API** as the name, under **Supported account types** select **Single tenant only**, and leave **Redirect URI** empty. Select **Register**. Open **API permissions**. If admin consent is not already granted, select **Grant admin consent for \[your tenant]**. Open **Expose an API** in the left navigation. Select **+ Add a scope**. Review the **Application ID URI**. Entra ID suggests a default value (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a`). The default is fine. Select **Save and continue**. You do not need to copy this URI; copy the scope URI in **Copy the scope URI** below. For **Scope name**, enter `Passport` without spaces or special characters. Leave **Who can consent** at the default. Enter a display name and description in the **Admin consent** fields, then select **Add scope**. Microsoft Entra ID Expose an API scope list showing the Passport scope URI and Enabled state Next to the scope URI in the **Scopes** list (for example, `api://cca588ed-dfe6-4fb4-b695-abfa23b6475a/Passport`), select **Copy**. Save it for [Update your Passport Library Item](#update-passport-library-item). #### Add the custom scope to your Passport app registration If you aren't already signed in, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) and open **Entra ID** > **App registrations**. Open the application you use for Passport **Web Login**. Open **API permissions** and select **+ Add a permission**. Open the **APIs my organization uses** tab and select **Passport - CA Policy API**. Select **Delegated permissions**, select the **Passport** permission, then select **Add permissions**. Select **Grant admin consent for \[your tenant]**. Microsoft Entra ID API permissions for Passport showing Microsoft Graph and Passport - CA Policy API delegated permissions #### Exclude Passport - CA Policy API from All resources policies Complete this step only when you use **Web Login** and want to exempt Passport from MFA through Conditional Access. Skip it if users complete MFA in the Entra ID web view at login. Policies scoped to **All resources** include sign-ins that use baseline scopes Passport requests at sign-in. Exclude **Passport - CA Policy API** so password verification and synchronization continue to work without an MFA requirement on those policies. In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Protection** > **Conditional Access** > **Policies**. Select each policy scoped to **All resources**, then open **Target resources**. Open the **Exclude** tab, select **Select resources**, then select **Passport - CA Policy API**. Select **Select**, then **Save**. Microsoft Entra ID Conditional Access policy Exclude tab showing Passport - CA Policy API selected under Select specific resources Repeat these steps for every Conditional Access policy scoped to **All resources**. If **Save** fails, confirm that **Passport - CA Policy API** does not allow public client flows. If the app has a redirect URI configured, remove it and try again. #### Update your Passport Library Item Complete this step when you follow **If you use Conditional Access policies** because you exempt **Web Login** from MFA as described above. In Iru Endpoint, open **Library** and edit your Passport Library Item configured for Microsoft Entra ID **Web Login**. On the [**Iru Endpoint** tab](#iru-endpoint), paste the scope URI from [Create the Passport - CA Policy API application](#create-passport-ca-policy-api-app) into **Additional scopes (optional)**, then select **Save**. Passport Library Item Additional scopes field showing the Passport - CA Policy API scope URI Repeat **Add the scope URI** for every Passport Library Item configured for Microsoft Entra ID **Web Login**. After you finish these updates, test Passport sign-in on an enrolled Mac. If sign-in fails, see [Passport Troubleshooting with Microsoft Entra ID (formerly Azure AD)](/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad). ## Microsoft Entra ID Troubleshooting If Passport sign-in fails with Entra ID, see [Passport Troubleshooting with Microsoft Entra ID (formerly Azure AD)](/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad). # Passport troubleshooting with Microsoft Entra ID Source: https://docs.iru.com/en/endpoint/library/passport/microsoft-entra-id/passport-troubleshooting-with-microsoft-entra-id-formerly-azure-ad Troubleshoot Passport issues with Microsoft Entra ID in Iru Endpoint. Resolve login failures, token errors, password sync problems, and configuration issues. This guide applies to Mac computers Note: Microsoft Entra ID [is the new name](https://learn.microsoft.com/en-us/entra/fundamentals/new-name) for Azure AD (Azure Active Directory) ### About This Article Use this article when Passport sign-in fails with Microsoft Entra ID (formerly Azure AD). It covers login checks, diagnostics, network requirements, and common Entra ID error codes. For setup, use [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) or [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login), then [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item). Starting **June 15, 2026**, Microsoft Entra ID handles Conditional Access for Passport sign-in differently. * **Mac Login:** See [Entra ID Passport Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login#june-2026-conditional-access-change) to confirm whether your tenant is affected and what to update before that date. * **Web Login:** Updates are required only if you use Web Login and want to exempt Passport from MFA in Conditional Access. See [Entra ID Passport Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login#june-2026-conditional-access-change). Microsoft explains the change in [this documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions). ### Login, Diagnostics, and Network At the Passport login window, always enter the user’s full email address in the username field so the session uses your IdP instead of local authentication. For how the login window and visibility settings interact with Passport, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). If a user cannot sign in, open Iru Endpoint Passport Diagnostics with **Command-Shift-K-L** on the Mac. The panel shows useful detail, including error messages returned from your IdP. Passport must reach Microsoft Entra ID to validate credentials. When you customize the Passport login window, enable the network manager so users can join Wi-Fi if needed. The control respects AirPort security settings in macOS. Passport shows a Wi-Fi icon at the upper-right of the login window; users can click it to join a password-protected network. Passport does not support captive portals, click-through acceptance pages, or enterprise 802.1X networks that require a separate username and password in that flow. To isolate network issues, try a mobile hotspot or wired Ethernet while testing at the Passport login window. ### Common Microsoft Entra ID Errors To look up Microsoft Entra ID sign-in error codes (often prefixed with `AADSTS`), use [login.microsoftonline.com/error](https://login.microsoftonline.com/error). **What you see:** Microsoft Entra ID message: Due to a configuration change made by your administrator, or because you moved to a new location, you must use multi-factor authentication to access the resource named in the error. **What to do:** * The user needs to complete multi-factor authentication. Multiple policies or settings can require MFA (for example Conditional Access, per-user enforcement, or client-requested MFA). **What you see:** Microsoft Entra ID message: User account \ from identity provider \ does not exist in tenant \ and cannot access the application \ in that tenant. The account needs to be added as an external user in the tenant first. **What to do:** * In the Microsoft Entra admin center, open **Users** > **All users** and confirm that the user exists. **What you see:** Microsoft Entra ID message: The user account \ does not exist in \ directory. **What to do:** * For Passport with MFA, each user in Microsoft Entra ID needs an **Email** value. Without it, the user may complete MFA in the web view but fail at the **Enter your Microsoft Entra ID password** verification step. In the Microsoft Entra admin center, open **Users** > **All users**, select the user, click **Edit properties**, enter an address in **Email**, and click **Save**. The value does not need to be a working mailbox; often it matches **User principal name**. **What you see:** Microsoft Entra ID message: InvalidUserNameOrPassword: error validating credentials due to invalid username or password. The user did not enter the right credentials. Some of these errors in logs are expected when users mistype credentials. **What to do:** * Confirm the username and password with your IdP. * Microsoft Entra ID may be federated with AD FS or another identity provider, which can surface this error to Passport. See **Authentication Flow in a Federated Environment** in [Using Passport in a federated Microsoft Entra ID environment](/en/endpoint/library/passport/microsoft-entra-id/using-passport-in-a-federated-microsoft-entra-id-environment-formerly-azure-ad). **What you see:** Microsoft Entra ID message: Client is public so neither ‘client\_assertion’ nor ‘client\_secret’ should be presented. **What to do:** * In the Entra admin center, open **Applications** > **App registrations** > **All applications** > \[your Passport app] > **Authentication** > **Platform configurations**, and align the platform and redirect URI with your Passport **Authentication mode** and with [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) or [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login): * **Mac Login:** Use the **Web** platform and redirect URI **[https://localhost.redirect](https://localhost.redirect)**. * **Web Login:** Use **Public client/native (mobile & desktop)** and redirect URI **[https://localhost](https://localhost)**. * Open **Certificates & secrets** and remove any **Client secret** on the app if it should be public-client only. * In Iru Endpoint, confirm the Passport Library Item **Client secret (optional)** field is empty. **What you see:** Microsoft Entra ID message: Invalid client secret provided. Ensure the secret being sent in the request is the client secret value. **What to do:** * In the Entra admin center, open **Applications** > **App registrations** > **All applications** > \[your Passport app] > **Authentication** > **Platform configurations**, and align the platform and redirect URI with your Passport **Authentication mode** and with [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) or [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login): * **Mac Login:** Use the **Web** platform and redirect URI **[https://localhost.redirect](https://localhost.redirect)**. * **Web Login:** Use **Public client/native (mobile & desktop)** and redirect URI **[https://localhost](https://localhost)**. * Open **Certificates & secrets** and remove the **Client secret** if the app is configured as a public client for Passport. * In Iru Endpoint, confirm the Passport Library Item **Client secret (optional)** field is empty. **What you see:** Microsoft Entra ID message: Due to a configuration change made by your administrator, or because you moved to a new location, you must enroll in multi-factor authentication to access the identifier shown in the error. **What to do:** * If you use **Mac Login**, the user may have legacy per-user MFA enabled. A managed user may need to register security info, or a federated user may need the MFA claim from the federated IdP. * Conditional Access, per-user enforcement, and other policies can also require MFA enrollment. **What you see:** * *Ticket decode failed* * *Failed to login with possible error: Unknown* **What to do:** * Remove the optional client secret from the Passport Library Item, let the device check in, sign out of the local user, and sign in again with Passport. * If it persists, rule out network issues (for example try a mobile hotspot). **What you see:** An error occurred fetching user info: No key was found matching "givenName". **What to do:** * In the Microsoft Entra admin center, open **Identity** > **Users** > **All users**, open the user who is signing in, and confirm that **First name** is populated. For Mac Login or Web Login setup, see [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) or [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login). # Passport in a federated Entra ID environment Source: https://docs.iru.com/en/endpoint/library/passport/microsoft-entra-id/using-passport-in-a-federated-microsoft-entra-id-environment-formerly-azure-ad Use Passport in a federated Microsoft Entra ID environment with Iru Endpoint. Configure authentication flows for ADFS and third-party federation services. This guide applies to Mac computers Note: Microsoft Entra ID [is the new name](https://learn.microsoft.com/en-us/entra/fundamentals/new-name) for Azure AD (Azure Active Directory) ### About Passport in Federated Microsoft Entra ID Environments Passport in a federated Microsoft Entra ID environment applies when Entra ID is the service provider (SP) for an external identity provider. Both **Mac Login** and **Web Login** need extra configuration so authentication and password validation can complete against Entra ID correctly. Starting **June 15, 2026**, Microsoft Entra ID handles Conditional Access for Passport sign-in differently. * **Mac Login:** See [Entra ID Passport Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login#june-2026-conditional-access-change) to confirm whether your tenant is affected and what to update before that date. * **Web Login:** Updates are required only if you use Web Login and want to exempt Passport from MFA in Conditional Access. See [Entra ID Passport Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login#june-2026-conditional-access-change). Microsoft explains the change in [this documentation](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions). ### How It Works Passport still uses Entra ID as the OIDC authority even when users federate through another IdP. For **Mac Login** and **Web Login**, create a [Home Realm Discovery (HRD)](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-authentication-for-federated-users-portal?pivots=powershell-hrd) policy in Entra ID with PowerShell so password validation can complete against Entra ID in a [federated environment](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-fed). ### Prerequisites Confirm everything below before you create the HRD policy. This article applies when you use Passport with Entra ID for **Mac Login** or **Web Login** in a federated tenant. * An active [Azure subscription](https://azure.microsoft.com/free/) (create a free account if needed). * A user who can manage directory apps and policies: **Global Administrator**, **Cloud Application Administrator**, **Application Administrator**, or **service principal owner**. * A Windows or Windows Server computer (physical or VM) where you can open **PowerShell** as administrator. * [AzureADPreview](https://learn.microsoft.com/en-us/powershell/azure/active-directory/install-adv2?view=azureadps-2.0#installing-the-azure-ad-module) installed, on a current [preview build](https://learn.microsoft.com/en-us/powershell/azure/active-directory/install-adv2?view=azureadps-2.0#updating-the-azure-ad-module). You cannot run GA and preview modules side by side; [uninstall the AzureAD module](https://learn.microsoft.com/en-us/powershell/azure/uninstall-az-ps) first if both are present. * Users who sign in with Passport must be represented in Entra ID in a way that supports your sign-in path. * **Hybrid Active Directory:** use [Microsoft Entra Connect](https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-password-hash-synchronization) with **password hash sync** where that applies. * **Cloud federated IdP:** confirm usernames and passwords from the federated IdP reach Entra ID as you expect for ROPC-style sign-in. * Entra ID app registration (Enterprise application) for Passport, following [Configure Passport with Microsoft Entra ID - Mac Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-mac-login) and/or [Configure Passport with Microsoft Entra ID - Web Login](/en/endpoint/library/passport/microsoft-entra-id/configure-passport-with-microsoft-entra-id-web-login), depending on which authentication mode you use. * [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) completed in Iru Endpoint for that Passport deployment. ### Authentication Flow in a Federated Environment The diagram below depicts the Passport authentication flow when Entra ID acts as a service provider (SP) federated with another identity provider (IdP). Passport authentication flow when Entra ID is federated with another identity provider When a user attempts to authenticate via Passport, the request looks like this: Passport sends an authentication request to Azure AD. Azure AD forwards the auth request to the federated IdP. The auth request is validated by the IdP and sent back to Azure AD. Azure AD receives the validation but has no reason to forward it to Passport, at which point the user's authentication attempt fails, and an error is delivered to Passport. ### Authentication Flow with HRD Configured The diagram below depicts the Passport authentication flow with an Azure AD Home Realm Discovery policy. When a user attempts to authenticate via Passport, the request looks like this: Passport authentication flow with Home Realm Discovery policy Passport sends an authentication request to Azure AD. Entra ID validates the authentication request using the HRD policy and responds to Passport with a successful user authentication response. ### Create an HRD Policy You need an HRD policy when you use Passport with Microsoft Entra ID and your tenant is federated with an external IdP. That requirement applies to both **Mac Login** and **Web Login**. Go to the Windows computer. Open PowerShell as an administrator. Connect to your Entra ID tenant with the command **Connect-AzureAD**. A web view will open prompting you to enter your Entra ID credentials. Create a new policy with the command below. This will allow users to authenticate to a specific application directly with Entra ID with their username and password in a federated environment. If you have existing HRD policies in your environment, you can set the *DisplayName* to something like **IruHRDPolicy**. ```powershell wrap lines icon="terminal" theme={null} New-AzureADPolicy -Definition @("{`"HomeRealmDiscoveryPolicy`":{`"AllowCloudPasswordValidation`":true}}") -DisplayName IruHRDPolicy -Type HomeRealmDiscoveryPolicy ``` Run the command **Get-AzureADPolicy** to list the policy that you've just created and copy the *ObjectID* string listed under the ID column in the output. Run the command **Get-AzureADServicePrincipal** to get the Service Principal (Azure Enterprise Application) **ObjectID**. If you know the name of the Enterprise Application, you can add the **-SearchString your\_app\_name\_here** to the command above. Example: **Get-AzureADServicePrincipal -SearchString "Iru Passport"** Run the following command to add the Iru Passport Enterprise Application to the HRD policy. Replace *\* with the Iru Enterprise App *ObjectID* copied earlier. Replace *\* with the HRD *ObjectID* copied earlier. ```powershell wrap lines icon="terminal" theme={null} Add-AzureADServicePrincipalPolicy -Id -RefObjectId ``` If you do not create the right policy, you can use the command below to remove it and try again. ```powershell wrap lines icon="terminal" theme={null} Remove-AzureADServicePrincipalPolicy -id -PolicyId ``` Check the apps assigned with **Get-AzureADPolicyAppliedObject -id \**. To disconnect the PowerShell session from Azure, run **Disconnect-AzureAD**. # Passport Configuration with Okta Source: https://docs.iru.com/en/endpoint/library/passport/okta/passport-configuration-with-okta Configure Passport with Okta in Iru Endpoint for macOS login and password synchronization. Set up the Okta app integration and authentication settings. This guide applies to Mac computers ### About Passport with Okta Passport with Okta enables users to log into Mac computers using their Okta credentials instead of separate local passwords. Passport connects Okta to macOS login. ### How It Works Passport integrates with your Okta organization to authenticate users at the macOS login screen. When users enter their Okta credentials, Passport verifies them against your Okta tenant and creates or updates the local Mac user account accordingly. ### Okta Application Configuration When configuring the Passport Library Item, you need the **Client ID** and **Identity provider URL**. In Okta, the client identifier may be labeled **Application ID**. Use these steps to configure the OIDC app and collect the required information. In your Okta Administrator Console, in the left menu pane, expand the Applications section and select **Applications**. Click **Create App Integration**. For **Sign-in method**, select **OIDC - OpenID Connect**. For Application Type, select **Native Application**. Click **Next**. In the **App integration name** field, enter a name such as *Iru Passport*. In the **Grant type** section, confirm that the checkbox for **Refresh Token** is deselected. This option must be turned off to ensure that Passport prompts users to update their Mac password while logged in if their Okta password changes. The **Store user password** setting in the Passport Library Item needs to be set to **Securely store password** for users to receive the password update prompt. If you're using Okta Identity Engine, click **Advanced** to show additional options. In the **Other grants** section, select the checkbox for **Resource Owner Password**. If your Okta instance hasn't yet been updated from Classic to Okta Identity Engine, also referred to as OIE, the **Interaction Code** grant type and other options will not be displayed. In the **Sign-in redirect URIs** section, click **Add URI**. In the new field that appears, enter the following: ``` https://localhost.redirect ``` The same Sign-in redirect URI must be used in the Passport Library Item in the Redirect URI field in the Authentication mode section. Okta Sign-in redirect URIs for Passport In the Assignments section, select whether to assign the app integration to everyone in your org, only to selected groups, or skip assignment until after app creation. Click **Save**. Okta app Assignments controlled access options ### Collecting Configuration Details Open a secure text document that you can use to store values for this OIDC app. You will need these details when you configure the Passport Library Item. In the General tab of the OIDC application you just created, on the right side of the **Client ID** field, click the **copy icon** that looks like a clipboard. Okta Passport Client ID on General tab Paste the value into your secure text document. Copy the formula for your **Identity provider URL** from the following text: ``` https://yourOktaDomain/.well-known/openid-configuration ``` Paste the text into your secure text document. In your secure text document, replace yourOktaDomain with your Okta domain. You do not need a custom Sign-On Policy Rule, but if you add one, ensure MFA is disabled. If you do not need to configure MFA, open the [**Iru Endpoint** tab](#iru-endpoint). Follow [the next section](#enable-multi-factor-authentication) if you do need to configure MFA. ### Enable Multi-Factor Authentication The MFA policy in Okta should be applied to Users or Groups, not to the Passport Application in Okta. When you use MFA with Passport, update Okta and the Passport Library Item. For more on how they can differ, see Okta's [Differences Between Okta Classic and OIE](https://support.okta.com/help/s/article/Setting-Up-Okta-Verify-Differences-Between-Classic-and-Okta-Identity-Engine-OIE?language=en_US) article. Expand the section for your Okta engine, or use the [Okta Identity Engine](#okta-identity-engine) or [Classic Engine](#classic-engine) links. **Okta Authenticators** Expand the **Security** section from the left-hand navigation. Click **Authenticators**. Ensure that at least one multifactor authentication method, such as Okta Verify, is listed. If no multifactor method is listed, click the **Add authenticator** button. Okta Security Authenticators with Add authenticator Click the **Add** button below each authenticator you need. Okta Add Authenticator list Complete any additional steps for the authenticator. Click **Add**. **Okta Global Session Policy** Expand the **Security** section from the left-hand navigation. Click **Global Session Policy**. Click **Add policy** to create a new policy, or to edit the existing **Default Policy**, continue to the next step. To edit the existing **Default Policy**, click the pencil icon in the **Actions** column for the Default Rule. Okta Global Session Policy Default Rule Set multifactor authentication to **Required**. Set **Users will be prompted for MFA** to **At every sign in**. Okta Edit Rule MFA Required at every sign in Scroll down and click **Update rule** or **Create rule**. **Authentication Policies** Expand the **Security** section from the left-hand navigation. Click **Authentication Policies**. Click **Applications**. Click **Switch policy** next to your Iru Passport application. Select **Password only** for the **Use this policy for Iru Passport** policy. Click **Save**. Okta Change Authentication Policy to Password only **Okta MFA Settings** Expand the **Security** section from the left-hand navigation. Click **Authentication**. Click **Sign On**. Click **Add New Okta Sign-on Policy**. Okta Authentication Sign On Add New Okta Sign-on Policy Enter a **Policy name** similar to MFA Required. Enter a **Policy Description**. Select the groups that will be assigned to this MFA requirement. Click **Create policy and add rule**. Okta Add Policy MFA Required Enter the **Rule name**. Select **Required** for multifactor authentication. Select **At every sign in** for the **Users will be prompted for MFA** setting. Okta Add Rule Require multifactor authentication Click **Create rule** at the bottom of the window. Okta Create rule for global session management Switch to the [**Iru Endpoint** tab](#iru-endpoint) and work through the Passport Library Item steps there. Start at the top of that tab. When you are done, return to this tab and continue with **Configure the Group Claim Filter in Okta** below. ### Configure the Group Claim Filter in Okta In your Passport OIDC application, configure the **Groups claim filter** so Okta sends the group claims Passport expects. This article uses names starting with *Mac-* as an example. In your Okta Administrator Console, in the left menu pane, expand the Applications section if necessary, then select **Applications**. Select the **Iru Passport** application that you previously created. Click the **Sign On** tab. In the **OpenID Connect ID Token** section, click Edit. Okta OpenID Connect ID Token settings In the **Groups claim filter** section, leave the default value: **groups**. Leave the middle field at the default: **Starts with**. In the right-most field, enter **Mac** if the Okta groups you use or will use start with **Mac**. Click **Save**. Okta Groups claim filter Starts with Mac If you have not already, use [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) to add the Passport Library Item and basic settings. The steps below are the **Iru Endpoint** configuration specific to Okta Passport. ### Authentication Mode Set **Authentication mode** in the Passport Library Item to match how users sign in with Okta. Use **Web Login** when MFA applies, and **Mac Login** when it does not. Complete the steps below first, using the values you collected on the **Okta** tab. Then follow **Web Login** or **Mac Login**. In the Passport Library Item, set **Identity provider** to **Okta**. In the **Identity provider URL** field, enter your Okta OIDC well-known configuration URL from the **Okta** tab. It follows this pattern: ```bash theme={null} https://{yourOktaDomain}/.well-known/openid-configuration ``` In the **Client ID (Password Sync)** field, enter the **Application ID** (client ID) from the OIDC app on the **Okta** tab. #### Web Login If you use multi-factor authentication with Passport, you must use **Web Login** as the authentication mode so users can complete MFA during sign-in. Under **Authentication mode**, select **Web Login**. In the **Redirect URI** field, enter the following: ``` https://localhost.redirect ``` Passport Library Item Web Login redirect URI for Okta Click **Save**. #### Mac Login If you are not using MFA with Passport, use **Mac Login** as the authentication mode. Users sign in with their Okta password at the Mac login window without the Web Login MFA flow. Under **Authentication mode**, select **Mac Login**. Passport Library Item Authentication mode set to Mac Login for Okta Click **Save**. ### User Provisioning If you want Passport to set each user's Mac account type from Okta group membership, use the **User provisioning** steps below on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). The groups you use in Okta do not have to start with *Mac-*, but the example groups in this article use that prefix. In the Passport Library Item, click the User account type menu in the User provisioning section and select **Specify per identity provider group**. With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user's IdP group membership returns both Administrator and Standard account types, the user is designated an Administrator. In the **Identity provider group** fields, enter your Okta group names. This article uses groups that start with *Mac-* as an example. For each **Identity provider group** row, set the **Account type** as appropriate. Passport Library Item User provisioning for Okta When **User provisioning** and related saves are complete in the Passport Library Item, switch back to the **Okta** tab and complete [Configure the Group Claim Filter in Okta](#configure-the-group-claim-filter-in-okta) if you have not already. Start at the top of that tab if you need the full flow. ### Troubleshooting Issues with Passport & Okta If you experience any issues with Passport & Okta, read our [Passport Troubleshooting with Okta](/en/endpoint/library/passport/okta/passport-troubleshooting-with-okta) article for additional information. # Passport Troubleshooting with Okta Source: https://docs.iru.com/en/endpoint/library/passport/okta/passport-troubleshooting-with-okta Troubleshoot Passport issues with Okta in Iru Endpoint. Resolve login failures, token refresh errors, password sync problems, and configuration conflicts. This guide applies to Mac computers ### About Passport Troubleshooting with Okta Passport troubleshooting with Okta involves resolving authentication issues that occur when using Passport with Okta as your Identity Provider (IdP). This guide helps identify and resolve common configuration and authentication problems specific to Okta integration. ### How It Works When Passport authentication issues occur with Okta, troubleshooting involves checking Okta application settings, verifying OIDC configuration, examining authentication flows, and resolving configuration mismatches between Passport and your Okta tenant. ### Login, Diagnostics, and Network At the Passport login window, always enter the user's full email address in the username field so the session uses your IdP instead of local authentication. For how the login window and visibility settings interact with Passport, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). If a user cannot sign in, open Iru Endpoint Passport Diagnostics with **Command-Shift-K-L** on the Mac. The panel surfaces useful detail, including error messages returned from your IdP. Passport must reach Okta to validate credentials. When you customize the Passport login window, enable the network manager so users can join Wi-Fi if needed. The control respects AirPort security settings in macOS. Passport shows a Wi-Fi icon at the upper-right of the login window; users can click it to join a password-protected network. Passport does not support captive portals, click-through acceptance pages, or enterprise 802.1X networks that require a separate username and password in that flow. To isolate network issues, try a mobile hotspot or wired Ethernet while testing at the Passport login window. ### Common Okta errors To look up Okta API error codes, see [Okta API Error Codes](https://developer.okta.com/docs/reference/error-codes/) on the Okta developer site. **What you see:** `"error":"Unauthorized","error_description":"Authentication Failed: Invalid user credentials"` **What to do:** * Confirm the username and password with your IdP. This response usually means the credentials do not match what Okta expects. * If the GET request to your OIDC well-known `openid-configuration` URL returns **200**, the **Identity provider URL** and **Client ID** in the Passport Library Item are typically reaching Okta correctly. In Okta, the same value may appear as **Application ID**. **What you see:** `"error":"access_denied","error_description":"End-user does not have access to this application"` **What to do:** * In Okta, confirm the user or group is assigned to the Passport OIDC application and that sign-on rules allow access. * If the GET request to your OIDC well-known `openid-configuration` URL returns **200**, the **Identity provider URL** and **Client ID** in the Passport Library Item are typically reaching Okta correctly. In Okta, the same value may appear as **Application ID**. # Passport Configuration with OneLogin Source: https://docs.iru.com/en/endpoint/library/passport/onelogin/passport-configuration-with-onelogin Configure Passport with OneLogin in Iru Endpoint for macOS login and password synchronization. Set up the OneLogin app integration and authentication. This guide applies to Mac computers ## About Passport with OneLogin Passport with OneLogin enables users to log into Mac computers using their OneLogin credentials. This integration provides secure authentication using your organization's OneLogin identity system with support for both standard and multi-factor authentication. ## How It Works Passport integrates with your OneLogin instance using OpenID Connect (OIDC) to authenticate users at the macOS login screen. Whether you need MFA for Passport sign-in determines how many OIDC applications you create in OneLogin and whether you set Authentication mode to Web Login or Mac Login in the Passport Library Item. ## Prerequisites * To add apps in OneLogin, use an account that is a Super User or Account Owner. ## Configure an OIDC App If you do not need MFA for Passport sign-in, set **Authentication mode** to **Mac Login** in the Passport Library Item and follow only the [Mac Login](#onelogin-oidc-mac-login) section (skip [Web Login](#onelogin-oidc-web-login)). If you need MFA at sign-in, set **Authentication mode** to **Web Login**. You must create **two** OIDC apps in OneLogin: **Mac Login** first (sign-in and password sync to the Mac), then **Web Login** (MFA in the embedded web view). Follow the **Mac Login** section, then the **Web Login** section, in that order. ### Mac Login Create the Mac Login OIDC application in OneLogin. This article uses the display name *Iru Passport Mac Login*. Every deployment uses this app. With **Mac Login** as the authentication mode, it is the only OneLogin OIDC app you add in this guide. With **Web Login** (MFA), add this app first, then continue to [Web Login](#onelogin-oidc-web-login). Log in to OneLogin as an Account owner or Super user. In your OneLogin admin console, navigate to the **Applications** page. In the upper-right corner, click **Add App**. In the search field in the upper-left corner, enter *OIDC*. Select **OpenID Connect (OIDC)**. In the **Display Name** field, enter a descriptive name such as *Iru Passport Mac Login*. Click the **Visible in portal** switch to the **Off** position; this app does not need to be visible in order for Passport to work, and it might be confusing for a user to see this app in their OneLogin portal. Click **Save**. In the left sidebar, click **Configuration**. In the **Redirect URIs** field, enter the following: ``` https://localhost.redirect ``` Passport doesn't require this value, but you cannot save the app configuration without some value in the Redirect URIs field. In the left sidebar, click **SSO**. Click the **Application Type** menu and select **Native**. Click the **Token Endpoint** menu and select **None (PKCE)**. Click **Save**. #### Collecting configuration details for Mac Login This OIDC app keeps the Mac password in sync with OneLogin. Open a secure text document that you can use to store values for this OIDC app. You will need the Client ID and Issuer URL details when you configure the Passport Library Item (you don't need the client secret). To the right of the **Client ID** field, click the **Copy to Clipboard** button (looks like a clipboard). Paste the Client ID into the secure text document. Right-click (or Control-click) the **Well-known Configuration** link and copy its value. The Issuer URL is your OIDC well-known configuration endpoint and follows this pattern: ```bash theme={null} https://{subdomain}.onelogin.com/oidc/2/.well-known/openid-configuration ``` Paste the Issuer URL into the secure text document. Save the secure text document. In OneLogin, assign the app to the users or groups who will be using Passport to log in to their Mac computers. If you are not using Web Login (no MFA), skip the [Web Login](#onelogin-oidc-web-login) section below, then continue with [Configuring a User Account Type by Identity Provider Group in OneLogin](#configuring-a-user-account-type-by-identity-provider-group-in-onelogin) if you need role-based account types, then open the [Iru Endpoint tab](#iru-endpoint). ### Web Login Use this section only when **Authentication mode** is **Web Login** (MFA). After you finish [Mac Login](#onelogin-oidc-mac-login), create the second OIDC app here. This article uses the display name *Iru Passport Web Login*. In your OneLogin admin console, navigate to the **Applications** page. In the upper-right corner, click **Add App**. If the **Add App** button does not appear, it's possible that you previously clicked **See the new apps list**. To make OneLogin display the **Add App** button, remove the string */admin2* from the URL. For example, instead of *[https://accuhive.onelogin.com/admin2/apps](https://accuhive.onelogin.com/admin2/apps)*, use *[https://accuhive.onelogin.com/apps](https://accuhive.onelogin.com/apps)*. In the search field in the upper-left corner, enter OIDC. Select **OpenID Connect (OIDC)**. In the Display Name field, enter a descriptive name such as **Iru Passport Web Login**. Click the **Visible in portal** switch to the **Off** position; this app does not need to be visible in order for Passport to work, and it might be confusing for a user to see this app in their OneLogin portal. Click **Save**. In the left sidebar, click **Configuration**. In the **Redirect URIs** field, enter the following: ``` https://localhost.redirect ``` In the left sidebar, click **SSO**. Click the **Application Type** menu and select **Native**. In the **Token Endpoint** section, click the **Authentication Method** menu and select **POST**. POST is required so users can complete MFA in the web view at Mac sign-in. Click **Save**. #### Collecting configuration details for Web Login This OIDC app supplies the Web Login fields for the Passport Library Item. Open a secure text document that you can use to store values for this OIDC app. You will need the Client ID and Client Secret for this POST app when you configure the Passport Library Item. If you already have a secure document from the Mac Login OIDC app, add a note that the new values are for the Web Login OIDC app. Copy the contents of the **Client ID** field. Paste the Client ID into the secure text document. Click **Show client secret**. Copy the client secret. Paste the client secret into the secure text document. Save the secure document. In OneLogin, assign the app to the users or groups who will sign in with Web Login (MFA). ## Configuring a User Account Type by Identity Provider Group in OneLogin Use this section when you map OneLogin roles to standard or administrator Mac accounts in Passport. It applies for both Mac Login (no MFA) and Web Login (MFA). When configuring whether a user will be a standard user or an admin user, follow the steps below. Log in to your OneLogin Console. Select Users > Roles. OneLogin Console Users menu with Roles Select **New Role** on the top right of the screen, and name your role. (*You will want to make sure your role name matches the IDP group name that you are using in your Iru Passport configuration).* In this example, the role is named Passport Admin Users. Finally, select your Iru Passport app that you created in OneLogin and click **Save** on the top right of the screen. Next, navigate to the Iru Passport app that you created in OneLogin. Select the **parameters** link and click the **Groups** field. In the "Default if no value selected" section, select User Roles from the drop-down list and make sure Semicolon Delimited Input is selected. Click **Save**. OneLogin Edit Field Groups with User Roles and Semicolon Delimited Input Finally, make sure your users are part of the role that you are creating, as well as a member of the Iru Passport application in OneLogin. To add a user to a role, select Users > Roles > *your role name (for example, Passport Admin Users)*, select the **Users** link, search for the user, click the blue **check box**, click the **Add to Role** link, and then click **Save** at the top right of the page. When OIDC apps and roles in OneLogin match what you need, open the [Iru Endpoint tab](#iru-endpoint) to enter values in the Passport Library Item. On that tab, User provisioning includes an example when a OneLogin role supplies the administrator group name. If you have not already, use [Configure the Passport Library Item](/en/endpoint/library/passport/configure-the-passport-library-item) to add the Passport Library Item and basic settings. The steps below are the Iru Endpoint steps specific to OneLogin Passport; use the values you collected on the [OneLogin tab](#onelogin). ### Authentication Mode Set **Authentication mode** in the Passport Library Item to match how users sign in with OneLogin. Use **Web Login** when MFA applies, and **Mac Login** when it does not. In OneLogin you always configure the Mac Login OIDC app; add the Web Login OIDC app as the second app when you use MFA, as on the [OneLogin tab](#onelogin). #### Web Login If you use multi-factor authentication with Passport, you must use **Web Login** as the authentication mode so users can complete MFA during sign-in. You should already have created two OIDC apps in OneLogin (Mac Login, then Web Login). When **Identity provider** in the Passport Library Item is **OneLogin** and **Authentication mode** is **Web Login**, the **second** OneLogin OIDC application must use the **POST** authentication method on the token endpoint (see the [Web Login](#onelogin-oidc-web-login) OIDC app steps on the [OneLogin tab](#onelogin)). Enter that second application's client ID in **Client ID (Web Authentication)**, the redirect URI in **Redirect URI**, and the client secret in **Client secret** on the Library Item (steps below). In the Passport Library Item, set **Identity provider** to **OneLogin**. In the **Identity provider URL** field, enter the OIDC well-known configuration URL (Issuer URL) from the **Mac Login** OIDC app you collected on the [OneLogin tab](#onelogin). It follows this pattern: ```bash theme={null} https://{subdomain}.onelogin.com/oidc/2/.well-known/openid-configuration ``` In the **Client ID (Password Sync)** field, enter the Client ID from the **Mac Login** OIDC application on the [OneLogin tab](#onelogin). Under **Authentication mode**, select **Web Login**. In the **Client ID (Web Authentication)** field, enter the client ID from the Web Login OIDC application you collected on the [OneLogin tab](#onelogin). In the **Redirect URI** field, enter the following: ``` https://localhost.redirect ``` In the **Client secret** field, enter the client secret from the Web Login OIDC application in OneLogin. Click **Save**. #### Mac Login If you are not using MFA with Passport, use **Mac Login** as the authentication mode. Users sign in with their OneLogin password at the Mac login window without the Web Login MFA flow. You should already have created one OIDC app in OneLogin (Mac Login only). In the Passport Library Item, set **Identity provider** to **OneLogin**. In the **Identity provider URL** field, enter the OIDC well-known configuration URL from the **Mac Login** OIDC app you collected on the [OneLogin tab](#onelogin). It follows this pattern: ```bash theme={null} https://{subdomain}.onelogin.com/oidc/2/.well-known/openid-configuration ``` In the **Client ID (Password Sync)** field, enter the Client ID from the **Mac Login** OIDC application on the [OneLogin tab](#onelogin). Under **Authentication mode**, select **Mac Login**. Click **Save**. ### User Provisioning If you want Passport to set each user's Mac account type from OneLogin roles, complete [Configuring a User Account Type by Identity Provider Group in OneLogin](#configuring-a-user-account-type-by-identity-provider-group-in-onelogin) first. Use the **User provisioning** steps below on the Passport Library Item [**Iru Endpoint** tab](#iru-endpoint). In the Passport Library Item, open the User account type menu in the User provisioning section and select **Specify per identity provider group**. With **User account type** set to **Specify per identity provider group**, open the account type drop-down below it and select Administrator or Standard user. If a user's IdP group membership returns both Administrator and Standard account types, the user is designated an Administrator. In each **Identity provider group** field, enter a role name that matches your OneLogin configuration. For each **Identity provider group** row, set the **Account type** as appropriate. Passport Library Item user account type by identity provider group When the Passport Library Item is saved, return to the [OneLogin tab](#onelogin) if you need to change OIDC apps or role mappings. If you experience any issues with Passport and OneLogin, read [Passport Troubleshooting with OneLogin](/en/endpoint/library/passport/onelogin/passport-troubleshooting-with-onelogin). # Passport Troubleshooting with OneLogin Source: https://docs.iru.com/en/endpoint/library/passport/onelogin/passport-troubleshooting-with-onelogin Troubleshoot Passport issues with OneLogin in Iru Endpoint. Resolve login failures, token errors, password sync problems, and app configuration conflicts. This guide applies to Mac computers ### About Passport Troubleshooting with OneLogin Passport troubleshooting with OneLogin involves resolving authentication issues that occur when using Passport with OneLogin as your Identity Provider (IdP). This guide helps identify and resolve common configuration and authentication problems specific to OneLogin integration. ### How It Works When Passport authentication issues occur with OneLogin, troubleshooting involves checking OneLogin application settings, verifying OIDC configuration, examining authentication flows, and resolving configuration mismatches between Passport and your OneLogin tenant. ### Login, Diagnostics, and Network At the Passport login window, always enter the user's full email address in the username field so the session uses your IdP instead of local authentication. For how the login window and visibility settings interact with Passport, see [Passport Compatibility](/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features#login-window). If a user cannot sign in, open Iru Endpoint Passport Diagnostics with **Command-Shift-K-L** on the Mac. The panel surfaces useful detail, including error messages returned from your IdP. Passport must reach OneLogin to validate credentials. When you customize the Passport login window, enable the network manager so users can join Wi-Fi if needed. The control respects AirPort security settings in macOS. Passport shows a Wi-Fi icon at the upper-right of the login window; users can click it to join a password-protected network. Passport does not support captive portals, click-through acceptance pages, or enterprise 802.1X networks that require a separate username and password in that flow. To isolate network issues, try a mobile hotspot or wired Ethernet while testing at the Passport login window. ### Common OneLogin Errors **What you see:** Error: Couldn't communicate with helper application (OneLogin) **What to do:** * Confirm the **Issuer URL** in Iru Endpoint matches your OneLogin OIDC well-known endpoint. It should follow this pattern: ``` https://.onelogin.com/oidc/2/.well-known/openid-configuration ``` **What you see:** Error: Unauthorized, MFA is required for this user (OneLogin) **What it means:** The user is likely affected by a **User** policy rather than an **App** policy. **What to do:** * Use an **App** policy for MFA so the user is prompted when accessing apps assigned in OneLogin, and do not rely on MFA enforced only on the User policy. This may affect MFA in other areas, such as accessing the OneLogin portal. OneLogin does not have a way to separate a User policy MFA requirement for the OIDC ROPG flow. * See OneLogin's [App Policies](https://onelogin.service-now.com/support?id=kb_article\&sys_id=76b83305db04a8143de43e043996192e) article. For setup steps, see [Passport Configuration with OneLogin](/en/endpoint/library/passport/onelogin/passport-configuration-with-onelogin). # Passport Compatibility with macOS & Iru Endpoint Features Source: https://docs.iru.com/en/endpoint/library/passport/passport-compatibility-with-macos-and-iru-endpoint-features Review Passport compatibility with macOS versions and Iru Endpoint features. Check supported configurations for FileVault, Platform SSO, and Login Window. This guide applies to Mac computers ## About Passport Compatibility When Passport is assigned to a Blueprint, some Library Item and macOS settings behave differently than they do without it. This article lists those settings, including Automated Device Enrollment, FileVault, Passcode, Login Window, and Blueprint Parameters. ## How It Works Passport interacts with Automated Device Enrollment, FileVault, Passcode, and Login Window. Some of those settings are compatible as-is. Others need the configuration described below. ## Library Items ### Automated Device Enrollment The following settings in the Automated Device Enrollment Library Item affect or are affected by Passport. #### Require Authentication If using Require Authentication within Automated Device Enrollment and assigning a user to a device record, prefilling initial account creation details is not recommended. Passport will use the account details provided upon the user's first login via the Passport login window. * Uncheck the **Prefill initial account creation details** checkbox. #### Primary Account Creation When using Passport, select **Skip primary account creation** under **Primary account type.** That way, when users arrive at the Passport login screen and log in using their Identity Provider (IdP) credentials, their Mac account will be provisioned. If you do not skip account creation, the device will display an error when attempting to create the local user account. Select the **Primary account creation** dropdown. Select **Skip primary account creation**. ### FileVault The **Enforce during Setup Assistant for Automated Device Enrollment (macOS 14+)** option in the FileVault Library Item is incompatible with Passport and should be disabled. When using Passport, the local user is created after Setup Assistant, which means that it won’t be possible to enable FileVault until Setup Assistant is complete. Navigate to the FileVault Library Item. Ensure that the **Enforce during Setup Assistant for Automated Device Enrollment (macOS 14+)** option is unchecked. ### Passcode When using Passport, it is highly recommended that the **Passcode** Library Item be removed from any Blueprint containing Passport. Your IdP should handle password requirements. If passcode requirements set by your IdP are less restrictive than those set by the **Passcode** Library Item, it will result in the user being unable to change their password because it doesn't meet the password requirements of the local Mac. If you need to enforce the **Passcode** policies for *Require Passcode After Sleep or Screen Saver Begins* and/or *Start Screen Saver After settings*, these are compatible with Passport. If you need to deploy these two settings, ensure that every other Passcode setting is disabled to avoid password sync issues. ### Login Window The following settings in the Login Window Library Item are compatible or incompatible with Passport as noted. #### Compatible with Passport The **Set lock message** option is compatible with Passport. The options in the **Logged in users** section are compatible with Passport. Fast user switching can be enabled with Passport without issues. The **Manage user visibility** option in the *User visibility* section of the Login Window Library Item is compatible with Passport. It controls whether the login window shows a list of users or username and password fields, and it also affects the FileVault unlock screen on Apple Silicon. You can disable the **Manage user visibility** option to leave the login window at its default behavior. * **Display a list of users:** Users select their account from a list. * **Display username and password fields:** The login window shows username and password fields. On Apple Silicon, the FileVault unlock screen also shows username and password fields while Intel will still show a list of users. #### Incompatible with Passport The items in the **Menu Bar** section are incompatible with Passport and should be unchecked. The items in the **Options** section are incompatible with Passport and should be unchecked. ## Parameters The following parameters require attention when using Passport. If you are using the **Enforce a custom policy banner** parameter, disable it for any Blueprints containing the Passport Library Item. Since Passport evaluates the User account type, and may change it from Administrator to Standard or vice versa, combination with the [Demote user accounts to Standard](/en/endpoint/blueprints/parameters/demote-user-accounts-to-standard) Parameter can cause reboot loops. If provisioning User accounts as administrators in your Passport Library Item, ensure the Demote user accounts to Standard Parameter is not enabled in the same Blueprint. Using the Demote user accounts to Standard Parameter on a Blueprint with Passport assigned is not recommended. Passport requires network connectivity to check user credentials against the IdP. When customizing the login window in Passport, show the network manager so users can join a Wi-Fi network as necessary. The network manager respects AirPort security settings in macOS. You can use the **Secure Wi-Fi Settings** parameter in Iru Endpoint to require local administrator credentials to change networks. If enabled, users will be prompted with a native authentication dialog at the Passport window when switching networks. To ensure that users can always log in to their Mac computers, Passport will allow them to log in using their IdP credentials when there is no network connectivity. ## macOS Features The following macOS features interact with Passport as described. Using Migration Assistant with Passport is not supported. If Migration Assistant was used with Passport, you can follow these steps to resolve the issue. When using Migration Assistant to migrate data from a device that is enrolled in Iru Endpoint, please remove Passport from the device that you are migrating from before attempting a migration. If Passport remains on the device and is migrated to the target device, users may get stuck at the Passport screen and won't be able to proceed. If you need assistance remediating this situation, please [reach out to support](/en/iru/iru-support/access-to-iru-support). In some situations, a user may be logged in to an Apple Account with an account name that matches the IdP account name. Much like Passport, an alias is created in the local directory to match this Apple Account account name. When the Apple Account matches the IdP account name, a collision can occur that will prevent the user from signing in with the IdP account name. This collision happens only when the user signs out of the Apple Account. The sign-out process removes the alias for the Apple Account. Since this alias matches the account name used by Passport, it removes the alias for Passport as well. To resolve this, the alias must be restored. This can be done manually using the Users & Groups pane in System Settings (or System Preferences) or in the Directory Utility app on the local computer. If you need assistance remediating this situation, please [reach out to support](/en/iru/iru-support/access-to-iru-support). Passport is compatible with local macOS accounts. Mobile accounts are unsupported. Before using Passport, convert existing mobile accounts to local accounts for successful account merging. To contact the IdP, Passport needs network connectivity. It’s common for people to use a portable Mac in various locations that provide a Wi-Fi network that the Mac has not yet joined. Passport displays a Wi-Fi icon in the upper-right corner of the screen. You can click the Wi-Fi icon to join a Wi-Fi network that accepts a password to join the network. At this time, Passport does not support networks that use captive portal, click-through authentication, or enterprise networks that require a username and password for 802.1X authentication. ## Identity Provider The following Identity Provider (IdP) behavior applies when using Passport. ### Temporary Passwords Temporary IdP passwords are incompatible with Passport when using the Mac Login Authentication mode. Temporary passwords are compatible with the Web Login Authentication mode. # User experience with Passport Source: https://docs.iru.com/en/endpoint/library/passport/user-experience-with-passport See what users experience with Passport on Mac. Understand the login screen, IdP authentication prompts, password sync notifications, and setup flow. This guide applies to Mac computers ### About Passport Passport lets you sign in to your Mac with the same email and password you use for work or school. You don't need a separate password just for your computer. ### How It Works When you reach the login screen, you enter your work or school email and password. Passport checks them with your organization's sign-in system and then logs you into your Mac. ### Logging in with Mac Login With Mac Login, you see the standard Mac login screen with username and password fields. If you see your organization's sign-in page (for example, Okta or another provider) in the login window instead, skip to the next section. At the login screen, enter your full work or school email address in the **username** field and your work or school password in the **password** field. After you sign in successfully, you'll be logged into your Mac. ### Logging in with Web Login With Web Login, your organization's sign-in page (for example, Okta or another provider) appears inside the login window. You may see that provider's branding and an extra verification step before you sign in. Sign in using your work or school credentials. If your organization uses an extra verification step, complete that when prompted. You may be asked for your work or school password one more time after verification. After you complete sign-in, you'll be logged into your Mac. ### Signing in with Only Your Mac Account (Local Login) If your IT team has allowed it, you can sign in using only your Mac account instead of your work or school account. Click the Profile icon at the top right of the login window. Click **Switch to Local Login**. Enter the username and password for your Mac account, then press **Enter**. To sign in with your work or school account again, click the Web Login icon. Click **Switch to Web Login**. ### Linking Accounts The first time you sign in, you may see an option to link your work or school account with an existing account on this Mac. Linking keeps all of your files and settings. After that, you'll sign in with your work or school email and password instead of a separate Mac password. Select **Link my existing account**. Account Setup dialog showing Link my existing account and Create a new account options at the Passport login window Click **Continue**. From the drop-down menu, select the Mac account you want to link to your work or school sign-in. Enter the password for that Mac account. Link Account dialog with local account dropdown and password field, and Back and Continue buttons Click **Continue**. A confirmation dialog appears. Click **Link this account** to confirm. This action cannot be undone. Confirmation dialog: Are you sure you want to link the user with your identity provider login, with Link this account and Cancel buttons ### Changing Keyboard Language at the Login Screen You can choose a different keyboard language on the login screen. This is helpful if you use a non-US keyboard. Your choice is saved and will still be there after you restart your Mac. In the upper-right corner of the login window, click the Keyboard icon. Choose the language you want for the keyboard. Passport login window keyboard menu open to choose an input language ### Resetting or Changing Your Password If you don't see the option to reset your password when you follow the steps below, ask your IT or support team to turn on that option for you. #### Reset Password from the Menu Bar (While Logged In) You can open your organization's password reset page from the Iru Endpoint menu so you can change your work or school password. Click the Iru Endpoint menu in the menu bar at the top of the screen. Click the gear icon. Choose the **Reset Password...** menu item. Iru Endpoint menu bar with the gear menu open; the Reset Password... item is shown A browser window opens with your organization's password reset page. Follow the steps there to set a new work or school password. #### Reset Password at the Login Screen If you're at the login screen and enter the wrong password three times, a link to reset your password may appear (if your organization has set this up). At the login screen, enter your work or school password incorrectly three times. If your organization offers password reset at the login screen, a link to reset your password appears. Passport login window with a link to reset the work or school password Click the link and follow the steps to set a new work or school password. #### When Passport Asks You to Update Your Mac Password Passport can check from time to time that your Mac password matches your work or school password. If you changed your work or school password, Passport may prompt you to update your Mac password so they stay in sync. In some setups, Passport only does this check when you sign in; in others, it may check every few minutes while you're logged in. Passport prompt to update the Mac password so it matches the work or school password # Network Authentication Overview Source: https://docs.iru.com/en/endpoint/networking-and-connectivity/network-authentication-overview Overview of 802.1X network authentication with Iru Endpoint. Configure certificate-based and credential-based authentication for Wi-Fi and Ethernet. ## About This Guide This guide explains the different types of network authentication you can configure in Iru Endpoint. It compares non-enterprise and enterprise Wi-Fi options so you can choose the right approach for your environment. For step-by-step configuration of network access, see: * [Configure the Wi-Fi Library Item](/en/endpoint/library/library-items-profiles/configure-the-wi-fi-library-item) * [Configure the Ethernet Library Item](/en/endpoint/library/library-items-profiles/configure-the-ethernet-library-item) ## Non-Enterprise Wi-Fi Authentication When you're setting up a Wi-Fi network in Iru Endpoint, you need to choose an authentication type. If your environment doesn't require enterprise-level authentication (like 802.1X), you have several options, each with different strengths and tradeoffs. ### Types of Non-Enterprise Authentication * **WPA3 Personal**: Newer standard with stronger protection, including against offline password guessing. Prefer for new hardware when devices and access points support it. * **Mixed-mode (WPA2/WPA3)**: Allows both WPA2 and WPA3. Useful during transition; note that overall security is limited by the weakest client. * **WPA2 Personal**: Current standard for most Wi-Fi without enterprise auth. Strong encryption (AES), widely supported. Good balance of security and ease of use for small and medium organizations; use a strong, unique password. * **WPA Personal (WPA-PSK)**: Shared password (pre-shared key). Largely replaced by WPA2 and WPA3. Use only for older devices; choose a strong password and plan to upgrade. * **WEP (Wired Equivalent Privacy)**: Older protocol, now considered insecure and easily cracked. Use only for legacy devices that cannot support anything else; keep it isolated from sensitive data. * **Open networks**: No password required. Anyone in range can connect. There is no encryption, so data is not protected. Best for public guest Wi-Fi or testing only; avoid for business use. ### Comparison: Non-Enterprise Wi-Fi Types | **Protocol** | **Authentication** | **Security level** | **Compatibility** | **Use cases** | **Notes** | | --------------------------------- | -------------------------------------- | ------------------------------------------------ | ------------------------------------------- | ------------------------------------------- | --------------------------------------------------- | | **WPA3 Personal** | SAE | Very high | Newer devices | New deployments, high-security environments | Latest standard; improved security features. | | **Mixed-mode (WPA2/WPA3)** | PSK, SAE | Variable | Mixed device environments | Transitioning networks | Security depends on the weakest link. | | **WPA2 Personal** | Pre-shared key (PSK) | High | Most modern devices | Home, small to medium businesses | Current standard; strong encryption. | | **WPA Personal** | Pre-shared key (PSK) | Moderate | Older devices | Small networks, temporary setups | Superseded by WPA2; use only if necessary. | | **WEP** | Shared key | Low | Legacy devices | Legacy systems | Easily cracked; not recommended for sensitive data. | | **Open networks** | None | Very low | Universal | Public Wi-Fi, testing | No encryption; easy to join but insecure. | ## Enterprise Wi-Fi Authentication Enterprise Wi-Fi uses **802.1X** to control who can join the network. Instead of a shared password, each user or device is authenticated individually, usually with credentials and often digital certificates. This improves security and makes it easier to manage access at scale. ### How 802.1X Works Four components are involved: * **MDM** (Iru Endpoint): Configures devices with credentials for 802.1X and deploys identity certificates (e.g., via SCEP or PKCS #12) so that methods like EAP-TLS work when the device connects. * **Supplicant**: The device (e.g. Mac, Windows laptop, or phone) that wants to connect, using credentials and certificates that MDM has deployed. * **Authenticator**: The network device (e.g. access point or switch) that acts as the gatekeeper. * **Authentication server**: Usually a RADIUS server; it checks credentials and tells the authenticator whether to allow access. MDM deploys certificates and configuration to the device first. The device then sends credentials to the authenticator, which forwards them to the authentication server. If the check succeeds, the device is granted access. The diagram below shows the flow at a glance. ```mermaid actions={false} lines theme={null} %%{init: {'sequence': {'mirrorActors': false}}}%% sequenceDiagram title 802.1X authentication flow participant M as MDM participant S as Supplicant (Device) participant A as Authenticator (Access Point) participant R as Auth server (RADIUS) M->>S: Deploy certs to device S->>A: Connection request / credentials A->>R: Access request R->>R: Verify credentials R->>A: Access-Accept or Access-Reject A->>S: Grant or deny access ``` ### Enterprise Authentication Types * **WPA3 Enterprise**: Builds on WPA2 Enterprise with stronger encryption and extra protections. Requires server certificate validation so users connect to the right network. Adds Management Frame Protection (MFP) to help prevent certain attacks. Optional 192-bit mode is available for highly sensitive environments. * **WPA2 Enterprise**: Pairs 802.1X with strong encryption (AES). Each user has a unique login; you can use passwords, certificates, or multi-factor authentication. Widely supported and the most common choice for organizations that need strong Wi-Fi security. ### Comparison: Enterprise Wi-Fi Types | **Protocol** | **Authentication** | **Security level** | **Key features** | **Use cases** | **Notes** | | --------------------------------- | -------------------------------------- | ------------------------------------------------ | ----------------------------------------------------------------- | ------------------------------------------------ | ---------------------------------------- | | **WPA3 Enterprise** | 802.1X, per-user | Very high | Server cert validation; MFP; optional 192-bit mode | New deployments, high-security environments | Builds on WPA2 with stronger protections | | **WPA2 Enterprise** | 802.1X, per-user | High | AES encryption; passwords, certificates, or MFA; widely supported | Most organizations needing strong Wi-Fi security | Most common choice for enterprise Wi-Fi | ### EAP Types The method used to authenticate users is the **Extensible Authentication Protocol (EAP)**. Common types (from highest to lowest security): * **EAP-TLS**: Uses client and server certificates for mutual authentication. Very secure but requires certificate management. * **PEAP and EAP-TTLS**: Use server certificates and user credentials (e.g. username and password). Easier to manage than EAP-TLS and still secure. * Other types (e.g. **EAP-FAST**, **LEAP**) exist but are less common and not recommended for new deployments. ### Comparison: EAP Types | **EAP type** | **Authentication** | **Security** | **Notes** | | -------------------------------- | ------------------------------------------------------------------- | ------------------------------------------ | ------------------------------------------------ | | **EAP-TLS** | Client and server certificates (mutual auth) | Very high | Very secure; requires certificate management | | **PEAP / EAP-TTLS** | Server certificates + user credentials (e.g. username and password) | High | Easier to manage than EAP-TLS; still secure | | **EAP-FAST, LEAP** | Various | Lower / legacy | Less common; not recommended for new deployments | ### Why Choose Enterprise Authentication? * Per-user or per-device credentials; no shared password to leak. * Centralized access control; disabling an account revokes Wi-Fi access immediately. * Support for certificate-based auth and multi-factor authentication. * Detailed logging and auditing for compliance and troubleshooting. ### Infrastructure Requirements Enterprise authentication requires extra infrastructure: a RADIUS server and, for certificate-based setups, a certificate authority. Many organizations already have these or use cloud-based options. For more on certificates and 802.1X, see [Using Identity Certificates for 802.1X Authentication](/en/endpoint/integrations/certificate-services/using-identity-certificates-for-802-1x-authentication). ### Related Articles Configure the Wi-Fi Library Item for network deployment Configure 802.1X authentication for wired networks Use identity certificates for 802.1X authentication Configure EAP types for 802.1X authentication # Add Apps from Apps and Books to Iru Endpoint Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint Add apps from Apple Business Manager Apps and Books to your Iru Endpoint Library. Search the App Store, purchase licenses, and assign to device Blueprints. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Apps and Books Integration With Apps and Books in Apple Business or Apple School Manager, you can deploy App Store and Custom Apps to macOS, iOS, iPadOS, tvOS, and visionOS devices through Iru Endpoint. This integration provides centralized app management and automated deployment capabilities. ### How It Works Apps and Books integration works by connecting your Apple Business or Apple School Manager account with Iru Endpoint through an **Apps and Books content token** tied to an **organizational unit** in the portal. When you assign app licenses to that same token in the portal, the apps automatically appear in your Iru Endpoint Library, where you can include them in Blueprints for automated deployment to managed devices. ### Prerequisites * **Apps and Books Configuration**: [Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books) in your Iru Endpoint tenant * **Apple Business or Apple School Manager access**: Ensure you have administrative access to your organization's portal account * **Apps and Books token**: Verify your Apps and Books token is properly integrated with Iru Endpoint ### Adding Apps and Books Apps Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) with a Managed Apple Account that can manage Apps and Books. Click **Apps & Services** at the top of the page. Click **View Store** in the middle of the page. Apple Business Apps & Services with View Store highlighted Search for the app, then select it from the results. Select which **token** to assign licenses to (use the same Apps and Books content token you integrated with Iru Endpoint). Set the **Quantity**. Click **Get** for a free app, or **Buy** for a paid app. Apple Business App Store for organizations with search, token assignment, quantity, and Get You will now see all available App Store Apps assigned to the **Apps and Books content token** you integrated with Iru Endpoint in your Iru Endpoint Library, and you will be able to include them in any of your Blueprints. ### Considerations * **iOS App Management**: Any app deployed to an iOS device in Iru Endpoint is marked as non-removable. You will need to remove your iOS device from the app's Library Item assignment to uninstall the app from the device * **Iru Self Service**: To deploy Self Service on iOS, iPadOS, or visionOS, search for **Iru Self Service** (app ID 1579981636) in Apple Business or Apple School Manager. See [Self Service for iOS, iPadOS, and visionOS](/en/endpoint/settings/self-service/self-service-for-ios-ipados-and-visionos). * **Custom Apps Support**: Iru Endpoint also supports Custom Apps in Apple Business or Apple School Manager. They will appear in your Iru Endpoint Library, and you will be able to include them in any of your Blueprints like any other App Store App. Formerly known as B2B Apps, these are different from Custom Apps in Iru Endpoint. For more information, please see [Apple's documentation](https://support.apple.com/guide/business/learn-about-custom-apps-axm58ba3112a/web) on Custom Apps * **Device Compatibility**: Verify that apps are compatible with your target device platforms (macOS, iOS, iPadOS, tvOS, visionOS) * **App Store Licensing**: Ensure you have appropriate App Store licenses for the apps you plan to deploy * **Quantity Management**: Plan your app quantities carefully to avoid over-purchasing or running out of licenses * **Apps and Books token limits**: Be aware of any limits on the number of apps that can be assigned to a single Apps and Books token * **App Updates**: Consider how app updates will be handled through the Apps and Books integration * **User Experience**: Test app deployment and user experience before rolling out to production devices * **Compliance Requirements**: Ensure deployed apps meet your organization's security and compliance requirements * **Backup Strategy**: Have a plan for managing apps if the Apps and Books integration becomes unavailable * **Documentation**: Keep records of app assignments and deployment configurations * **Support**: Contact Apple Support for issues related to Apps and Books functionality * **Integration Monitoring**: Regularly monitor the Apps and Books integration status and app availability # Adding Devices to Apple Business or Apple School Manager Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/adding-devices-to-apple-business-manager Add Apple devices to Apple Business Manager for Automated Device Enrollment with Iru Endpoint. Register using serial numbers, resellers, or Apple Configurator. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Adding Devices to Apple Business or Apple School Manager Adding devices to Apple Business or Apple School Manager enables automated device enrollment and centralized management of Apple devices. This process allows organizations to manage devices that were not automatically registered in the portal at purchase (for example, consumer channel purchases). ### How It Works Devices are added to Apple Business or Apple School Manager using Apple Configurator, which connects to the device and registers it with Apple's servers. Once added, devices can be assigned to MDM servers like Iru Endpoint for automated enrollment and management. The process requires physical connection to a Mac computer and may involve device erasure. ### Prerequisites * **Apple Configurator 2**: Download and install Apple Configurator 2 from the Mac App Store * **Apple Account**: Ensure you have access to a Managed Apple Account for Apple Business or Apple School Manager * **Physical Access**: Devices must be physically connected to a Mac computer * **Network Connectivity**: Ensure devices can connect to Apple's activation servers * **Backup Strategy**: Back up device data before proceeding as devices will be erased ### Adding macOS Devices * **Operating System Limitations**: Mac computers on Big Sur or earlier operating systems cannot be added to Apple Business or Apple School Manager using Apple Configurator. [Some resellers](https://support.apple.com/kb/PH26932?locale=en_US) may allow past purchases to be added to your organization's account there. Contact your reseller or Apple Store Business Representative for more information * **Apple Configurator Method**: If you're adding Mac computers to Apple Business or Apple School Manager without the assistance of a reseller, you will need to use Apple Configurator for iOS. Follow this [Apple Support Guide](https://support.apple.com/guide/apple-configurator/welcome/ios) for instructions ### Adding iOS, iPadOS, and tvOS Devices Any Apple devices that are physically connected to your Mac will be **erased** by proceeding with the following steps. This is required and cannot be skipped. Please disconnect any devices you aren't planning to add to Apple Business or Apple School Manager. If needed, back up your device before proceeding. * **30-Day Provisional Period**: After the devices are placed into Apple Business or Apple School Manager, the user has a **30-day provisional period** to remove the device from the portal and from MDM. The provisional period begins after the device is activated. After 30 days, the device can only be released through the portal * **Apple Configurator for iOS**: iOS and iPadOS devices can also be added to Apple Business or Apple School Manager using Apple Configurator for iOS. For further instructions on adding them using that method, follow [this Apple Support Guide](https://support.apple.com/en-gb/guide/apple-configurator/apd97373af1e/1.1/ios/17.0) * **Enrollment Limitation**: **Enrolling iOS, iPadOS, and tvOS devices in Iru Endpoint via Apple Configurator is not supported.** The method outlined in this document will add these devices to Apple Business or Apple School Manager, but will not enroll them within Iru Endpoint. To enroll devices in Iru Endpoint after they appear in the portal, review our enrollment guides: * [Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment) * [Enrolling Apple TV Devices](/en/endpoint/enrollment/apple/enrolling-apple-tv-devices) ### Downloading Apple Configurator You can download Apple Configurator 2 by [visiting this link](https://apps.apple.com/us/app/apple-configurator-2/id1037126344?mt=12). To complete the download, you will need an [Apple Account](/en/endpoint/enrollment/apple/apple-accounts-overview). ### Creating a Wi-Fi Profile Unless using a wired internet connection local to the device, a Wi-Fi profile is required for the device to reach Apple's activation servers. Ensure you create a profile that will allow the device to connect to the internet. In Apple Configurator, click **File,** then **New Profile** from the menu bar. In the **General** section, **fill in the following profile details**. * **Name:** For example: "Wi-Fi Profile" * **Identifier:** Leave as is. This code is unique to the profile making future updates identifiable * **Organization:** Your company name * **Description:** Provide a brief description. For instance: "Wi-Fi Provisioning Profile" * **Automatically Remove Profile:** Set this option to **After Interval** and set **0 days, 1 hour** Click the **Wi-Fi** payload option on the left-hand side, and select **Configure**. Input your organization's **valid Wi-Fi network details**. Select **File**, then **Save** from the Menu bar and save the file. Note the location where you save this file - you'll need it later. ### Adding Devices to Apple Business or Apple School Manager **Connect your device** directly to your Mac and open **Apple Configurator**. If you are trying to connect an Apple TV 4K (which does not have a physical port to connect to) follow [this Apple Support article](https://support.apple.com/en-us/HT208124) on how to connect wirelessly. Click on the device inside of Apple Configurator, and click **Prepare**. Select **Manual Configuration**. Select **Add to Apple Business or Apple School Manager**. Deselect **Activate and Complete Enrollment** and click **Next**. Select New Server... and click **Next**. Enter a name of your choosing in the **Name** field. Enter the following URL in the **Host name or URL** field. Please note that this URL **will not verify**. `https://myserver.local/devicemanagement/mdm/dep_mdm_enroll` Click **Next**, don't add a certificate, then click **Next** again. Assign to the **Organization** you have set up in Apple Business or Apple School Manager and click **Next**. Optionally, select which setup screens you prefer to skip during setup, then click **Next**. Choose the **Network Profile** you created in the first part of this guide. Sign in to your **Apple Business or Apple School Manager** account using your Managed Apple Account and password, and click **Next**. Leave the device plugged in and allow the process to complete. If prompted that the device is already set up and must be erased, click **Erase** to continue. **Do not proceed with the initial device Setup Assistant** without following the next steps first. The device may need to be erased again if the next steps are not performed prior to device setup. ### Assigning Devices in Apple Business or Apple School Manager Sign in to **Apple Business or Apple School Manager** and go to the **Devices** section. Click the **Search Devices** option in the upper left-hand corner, and paste in the serial number of the device we just added to Apple Business or Apple School Manager. Click the **Edit MDM Server** button and assign it to your Iru Endpoint server. Click **Continue**. You will receive a confirmation screen that the device assignment has been updated. Sign in to the **Iru Endpoint** Web App, go to **Enrollment** → **Automated Device Enrollment**, and confirm that you see the desired device listed. If you don't see the device listed, click **Fetch devices** in the top right-hand corner to force Iru Endpoint to check for newly added devices. Once confirmed, proceed with the device setup. Properly configured devices will present a **Remote Management** prompt during Setup Assistant. ### Considerations * **Device Erasure**: All devices will be erased during the Apple Business or Apple School Manager addition process * **Backup Requirements**: Always back up device data before proceeding with the addition process * **30-Day Provisional Period**: Users have 30 days to remove devices from Apple Business or Apple School Manager after activation * **Setup Assistant**: Follow proper setup procedures to avoid device re-erasure * **Physical Connection**: Devices must be physically connected to a Mac computer for the process * **Apple Configurator Requirements**: Download and install Apple Configurator 2 from the Mac App Store * **Wi-Fi Profile**: Create appropriate Wi-Fi profiles for devices to connect to activation servers * **Network Connectivity**: Ensure devices can connect to Apple's activation servers during the process * **Apple Business or Apple School Manager access**: Ensure you have administrative access to the portal * **MDM Server Assignment**: Assign devices to the correct Iru Endpoint MDM server after addition * **Device Verification**: Verify devices appear in Iru Endpoint after assignment * **Documentation**: Keep records of device serial numbers and assignment details * **Testing**: Test the device addition process in a controlled environment before production * **Monitoring**: Regularly monitor device status and enrollment success rates * **Support**: Contact Iru Endpoint Support for assistance with complex device addition scenarios # Apple Integrations Overview Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/apple-integrations-overview Overview of Apple integrations in Iru Endpoint including APNs, Automated Device Enrollment, Apps and Books, and Apple Business Manager configurations. This guide applies to Apple devices **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ## Core Integration Components ### Apple Business or Apple School Manager **Apple Business** (businesses) and **Apple School Manager** (education) are the central portals for managing your organization's Apple devices and services with Iru Endpoint. * **[Configure Automated Device Enrollment](/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment)** - Set up Automated Device Enrollment (ADE) for zero-touch deployment and lifecycle management of corporate Apple devices * **[How To Verify Apple Business or Apple School Manager Domains](/en/endpoint/settings/apple-integrations/how-to-verify-apple-business-manager-domains)** - Complete domain verification in your Apple portal to secure Managed Apple ID domains and prevent ownership conflicts * **[Adding Devices to Apple Business or Apple School Manager](/en/endpoint/settings/apple-integrations/adding-devices-to-apple-business-manager)** - Add existing Apple devices using Apple Configurator for automated device enrollment and management ### Apple Push Notification Service Apple Push Notification service (APNs) enables secure communication between Iru Endpoint and your managed Apple devices. * **[Configure Apple Push Notification Service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service)** - Set up Apple Push Notification service (APNs) for secure Mobile Device Management (MDM) communication and device management across Apple devices ### Apps and Books Integration Apps and Books (formerly Volume Purchasing Program) allows centralized app license management and distribution. * **[Configure Apps and Books](/en/endpoint/settings/apple-integrations/configure-apps-and-books)** - Set up Apps and Books integration for App Store app distribution and license management through Apple Business or Apple School Manager * **[Add Apps from Apps and Books to Iru Endpoint](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint)** - Deploy App Store and Custom Apps to macOS, iOS, iPadOS, tvOS, and visionOS devices through Apple Business or Apple School Manager integration ### Advanced Token Management For organizations with complex device management needs, advanced token management capabilities are available. * **[Configure multiple ADE tokens using the Iru Endpoint API](/en/endpoint/settings/apple-integrations/configure-multiple-automated-device-enrollment-tokens)** - Set up multiple ADE tokens using API automation for bulk operations and token lifecycle management * **[Renew, update, or delete ADE tokens using the Iru Endpoint API](/en/endpoint/settings/apple-integrations/renew-update-or-delete-multiple-automated-device-enrollment-tokens)** - Manage multiple ADE tokens using API automation for bulk operations and token lifecycle management ### Support and Troubleshooting When you need additional assistance with Apple-specific issues, specialized support resources are available. * **[AppleCare Enterprise Support](/en/endpoint/settings/apple-integrations/applecare-enterprise-support)** - Access AppleCare Enterprise Support for Apple Business or Apple School Manager, APNs, hardware, and operating system issues requiring Apple's direct assistance ## Integration Workflow Start by setting up APNs to establish secure communication with Apple devices. This is a prerequisite for all other Apple integrations. Configure your Apple Business or Apple School Manager account and verify domains to enable device management and user provisioning. Set up ADE to enable zero-touch device enrollment and automatic configuration deployment. Set up Apps and Books integration for centralized app license management and distribution. Add existing devices to Apple Business or Apple School Manager using Apple Configurator for automated enrollment. Use Apps and Books integration to distribute App Store and Custom Apps to managed devices. # AppleCare Enterprise Support Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/applecare-enterprise-support Access AppleCare for Enterprise support through Iru Endpoint. Get priority hardware service, technical support, and dedicated Apple account management. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About AppleCare Enterprise Support In certain situations, Iru Endpoint support might suggest reaching out to the AppleCare Enterprise Support team. This is particularly relevant for issues related to Apple Business or Apple School Manager, Apple Push Notification service, Apple hardware, macOS, iOS, iPadOS, tvOS or visionOS where AppleCare might be better equipped to assist. ### How It Works AppleCare Enterprise Support provides specialized assistance for enterprise-level Apple services and hardware issues. When Iru Endpoint Support Engineers identify issues that require Apple's direct intervention, they will recommend contacting AppleCare Enterprise Support. Both support teams can coordinate on cases when necessary. ### When to Contact AppleCare Enterprise Support Contact AppleCare Enterprise Support for issues related to: * **Apple Business or Apple School Manager**: Enrollment, configuration, or integration problems * **Apple Push Notification Service**: Certificate issues or communication problems * **Apple Hardware**: Device-specific hardware failures or malfunctions * **Operating Systems**: macOS, iOS, iPadOS, tvOS, or visionOS system-level issues * **Enterprise Services**: Advanced Apple enterprise features and configurations If an Iru Endpoint Support Engineer advises you to contact AppleCare Enterprise Support directly, please provide them with as much context from your Iru Endpoint support case as possible, if requested. Iru Endpoint collaborates closely with AppleCare, and both support teams can coordinate on cases when necessary. Make sure to share your Iru Endpoint ticket number with AppleCare Enterprise Support if it's anticipated that both teams will need to work together to resolve your issue. ### Contacting AppleCare Enterprise Support You can reach AppleCare using your AppleCare Professional Support Agreement or by contacting them using [the global phone numbers](https://support.apple.com/HT201232). Please use the **Enterprise** number. **United States - Enterprise Support**: 1-866-752-7753 ### AppleCare Enterprise Support Hours For customers with an AppleCare Professional Support Agreement, the [AppleCare Enterprise Portal (AEP)](https://enterprise.apple.com/) is available seven days a week, 24 hours a day. Please refer to your Support Agreement Proof-of-Coverage documentation for more details. ### Contacting Apple for Deployment Programs Support If you need assistance enrolling in Apple Business or Apple School Manager, please refer to [the Apple Business Support website](https://support.apple.com/business). You can reach AppleCare Deployment Programs Support by phone at **1-866-902-7144** ### Contacting Apple for Apple Push Notification Services Certificates For help with Apple Push Notification service, please refer to the [Contact Apple for help with Push Notification Service Certificates web page](https://support.apple.com/HT208643). You can reach Apple Deployment Programs Support by phone at **1-866-902-7144** ### Considerations * **Support Escalation**: Contact AppleCare Enterprise Support when Iru Endpoint Support recommends it * **Case Context**: Provide AppleCare with detailed context from your Iru Endpoint support case * **Ticket Coordination**: Share your Iru Endpoint ticket number with AppleCare for coordinated support * **Issue Classification**: Understand which issues require Apple's direct intervention * **Support Agreements**: Ensure you have appropriate AppleCare Professional Support Agreement coverage * **Portal Access**: Use the AppleCare Enterprise Portal (AEP) for 24/7 support when available * **Phone Support**: Use the Enterprise phone numbers for priority support access * **Response Times**: Be aware of AppleCare Enterprise Support response time expectations * **Follow-up**: Coordinate with both Iru Endpoint and AppleCare teams as needed * **Escalation Process**: Follow proper escalation procedures for urgent issues * **Communication**: Maintain clear communication between all support teams * **Knowledge Sharing**: Share relevant information between Iru Endpoint and AppleCare teams * **Documentation**: Keep records of all support interactions and case numbers * **Resolution Tracking**: Track issue resolution progress across multiple support channels * **Support Documentation**: Keep detailed records of all support interactions and resolutions # Configure Apple Push Notification Service Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service Set up Apple Push Notification service (APNs) for Iru Endpoint. Generate the CSR, upload to Apple, and configure the push certificate for MDM communication. ### About Apple Push Notification Service Apple Push Notification service (APNs) is a critical component in the context of Mobile Device Management (MDM) for Apple devices. APNs keeps a persistent connection between MDM solutions and Apple devices across both public and private networks. This service allows MDM servers to send notifications to devices, enabling remote management tasks such as applying configurations, installing software, locking or wiping devices, and more. ### How It Works APNs operates through a secure certificate-based authentication system. MDM solutions require an APNs certificate to communicate with Apple devices. When an MDM action is initiated, a notification is sent to APNs, which then notifies the device. The device checks in with the MDM server, receives the command, and executes the required action. This process enables real-time device management and configuration deployment. ### Prerequisites * **Apple Account**: Ensure you have access to a managed Apple Account for creating and renewing APNs certificates * **Network Access**: Verify network configurations allow necessary traffic to Apple's network for APNs functionality * **macOS Computer**: Use a macOS computer for best results when configuring APNs * **Certificate Management**: Plan for annual certificate renewal to avoid service disruptions For a full list of network requirements, please see our [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks) support article. ### Best Practices for Managing Apple Push Notification service * Use a managed Apple Account that is accessible by multiple team members for creating and renewing APNs certificates * Plan ahead for certificate renewal to avoid disruptions in MDM communication * Ensure network configurations allow necessary traffic to Apple's network for APNs to function correctly. For a full list of network requirements, please see our [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks) support article ### Configuring Apple Push Notification Service For best results, use a macOS computer. Navigate to your Iru Endpoint Web App (e.g., accuhive.iru.com). In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Under Apple Push Notifications service (APNs), click **Set up APNs**. Follow the on-screen instructions to create a new APNs certificate. ### Renewing Your Apple Push Notification Service Certificate APNs certificates must be renewed annually. If the certificate expires, it can lead to issues such as the inability to manage existing Apple devices and enrollment failure for new devices. Your APNs certificate can be renewed at any time. For best results, monitor the certificate expiration date in the Iru Endpoint Web App and plan to renew it before it expires. Iru Endpoint will send email reminders to Team Members with Admin or Account Owner permissions starting 30 days before certificate expiry. In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Under Apple Push Notifications service (APNs), click **Renew certificate**. Follow the on-screen instructions to renew your APNs certificate. Apple integrations tab showing Renew certificate button under APNs for certificate renewal ### Troubleshooting APNs Certificate Renewal When uploading a new APNs certificate, you may see an error stating, "This doesn't appear to be a valid certificate." This issue can arise for a few different reasons, including: * **Different Apple Account**: The Apple Account used to create the new certificate is different from the one used for the original certificate * **New Certificate Upload**: The certificate was uploaded as a new one instead of renewing the existing certificate * **File Extension Issues**: The uploaded certificate does not have the .pem file extension or has been renamed from its original name, *MDM\_Iru Endpoint, Inc.\_Certificate.pem* If you need to change the Apple Account that is used for an APNs certificate, it is recommended to do so before renewing the original certificate. To start the process of migrating an APNs certificate to a new Apple Account, you can [Contact Apple's Deployment Programs Support team](https://support.apple.com/en-us/HT208643). ### Disconnecting APNs Only disconnect your APNs certificate if you need to replace it with a new one. Replacing your APNs certificate will break MDM communication on all of your enrolled Apple devices. You will need to re-enroll all devices under the new APNs certificate. In the sidebar, click the **Account Menu Button**, then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Under Apple Push Notifications service (APNs), click **Disconnect**. Apple integrations tab showing Disconnect button under APNs for replacing certificate If you accidentally disconnect your APNs certificate and need to reconnect it for renewal, you can do so by following the configuration steps in Iru Endpoint. Then, proceed to [identity.apple.com](https://identity.apple.com) to complete the certificate renewal process. ### Considerations * **Certificate Renewal**: APNs certificates must be renewed annually to maintain MDM communication * **Renewal Planning**: Plan certificate renewal well in advance of expiration * **Team Notifications**: Iru Endpoint sends email reminders 30 days before certificate expiry * **File Naming**: Maintain original certificate file names and .pem extensions * **Account Consistency**: Always use the same Apple Account for certificate creation and renewal * **Apple Account Management**: Use a managed Apple Account accessible by multiple team members * **Migration Planning**: Plan carefully if changing Apple Accounts for APNs certificates * **Disconnection Impact**: Disconnecting APNs affects all enrolled devices and requires re-enrollment * **Network Requirements**: Ensure proper network configuration for APNs traffic * **Certificate Security**: Store APNs certificates securely and never share them publicly * **Testing**: Test APNs functionality after configuration and renewal * **Monitoring**: Regularly monitor certificate status and device communication * **Backup Strategy**: Have a plan for managing devices if APNs becomes unavailable * **Documentation**: Keep records of certificate creation, renewal, and Apple Account information * **Support**: Contact Iru Endpoint Support for assistance with complex APNs scenarios # Configure Apps and Books Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/configure-apps-and-books Configure the Apple Apps and Books integration in Iru Endpoint. Connect Apple Business Manager to manage volume-purchased app licenses and assignments. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your Iru Endpoint tenant before Apps and Books can be configured. ### About Apps and Books Integration Apps and Books (formerly Apple's Volume Purchasing Program or VPP) is a feature that makes it easy for organizations to deploy App Store Apps to their Apple devices using MDM. Integrating Apps and Books allows you to distribute App Store Apps directly to managed devices without end users needing an Apple ID. It helps track and control licensing and provides a method to revoke and reassign them as needed. ### How It Works Apps and Books integration works by connecting your Apple Business or Apple School Manager account with Iru Endpoint through Apps and Books content tokens. When you purchase app licenses in the portal and assign them to your Iru Endpoint MDM server, they become available as Library Items in your Iru Endpoint library, where they can be assigned to Assignment Maps for automated deployment. ### Prerequisites * **Apple Push Notification Service**: [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your Iru Endpoint tenant * **Apple Business or Apple School Manager access**: Ensure you have administrative access to your organization's portal * **Organizational unit setup**: Create a dedicated organizational unit in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant * **Apps and Books token**: Download a dedicated Apps and Books content token for your Iru Endpoint integration For more information on syncing apps from Apps and Books to your Iru Endpoint library, please see our [Adding Apps from Apps and Books to Iru Endpoint](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint) support article. ### Configuring Apps and Books Apps and Books (formerly VPP) allows you to distribute App Store Apps to your organization's devices. You cannot share the same Apps and Books token across multiple MDM servers in the portal. It is highly recommended that you [create a new organizational unit](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant and use a dedicated Apps and Books token. [Create a new organizational unit](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) in Apple Business or Apple School Manager. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Click the **Set up Apps and Books** button inside **Apps and Books**. In the new window, you will be asked to sign in to [Apple Business](https://support.apple.com/guide/business/welcome/web) or [Apple School Manager](https://support.apple.com/guide/apple-school-manager/welcome/web) to complete the final steps for integration. In Apple Business or Apple School Manager, click your **organization name** at the top right of the page. Click **Settings**. Apple Business or Apple School Manager with organization menu open and Settings option After you open **Settings**, you should already be on **Payments & Billing** → **Apps & Books**. This view is where your organization's Apps and Books content tokens appear. Under **Content Tokens**, click **Download** next to the token you want to use with Iru Endpoint. Apple Business or Apple School Manager Payments and Billing Apps and Books Content Tokens with Download Navigate back to the Iru Endpoint Web App and upload your **token**. Click **Complete Apps and Books setup**. Once the Apps and Books integration is completed, you will be able to update apps automatically when Iru Endpoint detects a new version. ### Manually Syncing Apps and Books with Apple Business or Apple School Manager Iru Endpoint periodically checks for new apps or license changes. If you need to trigger a sync between Iru Endpoint and Apple Business or Apple School Manager immediately, you can use the **Sync App Store Apps** button (double arrows) next to the **Add Library Item** button. Library view showing Sync App Store Apps button next to Add Library Item for manual Apps and Books sync ### Duplicating Apps and Books Library Items The ability to duplicate Apps and Books Library Items allows you to create multiple configurations of the same app and assign these to different Blueprints. All Apps & Books app instances of the same Apps and Books Library Item share the same license pool across all Blueprints and assignments. Duplication works the same way as for other Library Items; for the full flow (including duplicating from an open Library Item), see [Library Item Duplication](/en/endpoint/library/library-items-profiles/library-overview#library-item-duplication) in Library Overview. The Okta Verify and Microsoft Authenticator Apps and Books Library Items cannot be duplicated due to their respective integrations with [Okta Device Trust](/en/endpoint/integrations/okta-device-trust-main/okta-device-trust) and [Microsoft Device Compliance](/en/endpoint/integrations/microsoft-device-compliance/getting-started-with-microsoft-device-compliance). Navigate to **Library**, then **App Store apps**. Find the Apps and Books Library Item you want to duplicate, then click the **ellipsis** next to its name. Click **Duplicate**. Library list with ellipsis menu open and Duplicate selected for a Library Item Click **Yes, duplicate** to confirm duplication. Edit the duplicated Apps and Books Library Item as needed. Once a duplicate has been created, the Library Item can be deleted, but at least one instance of the specific Apps and Books Library Item must remain. ### Removing Apps and Books Licenses Navigate to **Library** then **App Store apps** and select the app you need to remove the license for. Next, click the blue **Edit** button on the bottom right. Change the Blueprint assignments in the **Assignment** section. Click **Save**. Within 5-10 mins of a successful MDM check-in, the application will remove itself from the device's Applications folder and free up a license to be assigned to a different Blueprint or device. ### Considerations * **Annual Expiration**: Apps and Books tokens expire annually. Iru Endpoint will display a banner starting 30 days before the token expires, ensuring you have ample time to renew it and avoid any service interruptions * **Password Changes**: If the password for the Apple Business or Apple School Manager account that downloaded the token is changed, the token will be invalidated and must be renewed * **Token Renewal Process**: Follow the same setup process to renew expired tokens * **Service Continuity**: Plan token renewal before expiration to avoid service disruptions * **Documentation**: Keep records of token expiration dates and renewal processes For more information about managing content tokens in Apple Business or Apple School Manager, please see the [Apple Business on Apple Support](https://support.apple.com/guide/business/manage-content-tokens-axme0f8659ec/web). * **Dedicated organizational unit**: Create a dedicated organizational unit in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant * **Token Security**: Store Apps and Books tokens securely and never share them across multiple MDM servers * **License Management**: Plan your app licensing strategy to avoid over-purchasing or running out of licenses * **License Pooling**: Understand that all instances of the same app share the same license pool * **Blueprint Assignment**: Plan your Blueprint assignments carefully to optimize license usage * **Sync Frequency**: Understand that Iru Endpoint periodically syncs with Apple Business or Apple School Manager, but manual sync is available when needed * **App Updates**: Configure automatic app updates to ensure users have the latest versions * **Duplication Limitations**: Be aware that some apps (Okta Verify, Microsoft Authenticator) cannot be duplicated due to integration requirements * **User Experience**: Test app deployment and user experience before rolling out to production * **Compliance Requirements**: Ensure deployed apps meet your organization's security and compliance requirements * **Backup Strategy**: Have a plan for managing apps if the Apps and Books integration becomes unavailable * **Documentation**: Keep records of app assignments and license usage * **Support**: Contact Iru Endpoint Support for assistance with complex Apps and Books scenarios * **Testing**: Test Apps and Books configuration in a controlled environment before production deployment * **Monitoring**: Regularly monitor app deployment success rates and license usage ### Related Articles Curate, create, and manage Library Items, including App Store apps synced from Apps and Books Sync purchased licenses into the Library and assign App Store app Library Items Configure how Iru Endpoint surfaces alerts when App Store app deployments or other Library Items report issues # Configure Automated Device Enrollment Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/configure-automated-device-enrollment Set up Automated Device Enrollment (ADE) in Iru Endpoint. Connect Apple Business Manager, configure MDM server tokens, and assign default Blueprints. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your Iru Endpoint tenant before Automated Device Enrollment can be configured. ### About Automated Device Enrollment Automated Device Enrollment (ADE) is an Apple feature that enrolls devices into Iru Endpoint out of the box. Corporate-owned iPhone, iPad, Mac, and Apple TV devices are managed and supervised as soon as they are activated. If a device is lost, stolen, erased, or restored, it enrolls back into its assigned MDM server. ### How It Works Automated Device Enrollment operates through a secure connection between Apple Business or Apple School Manager and Iru Endpoint. When devices are purchased from Apple or authorized resellers, they are automatically added to your organization's account in the same portal. Once assigned to Iru Endpoint, devices check with Apple during activation to verify organizational ownership and retrieve configuration settings. ### Prerequisites * **Apple Push Notification Service**: [Apple Push Notification service](/en/endpoint/settings/apple-integrations/configure-apple-push-notification-service) must be configured in your Iru Endpoint tenant * **Apple Business or Apple School Manager access**: Ensure you have administrative access to your organization's portal * **Device Purchase**: Devices must be purchased from Apple or authorized resellers to be automatically added to Apple Business or Apple School Manager * **Network Connectivity**: Ensure devices have internet connectivity during the enrollment process Some Apple devices can be added using Apple Configurator after purchase. See our [Adding Devices to Apple Business or Apple School Manager](/en/endpoint/settings/apple-integrations/adding-devices-to-apple-business-manager) support article for more information. ### Automated Device Enrollment Process Once devices are available in Apple Business or Apple School Manager, you can assign them to an MDM server like Iru Endpoint. This assignment initiates a sync between Apple and Iru Endpoint (handled by the Automated Device Enrollment token), making device serial numbers available in an Awaiting Enrollment status where they can be assigned to an Assignment Map in the Iru Endpoint Web App. When a device is powered on and connected to a network, it checks with Apple to verify organizational ownership, then retrieves and applies the configuration assigned by Iru Endpoint. ### Configuring Automated Device Enrollment In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Integrations**. Screenshot of the account menu with Integrations option highlighted Select the **Apple integrations** section. Under Automated Device Enrollment, click **Set up Automated Device Enrollment**. In the setup wizard, continue until Iru Endpoint provides a **PEM** public key file (download or save it when prompted). You will upload this file to Apple Business or Apple School Manager in the next steps. Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) with a Managed Apple Account that can manage device management services. Click the **Devices** tab at the top of the page. In the left sidebar, click **Management**. Scroll to the bottom of the **Management Services** list and click **Add** next to **Add device management service**. Apple Business or Apple School Manager Management Services list with Add device management service In the **Service Name** field, enter a name for this MDM integration (for example, **Iru Endpoint**). If your organization needs it, select **Allow this service to release devices**. Upload the **PEM** file from Iru Endpoint. Click **Next**. Add device management service form with Service Name, release devices option, and public key upload Click **Download Service Token**. Apple Business or Apple School Manager Download Service Token action Click **Done**. Return to Iru Endpoint and upload the **.p7m** service token file when prompted. Complete any remaining steps in the wizard and click **Done**. ### Considerations * **APNs Configuration**: Ensure Apple Push Notification service is properly configured before setting up ADE * **Network Requirements**: Verify network connectivity and firewall settings for Apple services * **Updates**: Stay informed about Apple's ADE requirements and updates * **Device Assignment**: Plan your device assignment strategy for Assignment Maps * **User Experience**: Test the enrollment process to ensure smooth user experience * **Testing**: Test ADE configuration in a controlled environment before production deployment * **Monitoring**: Regularly monitor ADE status and device enrollment success rates * **Security Policies**: Configure appropriate security policies for corporate-owned devices * **Lost Device Protection**: Understand how ADE helps protect against lost or stolen devices * **Compliance Requirements**: Ensure ADE configuration meets your organization's compliance needs * **Device Lifecycle**: Plan for device management throughout the entire lifecycle * **Backup Strategy**: Have a plan for managing devices if ADE becomes unavailable * **Documentation**: Keep records of ADE configuration and device assignments * **Support**: Contact Iru Endpoint Support for assistance with complex ADE scenarios # Configure multiple ADE tokens using the Iru Endpoint API Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/configure-multiple-automated-device-enrollment-tokens Configure multiple Automated Device Enrollment tokens with the Iru Endpoint API to link several Apple Business or School Manager accounts to MDM servers. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Multiple ADE Token Configuration Configuring multiple Automated Device Enrollment (ADE) tokens allows you to manage multiple Apple Business or Apple School Manager integrations simultaneously. This process uses the Iru Endpoint API to automate token creation and management, enabling bulk operations and improved token lifecycle management. ### How It Works Multiple ADE token configuration works by using the Iru Endpoint API to create, manage, and monitor multiple ADE integrations. The process involves downloading public keys, creating integrations through API calls, and verifying successful token creation. This approach enables automated management of multiple Apple Business or Apple School Manager connections. ### Configuring an Iru Endpoint API token If you do not feel confident in completing this process yourself, please reach out to [Iru Endpoint Support](/en/iru/iru-support/access-to-iru-support) for additional guidance. It is highly recommended that you renew the current Automated Device Enrollment token in Iru Endpoint ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations** → Apple integrations → Automated Device Enrollment > Renew) before starting this process. Only the latest Automated Device Enrollment token that you add will be displayed on your Apple integrations page; renewing your existing token first makes the process easier. Prepare an API token and store it in a secure location. You can read more about this in our [Iru Endpoint API](/en/endpoint/api/iru-api-overview) article. #### Create or Modify an API Token Create a new API token or modify an existing one with ADE permissions. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Access** in the menu. Screenshot of the account menu with Access option highlighted Select the **API tokens** tab. Create or modify the existing API Token to include all ADE-related permissions. Access page showing API token configuration with Automated Device Enrollment permissions ### Preparing Postman Most of the steps moving forward will be performed inside the Postman application on your device. You can skip this section if you already have Postman configured. Check your Collection for the Automated Device Enrollment integrations folder. Define your API URL if undefined in the Iru Endpoint API folder at the top of the collection. Define the API Token in your Environment variables following our How to Set Up the Iru Endpoint API in Postman article. ### Downloading Public Key Now that Postman is configured with the API Key and Iru Endpoint Subdomain, you can download the public key. Select the Iru Endpoint API > Automated Device Enrollment Integrations > GET Download ADE public key in the Collection. Click the Send button. Copy the output and paste it into a text editor. Set the file format to plain text. Save the text file with the .pem certificate file extension. Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) with a Managed Apple Account that can manage device management services. Click the **Devices** tab at the top of the page. In the left sidebar, click **Management**. Scroll to the bottom of the **Management Services** list and click **Add** next to **Add device management service**. Apple Business or Apple School Manager Management Services list with Add device management service In the **Service Name** field, enter a name that identifies this MDM integration (for example, one that matches how you will label the token in Postman). If your organization needs it, select **Allow this service to release devices**. Upload the **.pem** file you saved from the public key output. Click **Next**. Add device management service form with Service Name, release devices option, and public key upload Click **Download Service Token**. Apple Business or Apple School Manager Download Service Token action Click **Done**. ### Creating Integration This section will cover using the API command that will complete the process of creating the new ADE connection. Use the **.p7m** file you downloaded from Apple Business or Apple School Manager. Select Iru Endpoint API > Automated Device Enrollment Integrations > POST Create ADE Integration in the Collection. Click on the Body tab that has a green dot and enter blueprint\_id, phone, and email. Click Select Files and attach the .p7m file. Click the Send button. You can repeat the Download public key and Create Integration processes for each additional integration you would like to add. ### Checking Current Integrations Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations command will give us all current ADE integrations so that we can verify that the integration was added successfully. Select Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations in the Collection. Click the Send button. If the count is equal to at least 2, the creation process is successful. ### Considerations * **API Token Security**: Store your API token in a secure location and never share it publicly * **Postman Configuration**: Ensure Postman is properly configured with the latest API collection * **Error Handling**: Monitor API responses for errors and troubleshoot accordingly * **Monitoring**: Regularly check integration status and token validity * **ADE Token Renewal**: Renew existing ADE tokens before creating new ones to maintain continuity * **Certificate Management**: Keep track of .pem and .p7m files for each integration * **Integration Limits**: Be aware of any limits on the number of ADE integrations per tenant * **Blueprint Configuration**: Ensure blueprints are properly configured before creating integrations * **Apple Business or Apple School Manager access**: Verify you have administrative access to the portal for MDM server creation * **Documentation**: Keep records of all created integrations and their configurations * **Testing**: Test integrations in a controlled environment before production deployment * **Backup Strategy**: Have a plan for managing integrations if API access becomes unavailable * **Support**: Contact Iru Endpoint Support for assistance with complex integration scenarios * **Compliance**: Ensure ADE integrations meet your organization's security and compliance requirements # How to Verify Apple Business or Apple School Manager Domains Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/how-to-verify-apple-business-manager-domains Verify your organization's domain in Apple Business Manager for use with Iru Endpoint. Complete DNS verification to enable Managed Apple IDs and federation. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Apple Business or Apple School Manager Domain Verification Domain verification is a security requirement that ensures only legitimate domain owners can create Managed Apple IDs using their domains. This process prevents unauthorized use of domains and protects against ownership conflicts. ### How It Works Apple Business or Apple School Manager domain verification requires you to prove ownership of your domain through DNS record verification. This process involves adding specific DNS records to your domain's DNS settings, which Apple then verifies to confirm your organization's ownership of the domain. ### Why Domain Verification is Required Before this new requirement, anyone could add a domain to their Apple Business or Apple School Manager account and create Managed Apple IDs using this domain, even if they didn't own it. This could lead to ownership conflicts and security concerns. However, now that Apple requires everyone to verify their Managed Apple ID domain names, you can be sure that your organization is the only one that can modify the DNS records for its domains. For more on domains in these services, see the user guide for [Apple Business](https://support.apple.com/guide/business/welcome/web) or [Apple School Manager](https://support.apple.com/guide/apple-school-manager/welcome/web) on Apple Support. ### Frequently Asked Questions #### If I used the domain before the mandatory verification requirement, is it automatically verified? No. Even if your Managed Apple ID domain name was in use well before the new verification requirement, it isn't grandfathered in. You still need to complete the verification process. #### What if more than one organization is using the domain? If your Managed Apple ID domain name is used by multiple organizations, this shouldn't present any ownership conflicts; each organization can independently verify the domain. However, only one organization can federate that domain. In this case, other organizations must move their Managed Apple IDs to another verified domain. Otherwise, they may receive error messages such as "Managed Apple ID ending with this domain name is not allowed." #### How soon do I have to verify the domain? You must verify your Managed Apple ID domain name within 14 calendar days of clicking the **Verify** button in Apple Business or Apple School Manager. #### Why did I get an email asking me to verify ownership of my domain? If you get an email asking you to verify your domain, then another organization has claimed a domain that's currently used by your Managed Apple IDs. You'll have to verify your domain ownership within 14 days of receiving this email. #### What if I can't or don't want to verify the domain? In this case, you must move the Managed Apple IDs that you aren't verifying to a reserved domain or a different verified domain; otherwise, you may receive error messages such as "Managed Apple ID ending with this domain name is not allowed." By "reserved domain," Apple is referring to the default domain that shows up under **Accounts**. It's the name of the domain that your organization enrolled in Apple Business or Apple School Manager plus a number: Iru Endpoint1.appleid.com, for example. ### Verifying Domains Associated with Your Apple Business or Apple School Manager Account Follow Apple's guide to add, link, or verify domains in the service you use: [Add and verify a domain in Apple Business](https://support.apple.com/guide/business/add-and-verify-a-domain-axm48c3280c0/web) or [Add and verify a domain in Apple School Manager](https://support.apple.com/guide/apple-school-manager/add-and-verify-a-domain-axm48c3280c0/web). ### Considerations * **DNS Access Requirements**: Ensure you have administrative access to your domain's DNS settings to add verification records * **Verification Timeline**: Complete domain verification within 14 days of initiating the process to avoid service disruption * **DNS records and account security**: Apple must be able to resolve your verification records on the public internet. Publish only the record types, names, and values Apple provides for verification. Do not add unrelated sensitive data to those records. Restrict and monitor access to your DNS provider accounts (least privilege, MFA, and change alerts), because anyone who can edit your DNS can disrupt verification or compromise your domain. * **Multiple Organizations**: Coordinate with other organizations using the same domain to prevent conflicts * **Reserved Domains**: Understand that reserved domains (like Iru Endpoint1.appleid.com) are available as fallback options * **Federation Limitations**: Only one organization can federate a domain, even if multiple organizations verify it * **Error Prevention**: Verify domains before creating large numbers of Managed Apple IDs to avoid migration issues * **Testing**: Test domain verification in a controlled environment before production deployment * **Backup Planning**: Have alternative domain options ready in case primary domain verification fails * **Migration Planning**: Plan for potential Managed Apple ID migrations if domain verification is not possible * **Documentation**: Keep records of verification processes and DNS record configurations * **Monitoring**: Regularly monitor domain verification status and renewal requirements * **Support**: Contact Apple Support if you encounter issues with the verification process * **Compliance**: Ensure domain verification aligns with your organization's security and compliance requirements # Remove App Store Apps from the Library Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/remove-app-store-apps-from-the-library Remove App Store apps from your Iru Endpoint Library. Revoke app licenses, unassign from Blueprints, and clean up unused volume-purchased applications. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ## About Removing App Store Apps from the Library You can remove App Store app Library Items from the Library when no licenses are assigned to the Apps and Books token in Apple Business or Apple School Manager for your Iru Endpoint tenant. First unassign the app's licenses in the portal, then remove the app from the Iru Endpoint Library. ## Unassigning App Store licenses in Apple Business or Apple School Manager Unassign all licenses for the app from the [organizational unit](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) used for your Iru Endpoint tenant's Apps and Books token in Apple Business or Apple School Manager before you remove the app from the Iru Endpoint Library. Sign in to [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) with a Managed Apple Account that can manage Apps and Books. Follow [Apple's instructions for configuring organizational units](https://support.apple.com/guide/business/configure-organizational-units-axmfdbe2cb0d/web) in Apple Business or Apple School Manager. You will transfer your app license(s) to this organizational unit in a later step. Click your **organization name** at the top right of the page. Click **Settings**. Apple Business or Apple School Manager with organization menu open and Settings option After you open **Settings**, go to **Payments & Billing** → **Apps & Books** if you are not already there. This view is where your organization manages Apps and Books licenses and content tokens. Find the app you want to unassign licenses from and select it. Next to the organizational unit used for your Iru Endpoint tenant's Apps and Books token, click **Transfer**. Apple Business or Apple School Manager app page with Manage licenses and Transfer for the organizational unit In the **Quantity** field, enter the total number of licenses assigned to that organizational unit. In **Transfer to**, choose the organizational unit you created earlier in these steps. Click **Transfer**. Apple Business or Apple School Manager Transfer Licenses sheet with Quantity, Transfer to, and Transfer You will see a **Processing** status where the Transfer option was previously. Wait for this to complete before proceeding. The licenses should now appear under the new organizational unit. Use the steps below to remove the app from your Library. ## Removing an App Store app from the Library After you have unassigned licenses in Apple Business or Apple School Manager, remove the app from your Iru Endpoint Library. Open your Iru Endpoint tenant in a web browser and sign in if needed. Select **Library** from the left navigation. Click the **Sync App Store Apps** button near the top right of the page. Library view showing Sync App Store Apps button near the top right Search for the app you want to remove from the Library. Click the ellipsis on the app tile. Choose **Delete** from the menu. Library app tile menu showing Delete option for removing App Store app from the Library If the **Delete** option is not available, check back later and click **Sync App Store Apps** again. If you still don't see it, open Apple Business or Apple School Manager. Confirm that no licenses for that app are assigned to the organizational unit used for your Iru Endpoint tenant's Apps and Books token. Confirm by clicking **Delete** in the prompt. Confirmation prompt for removing App Store app from the Library ## Related Documentation Curate and manage Library Items and add them to Blueprints. Set up Apps and Books integration for App Store app distribution and license management. Deploy App Store and Custom Apps through Apple Business or Apple School Manager integration. Apple Business or Apple School Manager, APNs, Apps and Books, and related integrations. # Renew, update, or delete ADE tokens via the Iru API Source: https://docs.iru.com/en/endpoint/settings/apple-integrations/renew-update-or-delete-multiple-automated-device-enrollment-tokens Renew, update, or delete Automated Device Enrollment tokens with the Iru Endpoint API to prevent expiration and maintain Apple Business connections. **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About ADE Token Management Automated Device Enrollment (ADE) tokens require periodic renewal and management to maintain device enrollment capabilities. This process allows you to efficiently manage multiple ADE tokens using API automation, reducing manual effort and ensuring consistent token lifecycle management. ### How It Works ADE token management involves using the Iru Endpoint API through Postman to perform bulk operations on multiple tokens. The process includes configuring API access, setting up environment variables, downloading tokens from Apple Business or Apple School Manager, and using automated workflows to renew, update, or delete tokens efficiently. If you do not feel confident in completing this process yourself, please reach out to [Iru Endpoint Support](/en/iru/iru-support/access-to-iru-support) for additional guidance. ### Prerequisites * Access to Iru Endpoint with API token creation permissions * Postman application installed and configured * Access to Apple Business or Apple School Manager * Multiple ADE tokens that need renewal or management * Basic understanding of API operations and Postman workflows ### Configuring an Iru Endpoint API token Prepare an API token and store it in a secure location. You can read more about this in our [Iru Endpoint API](/en/endpoint/api/iru-api-overview) article. You can skip this section if you already have an API token prepared. Create a new API token or modify an existing one with the required permissions. In your Iru Endpoint tenant, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access** → **API tokens**. Create or modify the existing API token to include all Automated Device Enrollment-related permissions. ### Preparing Postman Most of the steps moving forward will be performed inside the Postman application on your device. You can skip this section if you already have Postman configured. Check your Collection for the Automated Device Enrollment integrations folder. Define your API URL if undefined in the Iru Endpoint API folder at the top of the collection. Define the API Token in your Environment variables following our How to Set Up the Iru Endpoint API in Postman article. ### Configuring Postman Environment Variables Now that the basics of Postman have been configured, you will need to define some Environment Variables in Postman to keep track of the Automated Device Enrollment servers. In Postman, click the **Environments** tab in the left sidebar, then click **Create Environment** to create a new environment. Name your environment (e.g., "Iru Endpoint API") and add the following variables: * **Variable**: `base_url` * **Initial Value**: `https://.api.iru.com/api/v1` * **Current Value**: `https://.api.iru.com/api/v1` Replace `` with your tenant's actual subdomain, or copy the base URL directly from your tenant. The URL shown in your tenant may use the `api.kandji.io` domain. Both `.api.iru.com` and `.api.kandji.io` will work without modification. * **Variable**: `token` * **Initial Value**: `your_api_token_here` * **Current Value**: `your_api_token_here` Click **Save** to save your environment, then select your newly created environment from the environment dropdown in the top-right corner. If you already have environment variables configured, you can add the new items to the existing variables. Navigate to **Iru Endpoint API** > **Automated Device Enrollment Integrations** > **GET List ADE Integrations** in the Collection. Click the **Send** button to execute the request. In the **Body** section of the Results, copy the top-level IDs of each Automated Device Enrollment token. For each token ID, create an environment variable with a naming scheme such as `ade_token_1`, `ade_token_2`, etc., incrementing the number for each token. Make a note of the associated `server_name` for each token. You will need this information when downloading the tokens from Apple Business or Apple School Manager. Paste the ID value for each token into the corresponding `ade_token_#` variable (e.g., `ade_token_1`, `ade_token_2`). You can set the variable type to secret so that the value of the variable is not visible. ### Downloading ADE Tokens Sign in to your [Apple Business](https://business.apple.com) or [Apple School Manager](https://school.apple.com) account. Click the **Devices** tab at the top of the page. In the left sidebar, click **Management**. In the **Management Services** list, select the service whose name matches the first ADE integration's `server_name` from the list you made earlier in Postman. Click the ellipsis (**…**) for that service. Click **Download Token**. Repeat this process for each token that you will be renewing. ### Creating Postman Folder Template Creating folders in Postman will make it easier to keep track of your Automated Device Enrollment tokens. Click on the ellipsis next to the Automated Device Enrollment Integrations folder. Click Add folder. Name the folder ADE\_Token1. Navigate to the **Automated Device Enrollment Integrations** folder and select the **Renew ADE Integration** and **Update ADE Integration** items. Right-click the selected items and choose **Copy**. Click on the ellipsis next to the ADE\_Token1 folder. Click **Paste** to add the copied items to the new folder. ### Modifying Renew Item Select the **Renew ADE Integration** item from your token folder. Rename it to **Renew ADE1 Integration** (or **Renew ADE2 Integration**, etc., based on your token number). In the section to the right, click on the address bar to the left of the **Send** button. Select the text inside `{{ade_token_ade}}` and update it to `{{ade_token_1}}` (or `{{ade_token_2}}`, etc., based on your token number). Click on the Body tab below. Enter the `blueprint_id`, phone, and email that should be associated with the token. For the file, click x by any current files, and then click Select Files. Choose the .p7m file that matches this ADE token. Save the changes. ### Modifying Update Item Select the **Update ADE Integration** item from your token folder. Rename it to **Update ADE1 Integration** (or **Update ADE2 Integration**, etc., based on your token number). In the section to the right, click on the address bar to the left of the **Send** button. Select the text inside `{{ade_token_ade}}` and update it to `{{ade_token_1}}` (or `{{ade_token_2}}`, etc., based on your token number). Click on the Body tab below. This is where you can enter new `blueprint_id`, phone, and email information. Save the changes. ### Duplicating ADE\_Token Folder Click on the ellipsis next to the ADE\_Token1 folder. Choose Duplicate. Update the contents of the folder using the process above. Make duplicates of the folder for each of your ADE tokens. ### Renewing ADE Integration Now that everything is configured, you can send the Renew command. Navigate to the specific token folder you created (e.g., **ADE\_Token1**, **ADE\_Token2**, etc.) and select the **Renew ADE1 Integration** (or **Renew ADE2 Integration**, etc.) item that corresponds to your token number. Click the Send button. ### Updating ADE Integration Updating the ADE Integration will allow you to change the associated Blueprint ID, phone number, and email address. Navigate to the specific token folder you created (e.g., **ADE\_Token1**, **ADE\_Token2**, etc.) and select the **Update ADE1 Integration** (or **Update ADE2 Integration**, etc.) item that corresponds to your token number. Update the details in the Body section that need updating. Click the Send button. ### Checking Current Integrations Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations command will give us all current ADE integrations so that we can verify that the integration was Renewed or Updated successfully. Select Iru Endpoint API > Automated Device Enrollment Integrations > GET List ADE Integrations in the Collection. Click the Send button. The `days_left` variable should be 364 if the Renew command was successful. To verify an update, check the information associated with the ADE token to verify that it was updated. ### Deleting Integration Iru Endpoint API > Automated Device Enrollment Integrations > DEL Delete ADE Integration command will delete the ADE integration associated with the supplied ADE Token ID. Select Iru Endpoint API > Automated Device Enrollment Integrations > DEL Delete ADE Integration in the Collection. Populate the `ade_token_id` variable with the ID of the ADE Token. Click the Send button. ### Considerations * **API Token Security**: Ensure API tokens are stored securely and have appropriate permissions for ADE operations * **Postman Configuration**: Proper Postman setup is essential for successful API operations * **Environment Variables**: Use environment variables to manage multiple token IDs efficiently * **Error Handling**: Be prepared to troubleshoot API errors and token validation issues * **Token Lifecycle**: ADE tokens have expiration dates and require periodic renewal to maintain enrollment capabilities * **Token File Management**: Keep track of downloaded .p7m files and associate them with correct token IDs * **Apple Business or Apple School Manager access**: Ensure you can sign in to the portal and download tokens * **Verification Process**: Always verify successful operations by checking integration status and token expiration * **Bulk Operations**: Use folder templates to efficiently manage multiple tokens * **Access Control**: Ensure only authorized personnel have access to token management operations * **Testing**: Test operations on a small scale before performing bulk operations * **Monitoring**: Regularly monitor token expiration dates and renewal schedules * **Documentation**: Keep records of token configurations and associated server names * **Backup Strategy**: Maintain backups of token configurations and API settings # Self Service: Bookmarks Source: https://docs.iru.com/en/endpoint/settings/self-service/self-service-bookmarks Add web bookmarks to the Self Service portal in Iru Endpoint. Give users quick access to company resources, documentation, and internal tools from their device. On iOS and iPadOS, Bookmarks are only supported on Self Service versions 1.4.4 and later. ### About Self Service Bookmarks Self Service Bookmarks provide users with quick access to essential work resources through organized links. Bookmarks can be categorized, recommended, and customized with icons to improve user experience and productivity. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works Self Service Bookmarks are created as Library Items that contain one or multiple bookmarks. These bookmarks support various URL schemes including web links, email addresses, and file paths. Users can access bookmarks through the Self Service app, where they are organized by category and displayed in alphanumerical order. ### Creating a Bookmarks Library Item Create a Bookmarks Library Item to hold bookmarks (links) for resources. To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. At the top of the Library Item, in the **Add a title** field, add a title. Select your desired [Blueprints](/en/endpoint/blueprints/assignment-maps/creating-a-blueprint). ### Adding Bookmarks to the Bookmarks Library Item You can add one or multiple bookmarks to the Bookmarks Library Item. Within a category, bookmarks are displayed in alphanumerical order. You can edit [Self Service settings](/en/endpoint/settings/self-service/self-service-settings) to change the order in which categories are displayed. Click **Add Bookmark**. Bookmarks Library Item with Add Bookmark button In the **URL** field, enter the appropriate URL. Bookmarks support the following URL schemes: * **http\://** or **https\://**: Opens in the default browser, which is Safari unless the user has selected a different one * **mailto://**: Opens in the default mail app, which is Mail unless the user has selected a different one. On iOS and iPadOS, if the user hasn't yet configured a mail account, tapping a mailto:// bookmark results in an error * **file://** (only supported on macOS): Opens a file from a specified path. Using three consecutive slashes, such as file:///path/to/file when defining file paths is recommended. macOS asks the user to grant Self Service the ability to read the folder that contains the file. After a user grants read access to the folder once, macOS should not ask again Add Bookmark form showing the URL field Optionally, in the **Icon** field, drag a custom icon or click **upload**. In the **Title** field, enter a title. Optionally, select a **Category** of Self Service for this bookmark to be displayed in (see [Self Service settings](/en/endpoint/settings/self-service/self-service-settings) to edit your more categories). Optionally, select the checkbox for **Recommended**. * When you open Self Service on macOS, Self Service displays Recommended apps, items, and bookmarks by default * When you open Self Service on iOS and iPadOS, Self Service displays Recommended apps and bookmarks at the top of Self Service by default * In Self Service for macOS, recommended bookmarks are displayed with a star icon Add Bookmark form showing Icon, Title, Category, and Recommended options Click **Done** to save your work and return to the list of bookmarks. Repeat the process to add more bookmarks. ### Editing or Deleting a Bookmark At the right side of the bookmark entry, click the **ellipsis**. Click **Delete** or **Edit**. Click **Close** to return to the list of bookmarks without saving your changes, or click **Done** to save your changes and return to the list of bookmarks. Click **Save** to save the changes to the Bookmarks Library Item. ### Considerations for Multiple Bookmarks Library Items * You can create as many Bookmarks Library Items as you wish. Self Service displays the aggregate of all applicable bookmarks for each section * If you create a bookmark in your Bookmarks Library Item, but it already exists in another Bookmarks Library Item that's assigned to one more assigned Blueprints, Iru Endpoint displays a dialog to ask if you want to "Save Duplicate Bookmarks?" * You may want to display a bookmark for the same URL in multiple categories depending on your needs. Using a separate Bookmarks Library Item for each category is one way to achieve that goal ### Considerations * **URL Scheme Support**: Bookmarks support various URL schemes including http/https for web links, mailto for email addresses, and file:// for local files (macOS only) * **Platform Compatibility**: iOS and iPadOS bookmarks require Self Service version 1.4.4 or later * **File Access Permissions**: macOS users may need to grant folder read access for file:// bookmarks, but this is typically a one-time permission * **Email Configuration**: mailto:// bookmarks require proper email account configuration on iOS/iPadOS devices * **Category Organization**: Use categories to organize bookmarks logically and improve user navigation * **Recommendation Strategy**: Mark important bookmarks as recommended to highlight them for users * **Custom Icons**: Upload custom icons to make bookmarks more visually recognizable * **Duplicate Management**: Be aware of potential duplicate bookmarks when using multiple Library Items * **Alphanumeric Ordering**: Bookmarks within categories are automatically sorted alphabetically * **Cross-Platform Display**: Recommended bookmarks appear prominently on both macOS and iOS/iPadOS * **Multiple Library Items**: Create separate Library Items for different categories or organizational needs * **User Experience**: Consider the user experience when organizing bookmarks and categories * **Resource Management**: Regularly review and update bookmarks to ensure they remain relevant and functional * **Testing and Validation**: Test bookmarks across different platforms and URL schemes to ensure proper functionality # Self Service for iOS, iPadOS, and visionOS Source: https://docs.iru.com/en/endpoint/settings/self-service/self-service-for-ios-ipados-and-visionos Configure Self Service for iOS, iPadOS, and visionOS in Iru Endpoint. Let users install approved apps and configurations from the Self Service web clip. This guide applies to iOS devices, iPadOS devices, and visionOS devices **Apple Business Manager** is now **Apple Business**. **Apple School Manager** is unchanged. For more information, see [Introducing Apple Business](https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/) and [Apple Business Manager is now Apple Business](https://support.apple.com/guide/apple-business-manager/apple-business-manager-is-now-apple-business-axmd79d79dea/web). ### About Self Service for iOS, iPadOS, and visionOS Self Service is an app on iOS, iPadOS, and visionOS that lets users discover and install IT-approved applications. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. For more information, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update). ### How It Works Self Service is distributed through Apple Business or Apple School Manager and automatically installs on managed devices. Users browse available applications, install approved software, and view device information. ### Acquiring Licenses for Self Service from Apple Business or Apple School Manager Before installing Iru Self Service on iOS, iPadOS, and visionOS devices, acquire licenses for the app. Follow the instructions to [add apps from Apps and Books to Iru Endpoint](/en/endpoint/settings/apple-integrations/add-apps-from-apps-and-books-to-iru-endpoint), and search for "Iru Self Service", or the app ID of 1579981636, in Apple Business or Apple School Manager. Be sure to acquire enough licenses for each iOS, iPadOS, and visionOS device you wish to have Self Service installed on. ### Installing Self Service Add the **Iru Self Service** Library Item to Blueprints you're using for iOS, iPadOS, and visionOS devices, either from the **Iru Self Service** Library Item in **Library**, or individually on each Blueprint as needed. Self Service will then install automatically on company-owned supervised devices. For devices enrolled through the Iru Endpoint Enrollment Portal, users will need to agree to install Self Service on their devices when prompted. ### Configuring Return to Service in Self Service Return to Service is available for devices running iOS and iPadOS 17 or later. After erase, the device advances through Setup Assistant and re-enrolls without user intervention. For more on Return to Service, including **Retry enrollment**, see [Erase an Apple Device](/en/endpoint/devices/device-actions/erase-a-device#return-to-service-ios-ipados-17). Under Options, check **Add to Self Service**. Optionally, configure a Wi-Fi profile so the device can join a network after erase. On iPhone and iPad devices running iOS 27 or iPadOS 27 or later, enable **Retry enrollment** in the Return to Service section of the Iru Self Service Library Item. If enrollment fails after erase, the device retries automatically, with an increasing delay of up to 5 minutes between attempts. Users do not see this option. The Self Service app uses the setting you configure. Self Service Return to Service options showing Add to Self Service checkbox and optional Wi-Fi profile configuration #### Return to Service in Self Service Considerations For more on Return to Service, including Activation Lock and Enterprise Wi-Fi, see [Erase an Apple Device](/en/endpoint/devices/device-actions/erase-a-device#return-to-service-ios-ipados-17). Cellular devices and devices connected via Ethernet do not require the Wi-Fi profile. Only Wi-Fi profiles scoped to the same Blueprint appear in the drop-down, including Custom Profiles with Wi-Fi payloads. This keeps Wi-Fi payloads from being orphaned on devices. Profiles that include a SCEP payload are not included. **Retry enrollment** requires iOS 27 or iPadOS 27 or later on iPhone and iPad. You set it on the Iru Self Service Library Item. Users do not see or change it. ### Opening Self Service #### iPhone and iPad Tap the **Iru Self Service** icon on your Home Screen to open the app. If you don't see the app, swipe down from the top of the screen to reveal the search field and search for Iru Self Service. The first time you open Self Service, the Analytics and Crash Reports screen appears. Configure the settings as you wish, then tap **Continue**. #### visionOS Open **Home View**, select **Apps View** in the tab bar, then look at the app and tap to open it. If you don't see the app, open **Control Center**, tap the **Search** button, then enter "Iru Self Service" and tap the result to open the app. The first time you open Self Service, the Analytics and Crash Reports screen appears. Configure the settings as you wish, then tap **Continue**. ### Navigating Self Service Self Service has several tabs at the bottom of the screen and will automatically open to the **Library** tab, which is the primary screen that users will interact with. Within the **Library** tab, **All** is always displayed. **Recommended** appears only when at least one assigned item is marked as recommended in Self Service settings. Additional categories display when an app in that category is assigned to the device's Blueprint. * **All**: Always displayed; includes all items available in Self Service * **Recommended**: Displayed only when one or more assigned items are marked as recommended * Admins can add categories in the Iru Endpoint web app in **Library** → **Self Service Settings** tab. A category will display on a device only if an app within that category is added to the Blueprint that the device is in Access the **Device Info** tab to see useful information about the device, such as serial number, model, and installed OS version. Use the **Search** tab to search for and install any app available in Self Service. Navigate to the **More** tab which includes an **About** screen (which displays the version information for the Self Service app itself), **Privacy**, and **Activity**. Open **Activity** to see previously installed app versions and the dates when they were installed. ### Installing Available Applications Apps available for Self Service installation will display an icon, name, and description. Tap **Get** to install the application from the Self Service **Library** screen. After installing an app, the button will change from Get to **Reinstall**. Tap the app icon for additional information about the app. ### Considerations * **License Management**: Ensure sufficient licenses are acquired from Apple Business or Apple School Manager for all devices * **Automatic Installation**: Self Service installs automatically on company-owned supervised devices * **User Consent**: Users need to agree to install Self Service on devices enrolled through the Iru Endpoint Enrollment Portal * **Return to Service**: Available for iOS and iPadOS 17+ devices. After erase, the device re-enrolls automatically. On iOS 27 or iPadOS 27 or later, you can enable **Retry enrollment** on the Iru Self Service Library Item. * **Wi-Fi Configuration**: Configure Wi-Fi profiles for devices that need network access after erase * **Category Management**: Categories display on devices only if apps within those categories are added to the device's Blueprint * **Search Functionality**: Users can search for and install any available app through the Search tab * **Device Information**: Serial number, model, and OS version * **Activity Tracking**: View previously installed app versions and installation dates * **Analytics Configuration**: Users can configure analytics and crash report settings on first launch * **Home Screen Access**: Self Service appears on device Home Screens for easy access * **App Management**: Users can reinstall apps and view detailed app information * **Multi-Platform Support**: Works across iOS, iPadOS, and visionOS devices * **Administrative Control**: You can configure categories and recommended items through the web app # Self Service for macOS Source: https://docs.iru.com/en/endpoint/settings/self-service/self-service-for-macos Configure Self Service for macOS in Iru Endpoint. Let users install approved apps, run scripts, and access resources from the Self Service application. This guide applies to Mac computers ### About Self Service for macOS Self Service is an application that lets IT administrators manage a personalized App Store for their organization. Users can download and install IT-approved software on their Mac computers, giving them more control over their devices and reducing the need for IT intervention. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Iru Endpoint** menu bar icon also changed from **Kandji** to **Iru** branding. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. Please update **scripts, automations, and utilities** that still reference the old app names. The app name and path in this guide match the current release. For more information, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update) and [Upgrade to Iru](/en/iru/platform-overview/upgrade-to-iru). ### How It Works You can make various software titles, scripts, and bookmarks available to end users through the Iru Endpoint Web App. When Mac computers enroll in Iru Endpoint, the Self Service app automatically installs. End users can then access the app from the Iru Endpoint Menu Bar, Application search, or their Applications folder. They can search through the available items and install them as needed. ### Self Service Security events End users can view quarantined files and blocked processes on their Mac by opening **Self Service** and selecting **Security events** in the left-hand navigation. For setup and behavior, see [Configure the EDR Library Item](/en/endpoint/endpoint-detection-response-edr/configure-the-edr-library-item#self-service-security-events). ### Launching Self Service Self Service can be opened from either the menu bar, Application search, the /Applications folder in Finder, or URL. The path to the Self Service app is: ``` /Applications/Iru Self Service.app ``` If an Iru Agent update is pending, Self Service for macOS will automatically close after 15 minutes of user inactivity. #### Launching Self Service from the Menu Bar In the menu bar, click the **Iru Endpoint** logo. Hover over **Iru Self Service** and click **Open**. Menu bar showing Iru Endpoint logo with Self Service option to open the app #### Launching Self Service from Application search In the Dock, click **Application search**. Click **Iru Self Service**. Application search showing Iru Self Service app icon to launch from the Dock #### Launching Self Service from Finder In the Dock, click **Finder**. In the Finder window sidebar, click **Applications** to open the Applications folder. Double-click **Iru Self Service**. Finder Applications folder showing Iru Self Service app to double-click and launch #### Launching Self Service from a URL In a web browser, enter the following URL then press Return: ``` iru://open-app/self-service ``` ### Navigating Self Service To navigate within Self Service, use the navigation bar on the left side of the app window. The All category is always visible, and any additional categories will automatically appear based on the Library Items assigned to the device. Use the **Search** function to find available items in Self Service. Navigate through the **Library** section which includes: * **All**: This category includes all items available to your device in Self Service * **Recommended**: Appears when one or more assigned items are marked as recommended; those items show a star icon next to their name * **Bookmarks**: Access links to essential work resources provided by your IT administrator * **Additional Categories**: Depending on your organization's setup, you may see other categories tailored to specific needs Access the **Device Info** section to see key device information, such as OS version, power percentage, storage capacity, and connected displays, on a single page. Use the **Sync** button to initiate device check-ins when requested by your IT administrators. Self Service Device Info with Sync button Use the **Updates** tab to see your recently updated apps, as well as apps that are ready to update. Self Service Updates tab with ready to update and recent activity ### Installing Available Applications Apps that are available for Self Service installation will display their app icon, app name, app description, and an install button. Self Service All apps library with Install and Open buttons Clicking the **Install** button downloads and installs the app. After installing an app, the button changes to **Open**. After an app has been successfully installed, more options will become available. #### Post-Installation Options To access the options available after installation, click the **ellipsis** next to the Open button. From there, you will see: * **Reinstall**: Reinstall the app * **Show in Finder**: Open a Finder window with the app's location * **Add to Dock**: Add the app icon to the currently logged-in user's Dock * **Support**: Opens the app's support webpage * **Show in App Store**: For Apps and Books apps only, launch the app's page in the Mac App Store Self Service post-installation options menu #### App Details Clicking an app **icon** or app **name** will bring up details about the app itself, including: * App icon * App name * Short description * Long description * Install button or Open button (after an app has been installed the Install button changes to the Open button) Self Service app details information popup ### Deep-Linking Self Service Items You can directly link to and share items in Self Service using deep links through the Share menu. To link to an item, use a URL with the `iru-self-service://` scheme: ``` iru-self-service://library/items/ ``` You can still use `kandji-self-service://` in existing links; they open in the current Self Service app with the same path. If needed, you can share links to Categories by secondary-clicking on them and selecting **Share**. ### Device Localization Support When a user configures their macOS device to use one of the supported languages as its primary language, the Self Service app displays localized text for non-customizable strings. No admin configuration is required to enable this capability. The following languages are supported: * Chinese (Simplified) * French / French (Canada) * German * Italian * Japanese * Portuguese * Portuguese (Brazil) * Spanish Self Service localized in Japanese ### Show or Hide the Iru Endpoint Menu With **Iru Self Service**, users can choose to show or hide the Iru Endpoint Menu. #### To Show the Iru Endpoint Menu Open Self Service. In the menu bar, select the **Help** menu. Click **Show Iru Endpoint Menu...** #### To Hide the Iru Endpoint Menu In the menu bar, click the **Iru Endpoint** jellyfish. Click the settings **gear**. Select **Hide Iru Endpoint**. ### Considerations * **Multiple Launch Methods**: Self Service can be accessed through various methods including menu bar, Application search, Finder, and direct URL * **Automatic Installation**: Self Service is automatically installed when Mac computers enroll in Iru Endpoint * **User Control**: Users have control over their device software while maintaining IT oversight and security * **Navigation Features**: The app provides search functionality, categorized libraries, device information, and update management * **Post-Installation Options**: Users can reinstall apps, add them to Dock, access support, and view in App Store * **Deep Linking**: Items can be shared with `iru-self-service://` URLs; existing `kandji-self-service://` links keep working * **Localization Support**: The app supports multiple languages automatically based on system settings * **Menu Management**: Users can show or hide the Iru Endpoint menu based on their preferences * **Device Information**: Users can view device details including OS version, power, storage, and connected displays * **Sync Functionality**: Users can manually initiate device check-ins when requested by administrators * **Update Management**: Users can view and manage app updates through the dedicated Updates tab * **Bookmark Access**: Quick access to essential work resources and links provided by IT administrators * **Recommended Items**: You can mark important items for easy user discovery # Self Service: Library Items Source: https://docs.iru.com/en/endpoint/settings/self-service/self-service-library-items Manage which Library Items appear in Self Service for end users. Configure app visibility, categories, and optional versus required installation policies. ### About Self Service Library Items Self Service Library Items provide a centralized way to distribute applications, scripts, and resources to users across different Apple platforms. This system allows administrators to make various Library Items available through the Self Service app, giving users on-demand access to approved software and tools. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. Please update **scripts, automations, and utilities** that still reference the old app names. ### How It Works Self Service Library Items work by configuring existing Library Items to appear in the Self Service app interface. Users can browse, search, and install available items on-demand, providing flexibility while maintaining security and compliance. Different Library Item types are available on different platforms, with macOS supporting the widest range of options. ### Available Library Items #### macOS Library Items The following Library Items can be made available to users via Self Service in macOS: * [App Store Apps (Apps and Books)](/en/endpoint/settings/self-service/self-service-library-items#app-store-apps-apps-and-books) * [Auto Apps](/en/endpoint/settings/self-service/self-service-library-items#auto-apps) * [Bookmarks](/en/endpoint/settings/self-service/self-service-library-items#bookmarks) * [Custom Apps](/en/endpoint/settings/self-service/self-service-library-items#custom-apps) * [Custom Printers](/en/endpoint/settings/self-service/self-service-library-items#custom-printers) * [Custom Scripts](/en/endpoint/settings/self-service/self-service-library-items#custom-scripts) * [Managed OS](/en/endpoint/settings/self-service/self-service-library-items#managed-os) #### iOS, iPadOS, and visionOS Library Items In iOS, iPadOS, visionOS, the following Library Items can be made available through Self Service: * [App Store Apps (Apps and Books)](/en/endpoint/settings/self-service/self-service-library-items#app-store-apps-apps-and-books) * [Bookmarks](/en/endpoint/settings/self-service/self-service-library-items#bookmarks) ### Enabling Self Service for Library Items Once you have Self Service settings configured in the Iru Endpoint Web App (**Library** → **Self Service Settings** tab), you can enable individual Library Items to appear in the Self Service app for your users. In the Library Item, the Self Service options and customizations will be displayed. In the Installation pop-up menu, choose either **Install on-demand in Self Service** or **Install and continuously enforce**. Choose an available category in the **Category** menu. Select **Recommended** if you want this item to appear in the Recommended section of the Self Service app. Click the **Edit** button to customize the appearance of the item in the Self Service app. ### Customizing a Library Item You can customize a Library Item for Self Service by clicking the **Edit** button on the item tile in the Customization section. In the Self Service **Customization** details pane, the following options are available. Enter a custom name in the **Name** field. The name will be prefilled from the App Store listing, Auto App item, or Library Item details. Enter a short description. This entry will be prefilled from the App Store or Auto App listing. Choose an available category from the Category menu. Select **Recommended** if you want the item to appear in the Recommended section of the Self Service app. Enter a long description. This entry will be prefilled from the App Store or will contain the description from the Auto App item. Select **Require users to read the description before installing** if you want to ensure that users are presented with that information before proceeding with the installation of the item. ### App Store Apps (Apps and Books) App Store apps may be offered through Self Service in macOS, iOS, iPadOS, visionOS. * When an App Store app's Installation option is set to **Install and Continuously Enforce,** you can still optionally show this item in Self Service. This may be useful if users need to try reinstalling the app for any reason. * When an App Store app's Installation option is set to **Install on-demand from Self Service,** the app will not be installed until the user installs the application from Self Service. * When Installing via Self Service, the latest version of the app will be installed. * Iru Endpoint will automatically take over management of licensed applications that are not from the App Store if set to **Install on-demand from Self Service**, as long as the bundle ID of the existing application matches that of the Apps and Books version. Your global or per-app update settings will be respected. When assigning an App Store app to a Blueprint and setting it to Install on-demand from Self Service, Iru Endpoint will not take over management if the end user previously installed the app. The app will be considered managed when the user initializes an installation through Self Service. Until completed, Iru Endpoint will not proceed to update the App Store app locally regardless of the global Apps & Books setting defined in **Integrations** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations** → Apple Integrations). ### Auto Apps [Auto Apps](/en/endpoint/library/auto-apps/auto-apps-overview) can be offered through Self Service in macOS only. * When an Auto App's Installation option is set to **Continuously Enforce,** you can still optionally show this item in Self Service. This may be useful if users need reinstall the application for any reason. * When an Auto App's Installation option is set to **Install on-demand from Self Service,** the app will not be installed until the user installs the application from Self Service. * When installing from Self Service, the latest version of the app will be installed. * If you configure version enforcement in the Updates section, the Auto App will be updated if the App is currently installed, either via Self Service or other means (such as if the user downloads it manually). ### Bookmarks [Bookmarks](/en/endpoint/settings/self-service/self-service-bookmarks) may be offered through Self Service in macOS, iOS, iPadOS, visionOS. Use bookmarks, which you configure in one or more Bookmarks Library Items, to give your users links to the resources they need at work via Iru Endpoint's Self Service app. When combined with the apps and scripts in Self Service, you can make your users more productive and improve your security posture by having Self Service be the one place they go for approved apps, scripts, and links to resources. ### Custom Apps [Custom Apps](/en/endpoint/library/library-items-profiles/custom-apps-overview) may be offered through Self Service on macOS. On Windows, Custom Apps (MSI, EXE) are deployed via Blueprint assignment only; see [Configure the Windows Custom App Library Item](/en/endpoint/library/library-items-profiles/configure-the-windows-custom-app-library-item) for step-by-step setup. * When a Custom App's Installation option is set to **Install and continuously enforce** or **Install once per device,** you can still optionally show the Custom App in Self Service. This may be useful if users need to try reinstalling the software. * When a Custom App's Installation option is set to **Install on-demand from Self Service,** the app will not be installed until the user installs the application from Self Service. * When a Custom App is set to **Restart after successful install** and installed via Self Service\*\*,\*\* end users will be given a 5 minute countdown before a restart occurs instead of the 30 minute countdown when run in the background by the Iru Agent. ### Custom Printers [Custom Printers](/en/endpoint/library/library-items-profiles/custom-printers-overview) may be offered through Self Service in macOS only. * When a custom printer's Installation option is set to **Install printer and continuously enforce** or **Install printer once per device,** you can still optionally show the printer in Self Service. This may be useful if users need to reinstall the printer for any reason. * When a custom printer's Installation option is set to **Install on-demand from Self Service,** the printer will not be installed until the user installs the printer from Self Service. ### Custom Scripts [Custom Scripts](/en/endpoint/library/library-items-profiles/custom-scripts-overview) may be offered through Self Service in macOS only. * When a custom script's Execution Frequency option is set to **Install once per device,** you can still optionally show this item in Self Service. This may be useful if users need to try to rerun the script for any reason. * When a custom script's Execution Frequency option is set to **Install on-demand from Self Service,** the app will not be installed until the user installs the application from Self Service. * When a custom script is set to **Restart after successful execution** and run via Self Service\*\*,\*\* end users will be given a 5 minute countdown before a restart occurs instead of the 30 minute countdown when run in the background by the Iru Agent. ### Managed OS [Managed OS](/en/endpoint/library/managed-os/configure-managed-os-for-macos) may offer major macOS upgrades through Self Service for macOS only. * When a Managed OS Library Item's Installation option is set to **Continuously Enforce,** you cannot show this item in Self Service. * When a Managed OS Library Item's Installation option is set to **Install on-demand from Self Service,** major macOS versions will not be enforced per the Updates configuration. * When upgrading via Self Service, the latest version of the major macOS version will be installed. * When set to **Install on-demand from Self Service**, the Managed OS item will be displayed in Self Service only when the user's Mac is on a previous major macOS version. ### Considerations * **Platform Compatibility**: Different Library Item types are available on different platforms - macOS supports the widest range, while iOS/iPadOS/visionOS support App Store apps and bookmarks only * **Installation Methods**: Choose between "Install on-demand" for user-initiated installations or "Install and continuously enforce" for automatic deployment * **Category Organization**: Organize Library Items into logical categories to help users find what they need quickly * **Recommendation Strategy**: Use the "Recommended" setting strategically to highlight important or frequently used items * **Customization Options**: Take advantage of customization features like custom names, descriptions, and icons to improve user experience * **Description Requirements**: Consider requiring users to read descriptions before installation for critical software or scripts * **Version Management**: Self Service installations always use the latest version, which may differ from continuously enforced items * **Management Takeover**: Iru Endpoint can automatically take over management of existing applications when installed via Self Service * **Restart Behavior**: Self Service installations provide shorter restart countdowns (5 minutes vs 30 minutes) for better user experience * **User Training**: Provide guidance to users about how to access and use Self Service effectively * **Security Posture**: Use Self Service as a centralized location for approved applications and resources to improve security * **Update Management**: Be aware that Self Service installations may not follow the same update schedules as continuously enforced items * **Testing and Validation**: Test Self Service items thoroughly before making them available to users * **Documentation**: Provide clear descriptions and instructions for complex items like scripts and custom applications # Self Service Settings Source: https://docs.iru.com/en/endpoint/settings/self-service/self-service-settings Configure Self Service portal settings in Iru Endpoint. Customize branding, enable platforms, set categories, and control which items users can install. ### About Self Service Settings Self Service acts as an internal app store for your users to self-install applications you make available to them. It provides a centralized way for users to discover and install approved applications while maintaining security and compliance standards. As of **April 8, 2026**, apps were updated from **Kandji** to **Iru** branding. The **Self Service** app name changed from **Kandji Self Service** to **Iru Self Service**. Please update **scripts, automations, and utilities** that still reference the old app names. For more information, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update) and [Upgrade to Iru](/en/iru/platform-overview/upgrade-to-iru). ### How It Works Self Service is automatically installed on all enrolled devices and provides a customizable interface for application distribution. On macOS devices, **Iru Self Service** is installed in the `/Applications` folder, while on iOS, iPadOS, and visionOS devices, the **Iru Self Service** App Store app appears on users' Home Screens. Administrators can customize the appearance, organization, and functionality to match their organization's branding and requirements. ### Configuring Self Service Self Service allows users to install apps in macOS, iOS, iPadOS, and visionOS. Auto Apps and Managed OS are available only in macOS. To customize Self Service: Navigate to the **Library** section in the left-hand navigation bar. Select the **Self Service settings** tab. Library with Self Service settings tab selected Click **Customize**. ### Configuring Branding and Preview You can customize the Self Service app with your company's name, logo, or other information. There are built-in previews to see how Self Service will look to your users, in both Light and Dark Modes and on each Apple platform. The Self Service preview may not show up on lower-resolution displays, including Retina displays in High DPI mode. #### Configuring Header and Subheader You can set a custom title and optional message for the Self Service banner. One good use of this space: to provide users IT-support contact information. Enter **Header** text that will be displayed in the Self Service header banner. Enter **Subheader** text that will be displayed under the header. #### Configuring Logo Upload your company's logo, which will be displayed next to the header in Self Service. A square logo (128x128 pixels) in PNG format with a transparent background is recommended. Click the **Upload** link, locate your logo in the Finder, and click the **Open** button. Your logo will be displayed where the default logo was previously, and you will see it in the preview. After you upload a custom logo, you can also add a logo for computers in Dark Mode. To remove the custom logos: Hover over the custom logo in the **Customize** Self Service panel. Click the **Trash** button. Your custom logo will be replaced with the default logo. ### Managing Categories Several default categories are provided to help organize your Self Service apps. In **Self Service Settings**, **Recommended** and **All** are default categories and cannot be deleted. On devices, **All** is always shown in the Library tab; **Recommended** appears only when at least one assigned item is marked as recommended. Other categories can be added, reordered, renamed, or deleted. #### Adding a Category Click **Add category** in the bottom right corner of the **Categories** section. Enter a **Name** for the new category (maximum 64 characters in length). Enter an optional **Description** for the category. Optionally, enter a search term for an icon in the Search field. Choose an icon for the category. #### Changing the Category Order Categories will display in Self Service in the same order in which they appear on the Self Service Settings page. Drag the categories using the slide bars on the left side of the Categories section. #### Editing or Deleting an Existing Category Click the three dots to the right of the category you want to edit or delete. Click **Edit** to change the category name, description, or icon. Click **Delete** to delete the category. You can't delete the Recommended or All categories. ### Considerations Align logo, colors, and header copy so Self Service feels like one catalog. Prefer square **128×128** pixel **PNG** logos with a transparent background, then add a **Dark Mode** logo after you customize Light Mode. Use the built-in previews for Light Mode, Dark Mode, and each platform before you rely on a design in production. The in-page preview may not appear on lower-resolution displays, including Retina displays in High DPI mode. Order and name categories for quick scanning, choose icons that match each group’s purpose, and remember **Recommended** and **All** cannot be deleted. Revisit categories as your app portfolio changes. Self Service is available on **macOS**, **iOS**, **iPadOS**, and **visionOS**. Spot-check the catalog on each platform your organization supports. Use **Header** and **Subheader** for IT contact details and short guidance users should see at the top of Self Service. Tell users how to open Self Service and what it is for. For walkthroughs aimed at end users, see [Self Service for macOS](/en/endpoint/settings/self-service/self-service-for-macos) and [Self Service for iOS, iPadOS, and visionOS](/en/endpoint/settings/self-service/self-service-for-ios-ipados-and-visionos). # Submit Feature Requests & Ideas Source: https://docs.iru.com/en/endpoint/settings/submit-feature-requests-and-ideas Submit feature requests and product ideas to the Iru team. Vote on existing suggestions, provide feedback, and track the status of your submitted requests. ### About Feature Requests You can submit feature requests or ideas directly through the Iru Web App. ### Submit a Feature Request In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Organization**. Account menu with Organization option Click the **Resources** tab. Select **Submit Feature Request** to send a feature idea, or **Auto App request** to suggest a new [Auto App](/en/endpoint/library/auto-apps/auto-apps-overview). Organization Resources tab showing Feature and Auto App requests options For questions or support, use the chat bubble in the upper right corner of the web app or [contact support](/en/iru/iru-support/access-to-iru-support). # My Account profile settings Source: https://docs.iru.com/en/endpoint/settings/user-preferences/my-account-profile-settings Manage your Iru Endpoint account profile settings. Update your name, email, password, notification preferences, and two-factor authentication configuration. ### About My Account Use **My Account** in the Iru Endpoint web app to update your profile photo and preferences for your own user. Changes do not affect other users in your tenant. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **My Account**. Left navigation with user name and My Account option Near the top right of the **My Account** page, click **Edit**. The page switches to edit mode and shows your profile photo with the controls you use to change it. My Account page in edit mode after choosing Edit, with profile photo controls ### Upload a New Profile Photo With **My Account** still in edit mode, use **Upload new photo** to pick an image from your computer. My Account edit mode showing upload new profile photo ### Preferences The **Preferences** section controls how your name, locale, dates, and email summaries appear for your account in the Iru Endpoint web app. My Account preferences in edit mode #### Preferred Name Use **Preferred name** to define how you want your name to appear. Enter or update the text in the field whenever you want to change it. #### Time Zone **Time zone** sets how dates and times are shown for your account. Open the list and pick the line that matches where you work (each entry lists an offset with a region or city). To follow the clock on the device you are using instead, choose **Device's Local Timezone**. Scroll the list to find the value you need. #### Language **Language** sets the display language for the Iru Endpoint web app for your user. Open the list and choose the locale you want. The menu shows every language Iru Endpoint currently supports for the interface. #### Display Relative Dates **Display relative dates** turns relative time labels on or off where the app supports them, instead of showing only fixed timestamps. Select **Yes** or **No**. #### Weekly Status Emails Use receive weekly status emails to turn optional summaries on or off for your **Iru Endpoint** tenant. Select **Yes** or **No**. Weekly email delivery reflects your saved choice starting the following week. If you choose **Yes**, messages follow the normal weekly schedule. This option is separate from the email categories available when subscribing on the [Iru Product Updates page](https://www.iru.com/updates/). Receive weekly status emails Yes or No options in My Account preferences After you adjust preferences, click **Save** near the top right of the page to apply your changes. These changes only affect your specific user. Your weekly status email preference takes effect starting the following week, and you can edit these preferences again at any time. ### Considerations Profile photo and preferences apply only to your account. [Weekly status emails](#weekly-status-emails) summarize system status, device counts, and important notifications for your tenant. Feature and product announcements use separate subscriptions on the [Iru Product Updates page](https://www.iru.com/updates/) and are described in [Iru Product Updates](/en/iru/platform-overview/iru-product-updates) in this documentation. Review remaining notification settings so you do not miss important alerts. Align with your team if everyone needs weekly summaries for operations or reporting. # Configure Windows Autopilot Source: https://docs.iru.com/en/endpoint/settings/windows-integrations/configure-windows-autopilot Configure Microsoft Entra ID for auto-enrollment of devices to Iru through Autopilot. Complete the Iru Endpoint wizard and assign Blueprints. This guide applies to Windows devices Windows Autopilot lets new Windows 11 devices enroll in Iru Endpoint during the out-of-box experience (OOBE). After you connect your Microsoft Entra ID tenant and register Iru as the MDM authority, users sign in with their Microsoft Entra ID credentials and the device completes enrollment without the manual enrollment portal. ### About Windows Autopilot Autopilot targets corporate devices that are registered with the Windows Autopilot service and assigned an Autopilot deployment profile through Intune. Iru Endpoint supplies the MDM Terms of Use URL, MDM Discovery URL, and enrollment defaults (including Blueprint assignment) in the wizard under **Integrations** → **Windows**. Device registration in Intune and Autopilot deployment profiles are Microsoft-side steps; they determine OOBE behavior before the user reaches the sign-in that triggers management enrollment. ### How It Works Run the Autopilot configuration wizard in Iru Endpoint to create or bind the Entra app registration and verify an Iru-managed domain. When a registered device comes online, Windows runs OOBE, applies your Autopilot deployment profile from Intune, then continues to Entra sign-in. Successful authentication enrolls the device into Iru Endpoint using the default Blueprint or [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing), depending on what you configured in the final wizard step. ### Prerequisites * **Windows platform** enabled for your tenant. If it is not on yet, turn it on in **Organization** first. See [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup#enable-windows-platform). * **Microsoft Entra ID permissions**: Ability to add custom domains, configure **Mobility (MDM and WIP)**, and create or edit app registrations (including API permissions and admin consent) * **[Microsoft Entra admin center](https://entra.microsoft.com)** access for your tenant * **Microsoft licensing** that covers Windows Autopilot and MDM auto-enrollment for your scenario * **Windows 11** devices that meet [Iru Endpoint Windows requirements](/en/endpoint/getting-started/platform-setup/windows-setup) (24H2 or 25H2 only; supported editions) * **Autopilot registration path** in place for your devices (OEM pre-registration, partner/CSP registration, or manual import) and **Intune** access to assign an Autopilot deployment profile ### Create the MDM Application and Enter Credentials Entra guidance appears on the left of the wizard; credential and flow fields are on the right. Start in **Iru Endpoint**, use the **Microsoft Entra ID** tab for the Microsoft Entra admin center steps, then return to **Iru Endpoint** when the steps below tell you to. ### Prepare the Autopilot wizard In Iru Endpoint, open **Integrations**. Under **Platform integrations**, select **Windows**. Click the **Configure Autopilot** button. On the Autopilot wizard page, use **Instructions** to locate **Step 6**, then copy the **MDM Terms of Use URL** and **MDM Discovery URL** shown there. Use the copy control next to each URL in the wizard. Manual typing often breaks enrollment discovery. Keep the values where you can paste them after you switch to the **Microsoft Entra ID** tab. Switch to the **Microsoft Entra ID** tab and continue with [**Creating the MDM application in Entra**](#creating-the-mdm-application-in-entra). ### Enter MDM credentials in the Autopilot wizard When **Grant admin consent** is done on the **Microsoft Entra ID** tab, return here and paste **Application (client) ID**, **Directory (tenant) ID**, **Secret value**, and **Secret ID** from the Microsoft Entra admin center into the wizard. On the right side of the wizard, enter: * **Application (client) ID** * **Directory (tenant) ID** * **Secret value** * **Secret ID** Use the values you copied while working in the **Microsoft Entra ID** tab. The MDM URLs must already be saved in Entra, and the client secret and Graph permissions must be in place with admin consent granted before **Next** will succeed. Select **Next**. If Entra fields change later, including secret rotation, return to [**Creating the MDM application in Entra**](#creating-the-mdm-application-in-entra) or [**Client secret and Graph permissions for the MDM app**](#client-secret-and-graph-permissions-for-the-mdm-app) to generate new values, then update these fields before continuing. After **Next** succeeds, switch to the **Microsoft Entra ID** tab and complete [**Verify Custom Domain**](#verify-custom-domain). ### Blueprint Settings and Finish Setup After the Application ID URI is saved in Entra ([**Application ID URI in Entra**](#application-id-uri-in-entra)), use the steps below to set **Default Blueprint** or **Blueprint Routing** for Autopilot enrollments, then **Finish Setup**. If that Entra step is not done yet, switch to the **Microsoft Entra ID** tab first. Select **Next**. Select the **Default Blueprint** for Autopilot enrollments, or choose **Blueprint Routing** if you use dynamic Blueprint assignment during enrollment. If Blueprint Routing is not set up yet, the wizard shows this warning: **Blueprint Routing has not been set up. Configure to save this setting.** Select **Configure Blueprint Routing** and complete [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing) before you can save. Select **Finish Setup**. Before you start in the Microsoft Entra admin center, complete [**Prepare the Autopilot wizard**](#prepare-the-autopilot-wizard) in the **Iru Endpoint** tab. You need the **MDM Terms of Use URL** and **MDM Discovery URL** from **Step 6** in **Instructions** on the Autopilot wizard page. ### Creating the MDM application in Entra Iru Endpoint supports both Microsoft Entra MDM **v1** and **v2** access tokens for Autopilot enrollment. Custom MDM applications created in Entra after July 1, 2026 issue v2 tokens by default (the token audience is the application’s client ID). Older apps may still use legacy v1 tokens (audience is the Application ID URI). Continue with the steps in this article either way. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com). In the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **Mobility (MDM and WIP)**. Click **Add application**. Click **Create your own application**. Enter **Iru Endpoint Management** as the **Name**. Click **Create** (or **Register**, depending on what the admin center shows). Under **MDM user scope**, select **Some** or **All**. Make sure the selected scope includes the users who will sign in during OOBE on Autopilot devices so their devices can auto-enroll. Under **Mobility (MDM and WIP)**, review every **other** MDM application (for example **Microsoft Intune** or another MDM still listed there) that still has **MDM user scope** set to **Some** or **All**. Do not assign the same users or groups to both that application's scope and this custom MDM app. Intune in this article is only for Autopilot device registration and deployment profiles; Iru Endpoint is the MDM enrollment target for the devices. Overlapping MDM user scopes can send OOBE to the wrong provider or prevent enrollment into Iru Endpoint. Paste the **MDM Terms of Use URL** and **MDM Discovery URL** you copied from **Step 6** in **Instructions** on the Iru Autopilot wizard page. Paste them into Entra exactly as shown. Click **Save**. ### Client secret and Graph permissions for the MDM app Click **Custom MDM application settings**. On **Overview**, copy **Application (client) ID** and **Directory (tenant) ID**. You'll paste them into Iru in [**Enter MDM credentials in the Autopilot wizard**](#enter-mdm-credentials-in-the-autopilot-wizard). Under **Manage**, select **Certificates & secrets**. Click **New client secret**. Enter a **Description** and choose **Expires**. Click **Add**. Copy the secret **Value** and **Secret ID** for Iru Endpoint. Under **Manage**, select **API permissions**. Click **Add a permission**. Click **Microsoft Graph**. Select **Application permissions**. In the permissions list, select each of the following: * `Application.Read.All` * `Domain.Read.All` * `Device.ReadWrite.All` * `DeviceManagementServiceConfig.ReadWrite.All` * `Group.ReadWrite.All` * `GroupMember.ReadWrite.All` Click **Add permissions**. Click **Grant admin consent for \[your tenant]**. If prompted, click **Yes** to confirm. When the MDM URLs are saved, the secret exists, and admin consent is granted, switch back to the **Iru Endpoint** tab and complete [**Enter MDM credentials in the Autopilot wizard**](#enter-mdm-credentials-in-the-autopilot-wizard). Then select **Next** in the wizard to continue with [**Verify Custom Domain**](#verify-custom-domain) in this tab. ### Verify Custom Domain In the [Microsoft Entra admin center](https://entra.microsoft.com), in the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **Domain names**. Click **Add custom domain**. Enter the custom domain shown in the Iru wizard into the **Custom domain** field. Click **Add domain**. In **Iru Endpoint**, in the Autopilot wizard, select **Next**. Iru applies the TXT record from Microsoft for DNS; propagation can take from a few minutes up to 48 hours. You can leave and return; progress is saved. In the [Microsoft Entra admin center](https://entra.microsoft.com), in the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **Domain names**. In the domain list, open the domain you added. Click **Verify**. In **Iru Endpoint**, in the Autopilot wizard, select **Next**. Iru checks verification status with Entra before you continue. ### Application ID URI in Entra In the [Microsoft Entra admin center](https://entra.microsoft.com), in the left navigation bar, ensure that the **Entra ID** section is expanded. In the left navigation bar, click **App registrations**. If the registration does not appear under **Owned applications**, select the **All applications** tab. Select **Iru Endpoint Management**. Under **Manage**, select **Expose an API**. Click **Edit** next to **Application ID URI**. Enter the Application ID URI value shown in the Iru wizard. Click **Save**. Switch to the **Iru Endpoint** tab and complete [**Blueprint settings and finish setup**](#blueprint-settings-and-finish-setup). ### Microsoft Intune: Device Registration and Deployment Profiles For how these Microsoft-side steps fit the full Autopilot flow with Iru Endpoint, see [**Considerations**](#considerations) → **Microsoft Intune and Autopilot end-to-end**. #### Register devices with Windows Autopilot Registration associates the device hardware hash with your tenant so Windows knows to run Autopilot OOBE. When a registered device first connects to the internet, Windows identifies it as an Autopilot device and starts that flow. Depending on how devices are purchased, you may not need to register devices manually at all. Common registration paths: * **OEM pre-registration**: Hardware manufacturers can register devices with Autopilot at purchase time. * **Partner (CSP) registration**: Cloud Solution Providers can register devices for you. * **Manual registration**: For existing devices, you can capture hardware hashes with PowerShell, export to CSV, and import into Intune. For procedures, see Microsoft's [Register devices in Windows Autopilot](https://learn.microsoft.com/en-us/autopilot/add-devices). #### Configure an Autopilot deployment profile The deployment profile controls which OOBE screens appear, including privacy settings, EULA, Windows Hello, and personal Microsoft account blocking. In Intune, create the profile and assign it to a Microsoft Entra **device** group whose members are your Autopilot-registered devices. The profile must be targeted at **devices**, not at users only, so Windows can apply it during OOBE before Microsoft Entra sign-in. The device does **not** need an active Intune MDM enrollment for Autopilot to hand off to Iru Endpoint as your MDM; the profile shapes OOBE only. Deployment mode options: On the **Out-of-box experience (OOBE)** page in Intune, set **Deployment mode** to one of the following values: * **User-driven**: The device is associated with the user who enrolls it. That user must supply their credentials during OOBE before enrollment can complete. * **Self-deploying**: The device is not associated with a user for that enrollment path, and user credentials are not required to enroll the device through Autopilot. With no user on the device in that state, user-based compliance policies do not apply; only compliance policies targeted at the device apply. If **Deployment mode** is **Self-deploying**, the device enrolls through that Microsoft flow into **Microsoft Intune**. It does not enroll into Iru Endpoint with the Autopilot configuration described here. Iru Endpoint does not support Autopilot self-deploying mode. Use **User-driven** deployment mode only: users sign in with Microsoft Entra ID during OOBE before MDM enrollment completes into Iru Endpoint. Microsoft documents each mode in [Windows Autopilot user-driven mode](https://learn.microsoft.com/en-us/autopilot/user-driven) and [Windows Autopilot self-deploying mode](https://learn.microsoft.com/en-us/autopilot/self-deploying). For creating a profile in Intune, including the **Deployment mode** control on the OOBE page, see [Configure Windows Autopilot profiles](https://learn.microsoft.com/en-us/autopilot/profiles). Common profile options: * **Privacy settings**: Hide or show the privacy settings page. * **End user license agreement (EULA)**: Skip the license screen when appropriate for your policy. * **Account change**: Block switching to a personal Microsoft account during setup. * **Windows Hello**: Skip or defer Hello setup. * **OEM registration**: Skip manufacturer-specific prompts. On the deployment profile **Assignments** tab in Intune, add that Microsoft Entra **device** group as the assignment target, not a user group, so the profile applies during OOBE before Microsoft Entra sign-in and MDM enrollment. ### Considerations For Autopilot to work end to end with Iru Endpoint, two Microsoft Intune responsibilities must be satisfied in addition to the Iru wizard: * **Autopilot device registration:** Devices are registered with the Windows Autopilot service (for example by an OEM, a partner, or your team in Intune). * **Autopilot deployment profile:** A deployment profile exists in Intune and is assigned to a Microsoft Entra **device** group that contains your Autopilot-registered devices. Use **User-driven** deployment mode only; Iru Endpoint does not support Autopilot self-deploying mode (see [**Configure an Autopilot deployment profile**](#configure-an-autopilot-deployment-profile) above). Neither step is performed in Iru Endpoint. The Iru Autopilot integration configures Entra and Iru for MDM enrollment; it does not register hardware with Autopilot or replace profile creation and assignment in Intune. For procedures and Microsoft Learn links for each task, use the preceding section [**Microsoft Intune: device registration and deployment profiles**](#microsoft-intune-device-registration-and-deployment-profiles). * **Default Blueprint**: Applies to new Autopilot enrollments going forward. Changing the default later does not retroactively move devices that already synced. * **Blueprint Routing**: Must be fully configured before you can save when Routing is selected as the default. If you cannot save on the last step, complete Routing setup from the warning link first. * **Client secret lifetime**: Secrets expire on the date you choose in Entra. Before expiry, create a new secret and update **Secret value** and **Secret ID** in **Integrations** → **Windows** → Autopilot configuration so enrollment keeps working. * **Admin consent**: API permissions need **Grant admin consent for the tenant**. Without consent, Iru cannot complete Graph operations required for the integration. * **Entra MDM access tokens**: Iru Endpoint accepts both v1 and v2 tokens issued for the custom MDM application. New apps created after July 1, 2026 use v2 by default; existing apps may still issue v1 tokens. * **Not supported with Autopilot for Iru**: Iru Endpoint does not support **Microsoft Entra hybrid joined** devices enrolling through this Windows Autopilot flow. Plan for **Microsoft Entra joined** devices when using Autopilot with Iru Endpoint. ### Best Practices If different users or devices should land in different Blueprints, set up [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing) before you finish the wizard. Note the client secret expiry when you create it and schedule rotation ahead of time in Entra, then update the secret fields in Iru Endpoint. After adding Graph application permissions, grant tenant-wide admin consent so the integration can run unattended. Confirm your Microsoft licenses cover Autopilot and MDM auto-enrollment for the accounts that sign in during OOBE. ### Troubleshooting **Checklist:** * Every Autopilot wizard step completed successfully in Iru Endpoint. * **MDM Terms of Use URL** and **MDM Discovery URL** in Entra match **Step 6** in **Instructions** on the Iru wizard page (paste exactly). * Admin consent is granted for every Graph application permission on the **Iru Endpoint Management** registration. * Autopilot registration and deployment profile assignments in Intune cover the device. * The Autopilot deployment profile uses **User-driven** mode. Iru Endpoint does not support Autopilot self-deploying mode. * Microsoft licensing supports Autopilot and MDM enrollment for the user. **Deployment mode set to Self-deploying** The Autopilot deployment profile for the device has **Deployment mode** set to **Self-deploying**. That path enrolls the device into **Microsoft Intune** for Autopilot; it does not enroll into Iru Endpoint with the configuration in this article (see [**Configure an Autopilot deployment profile**](#configure-an-autopilot-deployment-profile)). In the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), edit the profile assigned to the Microsoft Entra **device** group that contains the device and set **Deployment mode** to **User-driven**. Confirm the profile shows **Assigned** for the device, then reset the device so OOBE runs again with the updated profile. **Overlapping MDM user scope in Entra** In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Mobility (MDM and WIP)** and review every **other** MDM application (for example **Microsoft Intune** or another MDM still listed there) alongside this custom MDM app. If two applications both have **MDM user scope** set to **Some** or **All** for the same users or groups, OOBE can send auto-enrollment to the other provider instead of Iru Endpoint. Ensure each user or group that should land in Iru Endpoint is in scope for only this custom MDM app, or set **MDM user scope** to **None** on MDM rows you no longer use for Windows enrollment. For the overlap warning and where to set scope, see the **Set MDM user scope** step under [Creating the MDM application in Entra](#creating-the-mdm-application-in-entra). **If the device still does not appear in Iru Endpoint** After **User-driven** is in effect and MDM scopes do not overlap for the enrolling user, use the checklist in **Devices do not enroll after Autopilot completes** on this page. If **Blueprint Routing** is selected but Routing is not configured, the wizard blocks **Finish Setup**. Select **Configure Blueprint Routing** from the banner, complete [Blueprint Routing](/en/endpoint/enrollment/blueprint-routing), then return and finish. ### Related Articles Platform requirements and enrollment prerequisites for Windows 11 in Iru Endpoint Manual enrollment portal, Enrollment codes, and Blueprint assignment for Windows Apple zero-touch enrollment with Apple Business or Apple School Manager Dynamic Blueprint assignment during enrollment using Assignment Rules # Accepting CVE Risks Source: https://docs.iru.com/en/endpoint/vulnerability-management/accepting-cve-risks Accept CVE vulnerability risks in Iru Endpoint when patching is not feasible. Document risk acceptance decisions, set expiration dates, and track exceptions. This guide applies to Mac computers and Windows devices ### About Accepting CVE Risks When managing vulnerabilities in your environment, you may need to accept certain Common Vulnerabilities and Exposures (CVE) risks based on your organization's security posture and business requirements. Iru Endpoint provides flexible options for accepting risks either indefinitely or for a specific timeframe. Please see our [Vulnerability Management Overview](/en/endpoint/vulnerability-management/vulnerability-management-overview) article for more information about vulnerabilities. ### How It Works CVE risk acceptance allows you to acknowledge vulnerabilities that you've determined are acceptable for your environment. When you accept a CVE risk, notifications and log events for that vulnerability are suppressed, but you can reverse the decision at any time to resume monitoring. Once you've accepted a CVE risk, the system automatically suppresses notifications and log events for that specific vulnerability. This helps reduce noise in your security monitoring while maintaining visibility into the decision-making process. You can track all risk acceptance decisions through the Vulnerability Management interface and on the [Unified Activity](/en/iru/platform-overview/unified-activity), and easily reverse them when your security posture changes. ### CVE Risk Acceptance Options When you review CVEs in Vulnerability Management, you can assess each one based on factors like severity, exploitability, and how it relates to your business needs. Sometimes, you might decide not to remediate a CVE right away. For example, maybe the latest patch isn't available yet, the issue is low priority, or the affected application is essential to your workflow and you've decided the risk is acceptable for now. Iru Endpoint gives you two options for accepting CVE risks: * **Accept risk indefinitely** - This permanently acknowledges the risk for the selected CVE. Notifications and log events for that CVE will be suppressed. * **Accept risk until a specific date** - This temporarily accepts the risk until the date you choose. After that date, the CVE returns to active status, and notifications and log events resume. You can also reverse your decision at any time. If you "un-accept" the risk, the CVE is treated as active again, and notifications and log events will start up where they left off. To exclude a device from Vulnerability Management counts and notifications without accepting risk for the CVE itself, see [Excluding Devices from Vulnerability Management](/en/endpoint/vulnerability-management/excluding-devices-from-vulnerability-management). ### Accepting a CVE Risk You can accept a CVE risk from the **Vulnerabilities** list or from the CVE detail view. Go to the **Vulnerability Management** section in the Iru Endpoint web app. In the **Vulnerabilities** list, click the **ellipsis** (**…**) next to the CVE you want to manage. Click **Accept risk**. Choose to accept the risk either indefinitely or until a specific date. Optionally, fill out the **Ticketing link** and **Comment** fields. Click **Accept risk**. Go to the **Vulnerability Management** section in the Iru Endpoint web app. Select the CVE you want to manage. Click **Change status**. Choose to accept the risk either indefinitely or until a specific date. Optionally, fill out the **Ticketing link** and **Comment** fields. Click **Accept risk**. Once accepted, Slack notifications and regular log events for that CVE will be suppressed. A log event will be created to record your action, including whether the acceptance is indefinite or has an expiration date. View it on the [Unified Activity](/en/iru/platform-overview/unified-activity). ### Un-accepting a CVE Risk Go to the **Vulnerability Management** section in the Iru Endpoint web app. Select the CVE you want to manage. Click **Change status**. Click **Un-accept risk**. Optionally, fill out the **Ticketing link** and **Comment** fields. Click **Confirm**. ### CVE Status Filters If you want to see which CVEs have accepted risks, use the **Status** filter in the Vulnerability Management interface and select **Risk accepted**. You’ll see a list of all CVEs with accepted risks, along with details about how long the acceptance lasts. ### CVE Timeline If you later decide to un-accept the risk, the CVE will go back to being treated as active. The **Timeline** tab in the CVE detail view shows the history of status changes, including the previous **Risk accepted** status and the current status. # Configure the Vulnerability Response Library Item Source: https://docs.iru.com/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item Configure the Vulnerability Response Library Item in Iru Endpoint. Define response policies for detected CVEs including severity thresholds and deadlines. This guide applies to Mac computers ### About Vulnerability Response Vulnerability Response enables you to automate the handling of security vulnerabilities (Common Vulnerabilities and Exposures, or CVEs) for macOS apps that exist in the Auto App catalog. You can set up rules that tell Iru Endpoint how to respond based on the severity of each CVE; when Iru Endpoint identifies an app with a known vulnerability, it can automatically update that app according to the rules you’ve put in place. You set those rules once. After that, matching CVEs are handled on check-in rather than as a one-off update each time a disclosure lands. ### How It Works Vulnerability Response scans and remediates all installed applications with a matching bundle ID in the Auto App catalog, even if the Auto App Library Item is not currently in your Library or assigned to a Blueprint. If an app is affected by multiple vulnerabilities with different severities, Vulnerability Response will perform the selected remediation action only for the highest applicable severity. On each Iru Agent check-in, Vulnerability Response compares the applications installed on your Mac fleet against existing CVEs in the National Vulnerability Database (NVD). If a match is found between a CVE and an installed app, Vulnerability Response will flag that match and perform the selected Remediation Action against the app to mitigate the vulnerability, if a matching bundle ID is found in the Auto App catalog. Once you've configured the Vulnerability Response Library Item, it monitors devices for known vulnerabilities. On each Iru Agent check-in, it compares installed applications against the CVE database by bundle ID in the Auto App catalog. When a match is found, it applies your Remediation Action for the highest applicable severity. Vulnerabilities in apps not supported as Auto Apps must be updated directly by the app developer. Requests for additional Auto App support can be submitted through the Iru Endpoint Web App using the [Feature Requests](/en/endpoint/settings/submit-feature-requests-and-ideas) button. ### Remediating Vulnerabilities #### Available Remediation Actions Vulnerability Response supports several remediation actions you can choose from when deciding how to handle security vulnerabilities in Auto Apps: **Enforce update upon detection**\ When a vulnerability is found, Iru Endpoint immediately updates the affected app to the latest version. **Enforce update on a timeframe**\ When you choose a timeframe, Iru Endpoint will update the app based on the selected enforcement timeframe. **No Action**\ If a vulnerability at this severity level is found, Iru Endpoint won't take any action. The Iru Agent respects the user's local time zone for update enforcement. #### Viewing Remediated CVEs When all affected software and devices associated with a CVE are patched, the CVE is assigned a **Remediated** status. Navigate to the Vulnerability Management tab. Use the **Status** filter and select **Remediated**. The Remediated status includes any CVE where all detections related to that CVE are no longer present on any monitored device. Use the **Remediation Status** data card to view the overall percentage of CVEs that have been fully remediated in your environment. ### CVE Detail View Selecting a specific CVE opens its detail view, where you can monitor progress and review device status related to that vulnerability. On the **Overview** tab, the **Impacted devices** section shows the percentage of devices remediated, along with remediated and active device counts for the selected CVE. Use the **Timeline** tab to track the history of the CVE, including when it was published, modified, and detected in your environment. ### Setting Up the Vulnerability Response Library Item To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the [Library Overview](/en/endpoint/library/library-items-profiles/library-overview) article. Give the Vulnerability Response Library Item a **name**. Select the **Blueprint**(s) you want to assign this Library Item to. Select the **Remediation action** for each CVE severity level. Click **Add application** to exclude an application from the auto-remediation rules. You can select apps you wish not to be auto-remediated from the library. If a vulnerability is detected on an application you have excluded, Vulnerability Response will take no action. Click **Save**. ### User Experience with Vulnerability Response Updates are delivered silently to the end user, following the same workflow as Auto Apps. When an enforcement deadline is reached and the affected app is open, users will see a prompt with a 5-minute countdown to close the application and save work. If the app isn't closed, it will be forcibly closed and updated. After updating, the app will reopen. ### Considerations **App Support Requirements** * Only app-based vulnerabilities are remediated, and only when Iru Endpoint provides a supported Auto App for the application * Vulnerability Response can update supported apps even if you aren't also using the Auto App Library Item for that app **Deployment and Configuration** * Deployment occurs via the Iru Agent, which is pre-installed on all enrolled Mac computers * No additional installation or configuration is needed; simply assign the Vulnerability Response Library Item to your Blueprints **App Blocking vs. Updates** * Vulnerability Response updates vulnerable apps; it doesn't block them at launch * The [App Blocking Library Item](/en/endpoint/library/library-items-profiles/configure-the-app-blocking-library-item) can be used to block apps if required **Policy Interactions** * If both an Auto App and a Vulnerability Response Library Item are targeting the same application, Vulnerability Response will update the app if the vulnerability is detected before the Auto App enforcement deadline * If a Mac is assigned both Vulnerability Response and Auto App Library Items with different enforcement deadlines for the same app, the earliest enforcement deadline will apply * Vulnerability Response takes priority over [phased rollout](/en/endpoint/library/auto-apps/understanding-auto-app-settings-for-macos#phased-rollout) when an update must be enforced sooner * Multiple Vulnerability Response Library Items can be configured within a Blueprint for different groups, but only one may be assigned per device * If a device qualifies for more than one, the last (furthest right in the Assignment Map) is applied **Status Changes** * If a CVE previously marked as "Risk Accepted" is patched, its status will change to "Remediated" * If the vulnerability is detected again and the policy isn't updated, its status will revert to "Risk Accepted" Please see our [Vulnerability Management Overview](/en/endpoint/vulnerability-management/vulnerability-management-overview) article for more information about vulnerabilities. # Excluding Devices from Vulnerability Management Source: https://docs.iru.com/en/endpoint/vulnerability-management/excluding-devices-from-vulnerability-management Exclude devices from vulnerability reporting in Iru Endpoint. Manage CVE exclusions individually or in bulk from a device record, Devices page, or CVE tab. This guide applies to Mac computers and Windows devices ### About Excluding Devices Some devices in your fleet may not need to be included in vulnerability reporting, such as dedicated test devices, devices assigned to employees on extended leave, or devices undergoing decommissioning. Excluded devices no longer contribute to affected-device counts, detection counts, the CVE **Devices** view, or vulnerability notifications. Please see our [Vulnerability Management Overview](/en/endpoint/vulnerability-management/vulnerability-management-overview) article for more information about vulnerabilities. ### How It Works Device exclusion lets you remove specific devices from fleet-wide vulnerability counts, views, and notifications. When you exclude a device, it no longer appears in CVE affected device totals or the **Devices** tab across Vulnerability Management, and vulnerability notifications for that device are suppressed. Detections remain visible on the device record, so you keep full visibility at the device level without those results affecting top-line reporting. If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, automated patching continues according to the configured remediation rules. You can exclude a device from its device record or from the **Devices** tab in any CVE detail view. From the **Devices** page or a CVE **Devices** tab, you can also exclude or remove exclusions for multiple devices at once. You can remove an exclusion at any time to resume monitoring. If a device is deleted from Iru Endpoint, its exclusion is removed automatically. ### Excluding a Device You can exclude a device from the device record in Iru Endpoint or from the **Devices** tab in a CVE detail view. Navigate to **Devices** in the Iru Endpoint web app and select the device you want to exclude. Click the **Device Action Menu** at the top right of the device record. Click **Exclude device vulnerabilities**. Device Action Menu on a device record with Exclude device vulnerabilities option highlighted Choose an **Enforcement timeframe**: * **Indefinitely** to exclude the device until you remove the exclusion * **Ignore until a specific date** to exclude the device until the date you select Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. Click **Save**. Exclude device vulnerabilities dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields Go to the **Vulnerability Management** section in the Iru Endpoint web app. From the **Vulnerabilities** list, select the CVE that includes the device you want to exclude. Select the **Devices** tab. Click the **ellipsis** (**…**) next to the device you want to exclude. Click **Exclude device vulnerabilities**. CVE Devices tab showing the ellipsis menu with Exclude device vulnerabilities for a device in the list Choose an **Enforcement timeframe**: * **Indefinitely** to exclude the device until you remove the exclusion * **Ignore until a specific date** to exclude the device until the date you select Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. Click **Save**. Exclude device vulnerabilities dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields ### Excluding Multiple Devices You can exclude multiple devices at once from the **Devices** page or from the **Devices** tab in a CVE detail view. Navigate to **Devices** in the Iru Endpoint web app. Select the checkboxes next to the devices you want to exclude. Click the **ellipsis** (**…**) in the bulk action bar at the bottom of the list. Click **Exclude device vulnerabilities**. Devices page with multiple devices selected and Exclude device vulnerabilities in the bulk action menu Choose an **Enforcement timeframe**: * **Indefinitely** to exclude the devices until you remove the exclusions * **Ignore until a specific date** to exclude the devices until the date you select Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. These details apply to all selected devices. Click **Save**. Go to the **Vulnerability Management** section in the Iru Endpoint web app. From the **Vulnerabilities** list, select the CVE that includes the devices you want to exclude. Select the **Devices** tab. Select the checkboxes next to the devices you want to exclude. Click **Exclude device vulnerabilities** in the bulk action bar at the bottom of the list. CVE Devices tab with multiple devices selected and Exclude device vulnerabilities in the bulk action bar Choose an **Enforcement timeframe**: * **Indefinitely** to exclude the devices until you remove the exclusions * **Ignore until a specific date** to exclude the devices until the date you select Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. These details apply to all selected devices. Click **Save**. ### Modifying or Removing a Device Exclusion You can modify or remove an exclusion from the device record or from the **Devices** tab in a CVE detail view. Navigate to **Devices** in the Iru Endpoint web app and select the excluded device. In the banner near the top of the device record, click **Modify**. Update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**. The dialog matches the one used when you first exclude a device. Device record banner showing Modify and Remove exclusion options for an excluded device In the banner near the top of the device record, click **Remove exclusion**. In the confirmation dialog, click **Remove exclusion** again. Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion Go to the **Vulnerability Management** section in the Iru Endpoint web app. From the **Vulnerabilities** list, select the CVE for the excluded device you want to manage. Select the **Devices** tab. Click the **Filters** button at the top right of the device list. Toggle **Show excluded devices**. Excluded devices appear in the list with an **Excluded** badge. CVE Devices tab filter options with Show excluded devices toggle enabled and excluded devices listed Click the **ellipsis** (**…**) next to the excluded device you want to modify. Click **Modify exclusion**. Update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**. Ellipsis menu showing Modify exclusion for an excluded device in the CVE Devices tab Click the **ellipsis** (**…**) next to the excluded device you want to remove. Click **Remove exclusion**. Ellipsis menu showing Remove exclusion for an excluded device in the CVE Devices tab In the confirmation dialog, click **Remove exclusion** again. Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion After you remove an exclusion, the device is included again in vulnerability scanning at the next scan cycle. ### Removing Multiple Device Exclusions You can remove exclusions from multiple devices at once from the **Devices** page or from the **Devices** tab in a CVE detail view. Navigate to **Devices** in the Iru Endpoint web app. Select the checkboxes next to the excluded devices whose exclusions you want to remove. Click the **ellipsis** (**…**) in the bulk action bar at the bottom of the list. Click **Remove exclusion**. Devices page with multiple excluded devices selected and Remove exclusion in the bulk action menu In the confirmation dialog, click **Remove exclusion** again. Go to the **Vulnerability Management** section in the Iru Endpoint web app. From the **Vulnerabilities** list, select the CVE for the excluded devices you want to manage. Select the **Devices** tab. Click the **Filters** button at the top right of the device list. Toggle **Show excluded devices**. Excluded devices appear in the list with an **Excluded** badge. CVE Devices tab filter options with Show excluded devices toggle enabled and excluded devices listed Select the checkboxes next to the excluded devices whose exclusions you want to remove. Click **Remove exclusion** in the bulk action bar at the bottom of the list. CVE Devices tab with multiple excluded devices selected and Remove exclusion in the bulk action bar In the confirmation dialog, click **Remove exclusion** again. After you remove exclusions, the devices are included again in vulnerability scanning at the next scan cycle. ### Considerations Excluding a device removes it from all CVE affected device counts across every vulnerability in Vulnerability Management. Exclusion is not scoped to a single CVE. Vulnerability detections remain visible on the device record. Exclusion affects top-level Vulnerability Management counts, views, and notifications only. To suppress a specific CVE without excluding the device entirely, use [Accepting CVE Risks](/en/endpoint/vulnerability-management/accepting-cve-risks) instead. If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, it continues to patch the device according to the configured remediation rules. Exclusion does not prevent automated remediation. If a device is deleted from Iru Endpoint, its exclusion is removed automatically. If the same device re-enrolls, it is monitored by default. Re-apply the exclusion manually if needed. An excluded device does not count toward the affected-device total for any CVE. Excluding a device does not change the **Remediated** status of a CVE by itself. Remediation status is based on active (non-excluded) devices only. If excluding a device means all remaining affected devices for a CVE are remediated, the CVE status updates to **Remediated**. Excluded devices are not hidden from the **Devices** section of Iru Endpoint. They are hidden from Vulnerability Management views and counts only. Exclusions are auditable. Each exclusion records who applied it, when, and any comment provided. Vulnerability notifications for excluded devices are suppressed while the exclusion is active. Removing an exclusion resumes notifications at the next scan cycle. ### Related Articles Detect CVEs across your fleet, prioritize by severity, and track remediation progress Accept CVE risks when patching is not feasible, set expiration dates, and track exceptions Automate remediation for vulnerable Auto Apps on macOS based on CVE severity # Vulnerability Management Overview Source: https://docs.iru.com/en/endpoint/vulnerability-management/vulnerability-management-overview Overview of vulnerability management in Iru Endpoint. Detect CVEs across your device fleet, prioritize by severity, and track remediation progress. This guide applies to Mac computers and Windows devices ### About Vulnerability Management Iru Endpoint's Vulnerability Management feature scans your entire fleet for known Common Vulnerabilities and Exposures (CVEs) based on data from the [National Vulnerability Database (NVD)](https://nvd.nist.gov/vuln), providing a clear, organized way to monitor and respond to vulnerabilities across your fleet. From the **Vulnerabilities** page, you can prioritize threats by severity, track remediation progress, and open a CVE detail view for devices, vulnerable software, and timeline history. ### How It Works Vulnerability Management continuously scans your Mac fleet for known security vulnerabilities by comparing installed applications against the National Vulnerability Database. The system provides multiple views to help you understand and prioritize threats, track remediation progress, and manage risk acceptance across your environment. Once you've enabled Vulnerability Management, it automatically begins scanning your devices every 15 minutes for application inventory updates. The system then matches these applications against the CVE database hourly to identify any known vulnerabilities. Our Security Research team proactively enriches CVE records missing pertinent data for accurate and timely matches. You can review results on the **Vulnerabilities** page, then open a CVE for Overview, Devices, Vulnerable software, and Timeline details. ### Vulnerability Management Capabilities #### Viewing CVEs Vulnerability Management identifies any known Common Vulnerabilities and Exposures (**CVEs**) within your fleet, leveraging information from the National Vulnerability Database (NVD). From the **Vulnerabilities** page in the Iru Endpoint Web App, you can view all relevant CVEs for specific applications. #### Automated Remediation (macOS) For macOS, the [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) lets you enforce updates for known vulnerable applications using Iru Auto Apps based on CVE severity, triggering automatic remediation on devices without manual intervention. #### Risk Acceptance Not every CVE poses the same level of threat. Some may be critical and require immediate attention, while others might be less urgent or not relevant to your environment. Please see our [Accepting CVE Risks](/en/endpoint/vulnerability-management/accepting-cve-risks) article for more information about how to accept CVE risks. #### Device Exclusion You can exclude specific devices from vulnerability reporting and notifications when they shouldn't affect fleet-wide counts (for example, test devices or devices undergoing decommissioning). Please see our [Excluding Devices from Vulnerability Management](/en/endpoint/vulnerability-management/excluding-devices-from-vulnerability-management) article for more information. **Key capabilities include:** * **Real-time scanning** of your entire Mac fleet for known vulnerabilities * **Multiple view options** to analyze threats from different perspectives * **Severity-based prioritization** using Common Vulnerability Scoring System (CVSS) and Known Exploited Vulnerabilities (KEV) scoring systems * **Remediation tracking** to monitor your progress in addressing vulnerabilities * **Automatic remediation** (macOS only) of known vulnerable applications based on CVE severity using Auto Apps updates * **Risk acceptance** for vulnerabilities that don't require immediate action * **Device exclusion** to remove specific devices from vulnerability counts, views, and notifications ### Vulnerabilities View The **Vulnerabilities** page provides a complete list of detected CVEs across your fleet, along with summary cards for: * **Vulnerabilities by severity** - Counts for Critical, High, Medium, and Low * **Remediation status** - Percentage remediated, plus counts for Remediated, Active, and Risk accepted * **Top software with vulnerabilities** - Software with the highest vulnerability counts You can search by **CVE ID** or **software**, and filter the list by: * **First Detected** * **Severity** * **Status** - Such as Active, Remediated, or Risk accepted * **Device** * **OS** * **Application** * **Packages** Use **Clear all** to reset filters. Table tools include **Edit columns**, **Expand table**, and **Export CSV**. The vulnerabilities table includes columns for **Vulnerability ID**, **Vulnerable software**, **Severity**, **CVSS** score, **Known exploit**, **First detected**, **Devices**, and **Status**. From the row **ellipsis** (**…**) menu, you can **Accept risk** or **Search NVD**. ### Remediation Filtering When all vulnerable software and devices impacted by a CVE are patched, the CVE will have a Remediated status. Use the **Status** filter and select **Remediated**. The list will be filtered to display only CVEs for which the CVE was fully remediated. ### CVE Information When you select a CVE, a detailed drawer opens with tabs for **Overview**, **Devices**, **Vulnerable software**, and **Timeline**. From the drawer header, you can **Search NVD**, **Change status**, or open **Actions**. **Overview Tab** The **Overview** tab provides an in-depth look at: * **Description** - Detailed explanation of the security issue * **Status** - Current CVE status, such as Active * **Severity** - Threat rating for the vulnerability * **CVSS score** - Numeric severity score * **Known exploit** - Whether the vulnerability has been exploited in the wild * **EPSS score** - Probability of being exploited in the next 30 days * **Age** - How long the CVE has been present in your environment * **Key dates** - Published on, Modified on, First detected, and Last detected * **Impacted devices** - Remediation progress, including remediated and active device counts * **Recommendations** - Guidance for addressing the vulnerability **Devices Tab** Use the **Devices** tab to view devices affected by the vulnerability. You can search and filter the list by **Detection date**, **Blueprint**, and **Device**. For each device, you can see: * **Device name** * **Serial number** * **Blueprint** * **OS version** * **Vulnerable software** - Link to view the vulnerable application and version installed on the device * **Excluded** badge - Shown when the device is excluded from Vulnerability Management From the **Devices** tab, you can exclude devices individually or in bulk, or remove exclusions. See [Excluding Devices from Vulnerability Management](/en/endpoint/vulnerability-management/excluding-devices-from-vulnerability-management). **Vulnerable Software Tab** The **Vulnerable software** tab lists the application, OS, and platform versions affected by the CVE. You can search and filter by **Detection date**, **Blueprint**, and **Device**. For each software item, you can see: * **Software name** and **version** * **Type** - Such as Application * **Affected device count** * **Platform** - Such as Windows or macOS * **View more details** - Expandable details for the software item **Timeline Tab** The **Timeline** tab shows a chronological history of events for the CVE, including when it was published, modified, and detected in your environment. Detection events link to affected devices. Published and modified events include a **View in NVD** option. ### CVSS Score The Common Vulnerability Scoring System (CVSS) is a method for calculating a qualitative measure of severity. Iru Endpoint Vulnerability Management uses the CVSS score to prioritize vulnerabilities and measure the severity of each vulnerability. The National Institute of Standards and Technology (NIST) maintains the [National Vulnerability Database (NVD)](https://nvd.nist.gov/vuln-metrics/cvss), which provides CVSS enrichment for all published CVE records. ### KEV Score The Cybersecurity Infrastructure Security Agency (CISA) maintains the authoritative source of vulnerabilities that have been exploited in the wild. Iru Endpoint Vulnerability Management uses the [Known Exploited Vulnerabilities (KEV) catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) to prioritize vulnerabilities. #### Report Inaccuracy If there are any issues with a detected CVE, click the **Report Inaccuracy** button. Select an issue from the drop-down menu. Optionally, enter a **description** of the issue. Click the **Report** button to complete the report. ### Application and OS Coverage Vulnerability Management scans the following directories for macOS Applications and all supported macOS versions (.app files only): * `/Applications` * `/Library` * `/Users` In addition, Vulnerability Management scans the entire disk for vulnerable Homebrew packages. Vulnerability Management scans the following across the system and user registry, Windows applications, and Windows 11 (24H2 or 25H2) operating systems: * `HKEY_LOCAL_MACHINE` * `HKEY_USERS` ### Update Frequency | Component | Frequency | | ------------------------------------- | ---------------- | | **Device App Inventory and Packages** | Every 15 minutes | | **App Vulnerability Matching** | Hourly | | **Vulnerability CVE Database** | Hourly | ### Considerations Iru Endpoint uses third-party vulnerability feeds and first-party research to identify CVEs across your fleet. First-party research fills gaps in public databases and enriches CVE data used for matching. **Third-party sources:** * CVE data from MITRE and the [National Vulnerability Database (NVD)](https://nvd.nist.gov/vuln) * Vendor security advisories from Apple, Microsoft, and other vendors * The [CISA Known Exploited Vulnerabilities (KEV) catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog), which identifies vulnerabilities exploited in the wild * Google Threat Intelligence for additional prioritization signals **First-party research:** * Iru's Security Research team discovers vulnerabilities, coordinates disclosure with vendors, and enriches CVE records that lack the data needed for accurate matching * The team also investigates malware and other threats that may not yet appear in public vulnerability databases * **macOS** * **Applications:** Scans the specified directories for `.app` files. Third-party applications installed outside those directories won't be detected. * **Homebrew packages:** Scans the entire disk for vulnerable Homebrew packages. * **Windows** * **Registry and applications:** Vulnerability Management scans the system and user registry and Windows applications. For supported versions and locations, see [Application and OS Coverage](#application-and-os-coverage). * System frameworks and libraries are not included in vulnerability scanning. * New vulnerabilities may not appear immediately after database updates * Allow up to an hour for new CVEs to be reflected in your fleet scan results * Device App Inventory and Packages updates every 15 minutes, but vulnerability matching occurs hourly * CVEs are marked as "Remediated" only when all affected software and active (non-excluded) devices are patched * Partial remediation won't change the overall CVE status * Excluded devices do not count toward affected-device totals * Use the **Devices** tab in a CVE detail view to track individual device remediation progress # Activity log Source: https://docs.iru.com/en/identity/administration/activity-log Review and filter a tenant-wide record of administrator actions, sign-in outcomes, and lifecycle changes in the Iru Identity activity log. The **activity log** is a running record of significant events in your tenant. Find it under **Activity** in the Iru dashboard. Use it to answer questions like *who changed this setting*, *did that sign-in succeed*, and *when did this user's access change*, without leaving the dashboard. The activity log is a read-only history. Events are recorded as they happen; you cannot edit or delete them. This makes the log a dependable source for reviews and investigations. ## What gets recorded Each entry captures a single event and the context around it. The log brings together several kinds of events in one place: Changes administrators make in the Iru dashboard: creating and editing users, groups, applications, policies, roles, and settings. The results of sign-in decisions, so you can see whether access was granted or denied and follow a user's recent activity. Events as users and access move through their lifecycle (for example a user becoming active or suspended, or access being granted and removed. ## Reading the log The activity list shows one row per event, sorted with the most recent first. Each row summarizes the event across these columns: | Column | What it tells you | | ---------------- | ----------------------------------------------------------------------------- | | **Occurred at** | When the event happened. | | **Instigator** | Who or what initiated the event. | | **Subject type** | The kind of object the event acted on, such as a user, group, or application. | | **Subject name** | The specific object the event acted on. | | **Action** | What was done. | | **Status** | The outcome of the event. | Select any row to expand it. The expanded view shows the event's details, including a **field-by-field list of what changed**, each affected field with its previous value and its new value, so you can see exactly what an action modified. Sort the list by any column header. Sorting by **Instigator** or **Subject name** is a quick way to group everything one administrator did, or everything that happened to a single user or app. ## Filtering to what matters The activity log can grow quickly, so Iru gives you a filter bar above the list. Build a filter on one or more fields to narrow the view: * **Occurred at:** restrict to a time window. * **Instigator:** focus on a specific administrator. * **Subject type** and **subject name:** focus on a kind of object, or one object in particular. * **Action:** focus on a kind of change. * **Status:** separate successful events from failures. Combine conditions to answer a precise question; for example, all events where the **subject type** is a user and the **status** indicates a failure, within the last week. ## Save reusable views When you find a filter you return to often, save it as a reusable **view** so you can reopen it with one click instead of rebuilding the conditions each time. Add the conditions you want in the filter bar until the list shows the events you care about. Save the current filter as a named view. It joins your list of saved views for the activity log. Drag your saved views into the order that suits your workflow, so the ones you use most sit first. Saved views are available across Iru wherever you filter lists. For example, you can save views for your applications list in the same way. A view stores a filter you defined; it does not change which events are recorded. ## Using the log for audit Because every significant event is captured with its instigator, subject, action, outcome, and the exact fields that changed, the activity log doubles as an audit trail. A few practices make it more useful: Save a view for high-signal events (failed sign-ins, role changes, or changes to authentication policies) and review it on a schedule so nothing unusual goes unnoticed. Filter by **subject name** to pull the full history of one user, group, or application, then expand individual events to see precisely what changed and who changed it. Filter by **instigator** and **status** to follow a user's recent sign-in outcomes when you are troubleshooting access or responding to a report. For how Iru protects your data and the controls behind your tenant, see [Security and privacy](/en/identity/security/security-and-privacy). ## Related Control who can administer Iru Identity and what each administrator can do. See the policies that produce the sign-in outcomes recorded here. # Administrators & roles Source: https://docs.iru.com/en/identity/administration/administrators-and-roles Control who can administer Iru Identity, assign built-in or custom admin roles, and scope each administrator's permissions to what their job needs. **Administrators** are the team members who can sign in to the Iru dashboard and manage Iru Identity: your directory, applications, policies, and settings. What each administrator can do is governed by the **role** assigned to them. You manage both under **Access** in the Iru dashboard, on the **Administrators** and **Roles** tabs. This is about the Iru dashboard, not the end-user app launcher. End users in your [directory](/en/identity/directory/directory-overview) sign in to reach their assigned apps but do not administer Iru. An administrator is a directory user who has also been granted an administrative role. ## How access is structured Permissions are not assigned one at a time. Instead, a **role** is a named bundle of permissions, and you grant someone access by assigning them a role. Manage roles once, and every administrator who holds a role inherits its permissions. ```mermaid theme={null} flowchart LR admin["Administrator
(a directory user)"] -->|"is assigned"| role["Role"] role -->|"grants"| perms["Permissions"] perms -->|"allow actions in"| console["The Iru dashboard"] ``` ## Administrators The **Administrators** tab lists everyone who can administer Iru Identity, with their name, username, email, status, and assigned role. Add an administrator to grant them access to the Iru dashboard, and open any administrator to review or change their role. One user is designated the tenant's **account owner**, its primary owner. An administrator sets the account owner from a user's record. On the **Administrators** tab, choose to add an administrator and enter their details, including the email and user principal name they sign in with. Choose the role that matches what they need to do. The role determines their permissions across the Iru dashboard. Revisit assignments as responsibilities change, and remove access promptly when someone no longer needs it. An administrator's **status** follows the same lifecycle as any directory user (pending, active, or suspended). Suspending a user blocks their access, including their ability to administer Iru, without deleting their record. See [Users](/en/identity/directory/users). ## Roles The **Roles** tab lists every role in your tenant. Each role has a **display name**, a short **slug** that identifies it, an indication of whether it is a **default** or **custom** role, and the **permissions** it grants. ### Default roles Iru Identity ships with a set of built-in **default roles** that cover common administrative needs. They are marked **Default** in the roles list, and their permissions are managed by Iru. | Role | Intended for | | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | | **Admin** | Full administration of Iru Identity. Reserve this for the small number of people who need to manage everything. | | **Standard** | Day-to-day administration: managing users, their authenticators and devices, and sending invitations, without the most sensitive controls. | | **Help Desk** | Front-line support, such as viewing devices and sending invitations, without broad configuration access. | | **Auditor** | Read-only visibility for review and oversight, without the ability to make changes. | | **Secrets Auditor** | Read-only oversight that extends to sensitive secret material, separated from general auditing. | Default roles cannot have their permissions edited; they are maintained by Iru so their behavior stays consistent. Assign a default role when it fits the job, and define a custom role when you need a different combination of permissions. ### Custom roles Custom roles are coming soon. Today you assign the built-in default roles above; creating your own roles with a tailored set of permissions is on the way. A **custom role** will let you grant exactly the permissions a job needs and nothing more, with each role's permissions grouped by area and described individually. Until then, pick the default role that best fits each administrator and follow the least-privilege guidance below. ### How permissions are expressed Each permission pairs a **resource** with an **action**, written as `resource.action`. For example, a permission on the user resource for the view action lets a role see users. A role's full capability is the set of permissions it carries. Some areas of identity data are governed by attribute-level permissions: a role that can view users can also see the underlying profile attributes for those users. Grant view access deliberately. See [Schema](/en/identity/directory/schema). ## Least-privilege guidance Roles exist so you can give each administrator only the access their work requires. A few practices keep administrative access tight: Assign the most limited role that lets someone do their job, and widen access only when a concrete need appears. It is easier to grant a missing permission than to notice an unused one. Full administration is powerful. Limit the number of people with the **Admin** role and prefer more focused roles (such as **Help Desk** or **Auditor**) for everyone else. When someone needs to review activity but not change it, an auditing role gives them visibility without the ability to make changes. Periodically check who holds which role and remove access that is no longer needed, especially the most privileged roles. The [activity log](/en/identity/administration/activity-log) records role and permission changes so you can see how access has shifted over time. Administrators reach sensitive controls, so make sure they are covered by strong [authentication policies](/en/identity/authentication/authentication-policies) and phishing-resistant [authenticators](/en/identity/authentication/authenticators). ## Related Review who did what in the Iru dashboard, including changes to roles and administrator access. Set the device-trust conditions enforced when users sign in to your apps. Manage the directory users that administrators are drawn from. How Iru isolates and protects your tenant and its data. # End-user experience Source: https://docs.iru.com/en/identity/administration/end-user-experience What end users see in Iru: an app dashboard that launches their apps, favorites for quick access, and a self-service account for passkeys and preferences. For users in your directory, everything you configure shows up in two places: an **app dashboard** that launches the applications assigned to them, and a **self-service account** where they manage their authenticators and preferences. Use this page when you're testing a setup or helping someone who is stuck. This is the **end-user** view, not the administrator dashboard. End users reach it after they sign in; administrators get a link to switch into the admin console. ## The app dashboard After signing in, each user lands on their app dashboard, an **app launcher** that shows the applications assigned to them as tiles. It opens with a welcome that notes their apps are provided by your organization, using the name you set in [organization settings](/en/identity/administration/organization-settings). The Iru app dashboard showing a Favorites section and a Your Applications grid of app tiles. Each application tile shows: | On the tile | What it shows | | ----------------- | ----------------------------------------------------------------------------- | | **Icon and name** | The application's logo and display name, so it is easy to recognize. | | **Description** | A short line describing the app. | | **Roles** | The role the user holds in that app, when one applies. | | **Last accessed** | When they last opened the app from here, or that they have never accessed it. | Selecting a tile signs the user straight in to that application; Iru completes the single sign-on, so there is no separate password to enter at the app. The set of tiles a user sees is exactly the applications they have been [assigned](/en/identity/applications/assigning-access) through a group. ```mermaid theme={null} flowchart LR signin["User signs in to Iru"] --> dash["App dashboard
tiles for assigned apps"] dash -->|"select a tile"| sso["Single sign-on"] sso --> app["The application, signed in"] ``` Because the launcher reflects access in real time, it is a fast way to verify a change: assign an app to a test user, sign in as them, and confirm the tile appears and opens the app. See the [Quickstart](/en/identity/getting-started/quickstart). ## Favorites Users can mark the apps they use most as **favorites** for quicker access. Hovering a tile reveals a star; selecting it adds or removes the app from their favorites. * Favorited apps appear in a **Favorites** section at the top of the app dashboard. * A user can switch between viewing just their favorites and viewing all their apps. * Favorites are personal to each user and do not affect anyone else or change who is assigned to an app. The exact surface differs by app: the **Iru Access desktop app** shows apps on a **Home** view with favorites surfaced at the top (alongside its other tabs), while the **mobile app** has a dedicated **Favorites** tab rather than a separate **Home** view. ## Finding an app quickly Alongside browsing tiles, users can **search** their apps by name from the app dashboard and open a match directly from the results. Recently opened apps are kept close at hand so they are one selection away the next time someone returns. ## Self-service account From the account menu, each user opens their **account settings**, organized into two areas. The **Profile** area shows a user's core identity details (name, username, email, and their Iru domain), drawn from their directory profile. Core identity fields are managed for them and shown read-only here. Users can set their own **preferences** (a **preferred name**, **language**, **time zone**, whether dates show in **relative** form, and whether they receive **email updates**) and upload a profile photo. The **Authenticators** area is where users manage the credentials they use to prove who they are, primarily **passkeys**. From here a user can: * See the authenticators registered to them, with when each was registered and last used. * Add a new authenticator. * **Suspend** an authenticator to block its use temporarily, or **delete** one they no longer use. The authenticator securing the current session is marked, and it cannot be suspended or deleted from that session; a safeguard against someone locking themselves out. **To register a passkey:** open the **Authenticators** area, choose **Add**, and follow the device's prompt to create a passkey with its biometric or screen lock. Registering more than one (for example, a laptop and a phone) means losing one device won't lock you out. For end-user steps, see [Manage authenticators](/en/identity/end-user/manage-authenticators). For signing in with a passkey in a browser, including a macOS troubleshooting tip, see [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). Adding a passkey requires an existing authenticator to confirm the request. A user with no authenticator yet cannot bootstrap one from self-service alone; send them a registration link to enroll their first authenticator. See [Installing Iru Access](/en/identity/end-user/installing-iru-access) for the end-user enrollment flow. Encourage users to register more than one so losing a single device does not lock them out. ## How it ties together What an end user sees and can do depends on how you've configured Iru: * **The directory** determines who they are. See [Users](/en/identity/directory/users). * **Assignments** determine which tiles appear. See [Assigning access](/en/identity/applications/assigning-access). * **Authentication policies** determine what they must prove to sign in and to open each app. See [Authentication policies](/en/identity/authentication/authentication-policies). * **Organization settings** determine the branding they see throughout. See [Organization settings](/en/identity/administration/organization-settings). ## Related The passkeys users manage in their self-service account. What users see and do as they authenticate to reach this app dashboard. Decide which applications appear as tiles for which users. Set the branding and name your people see across their app dashboard. End-user guide for passkeys, Iru Access, and backup devices What end users see when they sign in and open apps First-time enrollment from an invitation # Application mapping Source: https://docs.iru.com/en/identity/applications/application-mapping Shape the identity statement an application receives (the SAML assertion or OIDC token) by mapping profile attributes into it with IQL. When someone signs in to an application through Iru, the app receives a signed **identity statement** (a **SAML assertion** or an **OIDC ID token**) that says who they are. **Application mapping** is how you decide what goes into that statement: for each field the app expects, you map a value drawn from the user's [profile](/en/identity/directory/schema). Every mapped value is written in **[IQL](/en/identity/getting-started/iql-expressions)** (Iru Query Language), the same expression language used for [Directory Sync attribute mapping](/en/identity/directory/attribute-mapping) and [Auto Group](/en/identity/directory/auto-groups) rules. A value can be a single profile field (`user.email`) or an expression that reshapes one (`user.email.lowerAscii()`). The application Mapping editor for a SAML app: the Subject mapped from the IQL expression user.id with name format Unspecified, and an Email attribute mapped from user.primaryEmail.email with name format Basic. ## What a mapping contains Every application maps two things into the statement it sends: * **The subject:** the primary identifier for the signed-in user. * **Attributes or claims:** any additional fields the app expects. ```mermaid theme={null} flowchart LR profile["User profile
attributes"] --> expr["IQL expression"] expr --> subject["Subject"] expr --> attrs["Attributes / claims"] subject --> stmt["Signed assertion / token"] attrs --> stmt stmt --> app["Your application"] ``` ### The subject The subject identifies the signed-in user. Its default depends on the protocol: | Protocol | Subject | Default value | | -------- | ------------------- | --------------- | | **SAML** | The **NameID** | `user.username` | | **OIDC** | The **`sub`** claim | `user.id` | You can change the value it draws from, and for SAML choose a **NameID format**. See [SAML applications](/en/identity/applications/saml-applications) and [OIDC applications](/en/identity/applications/oidc-applications) for the protocol-specific options. ### Attributes and claims Beyond the subject, add each field the app needs. For every one you set its **name** (what the app expects), its **value** (the IQL expression that produces it), a protocol detail (an **attribute name format** for SAML, or a **scope** for OIDC), and whether it is **enabled**. ## How you build a mapping Mapping lives in the application's **draft**, alongside its protocol settings. For the subject and each attribute or claim, write an [IQL](/en/identity/getting-started/iql-expressions) expression. The editor suggests the available `user` fields and functions as you type and checks the expression, so mistakes surface before you publish. A live **preview** renders the exact assertion or token Iru will send, so you can confirm its shape before going live. Set the draft as **current** to make the mapping live. See [Applications overview](/en/identity/applications/applications-overview) for the version model. Map only what the app needs. Each app receives exactly the attributes you map into it, so a given service sees only the profile details required to identify the user. ## Mapping for provisioning Mapping shapes more than sign-on. For apps with [provisioning](/en/identity/applications/provisioning), the mapping also has a **provisioning view** that controls which profile attributes Iru sends when it creates or updates the account in the app. ## Where to go next The full IQL reference: fields, operators, functions, and examples. NameID formats and attribute mapping for SAML apps. Subject and claim mapping for OIDC apps. Map the attributes Iru sends when it creates and updates accounts in an app. # Application templates Source: https://docs.iru.com/en/identity/applications/application-templates Add applications to Iru Identity from a catalog of ready-made templates, then customize SAML or OIDC settings by ejecting from the template. An **application template** is a ready-made definition for a known service. Creating an app from a template fills in the standard configuration (protocol settings and attribute mapping) so you only supply what is specific to your tenant, such as the web addresses for your instance of the app. Templates live in the **App Templates** catalog. Each template has an icon and one or more **versions**, and is identified by a short slug. Templates are the fastest way to add an app. Reach for the catalog first, and only build a [custom SAML](/en/identity/applications/saml-applications) or [OIDC](/en/identity/applications/oidc-applications) app when no template fits. ## Create an application from a template In **Apps**, choose to add an application and search for your service by name. Recommended templates appear as you type; you can also browse the full template library. Select the template, then choose the **version** you want. Different versions cover different configurations of the same service. Set the **display name** that will appear in your dashboard, and provide any values the template asks for; these vary by template, and are typically the web addresses or identifiers unique to your instance of the service. Iru creates the application from the template and opens it. The protocol settings and attribute mapping are already in place. Assign the groups that should have the app, then activate it. See [Assigning access](/en/identity/applications/assigning-access). ## Working with a template-based app An app created from a template stays linked to it. On the app's page, the header shows which **template** and **template version** it came from. You can change the selected version or update the tenant-specific values, and Iru keeps the standard configuration aligned with the template. Because the standard configuration is managed by the template, the protocol settings on a template-based app are not freely editable. To take full control, eject the app from its template. ## Eject from a template **Ejecting** detaches an app from its template so you can edit every setting directly, exactly like a custom app. Use it when you need to diverge from what the template provides. On the application's page, open the actions menu in the header. Confirm the action. The app keeps its current configuration but is no longer linked to the template. All protocol settings and attribute mappings are now editable. Edit them in a draft and set it as current, the same as any other app. Ejecting is one-way. Once an app is detached, it no longer receives template updates and cannot be re-linked. Eject only when you genuinely need to customize beyond the template. ## Where to go next How apps, protocols, and versioning work in Iru. Configure an ejected or custom SAML app in detail. Configure an ejected or custom OIDC app in detail. Grant the app to users and groups. # Applications overview Source: https://docs.iru.com/en/identity/applications/applications-overview Connect the services your users sign in to: how Iru acts as their identity provider over SAML or OIDC, and how you add and version an app. An **application** is a service your users sign in to through Iru. For each application, Iru is the **identity provider**: when someone opens the app, the app trusts Iru to run the sign-on and vouch for who they are. Iru sends the app a signed statement of identity using the single sign-on standard the app supports. You manage applications in two dashboard areas: * **Apps:** the apps you have added, including custom apps and apps created from a template. * **App Templates:** a catalog of ready-made app definitions you can start from. See [Application templates](/en/identity/applications/application-templates). The Applications list with a Zoom app of type SAML and status Active, plus columns for Created On, Last Updated, and a copyable Application ID. ## Choose a protocol: SAML or OIDC Every application uses one **protocol type**, chosen when you add it: **SAML** or **OIDC**. Pick whichever standard the app supports for single sign-on. Both let Iru sign users in; they differ in the details Iru exchanges with the app. Iru gives the app **service-provider-facing details** (an entity ID, an ACS URL, and downloadable metadata) and signs the response and assertion it sends. You choose the NameID format and map profile attributes into the assertion. Configure one in [SAML applications](/en/identity/applications/saml-applications). Iru issues the app a **client ID** and **client secret**, and sends an ID token after sign-on. You set redirect URIs, choose scopes, and map profile attributes into the token's claims. Configure one in [OIDC applications](/en/identity/applications/oidc-applications). | | SAML | OIDC | | ----------------------- | ------------------------------------------------------ | ------------------------------------------------------- | | Iru gives the app | Entity ID, ACS URL, metadata, signing certificate | Client ID, client secret, discovery and token endpoints | | Identity is sent as | A signed assertion | A signed ID token | | Identifier for the user | **NameID** (Subject) | **Subject** (`sub` claim) | | You configure | NameID format, attribute mapping, signing certificates | Redirect URIs, scopes, claim mapping, key rotation | A protocol is chosen per application and cannot be switched afterward. If you need the other protocol, add a new application. ## How an application maps identity Each application maps **user-profile attributes** into the identity Iru sends, so the app receives the fields it expects. Every app has a **subject**, the primary identifier for the signed-in user, plus any additional attributes you add. * For **OIDC**, the default subject is the `sub` claim, mapped from the user's `user.id`. * For **SAML**, the default Subject is mapped from the user's `user.username`. You can add, rename, enable, and disable attributes, and a live preview shows the assertion or token that will be produced. See [Application mapping](/en/identity/applications/application-mapping) for how mapping works and the IQL behind it, and each protocol's page for its specifics. ## How versioning works Applications are **versioned** so you can change configuration safely without disrupting users who are signing in. ```mermaid theme={null} flowchart LR draft["Draft
(editing)"] -->|"Set as current"| current["Current
(live sign-on)"] current -->|"a new version
is set current"| archived["Archived
(kept for reference)"] current -->|"Clone & edit"| draft2["New draft"] archived -.->|"can be restored"| current ``` You make changes in a **draft** version. Drafts are not live, so editing one never affects the version users are signing in with. Publishing a draft makes it the **current** version, the configuration Iru uses for live sign-on. There is one current version at a time. When a new version becomes current, the previous current version becomes **archived**. Archived versions are kept for reference and can be restored at any time from the version selector. To revise a published app, use **Clone & Edit** to copy the current version into a new draft, make your changes, then set the draft as current. ## Active and inactive Separately from versioning, an application is either **active** or **inactive**, toggled from the app's header. The current version is live. People who are assigned can sign in, and any configured provisioning runs. Sign-on is stopped without deleting the app or its configuration. People can no longer reach it, and further provisioning actions pause. Deactivating is reversible; reactivate the app at any time. An active application cannot be deleted. Deactivate it first if you intend to remove it. ## Add an application From **Apps**, choose to add an application and either start from a template or build a custom app. The Add application panel with a search box, recommended templates (WorkRamp, Shopify Plus, Jenkins, Asana) and a View all templates link, plus OIDC and SAML options to create an app from scratch. Search the catalog for your service and create the app from a template. The standard configuration is filled in, so you only supply what is specific to your tenant. See [Application templates](/en/identity/applications/application-templates). Enter a name and pick a protocol (**SAML** or **OIDC**) to build the app from scratch. Iru creates it as a draft for you to configure. Fill in the SAML or OIDC settings and the attribute mapping. See [SAML applications](/en/identity/applications/saml-applications) or [OIDC applications](/en/identity/applications/oidc-applications). Assign the groups that should have the app, then activate it. See [Assigning access](/en/identity/applications/assigning-access). ## Where to go next Start from a ready-made definition in the catalog. Configure a SAML app: provider details, NameID, and signing certificates. Configure an OIDC app: credentials, redirect URIs, scopes, and claims. Grant the app to users and groups, and review who has access. Create and remove accounts in the app automatically as access changes. Decide who can sign in to the app and what they must prove. # Assigning access Source: https://docs.iru.com/en/identity/applications/assigning-access Grant an application to groups in Iru Identity, review effective users, and learn why group-based assignment scales better than direct user assignment. Adding an application makes it available in your tenant, but no one can reach it until you **assign access**. You grant access by assigning **groups** to the app; access follows group membership, so there are no per-user app assignments to maintain. The fully-resolved set of users who end up with access is the app's **effective users**. ## Assign groups You grant access only by assigning **groups**. On the application's **Assignments** tab, choose **+ Assignment**: * **Group:** the group that should have the app. * **Roles:** the role or roles applied to that group. Everyone in the assigned group gets access. The **group** determines who can reach the app; the **roles** you select apply to that group and are asserted at sign-on. They do not grant access on their own. Membership stays in sync as users join or leave the group. You cannot assign individual users to an application, and you cannot grant access by role alone. Access always follows group membership. ```mermaid theme={null} flowchart LR u2["User"] --> g1["Group"] u3["User"] --> g1 g1 -->|"assigned"| app["Application"] app --> eff["Effective users
(everyone with access)"] ``` Combine an [authentication policy](/en/identity/authentication/authentication-policies) with assignment: assignment decides **who can reach** the app, and the policy decides **what they must prove** to sign in. ## Prefer group-based assignment Access is always granted through **groups**, so it follows your directory membership automatically; there are no per-user app assignments to track. When access is granted through a group, adding or removing a user from the group grants or revokes the app automatically, with no per-app edits. One group can be assigned to many apps. You manage access by editing the group, not by touching every application. An [Auto Group](/en/identity/directory/auto-groups) updates its own membership from an attribute rule, so access tracks users' profiles (department, role, location) with no manual steps. Reviewing one group's membership is easier than reconciling individual assignments across many apps. For how to build and manage groups, see [Groups](/en/identity/directory/groups) and [Auto Groups](/en/identity/directory/auto-groups). ## Review assignments and effective users On the **Assignments** tab, the table lists each **group** assigned to the app and the **role** or roles applied to that group. To confirm exactly who has access, open the **Effective Users** tab. It shows every user with access through an assigned group, with the date their access began. This resolved view is the source of truth for who can sign in, and (for apps with [provisioning](/en/identity/applications/provisioning), who gets an account created in the app. Removing someone's last path to access (removing them from every group assigned to the app, or unassigning those groups from the app) drops them from the effective set, and they can no longer sign in to the app. ## Roles within an application Some apps expect a **role** at sign-on (administrator, member, and so on), not just identity. When you choose **+ Assignment**, the **Roles** field applies a role to the group you selected. Define the available roles and how they are asserted on the application's **Roles** tab. See [Roles & Bundles](/en/identity/applications/roles-and-bundles). When the **role assertion method** is set to **None**, only the **Default** role can be assigned to groups on the **Assignments** tab. ## Favorites End users can mark the apps they use most as **favorites** from their app dashboard, which pins those apps for quick access. Favorites are a personal convenience and do not change who is assigned or what access anyone has. ## Where to go next Assert a role to the app and vary session length and risk by role. Create the groups you assign to applications. Drive group membership (and therefore access) from attribute rules. Turn assignment into real accounts in the app, created and removed as access changes. Decide what assigned users must prove to sign in. # OIDC applications Source: https://docs.iru.com/en/identity/applications/oidc-applications Configure an OIDC application in Iru Identity: client credentials and rotation, redirect URIs, scopes, claim mapping, signing keys, and session length. An **OIDC application** lets users sign in to a service that supports OpenID Connect, with Iru acting as the identity provider. Iru issues the service a **client ID** and **client secret**, sends an **ID token** after sign-on, and maps your users' profile attributes into that token's **claims**. Use these sections to configure a custom OIDC app or one you have [ejected from a template](/en/identity/applications/application-templates). You edit configuration in a **draft** and then set it as the current version; see [Applications overview](/en/identity/applications/applications-overview) for the version model. ## Step 1: Save the client credentials When you create an OIDC app, Iru generates a **client ID** and **client secret**. The secret is shown **only once**, so copy both into a secure place before closing the dialog. The client secret is not displayed again after creation. If you lose it, rotate the secret to generate a new one. The app's **Protocol details** also list the endpoints the service needs to talk to Iru: | Detail | What it is | | ---------------------- | ------------------------------------------------------------------------------------ | | **Client ID** | The app's public identifier. | | **Well-Known URL** | The OpenID discovery document; many services configure everything from this one URL. | | **Token Endpoint** | Where the service exchanges an authorization code for tokens. | | **User Info Endpoint** | Where the service reads profile claims for the signed-in user. | ## Step 2: Set redirect URIs In the app's **draft**, under the OIDC settings, add the URIs Iru is allowed to redirect to: Where Iru returns the user after a successful sign-on. Add every URL the service uses. Where Iru returns the user after sign-out. Redirect URIs must match exactly. There is an option to allow wildcards in redirect URIs; leave it off unless the service specifically requires it, since exact matching is safer. ## Step 3: Choose scopes **Scopes** control which categories of claims the service may request. Iru offers the standard OpenID Connect scopes: | Scope | Grants access to | | ------------------------------------- | ------------------------------------------------------------------------ | | **OpenID** (`openid`) | Required for OpenID Connect; always included. | | **Profile** (`profile`) | Basic profile claims. | | **Email** (`email`) | The user's email. | | **Address** (`address`) | The user's address. | | **Phone** (`phone`) | The user's phone number. | | **Offline access** (`offline_access`) | A refresh token, so the service can stay signed in without re-prompting. | `openid` is always present and cannot be removed. Enable only the additional scopes the service genuinely needs. ## Step 4: Map the subject and claims Open the application's **mapping**. The mapping has a **Subject** plus any additional **claims**. ### Subject The subject is the primary identifier for the signed-in user, sent as the `sub` claim. For an OIDC app, the default subject is mapped from the user's `user.id`. You can change the value it draws from and associate it with a scope. ### Claims Add any extra claims the service expects in the ID token. For each one you set: * A **Name:** the claim name. * A **value:** the profile attribute or expression it draws from. * A **scope:** the scope the claim belongs to. * Whether it is **enabled**. A live **preview** shows the token that will be produced, so you can confirm the claims before publishing. Some claim names are reserved by the OpenID Connect standard and cannot be used as custom claims: `iss`, `aud`, `exp`, `nbf`, `iat`, and `jti`. ## Step 5: Rotate the client secret The client secret can be rotated without re-creating the app, from the app's **Protocol details → Client secrets**. **Rotate** issues a new client secret while the previous one keeps working for **24 hours**, so you can update the service before the old secret stops. During that window the previous secret is listed with an **Expires Soon** badge; a newly issued secret is long-lived. **Invalidate** ends the current secret immediately, with no grace period. Use it if a secret may have been exposed, then update the service right away. Iru manages the signing keys it uses to sign ID tokens and publishes them at the discovery and keys endpoints, so services validate tokens automatically; there is nothing to rotate by hand. ## Step 6: Publish, assign, and activate Publish your draft so it becomes the live configuration. Assign the groups that should have the app. See [Assigning access](/en/identity/applications/assigning-access). Make the app active so assigned users can sign in. Sign in as a test user from the app dashboard to confirm the experience. ## Authentication flow An OIDC app signs users in with the **authorization code flow**: The app sends the user to Iru to sign in. Iru authenticates the user and evaluates the app's [authentication policy](/en/identity/authentication/authentication-policies). Iru redirects back to the app's **redirect URI** with a short-lived authorization **code**. The app exchanges the code at Iru's **token endpoint** for an **ID token** (who the user is) and an **access token**. The app can call the **user info endpoint** with the access token to read profile claims, and (if you enabled `offline_access`) use a **refresh token** to stay signed in. Most libraries configure this entire flow from the **Well-Known URL** in **Protocol details**. ## Where to go next Grant the app to users and groups. Create and remove accounts in the app automatically as access changes. Decide who can sign in and what they must prove. Review protocols and the draft-to-current version model. # Provisioning Source: https://docs.iru.com/en/identity/applications/provisioning Automatically create, update, and remove accounts in your apps with SCIM as access changes, plus group-linked provisioning, manual syncs, and history. **Provisioning** keeps the accounts inside your applications in step with your directory. For apps that support it, Iru uses **SCIM** to create and update an account when access is granted, and to remove it when access is revoked, so an app account exists exactly while a user is assigned. This is **outbound** provisioning, from Iru into your apps. (Bringing users *into* the directory from an HR system or a file is inbound provisioning; see [Directory Sync](/en/identity/directory/directory-sync).) ## How provisioning relates to assignment Provisioning acts on the app's **effective users and groups**, the users who have access through group assignment. Assignment decides *who*; provisioning turns that into real accounts. ```mermaid theme={null} flowchart LR assign["Assigned groups"] -->|"granted"| create["Create / update account"] assign -->|"revoked"| remove["Remove account"] create --> app["Account in your app"] remove --> app ``` See [Assigning access](/en/identity/applications/assigning-access) for how the effective set is built. ## Enable provisioning Provisioning is configured per application, in the app's **draft**. Once enabled, you point Iru at the app's SCIM endpoint and choose which events to send. Enable SCIM provisioning for the application. Provide the app's SCIM **base URL** and the **bearer token** Iru should authenticate with. Get both from the application you are provisioning into. If the app already has accounts, choose whether Iru matches users by **username** or **email**, so existing accounts are reused rather than duplicated. Enable the operations you want Iru to perform: **create users**, **update users**, and **delete users**. For removals, you choose separately what happens when someone is **unassigned** from the app versus **removed from the directory** (see below). The app's **mapping** includes a provisioning view, so you control which profile attributes Iru sends to the app when it creates or updates an account. Set the draft as current and keep the app active. Provisioning runs while the app is active and pauses when it is deactivated. Provisioning sends accounts only for users who are assigned. If no one is assigned yet, grant access first; see [Assigning access](/en/identity/applications/assigning-access). ## What happens when access is removed Removal has two triggers, and you choose what Iru does to the app account for each one **independently**: * **Unassigned from the app:** the user stays in your directory but is no longer in a group assigned to the app. * **Removed from the directory:** the user's directory record is deleted entirely. For each trigger, pick one of three actions: | Action | What Iru does to the app account | | -------------- | -------------------------------------------------------------------------------------------------------------------------- | | **Delete** | Asks the app to delete the account. | | **Deactivate** | Marks the account inactive in the app (its `active` flag set to `false`), leaving it in place so it can be restored later. | | **Do nothing** | Leaves the account exactly as it is in the app. | A common setup is **Deactivate** when someone is unassigned (so access can be restored quickly) and **Delete** when someone is removed from the directory. Use **Do nothing** for apps where you would rather clean up accounts by hand. Whether deactivating or deleting an account also ends that user's **active session** inside the app is up to how the app handles the signal Iru sends. See [Credentials and sessions](/en/identity/security/credentials-and-sessions). ## Group-linked provisioning In addition to accounts, Iru can **push groups** to apps that support SCIM groups, so group structure is mirrored in the app. You choose which groups to push: * **Application role groups:** the groups tied to the app's roles, or * **Selected groups:** a specific set of groups you pick. When the app already has its own groups, the application's **downstream groups** view lets you **link** an Iru group to an existing group in the app (called **adopting** it), instead of creating a duplicate. Each link shows its sync status so you can see which groups are in step. ## Run a sync manually Iru syncs automatically as access changes, but you can force a sync when you need a change reflected right away (for example after fixing a configuration issue. From the app's **effective users**, trigger a sync for a specific user to re-send their account state to the app. From the app's **effective groups**, trigger a sync for a specific group to re-send its membership to the app. ## Review provisioning history The application's **provisioning history** shows each sync run and its outcome, so you can confirm what Iru sent and troubleshoot anything that failed. Each run summarizes how many records **succeeded**, are **pending** or **waiting**, or **failed**, broken out by application, users, and groups. Recent runs refresh on their own while they are still in progress. When something does not go through, a **processing errors** view lists the affected user or group, the operation attempted, and the error returned by the app; the detail you need to fix the cause and re-sync. Deactivating an application stops further provisioning, but users keep whatever account state they currently have in the app. To fully remove accounts, remove the assignments first (so revocation provisions the removals), then deactivate. ## Where to go next Control who is provisioned by managing assignments and group membership. Build the groups you push to apps and link to their groups. Bring users into the directory from your HR system (the inbound side). Review the app, protocol, and version model. # Roles and role bundles Source: https://docs.iru.com/en/identity/applications/roles-and-bundles Assert a role to an application based on group membership in Iru Identity, and control session length and risk per role using role bundles. Many applications expect to know **what role** a user has (administrator, member, viewer, and so on), not just who they are. Iru can assert a role to an application at sign-on, decided by the user's group membership, and can vary **session length** and **risk** by role. You configure this on an application's **Roles** tab. Like the rest of an app, you edit it in a draft and publish it; see [Applications overview](/en/identity/applications/applications-overview). ## How a role reaches the application ```mermaid theme={null} flowchart LR group["Group membership"] --> role["Role"] role -->|"role identifier"| method["Role assertion method"] method --> app["Application"] ``` A **role** is granted to one or more [groups](/en/identity/directory/groups). When someone in those groups signs on, Iru asserts the role's **identifier** to the application using the method you choose. ## Role assertion method This decides how (or whether) the role is sent to the application. | Method | What it does | | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **None** | The application does not receive a role over single sign-on. Role bundles are turned off. On the **Assignments** tab, only the **Default** role can be assigned to groups. | | **Groups** | The role identifier(s) are sent as values in the groups the application receives. | | **Custom attribute** | The role identifier(s) are sent in a custom attribute or claim you name, as a single value or an array. For SAML apps you also choose the attribute name format. | ## Role bundles Roles live inside **role bundles**, which group related roles and decide whether a user can hold more than one of them at once. | Bundle setting | What it does | | --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Display name** | The bundle's name in the dashboard. | | **Bundle identifier** | A unique identifier used only to organize related roles. It is **not** sent to the application as a role value. | | **Exclusivity mode** | **Include all** asserts every role the user qualifies for in the bundle. **Priority** asserts only the single highest-priority role, so the roles are mutually exclusive. | In **Priority** mode, each role carries a unique **priority** number, and the role with the best priority wins when someone qualifies for more than one. ## What a role contains The role's name in the dashboard, and the **role identifier** that is asserted to the application (the value the app receives for this role). The [groups](/en/identity/directory/groups) whose members receive the role. Basing roles on groups keeps role assignment following your directory. How long a session granted through this role lasts, in minutes. Different roles can carry different session lengths. Set this to **0** to fall back to the application default (**60 minutes** unless you change it on the app). An optional [risk level](/en/identity/authentication/risk-based-access) classification for the role, so you can label more sensitive roles consistently. Every application starts with a **Default** bundle and role, so access works out of the box. Add bundles and roles only when an application needs role-based access. ## Configure roles for an application On the app's **Roles** tab, set how roles should reach the application: **Groups** or a **Custom attribute**, or **None** if the app doesn't take a role over single sign-on. Add a bundle, give it a name and identifier, and choose **Include all** or **Priority** exclusivity. For each role, set its identifier, assign the groups that should receive it, and set the session duration and (optionally) a risk level. In **Priority** bundles, give each role a priority number. Set the draft as current. From then on, sign-on asserts each user's role according to your bundles. ## Where to go next Grant who can reach the app in the first place. Roles are granted to groups; organize membership there. Where the custom attribute name format is set for SAML role assertion. Where roles ride along as a claim for OIDC apps. # SAML applications Source: https://docs.iru.com/en/identity/applications/saml-applications Reference for SAML application settings in Iru Identity: provider details, request and response handling, signing, attribute mapping, and session length. A **SAML application** lets users sign in to a service that supports SAML single sign-on, with Iru acting as the **identity provider (IdP)**. Iru gives the service the provider-facing details it needs, signs the response and assertion it sends, and maps your users' profile attributes into that assertion. You edit a SAML app's configuration in a **draft** and then set it as the current version. See [Applications overview](/en/identity/applications/applications-overview) for the version model. Below is a field-by-field reference for every setting, grouped exactly as the editor presents them. Most services need only a handful of these settings, typically the ACS URL, the Service Provider Entity ID, and the mapping. The defaults are chosen to work with common service providers; change the rest only when your service's documentation calls for it. ## Protocol details: what Iru gives the service provider Open the application's **Protocol details** to copy the values your service provider needs to trust Iru. These are generated by Iru. | Detail | What it is | | --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Metadata URL** | A single document describing Iru's SAML settings for this app. Many services configure everything from this URL; you can also view or download the metadata file. | | **IdP Entity ID** | Iru's identifier as the identity provider for this app. | | **Single Sign On Service** | The URL the service provider sends authentication requests to (and where IdP-initiated sign-on begins). | | **IdP Signing Certificate** | The certificate the service uses to verify that a response genuinely came from Iru. Its subject, expiry, and fingerprint are shown, and you can copy or download it. | If the service can import metadata, point it at the **Metadata URL** (or upload the downloaded file). It carries the entity ID, sign-on URL, and signing certificate together, so there is less to enter by hand. ## Provider details: what you tell Iru about the service | Setting | What it does | | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **ACS URL** | The Assertion Consumer Service URL, the destination Iru sends the SAML response to. Required, and must be a valid `https` URL. | | **Service Provider Entity ID** | The service provider's own identifier. Iru uses it as the default audience and (optionally) to validate the request issuer. | | **Unsolicited authentication** | Whether the service supports **IdP-initiated** sign-on (the user starts from Iru). Set **Supported** if the service accepts a response it didn't request; otherwise set **Unsupported**. | | **Alternative authentication URL** | Shown when unsolicited authentication is **Unsupported**: the URL Iru sends users to so the service can start the sign-in itself (service-provider-initiated). | These settings govern the **AuthnRequest** that a service provider sends to start sign-on. ### Validate issuer How strictly Iru checks the **Issuer** in an incoming request. | Option | What it does | | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | | **Must match Service Provider Entity ID** | The request's issuer must equal the Service Provider Entity ID you entered above. | | **Must match custom value** | The issuer must equal a **Custom value** you specify (use this when the service's issuer differs from its entity ID). | | **Ignore** | Do not validate the issuer. | ### Authentication request restriction Controls **whether the request must be signed** and **which ACS URL** Iru replies to. "Follow" uses the ACS URL from the request; "pinned" always uses the ACS URL configured in **Provider details**. | Option | Request must be signed? | Response is sent to | | ----------------------------- | ----------------------- | -------------------------- | | **Any request and follow** | No | The ACS URL in the request | | **Any request and pinned** | No | The configured ACS URL | | **Signed request and follow** | Yes | The ACS URL in the request | | **Signed request and pinned** | Yes | The configured ACS URL | **Pinned** is the safer choice: it ignores any ACS URL supplied in the request, so a tampered request cannot redirect a response elsewhere. Prefer **Signed request and pinned** when the service supports signing its requests. When you choose a **Signed request** option, you also set how Iru verifies that signature: | Setting | What it does | | ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Allowed signing algorithms** | The request signature algorithms Iru will accept: any of `RSA-SHA1`, `RSA-SHA256`, `RSA-SHA384`, `RSA-SHA512`. Select the ones your service uses; avoid `RSA-SHA1` unless required. | | **Allowed digest algorithms** | The request digest algorithms Iru will accept: any of `SHA1`, `SHA256`, `SHA384`, `SHA512`. | | **Signing Certificate** | The certificate Iru uses to verify the service's signed requests. Upload the service provider's request-signing certificate. | ### Delivery and identifiers | Setting | What it does | | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **HTTP Method** | How the SAML response is delivered: **HTTP-POST** (an auto-submitting form, the common choice) or **HTTP-REDIRECT**. | | **IdP Entity ID** | The issuer Iru declares in the response. Leave on **Use default** (shown in Protocol details), or choose **Specify custom** to declare a different **Custom IdP Entity ID**. | | **Audience** | Who the assertion is intended for. **Use default** sends the Service Provider Entity ID; choose **Specify custom** to send a different **Custom Audience**. | | **Recipient** | The recipient declared in the assertion. **Use default** uses the ACS URL (the destination); choose **Specify custom** to send a different **Custom Recipient**. | | **Fallback relay value** | The RelayState Iru uses when the service didn't supply one, typically where the user should land in the app. | | **Error action** | What happens when a sign-on can't complete: **Iru** shows an Iru error page, or **Protocol** returns the error to the service provider to handle. | ### Signing | Setting | What it does | | --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | | **Signing method** | Which parts of the message Iru signs: **Response**, **Assertion**, or **Both - Response and Assertion**. Match what the service requires. | | **Signing algorithm** | The signature algorithm Iru signs with: `RSA-SHA1`, `RSA-SHA256`, `RSA-SHA384`, or `RSA-SHA512`. `RSA-SHA256` suits most services. | | **Digest algorithm** | The digest algorithm used in the signature: `SHA1`, `SHA256`, `SHA384`, or `SHA512`. | Iru signs with its own **IdP Signing Certificate** (the one shown in Protocol details), so there is no signing certificate to upload here. ### Encrypt assertions | Setting | What it does | | --------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Encrypt assertions** | **Unencrypted** (default) or **Encrypted**. Turn on only if the service requires encrypted assertions. | | **Use the Request signing certificate** | When encrypting, reuse the service's request-signing certificate as the encryption certificate instead of uploading a separate one. (Requires a signing certificate to be configured in the **Request** section.) | | **Encryption Certificate** | The service provider's certificate Iru encrypts the assertion to, when you are not reusing the request-signing certificate. | | **Encryption algorithm** | The content-encryption algorithm: `AES-128-GCM`, `AES-192-GCM`, `AES-256-GCM`, `AES-128-CBC`, `AES-192-CBC`, or `AES-256-CBC`. Use what the service expects (a GCM option is a good default). | | **Key transport algorithm** | How the encryption key is protected: `RSA-OAEP` or `RSA-PKCS1-v1.5`. | ### Advanced | Setting | What it does | | -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Use namespace prefixes** | Adds explicit XML namespace prefixes (`saml2p`, `saml2`, `ds`, `xenc`) to the response. Enable it if the service's SAML parser requires prefixed elements. | Open the application's **mapping** to control the identity in the assertion. It has two parts: the **Subject** (the NameID) and any additional **attributes**. ### Subject (NameID) The Subject is the primary identifier for the signed-in user. By default it is drawn from the user's `user.username`; you can change the value it draws from and choose a **NameID format**: | NameID format | Use when the service expects… | | --------------- | ---------------------------------------------------------------- | | **Email** | An email address as the identifier. | | **Persistent** | A stable, opaque identifier that stays the same across sessions. | | **Transient** | A temporary identifier that may change each session. | | **Unspecified** | No particular format. | ### Attributes Add each attribute the service needs in the assertion. For every attribute you set: * A **Name:** the attribute name the service provider expects. * A **value:** the profile attribute or expression it draws from (for example, `user.email` or a combination of fields). * An **attribute name format:** **Unspecified**, **URI**, or **Basic**. * Whether it is **enabled**. A live **preview** renders the assertion that will be produced, so you can confirm its shape before publishing. `Subject` is reserved as the NameID and cannot be reused as a custom attribute name. The default session length is **60 minutes** in the SAML app assertion or OIDC token. The matching role's session length overrides that value. On the role, set session length to **0** to use the application default instead. See [Roles and role bundles](/en/identity/applications/roles-and-bundles). | Setting | What it does | | ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | | **Session Length Supported** | **Supported** populates the assertion's `notOnOrAfter` (session expiry) from the length below; **Unsupported** omits it. | | **Default session length (minutes)** | The application default written into the assertion. Defaults to **60**. Valid on the app as **10** to **2880** minutes. | ## Certificates at a glance A SAML app involves up to three certificates: Iru signs the response and/or assertion with its own certificate, shown in **Protocol details**. The service uses it to confirm the message came from Iru and was not altered. Nothing to upload. Upload the service provider's certificate so Iru can verify the **signed authentication requests** it sends. Configured in the **Request** section, and only needed when you require signed requests. The service provider's certificate Iru **encrypts the assertion** to, used only when **Encrypt assertions** is on. You can reuse the request-signing certificate instead of uploading a separate one. ## Publish, assign, and activate Publish your draft so it becomes the live configuration. Assign the groups that should have the app. See [Assigning access](/en/identity/applications/assigning-access). Make the app active so assigned users can sign in. Sign in as a test user from the app dashboard to confirm the experience, and use the mapping **preview** to check the assertion. ## Where to go next Grant the app to users and groups, and shape app roles. Create and remove accounts in the app automatically as access changes. Configure an app that uses OpenID Connect instead of SAML. Review protocols and the draft-to-current version model. # Authentication policies Source: https://docs.iru.com/en/identity/authentication/authentication-policies Decide who can sign in to each application in Iru Identity and what factors they must prove, using authentication policy rules evaluated on every sign-in. An **authentication policy** is the rulebook Iru applies whenever someone signs in to an application. It looks at the sign-in, evaluates a set of conditions you define, and produces a single **decision** (allow or deny). You manage policies in the dashboard under **Policies → Authentication policies**. A policy lets you express requirements like *"only allow sign-in from a managed, encrypted device"* or *"only allow current macOS versions"*, and have them enforced consistently for every user and every sign-in. A policy only takes effect once it is **assigned to one or more applications**. An application's policy governs sign-in to that application; see [Assign a policy to applications](#assign-a-policy-to-applications). ## How a policy is structured A policy is a set of **rules** arranged as a tree of **conditions**. Iru walks the tree from the top each time it evaluates the policy: * **Branch conditions** send the sign-in down different paths based on context. For example, a policy branches on the kind of device signing in, so a macOS device is checked against macOS requirements and a Windows device against Windows requirements. * **Requirement conditions** check that something is true; for example, that a device's disk is encrypted or that it is managed. Each requirement that is not met is recorded as a **violation**. When the walk finishes, the policy has either passed (no violations) or failed (one or more violations). ```mermaid theme={null} flowchart TD start["Sign-in to an assigned app"] --> branch{"What kind of
device is this?"} branch -->|"macOS"| mac["Check macOS
requirements"] branch -->|"Windows"| win["Check Windows
requirements"] branch -->|"Mobile"| ios["Check mobile
requirements"] mac --> decision{"All requirements
met?"} win --> decision ios --> decision decision -->|"Yes"| allow["Allow: issue sign-on"] decision -->|"No"| deny["Deny: record violations"] ``` The authentication policy editor: a Trigger node connected to an Enforce Device Health node that branches into macOS, Windows, iOS, and Android columns. Each platform lists device-health checks such as FileVault, BitLocker, Jailbroken, Passcode Set, and OS Version, each set to Enabled, Disabled, or Ignored. ## How a policy is evaluated at sign-in ```mermaid theme={null} sequenceDiagram participant U as Person participant A as Application participant I as Iru Identity U->>A: Open the app A->>I: Ask Iru to authenticate I->>I: Confirm who the user is I->>I: Evaluate the assigned policy alt Policy passes I-->>A: Issue single sign-on A-->>U: Grant access else Policy fails I-->>U: Deny and explain what was missing end ``` Every sign-in to an application produces a decision, and Iru records that decision, including any violations, so you can review what happened later in the [activity log](/en/identity/administration/activity-log). A policy decides **whether** a sign-in is allowed and **what must be true** for it. Whether a user is *assigned* the application is a separate check. Both must succeed for someone to reach an app. See [Assigning access](/en/identity/applications/assigning-access). ## What a policy can require A passkey or Iru Access authenticator is **always required** to sign in; that is built in for everyone, not something a policy turns on. What a policy adds on top is **device trust**: which devices may sign in and the shape they must be in. Require sign-in from a known, healthy, managed device (for example, one with disk encryption on. See [Device trust](/en/identity/authentication/device-trust). Allow sign-in only from the device platforms you choose, and deny the rest. Require per-platform signals such as disk encryption, a firewall, or a minimum OS version. See [Device trust](/en/identity/authentication/device-trust). ## What happens when a policy fails When a sign-in does not meet a policy's requirements, Iru **denies** it and records the reason as one or more **violations**. Each violation captures the requirement that was not met, what the policy expected, and what was actually seen; for example, a requirement that disk encryption be *enabled* when it was found *disabled*. If a policy is configured so that no path can succeed (for example, no device platform is allowed, then every sign-in to the applications it governs will be denied. Review the policy's allowed platforms before assigning it broadly. ## Build a policy In **Policies → Authentication policies**, choose **Add policy** and give it a clear name and description. The name is how you will recognize it when assigning it to applications. Add the conditions the sign-in must meet. You can allow sign-in only from specific device platforms and, for each, require device health signals such as disk encryption being on or the device being managed. See [Device trust](/en/identity/authentication/device-trust) for the full set of available signals. Attach the policy to the applications it should govern. From that point on, every sign-in to those apps is evaluated against this policy. Sign in as a test user to an assigned app and confirm the outcome. If access is denied unexpectedly, review the recorded violations in the [activity log](/en/identity/administration/activity-log). ## Assign a policy to applications A policy does nothing until it is attached to applications. Each policy keeps a list of the applications it is **scoped to**, and you attach or detach applications from the policy's page in the dashboard. An application's assigned policy is what Iru evaluates whenever someone signs in to that application. Group applications with the same security needs under a shared policy. When your requirements change, you update one policy instead of editing every app. ## Where to go next The credentials users use to prove who they are on every sign-in. Require known, healthy, managed devices as a condition of access. Let access adapt to how trustworthy a sign-in looks. See what evaluation looks like from the user's side. # Authenticators Source: https://docs.iru.com/en/identity/authentication/authenticators The credentials users use to prove who they are in Iru: passkeys, the Iru Access app, and connected federated providers, and how you oversee them. An **authenticator** is something a user uses to prove who they are when they sign in. Iru is built around strong, phishing-resistant authenticators, so the secret needed to sign in never has to be typed or shared with the apps users use. Users prove who they are to Iru in one of these ways: The primary authenticator. A passkey lets someone sign in with the fingerprint, face, or screen lock they already use on their device, with no password to remember or reuse. Passkeys are **phishing-resistant**: they only work with Iru, so they cannot be captured and replayed on a fake sign-in page. The Iru Access app, installed on a user's computer or mobile device. Users register it from an invitation and then use it to confirm sign-in; like a passkey, it is tied to the device and unlocked with the device's biometric or screen lock. Iru Access also reports [device health](/en/identity/authentication/device-trust) for device-trust policies. Instead of an Iru authenticator, a user can sign in through an identity provider you have connected (Google, Microsoft, or any SAML or OIDC provider). The external provider verifies them and Iru trusts the result. This is set up under [Federated Authentication](/en/identity/connections/connections-overview), not enrolled per user. Passkeys and Iru Access are **phishing-resistant** authenticators Iru manages directly, and are the recommended way to sign in. When someone signs in through a **federated provider** instead, the strength of that sign-in depends on the controls that provider enforces. ## Why passkeys Passkeys are the recommended way for users to sign in to Iru. A passkey is bound to Iru, so there is no shared secret an attacker can trick someone into entering on a look-alike site. Users unlock their passkey with the biometric or screen lock already on their device, so there is no password to create, rotate, or forget. The part of the passkey needed to sign in stays on the user's device and is never sent to Iru or to the apps they open. Signing in with a passkey is a single quick gesture, which makes a strong requirement easy for users to live with. ## Status: active or suspended Every authenticator has a **status**: | Status | What it means | | ------------- | ------------------------------------------------------------------------------------------------------ | | **Active** | The authenticator can be used to sign in. | | **Suspended** | The authenticator is kept on the user's account but cannot be used to sign in until it is reactivated. | Suspending an authenticator blocks its use without removing it, which is useful while you investigate something. Removing an authenticator deletes it entirely. ## Self-service and admin oversight Authenticators are owned by the users who use them, with administrator oversight for when something needs attention. Users manage their own authenticators from their account in Iru. They can add a passkey, see the authenticators registered to them, and remove one they no longer use. Because passkeys live on personal devices, self-service enrollment is the normal way users get set up. See [End-user experience](/en/identity/administration/end-user-experience). As an administrator, you can **review** the authenticators registered to a user, **suspend** one to block its use, or **remove** one (for example, when a device is lost or someone leaves. Administrators do not see the secret behind an authenticator; they manage which authenticators exist and whether they are active. For **Iru Endpoint** tenant administrator passkeys, see [Passkeys & Social Login](/en/iru/access/passkeys-and-social-login). If someone is locked out, see [Iru Account Recovery](/en/iru/access/iru-account-recovery). Make sure users can register more than one authenticator where possible, so losing a single device does not lock someone out. Removing or suspending a user's only active authenticator will prevent them from signing in until they enroll a new one. ## How authenticators and policies fit together Every sign-in is proven before access is granted, whether with an Iru authenticator (passkey or Iru Access) or through a connected federated provider. A strong authenticator is the built-in default; it is not something you switch on in a policy. An [authentication policy](/en/identity/authentication/authentication-policies) then layers **device trust** on top, deciding which devices may complete the sign-in and the health they must be in. ```mermaid theme={null} flowchart LR user["User signs in"] --> auth["Authenticator or
federated provider"] auth -->|"proves identity"| policy["Authentication policy
checks device trust"] policy -->|"conditions met"| app["Access to app"] ``` ## Where to go next Layer device-trust conditions on top of the authenticator every sign-in uses. See how users use their authenticators when they sign in. Let users sign in through Google, Microsoft, or a SAML or OIDC provider. How Iru protects the credentials behind authenticators and the sessions they create. What self-service looks like for users in your directory. Passkeys for Iru Endpoint tenant administrator sign-in End-user guide for passkeys, Iru Access, and backup devices Help team members regain access when they lose a passkey # Deploy Iru Access Source: https://docs.iru.com/en/identity/authentication/deploy-iru-access Roll out the Iru Access app through your MDM so Mac computers, iPhone devices, iPad devices, and PCs are recognized as managed, or share it for BYO. **Iru Access** carries each user's device-bound sign-in credential and reports [device health](/en/identity/authentication/device-trust). *How* you deliver it decides whether a device is recognized as **managed**: * **Managed deployment:** installed and configured through your MDM. Iru recognizes the device as managed, so [authentication policies](/en/identity/authentication/authentication-policies) that require the **managed** attribute are satisfied. * **Unmanaged deployment:** a personal or BYO device the user sets up themselves. It still registers a working authenticator and reports health signals, but it is **not** recognized as managed, so policies that require the managed attribute won't pass on it. Both paths give the user a working Iru Access authenticator and report device health. The only difference is whether the device counts as **managed** for device-trust decisions. ## Managed deployment Install and configure Iru Access through your MDM so enrolled devices count as **managed** for [device trust](/en/identity/authentication/device-trust). ### Create an MDM connection An [MDM connection](/en/identity/authentication/mdm-connections) is what lets Iru recognize devices enrolled in your MDM as managed. Create one for each MDM instance you use with Iru Identity. 1. In Iru Identity, go to **Policies → MDM Connections** and choose **+ MDM Connection**. 2. Under **Select a connection type**, pick one: * **Iru Endpoint Instance:** Pre-populate connection fields from your Iru Endpoint instance. * **Custom MDM Connection:** Create a custom MDM connection with manual entry. 3. Give the connection a **display name**. We recommend your MDM server's domain. 4. Choose a **platform**: Apple, Windows, or both. 5. Enter the platform details: * **Apple:** the **APNs topic** and **Check-in URL** of your MDM server. * **Windows:** the **Provider ID** and **Discovery service URL** of your MDM server. Not sure of those values? See [Resources](#resources) for helper scripts you can run on an already-enrolled device to read them off. After the connection is created, deploy Iru Access to each platform below. ### macOS In Iru Identity, on **Policies → MDM Connections**, click the download button to the left of **+ MDM Connection**, then choose **macOS Profile**. Deploy the profile to your Macs. It already contains the Associated Domains and single sign-on extension settings (with your organization's domains filled in), so you don't have to assemble them by hand. If your MDM configures these as native payloads instead of an uploaded profile, replicate the following. Substitute `` with each domain your connection uses (a connection may include more than one). * **Associated Domains:** application identifier `N5M3B34269.com.iru.Access`, with an associated domain of `authsrv:` for each domain. * **Single sign-on extension** (Extensible SSO, **Redirect** type): extension identifier `com.iru.Access.SSOExtension`, team identifier `N5M3B34269`, and these redirect URL values for each domain: ``` https:///api/v1/saml/sso https:///api/v1/oauth/authorize https:///api/v1/saml/login ``` * **Managed login items:** allow team identifier `N5M3B34269` for `com.iru.Access`, `com.iru.Access.IruDaemon`, and `com.iru.Access.Menu` so the Iru Access helper, background service, and updater can run. **With Iru Endpoint:** add the **Iru Access** Auto App for Mac from **Auto Apps** in the Library, assign it through a Blueprint, and scope it to your Macs. See [Auto Apps Overview](/en/endpoint/library/auto-apps/auto-apps-overview). **With another MDM:** download [Iru Access for macOS](https://updater.iru.com/iru-access-macOS/download), upload the package to your MDM, and scope it to your Macs. Copy the [Iru Access managed registration script](https://github.com/kandji-inc/support/blob/main/Identity/iru-access-managed-registration/iru_access_managed_registration_macos.zsh) from the [Iru Support GitHub repository](https://github.com/kandji-inc/support/tree/main/Identity). In the **USER INPUT** section near the top of the file, set `regToken` to your MDM connection's **client secret** and `regTokenDomain` to your **base** tenant domain: ```zsh theme={null} # USER INPUT regToken="mdm-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" regTokenDomain="yourcompany.iru.com" ``` Add a **Mac Custom Script** Library Item from the Library, paste the modified script into **Audit Script**, and assign it through the same Blueprint as the Iru Access app. Set **Execution Frequency** to **Run every 15 minutes** so the script retries at each check-in until Iru Access is installed and the secret is stored. Because the script is idempotent, **Run daily** also works if you prefer less frequent runs. See [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview) (Mac tab). Upload the modified script using your platform's custom script or policy tooling. Run it on a recurring schedule after Iru Access is installed so new devices pick up the secret once the app is present. ### iOS, iPadOS, and visionOS **Requirements** * **iOS and iPadOS:** Devices must run **18.4 or later**. * **Apple Vision Pro:** Iru Access installs as the iPad app. In Iru Identity, on **Policies → MDM Connections**, click the download button to the left of **+ MDM Connection**, then choose **iOS Profile**. Deploy the profile to your devices. * **Single sign-on extension** (Extensible SSO, **Redirect** type): extension identifier `com.iru.AccessMobile.SSOExtension`, team identifier `N5M3B34269`, and these redirect URL values for each domain: ``` https:///api/v1/saml/sso https:///api/v1/oauth/authorize ``` Distribute [Iru Access on the App Store](https://apps.apple.com/us/app/iru-access/id6752437810) through your MDM as a managed app, and scope it to your devices. In your MDM, set **managed app configuration** on Iru Access (bundle ID `com.iru.AccessMobile`). Set two keys: * **`mdmSecret`** (String, required): your MDM connection's **client secret**. * **`mdmSecretDomain`** (String, required): your **base** tenant domain (for example `yourcompany.iru.com`). Set `mdmSecretDomain` to your **base** domain (`yourcompany.iru.com`), not the `id.` subdomain that invitation links use (`yourcompany.id.iru.com`). If the `id.` subdomain is included, the secret isn't applied and the user falls back to entering it by hand. ```xml Managed app configuration (plist) theme={null} mdmSecret mdm-REPLACE-WITH-MDM-CONNECTION-CLIENT-SECRET mdmSecretDomain yourcompany.iru.com ``` With this configuration, registration is **credential-free**: the user never enters a secret, scans a QR code, or waits for manual approval. They still open their **invitation** (emailed to them, or a link you push to managed devices) or the in-app onboarding screen, tap **Continue**, and confirm with Face ID or Touch ID. With Iru Endpoint, apply this dictionary through **Set app configuration** on the Iru Access App Store app. See [Using AppConfig](/en/endpoint/library/library-items-profiles/using-appconfig) for deployment steps. ### Windows **Requirements** * **Windows 11 24H2 or 25H2** Windows deployment has two parts: deploy **Iru Access** through your MDM, then store your MDM connection's **client secret** on each PC with the registration script. Registration still requires the user to open their invitation and confirm with **Windows Hello**. **With Iru Endpoint:** add the **Iru Access** Auto App for Windows from **Auto Apps** in the Library, assign it through a Blueprint, and scope it to your PCs. See [Auto Apps Overview](/en/endpoint/library/auto-apps/auto-apps-overview). **With another MDM:** download [Iru Access for Windows](https://updater.iru.com/iru-access-windows/download), upload the package to your MDM, and scope it to your PCs. Copy the [Iru Access managed registration script](https://github.com/kandji-inc/support/blob/main/Identity/iru-access-managed-registration/iru_access_managed_registration_windows.ps1) from the [Iru Support GitHub repository](https://github.com/kandji-inc/support/tree/main/Identity). Add a **Windows Custom Script** Library Item from the Library, upload the script, and assign it through the same Blueprint as the Iru Access app. In [**Command line parameters**](/en/endpoint/library/library-items-profiles/custom-scripts-overview#command-line-parameters-optional), pass your client secret and base tenant domain: ``` manage --secret --domain yourcompany.iru.com ``` Use your connection's **client secret** and **base** tenant domain (`yourcompany.iru.com`), the same values as on macOS and iOS. Store the client secret with this script rather than writing the registry directly. It's encrypted to the device, so a value pushed by raw registry or OMA-URI won't be usable. Set **Execute in** to **64 bit**. Windows Custom Scripts run once per device when assigned. See [Custom Scripts Overview](/en/endpoint/library/library-items-profiles/custom-scripts-overview) (Windows tab). Deploy the script using whatever script or PowerShell policy tooling your platform supports. Pass the `manage --secret` and `--domain` arguments your MDM allows, and run elevated so the script can write to `HKLM`: ```powershell theme={null} .\iru_access_managed_registration_windows.ps1 manage --secret --domain yourcompany.iru.com ``` To confirm the secret is stored or to clear it, run the script from an elevated PowerShell session with arguments. See Microsoft's [Getting Started with PowerShell](https://learn.microsoft.com/en-us/powershell/scripting/learn/ps101/01-getting-started?view=powershell-7.5#starting-powershell-elevated-as-an-administrator) for how to open PowerShell as an administrator. ```powershell theme={null} # Verify: prints ":", never the secret itself .\iru_access_managed_registration_windows.ps1 manage --list # Rotate or remove .\iru_access_managed_registration_windows.ps1 manage --clear "yourcompany.iru.com" ``` With the app deployed and the client secret stored, the user opens their **invitation**, which launches Iru Access, and confirms with **Windows Hello**. Because the device is enrolled in your MDM and carries the stored client secret, Iru recognizes it as **managed**. Iru Access registers its **passkey plugin** with Windows automatically the first time it runs, after which it appears under **Settings ▸ Accounts ▸ Passkeys ▸ Advanced options**. Turning that toggle **on** is owned by Windows and the user. It can't currently be forced on centrally through MDM. The [end-user guide](/en/identity/end-user/installing-iru-access) covers that step. ## Unmanaged deployment For personal or bring-your-own devices, there is nothing to configure in an MDM. The user installs Iru Access and registers from their invitation. ### macOS Share [Iru Access for macOS](https://updater.iru.com/iru-access-macOS/download) with the user. They download and install it, then register from their invitation. For step-by-step guidance, see [Installing Iru Access](/en/identity/end-user/installing-iru-access). ### iOS, iPadOS, and visionOS Share [Iru Access on the App Store](https://apps.apple.com/us/app/iru-access/id6752437810) or their invitation link with the user. They install the app, then register. **Requirements** * **iOS and iPadOS:** The device must run **18.4 or later**. * **Apple Vision Pro:** Install from the App Store as the iPad app. For step-by-step guidance, see [Installing Iru Access](/en/identity/end-user/installing-iru-access). ### Windows Share [Iru Access for Windows](https://updater.iru.com/iru-access-windows/download) with the user. They download and install it, then register from their invitation. **Requirements** * **Windows 11 24H2 or 25H2** For step-by-step guidance, see [Installing Iru Access](/en/identity/end-user/installing-iru-access). Unmanaged devices still register a working authenticator and report health signals, but they are **not** recognized as managed. Policies that require the managed attribute won't pass on them. Use a **managed deployment** for devices that need to meet those policies. ## Resources Run these helper scripts on a device already enrolled in your MDM to collect the MDM server details you need when creating a connection. Both are maintained in the [Iru Support GitHub repository](https://github.com/kandji-inc/support/tree/main/Identity). The [macOS Collect MDM details script](https://github.com/kandji-inc/support/blob/main/Identity/iru-access-collect-mdm-details/collect_mdm_details_macos.zsh) reads the **APNs topic** and **MDM Check-in URL** from an enrolled Mac. The [Windows Collect MDM details script](https://github.com/kandji-inc/support/blob/main/Identity/iru-access-collect-mdm-details/collect_mdm_details_windows.ps1) reads the MDM server's **Provider ID** and **Discovery service URL** from an enrolled Windows device. Run it in PowerShell. ## Where to go next Diagnose associated-domain approval and extension loading on a Mac. Set up and manage the connection that makes a device count as managed. Require managed, healthy devices as a condition of access. The end-user walkthrough for setting up Iru Access on a personal device. How Iru Access fits alongside passkeys as an authenticator. # Device trust Source: https://docs.iru.com/en/identity/authentication/device-trust Require sign-in from known, healthy, managed Mac computers, iPhone devices, iPad devices, and PCs using signals reported by the Iru Access agent. **Device trust** lets an authentication policy take the device into account before granting access. Instead of only asking *who* is signing in, a policy can also ask *what they are signing in from*, and require that the device be known, healthy, and managed. Device trust is one of the conditions an [authentication policy](/en/identity/authentication/authentication-policies) can enforce. Below is where device information comes from and the signals a policy can require. ## Where device information comes from Device health comes from the **Iru Access** app (the same app users use to sign in) running on the device. When a device is first set up, Iru confirms it is a genuine, registered device; from then on, Iru Access reports the device's health signals to Iru, where your authentication policies can use them. Iru Access reports these signals when a device is registered, each time the user signs in, and (on computers) on a regular background check-in. ```mermaid theme={null} flowchart LR agent["Iru Access
on the device"] -->|"device and health signals"| iru["Iru Identity"] iru -->|"available to"| policy["Authentication policies"] ``` Policies that require device health treat those snapshots as time-sensitive. If a device's health or Play Integrity snapshot is **missing**, or **older than 24 hours**, the policy **denies** sign-in. Keep Iru Access installed and able to check in so signals stay fresh enough for enforcement. Device signals are available only for devices that have **Iru Access** registered, so roll it out before requiring device trust. See [Authenticators](/en/identity/authentication/authenticators) for how users set up Iru Access. Iru recognizes laptops, desktops, phones, and tablets across macOS, Windows, and iOS. ## What "trusted" can mean A device-trust requirement is a combination of signals you choose. In plain terms, a policy can require that a device is: The device is a genuine, recognized device rather than an unknown or spoofed one. Iru can confirm a device is **attested** before trusting its signals. The device is enrolled in your organization's device management. Iru determines this from the management evidence Iru Access reports, such as an enrollment profile on a Mac, MDM enrollment on a Windows PC, or managed-app configuration on a mobile device. The device's disk encryption is turned on, so data at rest is protected if the device is lost or stolen. The device meets the posture you require; for example, its protective features are on and it is running an acceptable operating-system version. Device-trust signals are only available for devices that have the Iru Access agent registered. A policy that requires a healthy device will deny sign-in from devices Iru has no trusted signals for, so roll out Iru Access across your fleet before applying such a policy broadly. ## How a policy uses device trust A policy first considers which **platform** a device is on, then applies the requirements you set for that platform. The available signals differ by platform because each operating system exposes different protections. On a Mac, Iru Access reports a rich set of signals: disk encryption (FileVault) on, the firewall on, System Integrity Protection on, a sealed (verified) system volume, and the operating-system version. Require the combination your policy needs. On Windows, Iru Access reports a rich set too: disk encryption (BitLocker) on, the firewall on, Microsoft Defender antivirus protection on, Secure Boot on, memory integrity on, a hardware security chip (TPM) present, and the operating-system build. If your organization runs a third-party antivirus instead of Microsoft Defender, test that signal before enforcing it. On a mobile device, Iru Access reports a smaller set: whether a passcode (screen lock) is set, and the operating-system version. **What some macOS signals mean:** *System Integrity Protection (SIP)* stops even an administrator from modifying protected system files; a *Signed System Volume (SSV)* is a cryptographically sealed, tamper-evident system volume; and the *single sign-on (SSO) extension* is the macOS component that lets Iru broker app sign-ins on the device. Requiring these confirms the device's core protections are intact. For each signal, you decide whether it must be **on**, must be **off**, or should be **ignored**; for versions, you choose the comparison and target. If a device does not meet a required signal, the sign-in fails and the unmet requirement is recorded as a violation. See [Authentication policies](/en/identity/authentication/authentication-policies) for how decisions and violations work. Only the platforms you enable in a policy are allowed to sign in to the applications it governs. If a platform is left disabled, devices on that platform are denied access. ## Build a device-trust requirement Make sure the devices you want to trust have **Iru Access** installed and registered. You can deploy it through your MDM, and users finish setup from an invitation. Without it, Iru has no signals for the device. See [Authenticators](/en/identity/authentication/authenticators) and [Deploy Iru Access](/en/identity/authentication/deploy-iru-access) for platform-specific rollout steps, including managed registration scripts. In **Policies → Authentication policies**, edit the policy that should enforce device trust. Turn on each device platform that should be permitted, and leave the rest off to deny them. For each platform, require the device health signals you need, such as encryption on, managed, and a minimum operating-system version. Assign the policy to the relevant applications and test sign-in from a managed device to confirm the outcome. ## Where to go next Combine device trust with authenticator and risk requirements. Iru Access is both how users sign in and how device signals are collected. Add context-aware risk on top of device trust. See how device signals flow through Iru. # MDM connections Source: https://docs.iru.com/en/identity/authentication/mdm-connections Connect a mobile device management service to Iru Identity so Apple platform devices and Windows PCs can enroll and be recognized as managed for device trust. An **MDM connection** links Iru to your mobile device management (MDM) service so devices can enroll and so Iru can recognize them as **managed** in [device-trust](/en/identity/authentication/device-trust) decisions. You manage these under **Policies → MDM Connections**. ## Choose a connection type When you choose **+ MDM Connection**, Iru Identity asks you to **Select a connection type**: | Type | What it does | | ------------------------- | --------------------------------------------------------------- | | **Iru Endpoint Instance** | Pre-populate connection fields from your Iru Endpoint instance. | | **Custom MDM Connection** | Create a custom MDM connection with manual entry. | ## Connection settings A connection has a **display name** and covers one or both platforms: | Setting | What it is | | ---------------- | ------------------------------------------------------------------------------ | | **APNs topic** | The Apple Push Notification service topic the MDM uses to reach Apple devices. | | **Check-in URL** | The URL Apple devices check in to during and after enrollment. | | Setting | What it is | | ------------------------- | ----------------------------------------------------------------- | | **Provider ID** | The identifier the MDM presents to Windows during enrollment. | | **Discovery service URL** | The endpoint Windows devices use to discover enrollment settings. | Not sure where to find these values? Run the **Collect MDM details** helper scripts on a device already enrolled in your MDM; the macOS script returns the **APNs topic** and **Check-in URL**, and the Windows script returns the **Provider ID** and **Discovery service URL**. See [Resources](/en/identity/authentication/deploy-iru-access#resources). ## Enrollment profiles For Apple platforms, download configuration profiles from **Policies → MDM Connections** in Iru Identity. Click the download button to the left of **+ MDM Connection**, then choose **macOS Profile** or **iOS Profile**. These configure **Iru Access** on a managed device (its privacy permissions and single sign-on extension) for deployment through your MDM; they don't enroll the device into MDM itself. ## Connection secrets A connection uses a **client secret** that you can rotate from the connection's **Client secrets** list: * **Rotate** issues a new secret while the previous one keeps working for **24 hours**, so you can update the MDM before the old secret stops. The previous secret shows an **Expires Soon** badge until it expires. * **Invalidate** ends a secret immediately; use it if a secret may have been exposed. ## How this relates to device trust A connected MDM is how Iru can tell that a device is **managed**. Combined with the health signals the [Iru Access](/en/identity/authentication/device-trust) app reports, your [authentication policies](/en/identity/authentication/authentication-policies) can require a known, managed, healthy device before granting access. ## Where to go next Use managed and health signals as conditions in a policy. How users install and register Iru Access on their devices. # Risk and adaptive access Source: https://docs.iru.com/en/identity/authentication/risk-based-access Make access adapt to context, so it tightens for sensitive apps and risky conditions and stays frictionless when a sign-in looks routine. Not every sign-in deserves the same treatment. A sign-in from a familiar, managed device to a low-stakes app is very different from access to a sensitive application. **Adaptive access** lets your authentication policies respond to that difference: asking for more when the situation warrants it and staying out of the way when it does not. Adaptive access is something an [authentication policy](/en/identity/authentication/authentication-policies) expresses. Below are the levers you can adapt on; the policy page explains how to combine them into a decision. ## What you can adapt on Today, the strongest lever for adaptive access is **device trust**: the conditions a policy places on the device a user signs in from. You apply it selectively by attaching stronger policies to your more sensitive applications: Require a known, healthy, managed device for sensitive apps, while allowing routine apps from any device. Use risk levels to classify how sensitive each app is, and attach stronger device-trust policies to your top tier. By tiering your applications and attaching stronger policies to the sensitive ones, you get access that adapts to context without slowing everyone down. ## Risk levels Iru also lets you define **risk levels**, named classifications you create to fit how your team already talks about risk. Risk levels give you a consistent vocabulary to organize applications and policies around their sensitivity. Today you can assign a risk level to an [application role](/en/identity/applications/roles-and-bundles) to mark more sensitive access. Risk levels are a classification you define. Automatically scoring each sign-in and feeding that score into policy decisions is an area Iru is expanding; see [Iru release stages](/en/iru/platform-overview/iru-release-stages) for how capabilities mature. Plan today around **device trust**, which is enforced now; a passkey or Iru Access is already required for every sign-in regardless. ## A practical approach Decide which applications are most sensitive. Define [risk levels](#risk-levels) that capture those tiers so the rest of your team shares the same language. Every sign-in already requires a passkey or Iru Access, so all access starts from a strong, phishing-resistant baseline; there is nothing to configure for that. For your most sensitive apps, add a [device trust](/en/identity/authentication/device-trust) requirement so only known, healthy devices get in. Watch how sign-ins are decided in the [activity log](/en/identity/administration/activity-log) and adjust so legitimate users are not slowed down unnecessarily. ## Where to go next Where device trust and your application tiers come together into one decision. Require a known, healthy device for sensitive access. The phishing-resistant proof every sign-in uses. Review how sign-ins are being decided over time. # The sign-in experience Source: https://docs.iru.com/en/identity/authentication/sign-in-experience What signing in to Iru looks like for end users, whether directly with a passkey or through a connected identity provider, and the app dashboard they land on. Whether someone signs in directly with Iru or through a provider you already run, they end up in the same place: an app dashboard of the applications they are allowed to use. ## How users sign in By default, **Iru Identity is your identity provider**: users sign in to Iru directly, and Iru signs them in to their apps. You can also let them sign in through a provider you already run, in specific situations. Both paths lead to the same app dashboard. The user proves who they are to Iru itself, typically with a **passkey** (a quick fingerprint, face, or screen-lock gesture) or the **Iru Access** app. No password required. This is how most users sign in. The user signs in with an existing provider, such as Google Workspace or Microsoft Entra ID, and Iru continues once the provider confirms them. This **federated** sign-in is for when you use Iru as an authentication layer into the Iru platform, or to ease a migration onto Iru Identity. ```mermaid theme={null} flowchart TD start["User starts sign-in"] --> choice{"How is sign-in
set up?"} choice -->|"Direct (default)"| direct["Prove identity to Iru
with a passkey or Iru Access"] choice -->|"Federated (optional)"| fed["Sign in with a
provider you already run"] direct --> policy["Iru evaluates the
authentication policy"] fed --> policy policy -->|"Allowed"| dash["App dashboard"] policy -->|"Denied"| stop["Access denied,
with the reason"] ``` The user always proves who they are with their authenticator (a passkey or Iru Access). Iru then evaluates the relevant [authentication policy](/en/identity/authentication/authentication-policies) before granting access. A policy can require a trusted device, so the exact prompts a user sees can depend on the app they are reaching and the rules you have set. Federated sign-in is configured through an identity provider connection. To set one up, see [Federated Authentication](/en/identity/connections/connections-overview). ## The app dashboard Once signed in, each user lands on their own app dashboard. It greets them by name and shows the applications your organization has assigned to them. Every application the user has access to appears as a tile. Selecting a tile signs them straight in to that app, with no separate password for the app itself. Users can star the apps they use most so they surface at the top of their app dashboard for quick access. The app dashboard only ever shows the apps a user is actually assigned, so what each user sees reflects the access you have granted them. To control who sees which apps, see [Assigning access](/en/identity/applications/assigning-access). Selecting an app tile starts a single sign-on into that app. If an app's policy requires something the user has not satisfied yet (such as enrolling a passkey), they are prompted at that point. For what end users see when they sign in and open apps, see [Accessing your apps](/en/identity/end-user/accessing-your-apps). For passkey and Iru Access setup, see [Manage authenticators](/en/identity/end-user/manage-authenticators). On macOS, if a passkey does not appear in the browser prompt, see the tip in [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). If 1Password autofill appears on the Iru sign-in page, see [1Password autofill](/en/identity/end-user/accessing-your-apps#1password-autofill). ## Where to go next A fuller tour of what end users see and manage in Iru, including their authenticators. Let users sign in through Google Workspace, Microsoft Entra ID, or another provider you already run. The passkeys and credentials users use to prove who they are. What Iru checks between sign-in and access. What end users see when they sign in and open apps from the app dashboard End-user guide for passkeys, Iru Access, and backup devices # Troubleshooting the macOS SSO extension Source: https://docs.iru.com/en/identity/authentication/troubleshoot-macos-sso Diagnose why the Iru Access single sign-on extension on macOS isn't intercepting sign-ins, using Apple's built-in command-line tools. Iru Access installs a macOS **single sign-on (SSO) extension**, a Redirect-type Extensible SSO extension that intercepts sign-ins to your Iru domains so users sign in with their device-bound credential. For it to work, macOS must have **approved the associated domains** for the extension, which your MDM normally pushes as part of the Iru Access configuration profile. If sign-ins on a Mac aren't being intercepted by Iru Access, the checks below confirm, in order, that the extension is **installed**, **loaded**, and that its **associated domains are approved**. They use Apple's own command-line tools and are safe to run on an enrolled Mac. For diagnosing an existing deployment only. To set up the configuration profile, the app, and registration, see [Deploy Iru Access](/en/identity/authentication/deploy-iru-access). **Values used below.** `N5M3B34269` is Iru's Apple Team ID, the same value in your Iru Access MDM profile, so the Iru Access App ID is always `N5M3B34269.com.iru.Access`. `yourcompany.id.iru.com` stands in for your organization's Iru sign-in domain; your real output shows your actual domains. The most common cause of a non-working SSO extension is that macOS has not approved the **associated domains**. List every associated-domain approval on the Mac: ```bash theme={null} sudo swcutil show ``` Look for an entry with **Service `authsrv`**, the Iru Access **App ID** `N5M3B34269.com.iru.Access`, and your Iru sign-in domain (one entry per domain your connection uses): ``` -------------------------------------------------------------------------------- Service: authsrv App ID: N5M3B34269.com.iru.Access Domain: yourcompany.id.iru.com User Approval: unspecified Site/Fmwk Approval: approved Flags: enterpriseManaged Last Checked: 2026-05-24 21:27:52 +0000 Next Check: 2026-05-29 20:38:54 +0000 -------------------------------------------------------------------------------- ``` What to check: **`Site/Fmwk Approval: approved`** is the line that matters. It means Apple validated the domain association for the extension. `denied`, or a missing entry, means the association has not been validated yet. * **`Flags: enterpriseManaged`** indicates the domain was pushed by your MDM, as expected for a managed deployment. If it is missing, the configuration profile with the Associated Domains payload may not have reached this Mac. * There should be **one entry per Iru domain** your connection uses (a connection may include more than one). A missing domain points to an incomplete profile. List the Iru Access app extensions registered with macOS: ```bash theme={null} pluginkit -v -m ``` You should see the SSO extension listed, for example: ``` com.iru.Access.SSOExtension(1.0) 8ACDABA9-0000-0000-0000-4E99DCF7F39D /Applications/Iru Access.app/Contents/PlugIns/SSOExtension.appex ``` What to check: * A `com.iru.Access.SSOExtension` line means the extension is registered. * No line at all means the Iru Access app is not installed, or its extension has not registered yet. Confirm the app is deployed and has been launched once. Stream the system's SSO extension manager and look for Iru Access being loaded: ```bash theme={null} log stream --debug --predicate 'category contains "SOExtensionManager"' ``` A healthy system logs the Iru extension as loaded (output similar to): ``` AppSSOAgent: (AppSSO) [SOExtensionManager] loadedExtensionWithBundleIdentifer: com.iru.Access.SSOExtension => ``` Any other single sign-on extensions installed on the Mac appear in the same list; the one that matters here is `com.iru.Access.SSOExtension`. Two live streams help when an approval is slow to land, or when a sign-in is not being intercepted. **Associated-domain checks:** watch macOS schedule and record domain approvals: ```bash theme={null} sudo swcutil watch --verbose ``` **The SSO agent:** watch the process that runs the extension during sign-in: ```bash theme={null} sudo log stream --debug --process AppSSOAgent ``` When the associated domains are **not** yet approved, the agent logs messages like these, which point straight at the cause: ``` com.iru.Access.SSOExtension hasAssociatedDomainsApproved = 0 Associated domain: validation failed for the SSO extension com.iru.Access.SSOExtension because it has no approved associated domains; it will be checked again when the extension is next used. ``` `hasAssociatedDomainsApproved = 0` means the domains are not approved yet. Once approval lands, these errors stop and sign-ins to your Iru domains are intercepted by Iru Access. ## Common causes and fixes | Symptom | Likely cause | Fix | | -------------------------------------------------------- | ---------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | | No `authsrv` entry in `swcutil show` | The Associated Domains payload did not reach the Mac | Re-deploy the Iru Access configuration profile from your MDM and confirm it is scoped to the device. | | Entry present but `Site/Fmwk Approval` is not `approved` | macOS has not validated the domain association, or the domain is wrong | Confirm the domain matches your Iru domain exactly, ensure the Mac can reach it over the network, then trigger a sign-in and re-check. | | `Flags` missing `enterpriseManaged` | The domains were not pushed by MDM | Use the MDM-delivered profile (managed deployment) rather than a hand-built one. | | `hasAssociatedDomainsApproved = 0` in AppSSOAgent | Domains not approved | Resolve the associated-domain approval above. macOS re-checks periodically and when the extension is next used. | | Extension missing from `pluginkit -v -m` | Iru Access not installed, or never launched | Deploy the app and launch it once so the extension registers. | After fixing a profile, approvals do not always refresh instantly. Trigger a sign-in to one of your Iru domains to prompt macOS to re-check, then re-run `sudo swcutil show`. ## Where to go next Set up the configuration profile, the app, and registration. The connection that pushes the profile and makes a device count as managed. Require managed, healthy devices as a condition of access. How Iru Access fits alongside passkeys as an authenticator. # Federated authentication connections Source: https://docs.iru.com/en/identity/connections/connections-overview Link Iru Identity to an identity provider your people already sign in with, to use Iru as an authentication layer or while migrating users onto it. A **connection** links Iru Identity to an external system you already run. In the dashboard, identity-provider connections live under **Access → Authentication**, and HR-system connections live under **Directory → Sync**. By default, Iru Identity is your **identity provider**: your users sign in directly with a passkey or the Iru Access app. An **identity provider connection** lets them sign in through a provider you already run instead, which is useful when you use Iru as an authentication layer into the Iru platform, or while migrating onto Iru Identity. Looking to sync users from an HR system? That's a separate, directory-side feature; see [Directory Sync](/en/identity/directory/directory-sync) under **Directory → Sync**. ```mermaid theme={null} flowchart LR people["Your people"] idp["Existing provider
(optional · migration)"] subgraph iru["Iru Identity"] signin["Sign-in"] end people -->|"sign in (passkey)"| signin idp -. "optional sign-in" .-> signin ``` These connections are how Iru reaches systems you already operate. To connect the apps your people *sign in to*, see [Applications](/en/identity/applications/applications-overview). For how Iru sits between your people, your providers, and your apps, see [System architecture](/en/identity/getting-started/system-architecture). ## Identity provider connections By default your users sign in to Iru directly. An identity provider connection lets them sign in through a provider you already operate instead. Reach for one in two situations: **When to connect an identity provider** * **Iru Identity as an authentication layer.** Every Iru tenant uses Iru Identity to manage admins and keep users in sync, but not every organization uses it as their full identity provider. If you use Iru mainly as the way users sign in to the Iru platform, connect the provider you already run so they can sign in with familiar credentials. * **Migrating to Iru Identity.** When you are moving from an existing provider to Iru Identity as your identity provider, connecting your current provider lets users keep signing in the usual way while you make the transition. Iru supports these connection types: | Type | Use it for | | ------------- | ------------------------------------------------------------------------------------------------- | | **Google** | Sign-in backed by Google accounts. A **Google Workspace** template pre-fills the connection. | | **Microsoft** | Sign-in backed by Microsoft accounts. A **Microsoft Entra ID** template pre-fills the connection. | | **SAML** | Any identity provider that speaks the SAML standard. | | **OIDC** | Any identity provider that speaks the OpenID Connect standard. | Iru also has a built-in sign-in option of its own, so you can connect an external provider for some users while others continue to sign in directly with an [authenticator](/en/identity/authentication/authenticators) such as a passkey. The **Google Workspace** and **Microsoft Entra ID** templates pre-fill the standard configuration so you only supply what is specific to your tenant. Reach for them before configuring a generic SAML or OIDC connection by hand. ### What you configure on every identity provider connection Each connection has one or more **use cases** that decide where it applies: * **End-user sign-in:** users use the connection to sign in to Iru and reach their apps. * **Device enrollment:** the connection is used while enrolling a device. You choose what a connection is used for, and a single connection can serve more than one use case. You can restrict a connection to one or more email **domains**, so only users whose email is in those domains use it. This lets you route different parts of your organization to different providers. When someone signs in through a connection, Iru matches them to a user in your [directory](/en/identity/directory/directory-overview) so the sign-in resolves to the right user. You choose what Iru matches on: | Match on | What it is | | -------------------- | ---------------------------------------------------------------- | | **UPN** | The user principal name the provider sends. | | **Username** | The user's username. | | **External ID** | An identifier carried from the provider. | | **Custom attribute** | A [profile attribute](/en/identity/directory/schema) you choose. | Pick the value that is stable and unique for every user, so each sign-in lands on exactly one user. Connect Google Workspace for end-user sign-in using the template. Connect Microsoft Entra ID for end-user sign-in using the template. Connect any SAML identity provider, with Iru acting as the service provider. Connect any OpenID Connect identity provider. ## Device trust signals Device health is not a connection. Signals such as whether a device is encrypted and healthy are reported by the **Iru Access** agent on each device, and your [authentication policies](/en/identity/authentication/authentication-policies) can require a known, healthy device before granting access. See [Device trust](/en/identity/authentication/device-trust). ## Where to go next See how connections relate to users, groups, applications, and policies. Shape what users see when they sign in through a connected provider. # Custom OIDC Source: https://docs.iru.com/en/identity/connections/custom-oidc Connect any OpenID Connect identity provider to Iru Identity for federated sign-in by registering Iru as a client and mapping claims to user attributes. When your identity provider speaks the **OpenID Connect (OIDC)** standard but is not covered by a ready-made template, connect it as a **custom OIDC** connection. Iru registers as a **client** of your provider: your provider authenticates the user and returns identity details to Iru, which Iru uses to start the session and match the user to an Iru user. Custom OIDC connections are **coming soon**. Google Workspace, Microsoft Entra ID, and custom SAML connections are available today. Most organizations that use Iru Identity as their identity provider have users sign in directly with a passkey or the Iru Access app. Connect an OIDC provider when you use Iru Identity as an authentication layer into the Iru platform rather than your primary identity provider, or to ease a migration onto Iru Identity. See [Federated Authentication](/en/identity/connections/connections-overview). You need administrator access to your Iru tenant, and administrator access to your OIDC identity provider, to complete this connection. ## Before you begin In your OIDC provider, create an application (client) for Iru, typically a **web** or **confidential** client that uses the authorization code flow. You will get a **client ID** and a **client secret** to enter into Iru. The exact steps live in your provider's console; follow its current documentation. Your provider needs to know where to send the user back after they sign in. Copy the **redirect URI** that Iru shows for this connection and add it to the list of allowed redirect URIs on your provider's application. Iru requests the standard OpenID Connect **scopes** (`openid`, `profile`, and `email`) so your provider returns the user's basic profile and email. Make sure your provider is configured to release the claim you plan to match on. Sign-in through a connection resolves to an existing Iru user. Add or import your users first; see [Importing users](/en/identity/directory/importing-users) or [Directory Sync](/en/identity/directory/directory-sync). ## Connect an OIDC provider In **Access → Authentication**, add an **authentication method** and choose **OIDC**. Provide the **client ID** and **client secret** from the application you registered with your provider, along with the details Iru needs to reach your provider's sign-in endpoints. Tell Iru which **claim** in your provider's response identifies the user - for example, the subject, email, or preferred username claim. This is the value Iru reads to recognize who signed in. Choose which Iru user value to match that claim against (UPN, username, external ID, or a custom attribute). Pick a value that is unique and stable for every user. See [user matching](/en/identity/connections/connections-overview#what-you-configure-on-every-identity-provider-connection). Select the connection's **use cases**: **end-user sign-in**, **device enrollment**, or both. If you want only users in specific email domains to use this connection, enable **domain restrictions** and add those domains. Save the connection, then sign in as a test user to confirm the hand-off: your provider authenticates the user, returns the identifying claim, and Iru matches them to the right user. The **user identifier claim** and your **user matching** choice work together: the claim is the value your provider sends, and matching decides which Iru user field it must equal. Choose a claim that your provider populates for everyone and that lines up with the Iru value you match on. ## How sign-in works once connected When someone signs in, Iru hands the sign-in off to your OIDC provider. The provider authenticates the user and returns identity claims, Iru matches them to an Iru user, and the session continues. Iru then evaluates the app's [authentication policy](/en/identity/authentication/authentication-policies) before granting access. For the full picture, see [System architecture](/en/identity/getting-started/system-architecture). ## Related Use cases, domain restrictions, and user matching, explained in one place. Connect an identity provider that uses SAML instead of OpenID Connect. Connect Google Workspace with its ready-made template. Connect Microsoft Entra ID with its ready-made template. # Custom SAML Source: https://docs.iru.com/en/identity/connections/custom-saml Connect any SAML 2.0 identity provider to Iru Identity for federated sign-in, with Iru acting as the service provider and mapping assertions to user attributes. When your identity provider speaks the **SAML** standard but is not covered by a ready-made template, connect it as a **custom SAML** connection. In this setup Iru acts as the **service provider (SP)**: your provider authenticates the user, then sends Iru a signed SAML response that Iru trusts to start the session. Most organizations that use Iru Identity as their identity provider have users sign in directly with a passkey or the Iru Access app. Connect a SAML provider when you use Iru Identity as an authentication layer into the Iru platform rather than your primary identity provider, or to ease a migration onto Iru Identity. See [Federated Authentication](/en/identity/connections/connections-overview). You need administrator access to your Iru tenant, and administrator access to your SAML identity provider, to complete this connection. Setting up SAML means exchanging a few values in both directions; this page walks through both sides. ## How the trust is established ```mermaid theme={null} sequenceDiagram participant Admin as You participant Iru as Iru (service provider) participant Idp as Your SAML provider Iru-->>Admin: Provide SP metadata, entity ID, and ACS URL Admin->>Idp: Register Iru as a service provider Idp-->>Admin: Provide entity ID, sign-in URL, signing certificate Admin->>Iru: Enter the provider's details and upload its certificate Note over Iru,Idp: Trust established; sign-in can be tested ``` Iru and your provider each need to trust the other. Iru gives you the details your provider needs to recognize Iru, and your provider gives you the details Iru needs to verify its responses. ## Before you begin From the connection in Iru, collect the values your provider will ask for - Iru's **SP metadata**, its **entity ID**, and its **ACS URL** (the address where your provider sends its SAML response). Many providers can import this in one step from the metadata. From your SAML provider, collect its **entity ID**, its **single sign-on URL**, and its **signing certificate** (the certificate Iru uses to verify the provider's signed responses). Sign-in through a connection resolves to an existing Iru user. Add or import your users first; see [Importing users](/en/identity/directory/importing-users) or [Directory Sync](/en/identity/directory/directory-sync). ## Connect a SAML provider In **Access → Authentication**, add an **authentication method** and choose **SAML**. Iru generates its service provider details for this connection. In your SAML provider, create a new application (relying party) for Iru and supply Iru's **entity ID** and **ACS URL**, or import Iru's **SP metadata** if your provider supports it. Configure the provider to release the **NameID** and any **attributes** you intend to match on. The exact relying-party screens live in your provider's console; follow its current documentation. Back in Iru, enter your provider's **entity ID** and **single sign-on URL**, then upload your provider's **signing certificate** so Iru can verify the SAML responses it receives. Tell Iru which value in the SAML response identifies the user: the **Subject** (NameID) or a named **attribute** the provider sends, and which Iru user value to match it against (UPN, username, external ID, or a custom attribute). See [user matching](/en/identity/connections/connections-overview#what-you-configure-on-every-identity-provider-connection). Select the connection's **use cases**: **end-user sign-in**, **device enrollment**, or both. If you want only users in specific email domains to use this connection, enable **domain restrictions** and add those domains. Save the connection, then sign in as a test user to confirm the round trip: Iru sends the request, your provider authenticates the user, and Iru matches them to the right user. Iru can also present a **request-signing certificate** so your provider can verify that sign-in requests genuinely came from Iru. If your provider expects signed requests, share Iru's request-signing certificate from the connection and enable signed requests on the provider side. ## Keeping the connection healthy The signing certificate you upload from your provider has an expiry date. When your provider rotates its certificate, upload the new one in Iru so sign-in keeps working. Plan the swap before the old certificate expires. This almost always traces back to **user matching**. Confirm the value your provider sends (the Subject or attribute) is present and unique for everyone, and that it matches the Iru user value you selected. ## Related Use cases, domain restrictions, and user matching, explained in one place. Connect an identity provider that uses OpenID Connect instead of SAML. See how federated sign-in fits into the wider identity layer. Shape what users see when they sign in. # Google Workspace Source: https://docs.iru.com/en/identity/connections/google-workspace Let users sign in to Iru Identity with their Google Workspace accounts using the built-in connection template for federated authentication and provisioning. Connecting **Google Workspace** lets your users sign in to Iru (and reach the apps you have assigned them) using the Google accounts they already have. Iru provides a **Google Workspace template** that pre-fills the standard configuration, so this is one of the quickest providers to connect. Most organizations that use Iru Identity as their identity provider have users sign in directly with a passkey or the Iru Access app. Connect Google Workspace when you use Iru Identity as an authentication layer into the Iru platform rather than your primary identity provider, or to ease a migration onto Iru Identity. See [Federated Authentication](/en/identity/connections/connections-overview). You need administrator access to your Iru tenant, and access to your Google Workspace administrator console, to complete this connection. ## Before you begin Note the email **domains** your users sign in with (for example, `yourcompany.com`). You can restrict the connection to these domains so only users in them use it. When someone signs in through Google, Iru matches them to a user in your directory. Decide which value to match on, typically the user's email or username. See [user matching](/en/identity/connections/connections-overview#what-you-configure-on-every-identity-provider-connection). Sign-in through a connection resolves to an existing Iru user. Add or import your users first; see [Importing users](/en/identity/directory/importing-users) or [Directory Sync](/en/identity/directory/directory-sync). ## Connect Google Workspace In **Access → Authentication**, add an **authentication method** and choose the **Google Workspace** template. Using the template fills in the standard settings for you. Follow the prompts to authorize Iru against your Google Workspace organization, signing in with a Google **super administrator** account when asked and consenting to the standard sign-in scopes (`openid`, `email`, and `profile`). If your organization provides its own OAuth client, create it in the Google Cloud Console, add the redirect URI Iru shows for this connection, and copy its client ID and secret into Iru. Google's console screens can change; follow Google's current documentation if the prompts differ. Select the connection's **use cases**: **end-user sign-in**, **device enrollment**, or both. Most setups enable end-user sign-in. If you want only users in specific email domains to use this connection, enable **domain restrictions** and add those domains. Choose how Iru matches a Google sign-in to an Iru user (by UPN, username, external ID, or a custom attribute). Pick a value that is unique and stable for every user. Save, then sign in as a test user whose email is in an allowed domain to confirm the hand-off to Google works end to end. Test with a single user before rolling the connection out broadly. If sign-in fails to land on the right user, revisit your **user matching** choice; the matched value must be present and unique for everyone who uses the connection. ## How sign-in works once connected When someone signs in, Iru hands the sign-in off to Google, Google confirms the user, and Iru continues the session before evaluating the app's [authentication policy](/en/identity/authentication/authentication-policies) before granting access. For the full picture, see [System architecture](/en/identity/getting-started/system-architecture). ## Related Use cases, domain restrictions, and user matching, explained in one place. Connect Microsoft Entra ID for sign-in with its own template. Shape what users see when they sign in. Connect a provider that is not covered by a template. # Microsoft Entra ID Source: https://docs.iru.com/en/identity/connections/microsoft-entra-id Let users sign in to Iru Identity with their Microsoft Entra ID accounts using the built-in connection template for federated authentication and provisioning. Connecting **Microsoft Entra ID** lets your users sign in to Iru (and reach the apps you have assigned them) using the Microsoft accounts they already have. Iru provides a **Microsoft Entra ID template** that pre-fills the standard configuration, so this is one of the quickest providers to connect. Most organizations that use Iru Identity as their identity provider have users sign in directly with a passkey or the Iru Access app. Connect Microsoft Entra ID when you use Iru Identity as an authentication layer into the Iru platform rather than your primary identity provider, or to ease a migration onto Iru Identity. See [Federated Authentication](/en/identity/connections/connections-overview). You need administrator access to your Iru tenant, and access to your Microsoft Entra ID administrator portal, to complete this connection. ## Before you begin In the Microsoft Entra admin center, **register an application** for Iru. Add the **redirect URI** Iru shows for this connection as a Web redirect URI, create a **client secret**, and grant the standard sign-in permissions (`openid`, `profile`, `email`, and `User.Read`), granting admin consent if your tenant requires it. Note the application's **client ID** and **client secret** and your Entra ID **domain** (for example, `contoso.onmicrosoft.com`) to enter into Iru. Microsoft's portal can change; follow Microsoft's current documentation if the steps differ. Note the email **domains** your users sign in with. You can restrict the connection to these domains so only users in them use it. Sign-in through a connection resolves to an existing Iru user. Add or import your users first; see [Importing users](/en/identity/directory/importing-users) or [Directory Sync](/en/identity/directory/directory-sync). ## Connect Microsoft Entra ID In **Access → Authentication**, add an **authentication method** and choose the **Microsoft Entra ID** template. Using the template fills in the standard settings for you. Provide your Microsoft Entra ID **domain**, the **client ID**, and the **client secret** from the application you registered. Iru uses these to establish trust with your Entra ID tenant. Select the connection's **use cases**: **end-user sign-in**, **device enrollment**, or both. Most setups enable end-user sign-in. If you want only users in specific email domains to use this connection, enable **domain restrictions** and add those domains. Choose how Iru matches a Microsoft sign-in to an Iru user (by UPN, username, external ID, or a custom attribute). Pick a value that is unique and stable for every user. Save, then sign in as a test user whose email is in an allowed domain to confirm the hand-off to Microsoft works end to end. If you intend to use this connection for **device enrollment**, you may need to enable **domain restrictions** first. Configure your domains before turning on the device enrollment use case. Test with a single user before rolling the connection out broadly. If sign-in fails to land on the right user, revisit your **user matching** choice; the matched value must be present and unique for everyone who uses the connection. ## How sign-in works once connected When someone signs in, Iru hands the sign-in off to Microsoft Entra ID, Entra ID confirms the user, and Iru continues the session before evaluating the app's [authentication policy](/en/identity/authentication/authentication-policies) before granting access. For the full picture, see [System architecture](/en/identity/getting-started/system-architecture). ## Related Use cases, domain restrictions, and user matching, explained in one place. Connect Google Workspace for sign-in with its own template. Shape what users see when they sign in. Connect an OpenID Connect provider that is not covered by a template. # Attribute mapping Source: https://docs.iru.com/en/identity/directory/attribute-mapping Map fields from a connected directory source to Iru Identity profile attributes, and transform values using IQL expressions before they reach user profiles. When Iru reads users from a connected source, it needs to know which incoming field fills which Iru profile attribute, and sometimes how to reshape the value along the way. You describe that with an **attribute mapping**: for each Iru profile attribute, you write an **expression** that produces its value from the source's fields. **Where attribute mapping applies.** You write attribute mappings when you **connect a source system** (the [Workday](/en/identity/directory/hris-workday) and [BambooHR](/en/identity/directory/hris-bamboohr) connectors, which expose their own fields for you to map. It does **not** apply to [CSV import](/en/identity/directory/importing-users): a CSV uses a fixed set of predefined columns, so there are no expressions to write. Mapping expressions are written in **IQL**, the same expression language Iru uses for [application claim and attribute mapping](/en/identity/getting-started/iql-expressions), Auto Group rules, and list filters. Here you'll map a connected **source system's** fields into your directory's [profile attributes](/en/identity/directory/schema); see [IQL expressions](/en/identity/getting-started/iql-expressions) for the full syntax. ## How a mapping works Each row in a mapping pairs one **target** (an Iru profile attribute) with an **expression** that draws from the **source** fields. ```mermaid theme={null} flowchart LR subgraph source["Source fields"] a["first_name"] b["email_work"] end expr["IQL expression"] --> target["Iru profile attribute"] a --> expr b --> expr ``` Iru reads the set of fields your source makes available. Those field names become the **identifiers** you can reference in expressions. See [Directory Sync](/en/identity/directory/directory-sync) for how discovery fits into setup. For each Iru attribute you want to fill, write an IQL expression. The simplest is just the source field name; more involved expressions combine or transform fields. Expressions are checked as you type and again when you save, so mistakes (an unknown field, a type error) surface before they ever reach a sync. When the sync runs, Iru evaluates each expression against the incoming row and writes the result to the attribute. Choose one stable, unique source field for the identifier that ties a source record to an Iru user, so each sync resolves to exactly one user. ## Writing expressions Expressions reference your source's fields and can transform them: upper/lower casing, splitting, concatenation, picking a list item, and so on. The full reference (objects, functions, operators, and examples) is on the [IQL expressions](/en/identity/getting-started/iql-expressions) page, since the same language powers both directory mapping and application mapping. A few quick examples: ``` // Use a field as-is work_email // Combine fields into a display name first_name + " " + last_name // The local part of an email, before the @ work_email.split("@")[0] ``` ## Where to go next The full IQL reference: objects, functions, operators, and examples. Connect an HR system and set up the mappings these expressions power. The targets your expressions write into. Another place attributes drive automation in your directory. # Auto groups Source: https://docs.iru.com/en/identity/directory/auto-groups Create groups in Iru Identity whose membership is computed from a profile attribute and updates itself automatically as user profiles change in the directory. An **Auto Group** decides its own membership. Instead of picking members by hand, you base the group on a [profile attribute](/en/identity/directory/schema), and Iru keeps the membership in sync: when a user's attribute value matches, they join; when it stops matching, they leave. Auto Groups appear in the same catalog as manual and built-in groups and are assigned to applications the same way. You never choose an Auto Group's members by hand; Iru computes them from a profile attribute and keeps them in sync as profiles change. ## How they work You enable Auto Groups on an attribute. From then on, Iru groups users by their value for that attribute and keeps each group's membership current. ```mermaid theme={null} flowchart LR attr["Attribute:
Department"] attr --> v1["Value: Engineering"] attr --> v2["Value: Sales"] attr --> v3["Value: Support"] v1 --> g1["Group: Engineering"] v2 --> g2["Group: Sales"] v3 --> g3["Group: Support"] ``` When an attribute drives Auto Groups, each distinct value becomes its own group. A user with `Department = Engineering` lands in the Engineering group; if their department later changes to Sales, Iru moves them out of the Engineering group and into the Sales group on its own. Attributes with a fixed list of **allowed values** are an especially clean fit, because the set of groups maps directly to the choices you defined. ## Membership updates automatically The defining trait of an Auto Group is that you never edit its members. They are recomputed from profiles, so membership stays correct as your directory changes: * **A new user** whose attribute matches is added to the group. * **An existing user** whose attribute changes is moved to the group that now matches. * **A user** whose value no longer matches, or who is removed, drops out of the group. Because access assigned to the group follows its membership, granting an app to an Auto Group means access tracks the attribute. Set it up once, and users gain and lose access as their profiles change, with no manual edits and no stale membership. You can't hand-pick members of an Auto Group; that's the point. To change who's in it, change the underlying profile data, or adjust which attribute drives the grouping. For ad-hoc membership, use a [manual group](/en/identity/directory/groups) instead. ## Relationship to attributes Auto Groups are only as good as the attribute behind them. Because each value becomes a group, an attribute with a fixed set of **allowed values** gives you a predictable, tidy set of groups, while a free-text attribute can produce a group for every distinct value users enter. For attributes that should drive groups, define them as fixed-choice (enumeration) attributes in your [schema](/en/identity/directory/schema). You'll get one group per allowed value and avoid surprise groups from typos or inconsistent entries. Turning Auto Groups off for an attribute, or removing the attribute, also removes the groups it produced and any access that depended on them, so review what's assigned before you change it. ## Roll Auto Groups up into a manual group An Auto Group can be a **member of a manual group**, which lets you combine several Auto Groups under one umbrella. Grant access (or attach a policy) to the manual group, and everyone in the nested Auto Groups is included automatically. For example, if a **Region** attribute drives one Auto Group per region, create a manual **Super Region - Americas** group and add the **US**, **Canada**, and **Brazil** Region groups to it. Anyone in those regions rolls up into the umbrella group through their Auto Group, with no manual upkeep, and as users change regions, the umbrella membership follows. Nesting goes one way: an Auto Group can be a **member** of a manual group, but an Auto Group's own membership is always computed from its attribute; you can't hand-add members to it. See [Groups](/en/identity/directory/groups) for how manual groups nest other groups. ## Put it together In your [schema](/en/identity/directory/schema), create or choose the attribute that should drive grouping, ideally one with a fixed list of allowed values. Flag the attribute to drive Auto Groups. Iru creates a group for each value and computes its membership from your users' profiles. Assign the Auto Groups to applications just like any other group. See [Assigning access](/en/identity/applications/assigning-access). As profiles change, membership and the access that follows it stay current on their own. ## Next steps Create the fixed-choice attributes that make the best Auto Groups. Compare Auto Groups with manual and built-in groups. # Directory overview Source: https://docs.iru.com/en/identity/directory/directory-overview The authoritative record of your people: users, the profile attributes that describe them, and the groups you organize them into. The **Directory** is where you manage who your people are. It holds your **users**, the **profile attributes** that describe each one, and the **groups** you organize them into. Everything else in Iru Identity builds on the directory: applications grant access to its users and groups, and authentication policies decide how those users sign in. In the dashboard, the Directory brings these sections together: Each user in your organization, with a profile, a status, and a record of how they were added. The schema of built-in and custom fields that every user profile can hold. Collections of users you assign access to as a unit (manual, built-in, or auto. Groups whose membership is computed from an attribute and stays current on its own. Bring users in, in bulk from a file, and review the results. Sync users from an HRIS or directory solution so the directory stays current automatically. The role each user holds, which governs what they can do in Iru. ## What lives in the directory ```mermaid theme={null} flowchart TD subgraph dir["Directory"] users["Users
everyone in your organization"] attrs["Profile attributes
built-in and custom fields"] groups["Groups
manual, built-in, auto"] end attrs --- users users --- groups attrs -. "can drive" .-> groups groups -->|"assigned to"| apps["Applications"] ``` * **Users** are everyone in your organization represented in the directory. Each has a profile, a sign-in identity, and a status that reflects where they are in their lifecycle. * **Profile attributes** are the fields a profile can hold: built-in facets such as name, email, and phone, plus any custom attributes you define in your [schema](/en/identity/directory/schema). * **Groups** are collections of users. You assign access to a group once, and everyone in it inherits that access. See [Groups](/en/identity/directory/groups). ## How users get into the directory There are three ways to add users, and you can mix them as your needs change. Create a user by hand from **Directory → Users**. Best for a few users or a quick test. Upload a CSV to create many users at once. See [Importing users](/en/identity/directory/importing-users). Connect an HR system so users are created, updated, and removed automatically on a schedule. See [Directory Sync](/en/identity/directory/directory-sync). Every user records a **source**, where they originated, such as added manually, imported from a file, or synced from a connected HR system. The source appears in the users list so you can always see how someone got into the directory. Manual entry and CSV import are great for getting started. When your HR system is the system of record for who works at your company, connect it so the directory keeps itself current as users join, change roles, and leave. ## The user lifecycle People join, move, and leave your organization, and their directory record follows along through a small set of statuses. ```mermaid theme={null} flowchart LR join["Joins"] --> pending["Pending"] pending -->|"first sign-in / activation"| active["Active"] active -->|"on leave / offboarding"| suspended["Suspended"] suspended -->|"returns"| active active -->|"leaves permanently"| removed["Removed"] suspended -->|"leaves permanently"| removed ``` | Status | What it means | | ------------- | --------------------------------------------------------------------------------------------------------------------------- | | **Pending** | The user has been created but is not yet active. This is the starting point for a freshly added or imported user. | | **Active** | The user is fully enabled and can sign in and reach the apps assigned to them. | | **Suspended** | The user's access is blocked, but their record and history are kept. Use this when someone is on leave or being offboarded. | Suspending is reversible; you can reinstate a suspended user, and they return to the status they held before. Removing a user is permanent and is meant for users who have left for good. The difference between suspending and removing, and how to invite users to finish setting up their accounts, is covered in [Users](/en/identity/directory/users). ## Where the directory is used The directory is the foundation the rest of Iru Identity stands on: * **Applications** grant access through assigned groups, and map profile attributes into the identity details each app receives. See [Assigning access](/en/identity/applications/assigning-access). * **Authentication policies** evaluate the user signing in and decide what they must prove. See [Authentication policies](/en/identity/authentication/authentication-policies). * **Auto Groups** read profile attributes to compute their membership automatically. See [Auto Groups](/en/identity/directory/auto-groups). New to Iru Identity? Start with [Key concepts](/en/identity/getting-started/key-concepts) for the full set of objects, then follow the [Quickstart](/en/identity/getting-started/quickstart) to stand up your first sign-on. # Directory Sync Source: https://docs.iru.com/en/identity/directory/directory-sync Keep your directory current by connecting an HRIS or directory solution for automatic sync, or import users from a file. Keep your [directory](/en/identity/directory/directory-overview) populated and up to date from the system that's the source of truth for who's in your organization. There are two ways to do it: Link a **live source** (an **HRIS** such as **Workday** or **BambooHR**, or another **directory solution**) and Iru pulls users from it and syncs on a schedule, creating, updating, and removing users on its own. More providers are on the way. No direct connector for your system? Export your users to a **CSV** (from a legacy HR system, a **Student Information System (SIS)**, or anything you can produce a file from) and upload it. Re-upload an updated export whenever your list changes to keep users current. When you connect a live source, updates flow into Iru on their own, so when someone is hired, changes roles, or leaves, your directory follows with no manual work. The rest of this guide covers connecting a source system; for the manual route, see [CSV import](/en/identity/directory/importing-users). Today you can connect the HR systems **Workday** and **BambooHR**, with more providers (including other directory solutions) on the way. Setup is the same guided flow for each; only a couple of steps differ by provider. Connecting a source system needs administrator access to your Iru tenant and administrator credentials for that system. The connection only **reads** users from the source; it never writes back to it. The Directory page in Iru on the Sync tab, listing connected sources with their status. ## How it works at a glance 1. **Choose** your provider. 2. **Connect:** enter credentials so Iru can read your user data. 3. **Configure** (some providers only): tell Iru where your data lives. 4. **Map** the source's fields to Iru fields. 5. **Enable:** turn on syncing and choose how often it runs. ```mermaid theme={null} flowchart LR connect["Connect
+ credentials"] --> discover["Iru reads
available fields"] discover --> map["Map fields
source → Iru"] map --> enable["Enable"] enable --> sync["Scheduled or
on-demand sync"] sync -->|"create / update / remove"| dir["Directory"] sync -->|"problems"| errors["Sync errors to review"] ``` Once a connection is enabled, Iru syncs on the **interval** you set, from every **30 minutes** up to once per **week**, or **manual only** if you prefer to run syncs yourself with **Sync now**. ## Ideas that apply to every connection * **Your source system leads.** Once connected, it's the authority on user data; Iru reflects what it sends. * **Every user needs a stable ID.** You pick one field that uniquely and permanently identifies each user, so Iru always updates the right record. * **You decide how fields line up.** Iru doesn't guess. You map each source field to the matching Iru field, and can transform values with **IQL** when they don't line up one-to-one. ## Set it up In **Directory → Sync**, select **Connect Source** and pick your provider: **Workday** or **BambooHR**. The Select user source picker opened from Connect Source, offering Workday, Bamboo, and an Other Sources option marked Coming Soon. Give the connection a **display name** (and optional **description**), then enter the credentials Iru needs for that provider. Iru submits them in the setup form; there is no separate provider consent window. * **Workday:** instance host, Workday tenant, Integration System User, and password. * **BambooHR:** company domain and API key. See the [provider guides](#choose-your-provider) for the exact fields. The Connect with Bamboo step with Display name, Description, Company domain, and API key fields. The Connect with Workday step asking for Integration user and Password. Use a dedicated admin / integration account where you can, so the connection keeps working regardless of any one user's status. Some providers need you to point Iru at the right data source. **Workday** asks for the **report name** that exposes the worker fields you want; the Integration System User from the previous step is what runs that report. **BambooHR** reads its standard employee directory, so it skips this step. See the [provider guides](#choose-your-provider) below. Iru reads the fields your provider makes available and lays them out for you to match. See [Map your data](#map-your-data) below. Save your mappings to finish setup. A new connection starts **disabled**, so nothing syncs until you've reviewed it, then **Enable** it to run the first import. Set the **sync interval** on the connection's Configuration tab, or leave it on **Manual only** and use **Sync now** when you want an update. ## Map your data Mapping is where most of the setup happens: connecting your source's fields to the matching fields in Iru. The Mapping tab of a connection, showing the Unique user identifier field and an Attributes list mapping Bamboo fields (firstName, lastName, workEmail) to Iru attributes (name.firstName, name.lastName, primaryEmail.email), with some values built from IQL expressions. ### Set a unique identifier Choose the field that uniquely identifies each user, often an **employee ID** or similar stable identifier. Iru relies on one stable value per user to update the *right* record on every sync, even when names or emails change. Pick something that never changes for a user. **Once you save the connection, the unique identifier can't be changed.** Changing it would break Iru's ability to recognize the users it has already imported. ### Match fields to Iru For each Iru attribute, pick the source field that should fill it. Four attributes are **required** and always mapped: * **Email** * **First name** * **Last name** * **Username** Any attribute you've marked required in your [schema](/en/identity/directory/schema) is required here too. Everything else is optional, but mapping it brings over the full picture of each user: title, department, manager, location, and more. ### Transform values with IQL Most fields are a simple pick-and-go. When the value you want needs to be *built* from a field rather than copied as-is, write a short **IQL** expression instead. As you type, Iru suggests the available fields and checks your expression, so you catch a typo or a missing field *before* you save, not during a sync. See [Attribute mapping](/en/identity/directory/attribute-mapping) and [IQL expressions](/en/identity/getting-started/iql-expressions) for the full syntax. Common examples (use your provider's own field names): * **Build a username from an email** (everything before the `@`): `email.split("@")[0]` * **Combine two fields** into one value: `firstName + " " + lastName` * **Prefer one field, fall back to another** when the first is blank: `optional.ofNonZeroValue(workEmail).orValue(homeEmail)` If a field is sometimes blank, guard against it so the sync doesn't trip on empty records. Wrap the value with `optional.ofNonZeroValue(...).orValue("")` before transforming it. For example, only deriving a username when an email exists: `optional.ofNonZeroValue(email).orValue("").split("@")[0]` ## Choose your provider The flow is the same for each; these guides cover the steps that differ. Read workers from a Workday report. Includes the report and integration-user step. Read from BambooHR's standard employee directory. No report to configure. | Step | Workday | BambooHR | | -------------------------------------------- | ------- | -------------------- | | Connect with credentials | Yes | Yes | | Configure a report | Yes | No (standard fields) | | Map fields (unique ID, required fields, IQL) | Yes | Yes | | Enable and sync on a schedule | Yes | Yes | ## What happens on each sync Once enabled, Iru syncs on the interval you choose and reconciles your directory with the source system: | Change at the source | What Iru does | | --------------------------- | ----------------------------------------- | | A new user appears | Creates a matching user in your directory | | A user's details change | Updates the user's profile attributes | | A user is no longer present | Removes the user from your directory | As profiles arrive and change, [Auto Groups](/en/identity/directory/auto-groups) update their membership automatically, so access follows users without manual work. The Effective Users tab of a connection, listing synced users such as Ashley Adams and Charlotte Abbott with their created date and ID. ## Sync schedule and on-demand sync On a connection's **Configuration** tab, set **Sync frequency** with the **Interval** control. Choose how often Iru pulls the latest directory, or set it to **Manual only** and sync on demand. Available intervals: * Manual only (no automatic sync) * Every 30 minutes * Every hour * Every 2 hours * Every 4 hours * Every 8 hours * Every 12 hours * Every day * Every 2 days * Every week The Sync schedule section with the Interval menu open, listing Manual only and options from Every 30 minutes through Every week. On the **Sync** tab, use **Sync now** to start a run immediately, and **Refresh** to reload the list of sync runs. Each run reads everyone from your directory source and adds or updates them in Iru. Select a run to see what it did and anything it could not sync. A failed run tries again at the next scheduled sync. ## Manage the connection over time From a connection's detail page you can: * **Re-authenticate:** submit fresh credentials when they expire or change, without touching your mappings. * **Edit your configuration or mappings:** adjust what's imported as your needs evolve. * **Set the sync interval** or run **Sync now**. * **Force attribute sync** (Workday): re-read the latest available fields from your report without waiting. * **Review activity, effective users, and sync errors:** see what's flowing in and spot anything that needs attention. * **Enable or disable** the connection, or remove it. The Configuration tab of a Bamboo connection showing Status Enabled, connection details with Needs re-authentication, and a Re-authenticate action in the row menu. On the **Directory → Sync** list, each connection shows whether it is **Enabled** or **Disabled**, plus a connection-health value: | Health | What it means | | --------------------------- | --------------------------------------------------------------------------------------- | | **Connected** | Iru can authenticate to the source with the credentials on file. | | **Needs re-authentication** | Credentials are missing, expired, or rejected. Re-authenticate before sync can succeed. | | **Not connected** | The connection is not ready to authenticate (for example, setup was left incomplete). | On the connection's **Configuration** tab, **Connection details** shows the same health for that provider. Use **Re-authenticate** to submit current credentials. Your attribute mapping is not affected. * **BambooHR:** re-enter the company domain and API key. * **Workday:** re-enter the Integration user and password. The Re-authenticate Workday dialog with Integration user and Password fields, noting that attribute mapping is not affected. Sync problems show up in two stages. Knowing which stage failed tells you where to look first. * **Pull-stage errors** happen when Iru cannot read from the source: bad or expired credentials, an unreachable instance, a missing report, or a rejected API call. Fix the connection (often with **Re-authenticate** or by correcting the report / domain settings), then run sync again. * **Apply-stage (sync) errors** happen after Iru has the records but cannot create or update a particular user in your directory. Iru records a **sync error** you can review: when it occurred, the affected user, the action Iru attempted, an error code, and a message. If many records fail with the same error, the cause is usually a mapping: a required attribute left unmapped, or a unique identifier that isn't actually unique. Fix the mapping, then let the next sync run. The Activity tab of a connection showing a FAILED entry and an expanded error detail explaining that a user could not be provisioned because a required attribute was missing. ## Related The Workday-specific setup, including the report step. The BambooHR-specific setup. The IQL you use to shape incoming values. The attributes your source fields map into. # Groups Source: https://docs.iru.com/en/identity/directory/groups Use manual, built-in, and auto groups in Iru Identity to assign application access to users as a unit, and learn how to grant access through group membership. A **group** is a collection of users that you assign access to as a unit. Grant an application to a group once, and everyone in the group inherits that access, so you manage access by editing membership instead of touching each user. You manage groups in **Directory → Groups**, where a single catalog lists every group with its name, description, type, and direct member count. The Groups tab of the Directory showing two groups: 'Accuhive Brands' of type Manual and 'Domain - accuhive.com' of type Auto, each with a direct member count. ## The three kinds of group Iru Identity has three kinds of group. They share the catalog and are all assignable to applications; what differs is how membership is decided. You choose the members yourself, and can nest other groups. Membership changes only when you change it. Provided automatically for every organization, for example a group that contains all your users. Membership is computed from a profile attribute and updates itself as profiles change. **Manual Groups** and **Auto Groups** each have their own guide; **built-in groups** are covered just below. ### Built-in groups **Built-in groups** exist for every organization without any setup. The primary example is a group that always contains **all users**, a convenient way to grant something to everyone. Because they are managed by Iru, their membership is maintained for you. ## Which kind should you use? Use an **[Auto Group](/en/identity/directory/auto-groups)**. If everyone in "Engineering" or everyone in a given office should get the same access, base the group on the attribute that says so. Membership then maintains itself as users join, move, and leave. Use the **built-in all-users group**. It's the simplest way to grant something to your whole organization. Use a **[manual group](/en/identity/directory/manual-groups)**. For a project team or a one-off set of users, pick the members yourself and nest other groups inside when it helps. ## Assigning access to groups Groups exist so you can grant access to many users at once. You assign a group to an application the same way you assign an individual. Everyone in the group, including members of any nested groups, gains access. ```mermaid theme={null} flowchart LR u1["User"] --> g["Group"] u2["User"] --> g nested["Nested group"] --> g g -->|"assigned to"| app["Application"] app --> access["Effective access
for all members"] ``` The full set of users who end up with access through a group is the application's **effective users**. Removing someone from the group removes their access; adding someone grants it, with no change to the application itself. Assign access to **groups** rather than individuals wherever you can, and base those groups on **attributes** where a rule fits. Access then follows your directory automatically. That's lifecycle automation in Iru Identity. See [Assigning access](/en/identity/applications/assigning-access) for the full assignment workflow. ## Next steps Build a group by hand, and nest groups for roll-ups. Compute group membership from a profile attribute. Shape the profile fields that Auto Groups build on. Assign groups to applications and review effective users. # Connect BambooHR Source: https://docs.iru.com/en/identity/directory/hris-bamboohr Connect BambooHR to Iru Identity so it reads the standard employee directory and keeps your Iru directory in sync as workers join, change, or leave. Connecting **BambooHR** lets Iru pull employee records straight from BambooHR and keep your [directory](/en/identity/directory/directory-overview) in sync. When someone is hired, changes roles, or leaves, those updates flow into Iru on their own. BambooHR setup is quick: **connect**, then **map your fields**. There's no report to configure. Iru reads directly from BambooHR's standard employee directory. For the BambooHR-specific steps only. For concepts shared across all sync connections (the unique identifier, required fields, IQL, and what happens on each sync), see [Directory Sync](/en/identity/directory/directory-sync). In **Directory → Sync**, select **Connect Source** and pick **BambooHR**. Give the connection a **display name** and an optional **description**. Enter your BambooHR **company domain** (the subdomain in your BambooHR URL, such as `acme` from `acme.bamboohr.com`) and an **API key** generated from your BambooHR account. Iru submits these credentials directly; there is no separate BambooHR window. Iru stores the API key encrypted and does not show it again after you save. The Connect with Bamboo step with Display name, Description, Company domain, and API key fields. Use a dedicated admin or integration account to generate the API key, so the connection keeps working regardless of any one user's status. BambooHR has a **standard set of employee fields** (first and last name, work and home email, phone numbers, job title, department, supervisor, hire date, address, and employee ID), so Iru already knows what's available and lays them out for you to match. There's nothing to build on the BambooHR side first. * **Set a unique identifier**, typically the BambooHR **employee ID**. Once you save the connection, it can't be changed. * **Map the required attributes:** **email, first name, last name, and username** must be mapped; everything else is optional. * **Transform with IQL when needed:** pick a field, or write a short IQL expression. Iru suggests the available BambooHR fields and checks the expression as you type. Examples with BambooHR fields: * Build a username from the work email: `workEmail.split("@")[0]` * Combine first and last name: `firstName + " " + lastName` * Prefer work email, fall back to home email: `optional.ofNonZeroValue(workEmail).orValue(homeEmail)` See [Map your data](/en/identity/directory/directory-sync#map-your-data) for more on mapping, including the safe pattern for sometimes-blank fields. Save your mappings. You'll land on the connection's detail page. Review everything, then **Enable**. A connection starts **disabled**, so enabling it kicks off the first import and keeps Iru in sync. On the detail page you can later **re-authenticate**, **edit your mappings**, set how often Iru syncs, run **Sync now**, and **review activity, effective users, and sync errors**. The Configuration tab of a Bamboo connection showing Needs re-authentication and a Re-authenticate action. **Coming from Workday?** BambooHR is a little simpler: Workday has an extra step where you point Iru at a custom report, while BambooHR reads its standard employee directory, so you go straight from connecting to mapping. Everything else (the unique identifier, required fields, and IQL) works the same way. ## Related The shared concepts behind every Directory Sync provider. The other supported HR system. Includes a report step. # Connect Workday Source: https://docs.iru.com/en/identity/directory/hris-workday Connect Workday to Iru Identity so it reads workers from a custom report and keeps your Iru directory in sync as people are hired, transferred, or terminated. Connecting **Workday** lets Iru pull worker records straight from a Workday report and keep your [directory](/en/identity/directory/directory-overview) in sync: when someone is hired, changes departments, or leaves, those updates flow into Iru on their own. For the Workday-specific steps only. For concepts shared across all sync connections (the unique identifier, required fields, IQL, and what happens on each sync), see [Directory Sync](/en/identity/directory/directory-sync). In **Directory → Sync**, select **Connect Source** and pick **Workday**. Give the connection a **display name** and an optional **description**. Enter the **instance host** and **Workday tenant** so Iru knows which Workday environment to call, then continue. Enter the **Integration user** (the Workday Integration System User that runs the report) and its **Password**. Iru submits these credentials directly; there is no separate Workday consent window. Iru stores the password encrypted and does not show it again after you save. The Connect with Workday step asking for Integration user and Password, with helper text that the account should be an Integration System User with access to the report. Use a dedicated Integration System User rather than a personal login, so the connection keeps working as users come and go. This is not the report owner. Enter the **report name** Iru should run. Everything Iru imports comes from the columns in that report, so make sure it includes every field you care about (email, name, department, manager, employee ID, and so on). Iru reads your report's columns and lays them out to match to Iru attributes. * **Set a unique identifier:** choose the column that uniquely identifies each user, usually an **employee ID**. Once you save the connection, it can't be changed. * **Map the required attributes:** **email, first name, last name, and username** must be mapped; everything else is optional. * **Transform with IQL when needed:** pick a column, or write a short IQL expression to build a value. Iru suggests your report's column names and checks the expression as you type. Examples (illustrative; use your report's own column names): * Build a username from an email: `email_work.split("@")[0]` * Combine two columns: `first_name + " " + last_name` * Prefer one column, fall back to another: `optional.ofNonZeroValue(email_work).orValue(email_home)` See [Map your data](/en/identity/directory/directory-sync#map-your-data) for more on mapping, including the safe pattern for sometimes-blank fields. Save your mappings. You'll land on the connection's detail page; review everything, then **Enable**. A connection starts **disabled**, so enabling it kicks off the first import and keeps Iru in sync. On the detail page you can later **re-authenticate**, **edit your report or mappings**, set how often Iru syncs, run **Sync now**, and **review activity, effective users, and sync errors**. The Re-authenticate Workday dialog with Integration user and Password fields. ## Related The shared concepts behind every Directory Sync provider. The other supported HR system, simpler and with no report step. # Importing users Source: https://docs.iru.com/en/identity/directory/importing-users Bulk-create and update Iru Identity users from a CSV file, with required columns, validation rules, re-upload behavior, and when to use HR sync instead. Import users in bulk from a **CSV** file when you need to add or update more than a handful at once. Each imported user carries the **`csv`** source tag, and re-uploading an updated file keeps them in sync. CSV import works well for initial loads and one-off updates. If your HR system is the ongoing source of truth, use [HR sync](#when-to-use-hr-sync-instead) instead. You can also include [custom attributes](/en/identity/directory/schema#custom-attributes) you have defined as columns in the file. In **Directory → Users**, click the arrow next to **+ User**, then choose **Import via CSV**. Re-upload whenever your list changes. You can combine CSV import with HR sync: many teams seed the directory with a CSV, then connect their HR system to keep it current. See [when to use HR sync](#when-to-use-hr-sync-instead). ## File requirements | Requirement | Detail | | ------------------------------------ | --------------------------------------------------------------------------------------- | | **Format** | Comma-separated values (`.csv`). | | **Encoding** | UTF-8. A leading byte-order mark (as Excel adds) is accepted and ignored. | | **First row** | A **header row** naming the columns. | | **Header names (core columns)** | **Case-sensitive** and must match exactly (`externalId`, not `ExternalID`). | | **Header names (custom attributes)** | Use `categorySlug.attributeSlug`. Capitalization and spacing in the header are ignored. | | **Maximum rows** | 50,000 data rows per upload. | | **Maximum file size** | 16 MB. | Imports are **all-or-nothing**. If the file has a structural problem, or any row fails validation, **nothing is imported**. Iru returns a report of every problem so you can fix the file and upload again. ## Columns The import dialog lists every column your file can include: required core columns, optional core columns, and any custom attribute columns from your [schema](/en/identity/directory/schema). Use the sample from **Download sample.csv** as your header template. When your column names match the sample, each row's values populate the matching profile fields on the user identified by `externalId`. ### Required Every row must include a non-empty value for each of these columns. | Column | Description | Rules | Example | | ------------ | --------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | ---------------------- | | `externalId` | Your stable identifier for the user; used to match rows on re-upload. | Non-empty; **unique within the file**. | `EMP-10482` | | `username` | The user's login username. | Non-empty. | `jane.doe` | | `email` | The user's primary email address. | A valid, **bare** address (no display name; `Jane ` is rejected). | `jane.doe@example.com` | | `firstName` | Given name. | Non-empty. | `Jane` | | `lastName` | Family name. | Non-empty. | `Doe` | ### Optional Leave a cell blank, or omit the column entirely, when a value is not needed. If `domain` is blank, Iru derives it from the email address. | Column | Description | Rules | Example | | --------------- | --------------------------- | ---------------------------------------------------------------------------------------- | --------------- | | `domain` | The user's domain. | If blank, derived from the part of `email` after `@`. Set it only when it should differ. | `example.com` | | `streetAddress` | Street line of the address. | Free text. | `123 Main St` | | `locality` | City or town. | Free text. | `San Francisco` | | `region` | State, province, or region. | Free text. | `CA` | | `postalCode` | Postal or ZIP code. | Free text. | `94105` | | `country` | Country. | Free text (for example an ISO country code). | `US` | | `phone` | Phone number. | Normalized to E.164; see [Phone numbers](#phone-numbers). | `+14155550101` | ### Custom attributes After you define custom attributes in your schema, the import dialog lists them under **Custom attribute columns**, named `categorySlug.attributeSlug` from the category slug and attribute slug. For example, `department` and `title` in a category whose slug is `extrainfo` appear as `extrainfo.department` and `extrainfo.title`. Add one column per attribute to your CSV header. Core column names must match exactly; custom attribute column names ignore capitalization and spacing. ### Sample file In the import dialog, click **Download sample.csv** for a starter file with all core columns and one example user. If your schema includes custom attributes, click the arrow next to **Download sample.csv**, then choose **With custom attributes**. That sample adds a column for each custom attribute in your schema and leaves those cells blank in the example row so you can fill them in. The core columns and example user stay the same. Replace the example user with your own rows and keep the header names unchanged. You do not need every optional column in every row. A row can include only the required columns, a partial address, or a phone number with or without a country code. Leave `domain` blank when it should match the email address, and leave custom attribute cells blank when you have no value for a user. ## Field behavior ### Domain derivation * If `domain` is **blank**, Iru takes it from the email address (`jane.doe@example.com` becomes `example.com`). * If `domain` is **provided**, that value is used as-is. * A domain that does not already exist is created automatically. ### Phone numbers Phone values are normalized to **E.164** (a leading `+`, country code, then digits, with no spaces or punctuation), the same way phone numbers are stored everywhere else in Iru Identity. | You enter | Stored as | Why | | ----------------- | --------------- | -------------------------------------------------------------------- | | `4155550101` | `+14155550101` | No country code; the default **`+1`** (North America) is added. | | `(415) 555-0101` | `+14155550101` | Separators removed, `+1` added. | | `14155550101` | `+14155550101` | Recognized as a North American number that already includes the `1`. | | `+14155550101` | `+14155550101` | Already E.164; kept as-is. | | `+44 7911 123456` | `+447911123456` | International (`+` present); country code kept, separators removed. | | `1-800-FLOWERS` | *rejected* | Contains letters. | | `555-0101` | *rejected* | Too few digits to be a valid number. | Numbers outside North America must include a `+` and their country code (for example `+44…`). Without a leading `+`, a number is assumed to be a 10-digit North American number and gets `+1`. ### Addresses Iru stores an address whenever **any** address column has a value. A partial address (only `locality` and `country`, for example) is fine; missing parts stay blank. If every address column is blank, no address is stored. ## Run the import The **Import users via CSV** dialog shows the required and optional core columns, any custom attribute columns from your schema, and **Download sample.csv** with an arrow for **With custom attributes**. Drag a file onto the upload area or browse to select one. In **Directory → Users**, click the arrow next to **+ User**, then choose **Import via CSV**. Review the column list in the dialog against the tables above. Click **Download sample.csv** for a file with core columns and one example user. If your file includes custom attribute columns, click the arrow next to **Download sample.csv**, then choose **With custom attributes**. Replace the example user with your own rows and keep the sample header names so each row maps to the right user and profile fields. Select your CSV or drag it onto the upload area. Iru validates the whole file first. If validation passes, rows are accepted and users are created or updated in the background. If validation fails, the dialog shows a report and nothing is imported. A successful upload reports how many users were staged and adds the import to your history, where you can review the outcome for each row. Users created by the import are **pending** until they finish setup. Invite them in [bulk](/en/identity/directory/users#resend-invites-in-bulk) from the users list, or [one at a time](/en/identity/directory/users#resend-an-invite-for-one-user) from a user record. See [Inviting users](/en/identity/directory/users#inviting-users) for how invitations work, including which email they go to. After you upload, Iru validates the entire file. If validation fails, nothing is imported. Fix the reported problems and upload again. When validation passes, rows are accepted and staged, and users are created or updated in the background. Check the import in your history to confirm each row. A row can still fail at apply time after the file is accepted; correct those rows and re-import them. See [Validation and errors](#validation-and-errors) for the two stages of checks. ## Create vs. update: re-uploading Users are matched on `externalId` within the `csv` source: * A **new `externalId`** creates a new user with the **`end-user`** role. * An **existing `externalId`** updates that user's profile from the row. Role and group memberships do not change. Re-upload a corrected or expanded CSV at any time to keep imported users in sync. Every `externalId` in a file must be unique. Re-upload the **complete** current file each time, not just the rows you changed. Each import is matched on `externalId`. ## Validation and errors Validation runs in two stages. Until the file is fully accepted, **nothing is imported**. The file cannot be processed. Common causes include a duplicate column, a missing required column, an empty file, a header with no data rows, or more rows than the limit. Fix the file and upload again. The file is well-formed, but one or more rows are invalid. Iru returns every problem with the **line** (the header is line 1, so the first data row is line 2), the **column** at fault (blank for whole-row issues), and a **message**. For example: | Line | Column | Message | | ---- | ------------ | ---------------------------- | | 3 | `email` | is not a valid email address | | 5 | `username` | is required | | 8 | `phone` | is not a valid phone number | | 9 | `externalId` | is duplicated in this file | Fix the listed rows and re-upload. After a file is accepted, rows are applied in the background. A row can still fail at this stage if, for example, the email is already in use by another user or a value conflicts with a [unique attribute](/en/identity/directory/schema). These **apply errors** are recorded on the import batch with the row's `externalId`, `username`, and error details. Correct those rows and re-import them. ## When to use HR sync instead Re-upload a CSV whenever your list changes and Iru re-checks every row. For continuous, hands-off provisioning, connect your HR system as the authoritative record instead. | | CSV import | HR system sync | | ------------------- | ------------------------------- | -------------------------------------- | | **Trigger** | You upload a file | Runs automatically on a schedule | | **Keeps current?** | When you re-upload | Yes (re-syncs automatically) | | **Create / update** | Both, matched on `externalId` | Both, automatically | | **Removal** | Manual | Can remove users as they're offboarded | | **Best for** | Initial loads, ad-hoc additions | Ongoing lifecycle automation | You can use both. Setup for HR sync is covered in [Directory Sync](/en/identity/directory/directory-sync). ## Next steps Automate creates, updates, and removals on a schedule. Define required and unique attributes before you import. Edit, suspend, and invite the users you've imported. Turn your imported users into assignable groups. # Manual Groups Source: https://docs.iru.com/en/identity/directory/manual-groups Groups whose members you choose by hand, including nesting other groups, for teams and ad-hoc sets of users that don't follow a rule. A **manual group** is one you build by hand: you add and remove members directly, and the membership stays exactly as you set it. Reach for a manual group when membership doesn't follow a rule: a project team, a pilot cohort, or any ad-hoc set of users. ## Direct members and effective users A manual group's **direct members** are whatever you add to it by hand, and a member can be a **user** or **another group**, including an **Auto Group**. Nesting groups lets you model your organization and roll smaller groups up into larger ones. The group's page reflects this with two views: * **Members:** the **direct members** you added: users and groups, each labeled by type. * **Effective Users:** the fully-resolved list of **only the users**, found by expanding every nested group recursively. This is who actually gains access when you assign the group to an application. The Members tab of a manual group named Accuhive Brands, listing one direct member 'Domain - accuhive.com' of type Group, with an Effective Users tab alongside Members. Roll several **Region** [Auto Groups](/en/identity/directory/auto-groups) up into a manual **Super Region** group: everyone in those Region groups is included automatically, and membership follows as users move, with no upkeep on the umbrella group. ## Create a manual group In **Directory → Groups**, add a group and give it a name and description. Add users, or add other groups to nest them. Membership stays exactly as you set it until you change it. Assign the group to applications so its members gain access. See [Assigning access](/en/identity/applications/assigning-access). Creating a new manual group with the Add new member panel open, toggled to Group, selecting the group 'Domain - accuhive.com' to add as a member. Membership is yours to manage; it doesn't update on its own. When who-needs-access follows an attribute (department, location, and so on), use an [Auto Group](/en/identity/directory/auto-groups) instead so it stays current. ## Next steps How manual, built-in, and Auto Groups compare. Let membership compute itself from a profile attribute. # Schema Source: https://docs.iru.com/en/identity/directory/schema The schema behind every user profile: built-in fields, the custom attributes you define, and how attributes feed Auto Groups and app mappings. Every user profile is shaped by your **schema**: the set of attributes a profile can hold. The schema starts with built-in fields that exist for everyone, and you extend it with **custom attributes** tailored to your organization. You edit the schema from **Directory → Users → Schema** (the schema control on the Users page is an icon button, not a text label). Attributes are more than storage. They are the raw material that [Auto Groups](/en/identity/directory/auto-groups) compute membership from and that applications map into the identity details they receive, so the schema you design here shapes access and automation across Iru Identity. The User Schema page showing the Default category with attributes such as Domain, Username, Iru Role, Name, and Email, each with a slug, type, and Unique, Required, and Auto Group columns. ## Built-in fields Every profile includes a set of built-in facets you don't have to define: * **Name**, used to build the user's display name. * **Emails**, **phone numbers**, and **addresses**, each entry carrying a **label** such as work or personal. * A **username** and **domain** that together form the sign-in identifier. * A **role**, a **status**, and a **source**. The **role** applies across Iru products, not only Identity. These are described alongside the rest of the profile in [Users](/en/identity/directory/users). **Supporting more than one email domain.** The **domain** a user can have comes from a fixed list of allowed values on the built-in domain field. If your organization uses several domains (for example `example.com` and `example.io`), add each one to that list in the schema; only domains defined there can be chosen when you create or import a user. ## Custom attributes A custom attribute adds a field to every user profile. When you create one, you give it: | Property | What it does | | ---------------- | ------------------------------------------------------------------------------------------ | | **Display name** | The human-readable label shown on the profile. | | **Slug** | A stable, machine-friendly identifier used when mapping the attribute into apps and rules. | | **Type** | The kind of value it holds, chosen from the **attribute types** below. | | **Description** | Optional guidance shown to admins editing the profile. | | **Category** | The section of the profile the attribute appears under (see below). | | **Required** | When on, a profile can't be saved without a value for this attribute. | | **Unique** | When on, no two users may share the same value for this attribute. | The Add Attribute dialog with Display Name, Slug, and Description fields, Category and Type selectors, and Unique and Required toggles. Choose **required** and **unique** deliberately. A required attribute must be present on every user, including those created by import or HR sync, so a record without it will fail to save. A unique attribute is a good fit for identifiers like an employee number. ### Attribute types When you add a custom attribute, you choose one of these types for the value it holds: | Type | What it holds | | --------------- | ------------------------------------------------------------------- | | **String** | Free-form text. | | **Integer** | A whole number. | | **Decimal** | A number that can have a fractional part. | | **Boolean** | A true or false value. | | **Enumeration** | A value chosen from a fixed list of options you define (see below). | | **Date** | A date value. | | **Binary** | A base64-encoded value. | | **JSON** | A structured JSON value, for nested or composite data. | A type is chosen when you create the attribute and **can't be changed later**. **Unique** is not available for **Boolean** or **Enumeration** attributes, whose values are meant to repeat across users. A **Binary** value is stored as base64 and isn't size-limited, so use it for **small** values such as a token or key, not large files. ### Attributes with a fixed set of choices Some attributes should only accept values from a known list (a department, a location, an employment type. For these, give the attribute a fixed list of **allowed values** (enumeration options). Each option has its own display name and identifier. Fixed-choice attributes are especially useful because they pair naturally with [Auto Groups](/en/identity/directory/auto-groups): each allowed value can become its own group, with membership computed automatically. ## Categories Attributes are organized into **categories**, the named sections a profile is grouped into, such as "Employment" or "Contact." Each category has a display name, an icon, and a position that controls its order on the profile. Grouping related attributes keeps long profiles readable and makes the schema easier to maintain. The Add Category dialog with Display Name, Slug, Icon, and Description fields. ## How attributes are used ```mermaid theme={null} flowchart LR attr["Profile attribute"] attr -->|"computes membership for"| dyn["Auto Groups"] attr -->|"mapped into"| apps["Application sign-on
(assertions and tokens)"] attr -->|"can be a condition in"| pol["Authentication policies"] ``` Flag an attribute to power **Auto Groups**, and Iru turns its values into groups whose membership updates as profiles change. Applications map profile attributes into the assertion or token they receive, so each app gets the identity details it expects. Design the schema before you bring users in at scale. Deciding which attributes are required, unique, and fixed-choice up front means imports and HR syncs land cleanly and your Auto Groups behave the way you expect. ## Next steps Turn an attribute into groups that maintain themselves. See attributes in action on individual profiles. # Users Source: https://docs.iru.com/en/identity/directory/users Create and manage users in your directory: their profiles, lifecycle statuses, and the difference between suspending and removing. A **user** is someone in your directory. Each user has a sign-in identity, a profile made up of attributes, and a status that reflects where they are in their lifecycle. You manage users from **Directory** in the left-hand navigation bar (under **Identity**), on the **Users** tab. The list shows each user's name, status, username, domain, primary email, role, source, and sign-in activity. Use these steps to manage users one at a time. To add many users at once, see [Importing users](/en/identity/directory/importing-users) or sync them from an HR system with [Directory Sync](/en/identity/directory/directory-sync). ## Create a user Navigate to **Directory** in the left-hand navigation bar (under **Identity**). Select the **Users** tab if it isn't already selected. Select **+ User** in the upper-right. A blank profile form opens. Give the user a name, a username, and at least one email address. The username and a domain together form how the user signs in. Click **+ Add** under **Additional Emails** if you want an alternate address for their invitation, such as a personal email. Add any other built-in details (phone numbers, addresses, a role) and fill in the custom attributes you have defined in your [schema](/en/identity/directory/schema). Click **Create**. The user is created with a **pending** status. After the user is created, a prompt asks whether to send the invitation now. Choose the email address that should receive the invite, such as their work or personal address, then click **Send now**. Or click **Later** to dismiss the prompt and send the invitation from the user's menu when you're ready. A user created this way has a **source** of having been added manually, which distinguishes them from users brought in by import or HR sync. ## The user profile A profile is a collection of facets. Some are built in; the rest are the custom attributes you define. Built-in facets include: | Facet | Notes | | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | | **Name** | The user's name, used to build their display name. | | **Emails** | One or more email addresses, each with a label such as work or personal. One is the primary email. | | **Phone numbers** | Zero or more numbers, each labeled. | | **Addresses** | Zero or more addresses, each labeled. | | **Username and domain** | Together, the identifier the user signs in with. | | **Role** | The role the user holds, which governs what they can do in Iru. See [Administrators & roles](/en/identity/administration/administrators-and-roles). | | **Status** | Where the user is in their lifecycle: pending, active, or suspended. | | **Source** | Where the user originated: added manually, imported, or synced from an HR system. | Beyond these, every **custom attribute** you define appears on the profile in its category. See [Schema](/en/identity/directory/schema) for how the schema is built. The attributes on a profile are the raw material that applications and policies use. An application maps profile attributes into the identity details it receives, and an [Auto Group](/en/identity/directory/auto-groups) can compute its membership from an attribute's value. ## Find and filter users The users list can be filtered, searched, and saved as reusable **views** - useful once your directory grows beyond a handful of users. ### Filters Add a **filter** to narrow the list by any attribute, built-in (status, domain, role, created date) or a custom attribute you have defined. Pick the attribute, choose an operator such as **equals**, and set the value; add more than one filter to combine conditions. The Users list filtered by Domain equals accuhive.com, shown as a removable filter chip above the list. ### IQL filters For more precise queries, switch the list from **Standard** to **IQL** and write the filter as an [IQL](/en/identity/getting-started/iql-expressions) expression, for example `domain == "accuhive.com"`. This is the same expression language that powers Auto Group rules and mapping. The Users list in IQL mode with the expression domain == accuhive.com in the search bar and a Revert button. ### Saved views Once you have built a filter you will reuse, open **Options → Create view**, give it a name, and save it. The view remembers your filters, so you can return to the same slice of the directory in one click. The Create view option with a name field set to Accuhive.com and a Save button. ## User statuses A user is always in one of three statuses, and you can filter the users list by status. Created but not yet active. This is where a freshly added or imported user starts, before they finish setting up their account. Fully enabled. The user can sign in and reach the applications assigned to them. Access is blocked, but the record and history are preserved. The user cannot sign in until they are reinstated. ### Suspending vs. removing Both stop a user from signing in, but they are different tools for different situations. Suspending blocks a user's access while keeping their record, profile, and history intact. Reinstating a suspended user returns them to the status they held before, so this is the right choice when someone is on leave, under investigation, or being offboarded but not yet fully gone. You can suspend a user whether they are active or still pending. Removing a user deletes their directory record. Reach for this only when a user has left for good and you no longer need to keep their identity. When your HR system is connected, an offboarding there can remove users from the directory automatically; see [Directory Sync](/en/identity/directory/directory-sync). Removing a user cannot be undone. If there is any chance the user will return, or you need to retain their history, suspend them instead. ## Inviting users A newly created user is **pending** until they finish setting up their account. Inviting a user sends an invitation to their email with a secure link to complete first-time setup, including registering an [authenticator](/en/identity/authentication/authenticators) such as a passkey. By default, invitations go to the user's **primary email**. If the profile has an additional email (typically a personal address), you can send the invitation there instead. Use that when the user cannot open their work mailbox until they have a passkey. * You can invite a single user from their profile, or invite pending users in bulk from the users list. * Invitations expire **48 hours** after they are sent. You can resend one if it was missed or has expired; sending a new invitation supersedes any earlier one for that user. ### Resend invites in bulk Navigate to **Directory** in the left-hand navigation bar (under **Identity**). Select the **Users** tab if it isn't already selected. Open **Preset Views** and choose **Pending**. Click the **ellipsis** in the upper-right, then select **Resend invites**. Use **Set all to** to send every selected invite to **Primary email** or **First additional email**. Clear or select checkboxes to exclude or include users. To choose an address for one user, open that row's **Email** dropdown and pick the address. Click **Send**. ### Resend an invite for one user Navigate to **Directory** in the left-hand navigation bar (under **Identity**). Select the **Users** tab if it isn't already selected, then open the user record. Click the **ellipsis**, then select **Resend invite**. Select the primary email or an additional email, then click **Send**. If a user loses access to their authenticators, **Reset** them from the user's profile. A reset removes their registered authenticators, ends their active sessions, and returns them to **pending**; then send a fresh invitation so they can register a new authenticator. (Sending an invitation is blocked while a user still has authenticators, which is why you reset first.) ## Next steps Define the custom attributes every user profile can hold. Assign access to groups instead of individuals so it scales. Add many users at once from a CSV file. Let your HR system create, update, and remove users for you. # Accessing your apps Source: https://docs.iru.com/en/identity/end-user/accessing-your-apps Open the applications your organization has given you straight from Iru Access, with no separate passwords to remember. Once you've [set up Iru Access](/en/identity/end-user/installing-iru-access), all the applications your organization has assigned to you are a click away, and you sign in to each one without a separate password. The Iru app dashboard showing a Favorites section and a Your Applications grid of app tiles. ## Find and open an app In your browser, open your organization's Iru site. The address is your organization's name followed by `.iru.com`, for example `yourcompany.iru.com`. That's your **app dashboard**. Not sure of the address? Ask your IT team, and bookmark it once you're there. Confirm it's you with your [passkey or the Iru Access app](/en/identity/end-user/manage-authenticators): a quick fingerprint, face, or screen-lock gesture. There's no separate password. Your **app dashboard** shows your assigned apps as tiles. Selecting one signs you straight in; Iru handles the sign-on for you. **On macOS**, if you are prompted for a passkey but the prompt does not include the passkey you previously created, open **System Settings > Privacy & Security > Passkeys Access for Web Browsers** and turn on access for the browser you are using. Then close and re-open your browser and try authenticating again. To add or manage passkeys, see [Manage authenticators](/en/identity/end-user/manage-authenticators). Each tile shows the app's name and icon, a short description, your role in the app (when it applies), and when you last opened it. You'll also find your apps in the **Iru Access** app itself: the **desktop app** shows them on a **Home** view with your favorites at the top, and the **mobile app** has a dedicated **Favorites** tab. ### 1Password autofill If 1Password is installed with autofill on, choosing a passkey on the Iru sign-in page can open a 1Password prompt you have to dismiss before you continue with biometric sign-in. Hide 1Password on that page so the extra prompt no longer appears. These steps can vary slightly depending on your operating system and browser. In your browser, open your organization's Iru site, for example `yourcompany.iru.com`. Right-click the page, then hover over **1Password - Password Manager**. Select **Hide on this page**. When 1Password says it will no longer make autofill suggestions on this page, click **OK**. ## Favorites and search * **Favorite** the apps you use most so they're front and center; look for the star on a tile to add or remove it. * **Search** your apps by name to jump straight to one, and recently opened apps stay close at hand. Your list only ever shows the apps assigned to you, so what you see reflects the access your organization has granted you. ## Your account settings From your **avatar** in the top-right of the dashboard, open **Account** to manage your own details and sign-in. It has two tabs: * **Profile:** your name, username, email, and Iru domain, plus preferences such as time zone, language, and whether you get weekly status emails. Use **Edit** to update them. * **Authenticators:** the passkeys and Iru Access devices registered to you. See [Manage authenticators](/en/identity/end-user/manage-authenticators). The Account settings Profile tab showing username, email, and Iru domain plus preferences such as time zone and language, with the avatar menu open to Account and Log out. ## Iru Spotlight (macOS) **Iru Spotlight** is Iru Access's built-in launcher: a quick way to find and open your apps, or find a user in your organization, without leaving what you're doing. The Iru Spotlight launcher with Zoom typed and a Zoom result listed under Apps, openable with Command-1. From anywhere, press **⇧⌘ Space** (the default shortcut). You can turn **Iru Spotlight** on or off and customize the shortcut in [Iru Access settings (macOS)](#iru-access-settings-macos). Start typing. Matching apps appear under **Apps**, alongside users in your organization. Press the number next to a result (**⌘ 1** for the first) or select it. Iru Access signs you in to that app in your chosen browser. Press **Esc** to close. ## Your apps in macOS Spotlight Iru Access also plugs into **macOS's own Spotlight** (**⌘ Space**). Search an app's name there and you'll see a **"Log in to Zoom with Iru Access"** action you can run right from Spotlight, with no need to open Iru Access first. macOS Spotlight showing a Zoom result with the subtitle 'Log in to Zoom with Iru Access' and an Open action. * Favorited apps rank higher in the results. * The same action is available through **Siri** and the **Shortcuts** app. This is macOS's system search (**⌘ Space**), separate from **Iru Spotlight** (default **⇧⌘ Space**, customizable in [Iru Access settings (macOS)](#iru-access-settings-macos)) above. You need **macOS 15 or later**. On **iPhone and iPad** (iOS/iPadOS 18+), your apps appear the same way in **Spotlight search**. ## Iru Access settings (macOS) On a Mac, open the **Iru Access** menu and choose **Settings…** (or press **⌘ ,**) to control how Iru Access behaves. * **Open apps with:** choose which browser your apps open in. By default that's your system browser; pick any installed browser and it saves right away, so every app you launch from Iru Access opens there. To use a different browser just once, **right-click an app** and choose **Open Once With** (your current default is marked **(Default)**). * **Show Iru Access in the Menu Bar:** keep Iru Access in the macOS menu bar so your apps are a click away without opening the main window. * **Iru Spotlight Shortcut:** turn **Iru Spotlight** on or off and set the keyboard shortcut that opens it from anywhere. The default is **⇧⌘ Space**. * **Appearance:** match your system theme, or force light or dark. These settings are macOS-only. On iPhone and iPad, apps open in your system default browser. ## Where to go next Set up Iru Access if you haven't yet. Add a backup passkey so you're never locked out. Overview of passkeys, Iru Access, and how sign-in works. # Installing Iru Access Source: https://docs.iru.com/en/identity/end-user/installing-iru-access Install and set up the Iru Access app on your Mac, iPhone, iPad, or PC so you can sign in quickly with a passkey and keep your device trusted for access. **Iru Access** is the app you use to sign in to your organization's applications. It holds a device-bound sign-in credential securely on your device and, on a managed device, confirms the device is healthy so you can reach what you need. Your IT team may deploy Iru Access to your device for you. If it's already installed, skip to [registering](#register-your-device). Otherwise, start from the invitation your organization sends you. ## Install Iru Access If the app isn't already on your device, install it from the **link in your invitation** or your organization's **Iru Access download page** (you can scan the QR code shown in the app's *Add New Device* screen or open the link). On iPhone and iPad, Iru Access is also available on the App Store. The Install Iru Access prompt with a Download for macOS button and Windows and iOS options. ## Register your device Opening your invitation brings you to a page where you choose how to register. Choosing **Iru Access** launches the app and walks you through registration; you can also register a standalone **passkey** or continue with a connected provider. For how standalone passkeys differ from Iru Access, see [Manage authenticators](/en/identity/end-user/manage-authenticators). The Accept your invitation page with options to register a passkey with Iru Access or a standalone passkey, or to log in with Google or Microsoft SSO. The Iru Access screens differ slightly by platform; follow the tab for your device. The link opens Iru Access on your device. If the link has expired you'll see **"Registration Failed"**; ask your administrator for a new one. Iru greets you with **"Welcome, \[your name]"** and shows your **Username** and **Iru server**. Check they're right and choose **Continue**. On the **"Finalize Registration"** screen, confirm with your device's biometric or screen lock (**Touch ID** on a Mac, **Face ID** on an iPhone, or your device passcode/password. This secures your credential to the device. You'll see **"Registration Complete"**. Choose **Done**; on a Mac you land on your Home screen, on iPhone/iPad on your Account screen. You're ready to [open your apps](/en/identity/end-user/accessing-your-apps). Iru Access on Windows requires **Windows 11 24H2 or 25H2**, and uses **Windows Hello** (your PIN, fingerprint, or face) to protect your credential. The link launches **"Iru Access Registration"** and briefly shows **"Reading registration info"** while it loads your invitation. If the link has expired, ask your administrator for a new one. Iru greets you with **"Welcome, \[your name]!"** and shows your **Username** and **Iru server**. Check they're right and choose **Continue**. On **"Finalizing registration"**, **authenticate with Windows Hello** when prompted. This secures your credential to the device. You'll see **"Registration Completed"** and land on the **Iru Access Home Screen**. So your browser can use Iru Access when you sign in, enable it once under **Settings ▸ Accounts ▸ Passkeys ▸ Advanced options** and turn on **Iru Access**. You're ready to [open your apps](/en/identity/end-user/accessing-your-apps). **Apple Vision Pro** is supported: Iru Access runs there as the iPad app, so follow the **iPhone & iPad** steps above. Set up more than one device (say your laptop and your phone) so losing one doesn't lock you out. See [Manage authenticators](/en/identity/end-user/manage-authenticators) for adding another device or a backup. ## Add another account Iru Access can hold more than one account at once, handy if you have a second Iru identity, such as a separate administrator account or an account at another organization. The macOS Iru Access menu bar menu, showing Add a new device, Register another account, Open Iru Admin Console, and Settings. On a Mac, open the **Iru Access** menu in the menu bar at the top of the screen: * **Register another account…** begins a fresh registration for an additional account; finish it from that account's invitation, exactly as you did the first time. * **Add a new device…** registers this Mac against an account you already use on another device; see [Manage authenticators](/en/identity/end-user/manage-authenticators). Each account you register stays available in Iru Access, so you can keep more than one identity set up at the same time. ## Where to go next Open your assigned apps once Iru Access is set up. Add another device or a standalone passkey, and manage what you have. What Iru Access shares with your organization, and what stays private. # Manage authenticators Source: https://docs.iru.com/en/identity/end-user/manage-authenticators Compare Iru Access to a standalone passkey, add another device or a backup authenticator, and manage the authenticators you use to sign in to Iru Identity. You prove it's you when you sign in with an **authenticator**; no password. Both kinds Iru uses are unlocked by your fingerprint, face, or screen lock, and because the secret never leaves your device, neither can be phished or reused on a fake sign-in page. ## Iru Access vs. a standalone passkey Iru offers two kinds of authenticator, and you may have both. They appear together in your in-app **Authenticators** list. | Authenticator | What it is | In the app it's labeled | | -------------- | ----------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- | | **Iru Access** | The Iru Access app registered to a specific device. Each device is its own authenticator. | "Iru Access on This Device" (this one) or "Iru Access" (another of your devices) | | **Passkey** | A standalone passkey you created in your **browser or operating system** and also use with Iru. | "Passkey" | You **create** a standalone passkey in your browser or operating system, not inside Iru Access - creating new passkeys through the app isn't supported. Iru Access can *use* a passkey you already have to set itself up on a device (below). ## Add another device or a backup Install Iru Access on the new device, open it, and choose **"Register with Existing Authenticator."** Then either enter the **6-digit code** shown on your existing device's **"Add New Device"** screen (the existing device approves with its biometric over Bluetooth), or confirm with a passkey you already have. In Iru Access choose **"Register with Existing Authenticator" → "A Passkey I use with Iru, but not Iru Access,"** enter your **Iru domain** (for example `yourcompany.iru.com`), and confirm with the passkey when prompted by your browser or device. **On Windows**, the entry point is labeled **"Register with existing passkey"** and asks for your **Iru domain** (for example `yourcompany.iru.com`). Once the device is registered, turn on its passkey plugin once under **Settings ▸ Accounts ▸ Passkeys ▸ Advanced options** so your browser can use Iru Access to sign in. **On macOS**, if a passkey does not appear when you sign in using a browser, see [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). ## Manage your authenticators See everything registered to you in the **Iru Access** app, or in your **Account settings** on the web (open **Account** from the avatar menu on your app dashboard, then **Authenticators**), with when each was added and last used. From there you can: * **Suspend** an authenticator to block it temporarily, **Activate** it again, or **Delete** one you no longer use. * You can't suspend or delete the authenticator securing your **current session** - a safeguard against locking yourself out. The Authenticators tab of Account settings listing an iPhone and a MacBook Pro; the MacBook Pro is expanded showing Active status, registered and last-used timestamps, type Iru Access, and a Suspend this authenticator button. ## If you lose a device There's no self-service way to recover access on your own. If you still have another registered device, set up your replacement from it using the steps above. If a lost device was your only authenticator, contact your administrator. They can send you a new invitation so you can set up a replacement device. See [Installing Iru Access](/en/identity/end-user/installing-iru-access) to register again. For browser sign-in help, including the macOS passkey prompt, see [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). ## Where to go next Set up the app that holds your credential. Open your apps once you're set up. Overview of passkeys, Iru Access, and how sign-in works # Start here Source: https://docs.iru.com/en/identity/end-user/start-here Learn what Iru Identity is, how you sign in to your work apps without a password using Iru Access, and the steps to get your account set up for the first time. **Iru Identity is how you sign in to your work apps.** Your organization uses it as the single, secure front door to the tools you use every day. You sign in to Iru once, and from there you can open every app your organization has given you - without a separate username and password for each one. You prove it's you with a **passkey** or the **Iru Access** app, using the fingerprint, face, or screen lock you already use on your device. There's no password to create, remember, or type. Your apps all live in one place: your **app dashboard**, ready to open in a click. That's the whole idea: **one sign-in, no passwords, all your apps in one place.** Your IT team decides which apps you can reach; you just sign in. If signing in without a password is new to you, here are the plain-English answers. A **passkey** is the modern replacement for a password. Instead of remembering and typing something, you sign in with the **fingerprint, face, or screen lock** you already use on your device. The secret that proves it's you stays **on your device** and is never sent anywhere, so there's nothing for anyone to steal, guess, or trick out of you. Setting one up is a single tap; so is using it. **Iru Access** is a small app from your organization that holds one of those passkeys, tied to your device. You register it once from an invitation, and from then on it's how you prove it's you when you sign in. It also lets your IT team confirm your device is healthy (**without** seeing your personal data (see [Your privacy](/en/identity/end-user/your-privacy)). Prefer a plain passkey in your browser or operating system? That works too. Because passwords are the weak link: they get phished, reused, leaked, and forgotten. You don't have one here because there's nothing to phish or leak: your sign-in lives on your device and is unlocked only by you. Nothing to create, nothing to rotate, and nothing a fake login page can trick out of you. ## Ready to set up? Get the app and register your device from your invitation. Open your work apps from your app dashboard and from Spotlight. Add a backup device or passkey so you're never locked out. Exactly what your organization can and can't see. # Your privacy Source: https://docs.iru.com/en/identity/end-user/your-privacy Understand what device signals the Iru Access app shares with your organization to keep your identity secure, and what information always stays private to you. The first time you open **Iru Access**, it shows you exactly where the line sits between protecting your work identity and your personal life. That line is built into how the app works. ## This is not a management app Iru Access protects your work or school identity. It shares your device's security posture, never your personal data: not your contacts, photos, messages, apps, or browsing history. Your organization sees only essential details: when you sign in, device type, operating system version, security heuristics, and coarse location based on your public IP address. When precise location is needed, we'll ask first and explain why. ## What your organization can and can't see | Shared (to keep your access secure) | Never shared (private to you) | | -------------------------------------------- | ----------------------------- | | When you sign in | Your contacts | | Your device type | Your photos | | Your operating system version | Your messages | | Your device's security posture | The apps you have installed | | Coarse location, from your public IP address | Your browsing history | If precise location is ever needed, Iru Access **asks you first and explains why**. It's never collected silently. ## Security posture, not your content The "security posture" Iru Access shares is a set of health signals, for example whether your device is encrypted, up to date, and protected by a screen lock. It lets your organization confirm you're signing in from a healthy device **without** looking at what's on it. Iru Access neither reads nor sends the contents of your device. ## Where to go next Set up Iru Access on your device. Sign in to your organization's apps once you're set up. # Iru Query Language Source: https://docs.iru.com/en/identity/getting-started/iql-expressions Iru Query Language (IQL) is Iru's expression language for shaping mapped values: fields, operators, string functions, conditionals, and null-safe helpers. When you map what an application receives at sign-on (the **Subject (NameID)** for a [SAML app](/en/identity/applications/saml-applications), or the **subject and claims** for an [OIDC app](/en/identity/applications/oidc-applications)), each value is an **IQL expression**. IQL lets you pull from a user's profile and reshape the value before it is sent. **IQL** (Iru Query Language) is Iru's expression language for **mapping**, used in several places: * The attributes and claims an application receives at sign-on. * The fields a connected source maps into your directory (see [Attribute mapping](/en/identity/directory/attribute-mapping)). * [Auto Group](/en/identity/directory/auto-groups) rules and list filters. The same syntax works everywhere IQL appears. IQL is built on [CEL (Common Expression Language)](https://cel.dev), the open expression-language standard, so any expression that is valid in CEL is valid in IQL. As you type, the mapping editor suggests the available fields, functions, and operators, and shows a live **preview** of the result. An expression must **type-check** in the editor and again when you save, so mistakes surface before they ever reach a sign-on or a sync. ## Referencing your data What you reference depends on where the expression runs: * **Application mapping** starts from the `user` object, whose fields are your directory's [profile attributes](/en/identity/directory/schema): ``` user.email user.username user.id ``` The defaults reflect this: an OIDC app's subject defaults to `user.id`, and a SAML app's Subject defaults to `user.username`. * **Directory Sync mapping** references the **source's field names** directly, as they come from the connected system: ``` email_work first_name ``` Field names are **case-sensitive**. Reach into nested values with a dot (`user.profile.team`), and into a list or map with `[...]` (covered below). ## Building blocks | Form | Example | What it is | | ---------------- | -------------------------- | -------------------------------------------- | | Field / variable | `first_name`, `user.email` | A value by name, or a field on a value. | | Method call | `user.email.upperAscii()` | A function called **on** a value. | | Indexing | `parts[0]` | An element of a list by zero-based position. | | Map key | `entry["label"]` | The value stored under a string key. | | Grouping | `(a + b) * c` | Parentheses to control evaluation order. | ## Literals ``` "hello" // string (double quotes) 'hello' // string (single quotes) 42 // whole number 3.14 // decimal number true false // booleans null // null ["a", "b", "c"] // list {"label": "work", "primary": true} // map (string keys) ``` Strings support the usual escapes, such as `\n`, `\t`, `\\`, `\"`, and `\uXXXX`. ## Operators | Operator | Example | What it does | | ----------- | ------------------------------ | ----------------------------------- | | `+` | `first_name + " " + last_name` | Adds numbers, or **joins strings**. | | `-` `*` `/` | `a * b` | Subtract, multiply, divide. | | `%` | `a % b` | Remainder (modulo). | | Operator | Example | What it does | | ----------------- | --------------------------- | --------------------- | | `==` `!=` | `user.domain == "acme.com"` | Equal, not equal. | | `<` `<=` `>` `>=` | `user.level >= 3` | Ordering comparisons. | | Operator | Example | What it does | | ----------------- | --------------------- | ------------ | | `&&` | `a && b` | And. | | \|\| | a \|\| b | Or. | | `!` | `!a` | Not. | | Operator | Example | What it does | | -------- | ---------------------------------------- | ----------------------------------------------------- | | `in` | `user.domain in ["acme.com", "acme.io"]` | True if the value is in a list, or a key is in a map. | | `? :` | `name != "" ? name : "unknown"` | Conditional: choose one value or another. | ### Precedence From tightest-binding to loosest. When in doubt, add parentheses. ``` 1) a.b a() a[i] () // member access, calls, indexing, grouping 2) !a -a // unary not, negation 3) * / % // multiply, divide, remainder 4) + - // add, subtract (and string +) 5) < <= > >= in // comparison and membership 6) == != // equality 7) && // and 8) || // or 9) ? : // conditional ``` ## String functions String operations are written as **methods** on a value, in the form `value.method(...)`: | Method | Example | What it does | | --------------------------- | ------------------------------------------- | ------------------------------------------------------------ | | `upperAscii` / `lowerAscii` | `user.email.lowerAscii()` | Upper- or lower-case the value. | | `trim` | `first_name.trim()` | Remove surrounding whitespace. | | `split` | `user.email.split("@")` | Split into a list by a separator; index it with `[n]`. | | `replace` | `phone.replace("-", "")` | Replace every occurrence of one substring with another. | | `contains` | `user.email.contains("+")` | True if the value contains a substring. | | `startsWith` / `endsWith` | `user.email.endsWith("@acme.com")` | Test how the value begins or ends. | | `indexOf` | `username.indexOf(".")` | Position of a substring, or `-1` if absent. | | `matches` | `user.email.matches("^[a-z]+@acme\\.com$")` | True if the value matches a regular expression. | | `size` | `user.email.split("@").size()` | Length of a string or list. Also available as `size(value)`. | ## Conditionals and defaults The conditional operator is the simplest way to supply a fallback when a value might be blank: ``` // Use the first name, or fall back to the username when it's empty user.firstName != "" ? user.firstName : user.username ``` For richer null handling, IQL also has **optional** (null-safe) helpers, below. ## Optional values Optional helpers let you work with values that **might be missing** without causing an error. An *optional* either holds a value or is empty. ``` optional.of(value) // wrap a value as an optional optional.ofNonZeroValue(value) // empty if the value is "zero" (see below) optional.none() // an empty optional ``` `ofNonZeroValue` treats these as empty: an empty string `""`, `0`, `false`, an empty list `[]`, an empty map `{}`, and `null`. ``` value.?field // optional field access (yields an optional) list[?i] // optional index (empty instead of an error if out of range) ``` ``` opt.hasValue() // true if the optional holds a value opt.value() // the inner value (errors if empty) opt.orValue(fallback) // the value, or the fallback if empty a.or(b) // the first of two optionals that has a value ``` ``` opt.optMap(x, expr) // transform the inner value if present, else stay empty opt.optFlatMap(x, expr) // like optMap, when expr itself returns an optional ``` ``` // A default when a field is empty optional.ofNonZeroValue(first_name).orValue("anon") // Split an email and safely take the domain, falling back to "" optional.ofNonZeroValue(email_work).optMap(e, e.split("@"))[?1].orValue("") ``` ## Comments and whitespace Whitespace is not significant, and `//` starts a comment that runs to the end of the line: ``` user.firstName + " " + user.lastName // build a display name ``` ## Examples ``` // A field, as-is user.email // Upper-case the value user.email.upperAscii() // Build a display name from two fields user.firstName + " " + user.lastName // The local part of an email, before the "@" user.email.split("@")[0] // A field from the user's first address user.addresses[0].city // Choose a fallback when a field is blank user.firstName != "" ? user.firstName : user.username // A structured value, built as a map {"email": user.email, "primary": true} ``` Use the **preview** in the mapping editor to confirm an expression produces what you expect before publishing; it renders the exact value Iru will send or store. ## Where to go next Map IQL values into the assertion or token an application receives. Use the same IQL to map a connected source into your directory. Drive group membership from IQL rules over profile attributes. The `user` fields your expressions draw from. # Key concepts Source: https://docs.iru.com/en/identity/getting-started/key-concepts Get to know the core objects in Iru Identity, including users, groups, applications, authentication policies, and connections, and how they relate. Iru Identity revolves around a handful of core objects. Learn what each one is and how they connect, and the rest of the product will make more sense. ## The big picture ```mermaid theme={null} flowchart TD conn["Federated Authentication"] -->|"sign-in"| dir subgraph dir["Directory"] users["Users"] groups["Groups"] attrs["Profile attributes"] end users --- groups attrs --- users attrs -. "drive" .-> groups groups -->|"assigned to"| apps["Applications"] users -->|"assigned to"| apps policy["Authentication policies"] -->|"govern sign-in to"| apps auth["Authenticators"] -->|"prove identity for"| apps apps -->|"accounts provisioned to"| saas["Your SaaS apps"] activity["Activity log"] -. "records everything" .- dir ``` ## Identity objects A **user** is someone in your directory. Each user has a profile made up of attributes (name, email, and any custom fields you define). A user moves through a lifecycle: they can be **pending** (created but not yet active), **active**, or **suspended**. Suspending a user blocks their access without deleting their record or history. The **schema** defines the attributes every user profile can hold. Beyond the built-in fields, you can add custom attributes with their own type, mark them required or unique, give them a fixed list of allowed values, and organize them into categories. Attributes are the raw material that policies, application mappings, and Auto Groups all build on. See [Schema](/en/identity/directory/schema). A **group** is a collection of users that you assign access to as a unit. There are three kinds: * **Manual groups**, where you choose the members. * **Built-in groups** that exist for every tenant, such as a group that contains all users. * **Auto Groups**, whose membership is decided by an attribute rule and updates itself as profiles change. See [Groups](/en/identity/directory/groups) and [Auto Groups](/en/identity/directory/auto-groups). ## Access objects An **application** is something users sign in to through Iru. Iru acts as the identity provider for the app using either **SAML** or **OIDC**. Each application maps user profile attributes into the assertion or token it sends, so the app receives the identity details it expects. Applications are versioned: you edit a **draft**, then publish it to make it the **current** version, and Iru keeps older versions for reference. An application can be **active** or **inactive**. A **template** is a ready-made application definition for a known service. Creating an app from a template fills in the standard configuration for you, so you only supply what is specific to your tenant. See [Application templates](/en/identity/applications/application-templates). You grant access by **assigning groups** to an application. The full set of users who end up with access through those groups is the application's **effective users**. See [Assigning access](/en/identity/applications/assigning-access). **Provisioning** keeps accounts in sync. **Inbound** provisioning brings users into the directory from a connected HR system or a file import. **Outbound** provisioning pushes account creation, updates, and removal from the directory into your connected apps, so an app account exists exactly while access is granted. See [Provisioning](/en/identity/applications/provisioning). ## Trust and policy objects A **policy** is a set of rules that decides whether a sign-in is allowed and what the user must prove first. When someone signs in to an app, Iru evaluates the governing policy and records the decision. See [Authentication policies](/en/identity/authentication/authentication-policies). An **authenticator** is something a user uses to prove who they are, such as a **passkey** or Iru Access. Users manage their own authenticators in self-service, and a strong authenticator is required for every sign-in. See [Authenticators](/en/identity/authentication/authenticators). Policies take the device into account. **Device trust** reflects whether the user is on a known, healthy device and can be a required condition for access. **Risk levels** are a classification you assign to organize apps by sensitivity. See [Risk and adaptive access](/en/identity/authentication/risk-based-access) and [Device trust](/en/identity/authentication/device-trust). An **identity provider connection** lets users sign in to the Iru platform through a provider you already run. Use this when Iru Identity is an authentication layer rather than your primary identity provider, or to ease a migration. See [Federated Authentication](/en/identity/connections/connections-overview). (To bring users into the directory from an HR system instead, see [Directory Sync](/en/identity/directory/directory-sync).) ## Administration objects | Object | What it is | | -------------------------- | ------------------------------------------------------------------------------------------------------------------- | | **Organization** | Your tenant: the isolated Iru environment that holds your directory, apps, and settings, including branding. | | **Administrators & roles** | The administrators who manage Iru Identity and the roles that define what each can do. | | **Activity log** | A record of significant events (who did what, and the results of sign-in decisions) that you can review and filter. | ## How a sign-in uses these objects 1. A user tries to open an **application**, which redirects them to Iru to sign in. 2. The user authenticates to Iru with a passkey or the Iru Access app, or through a connected provider, and Iru identifies the matching **user** in the **directory**. 3. The application's **authentication policy** evaluates the sign-in for **device trust**. The user has already proven who they are with their authenticator in the previous step. 4. If the policy passes and the user is assigned the **application**, Iru issues the sign-on and the user reaches the app. 5. The **activity log** records the outcome. Assign access to **groups**, and base group membership on **attributes** where you can. Access then follows users automatically as their profiles change. That's lifecycle automation in Iru Identity. # Iru Identity overview Source: https://docs.iru.com/en/identity/getting-started/overview Connect your people to the apps they use with Iru Identity, one place to manage identities, single sign-on, provisioning, and access policies for your tenant. Iru Identity is the workforce identity and access management product in the Iru platform. It gives IT and security teams a single place to manage who your people are, which applications they can reach, and the conditions they must meet to sign in. With Iru Identity, your team can: Act as the identity provider for your apps so users sign in once with a single Iru identity and reach everything assigned to them. Keep an authoritative directory of users and groups, with a profile schema you control and membership that can update itself from your attributes. Bring people in from your HR system or a file, then provision and deprovision their app accounts automatically as they join, move, and leave. Set device-trust conditions for each app (required platforms and device health) on top of the strong authenticator every sign-in already uses. ## Our ethos Iru Identity is built on a simple belief: identity should be secure by design, easy to understand, and respectful of users. We believe strong security should not depend on brittle passwords, hidden complexity, or constant user friction. A user's identity should be anchored in trusted devices, phishing-resistant authentication, clear administrative controls, and systems that behave predictably under pressure. Our goal is to give organizations confidence without turning identity into a maze. Iru keeps access decisions understandable, device trust visible, and authentication resilient by default. Security should feel rigorous to administrators, easy for users, and honest in how it represents risk. Identity is the boundary between people, devices, applications, and the work they are trusted to do. Iru Identity exists to make that boundary stronger, cleaner, and easier to operate. ## What Iru Identity does Iru Identity sits between your people and your applications and handles the work of proving who someone is and what they are allowed to use. * **Single sign-on.** Iru Identity is the identity provider for the apps you connect. People authenticate once with Iru, typically with a passkey or the Iru Access app, and launch their apps from an app dashboard, using the SAML and OIDC standards your apps already support. * **A directory you control.** Manage users and groups, define the profile attributes that matter to your organization, and let group membership follow those attributes automatically. * **Lifecycle automation.** Bring people in from your HR system or another source of truth, and push account creation, updates, and removal out to your apps so access matches reality. * **Access policies.** Build authentication policies that decide who can sign in to each app and what they must prove first, and layer in risk and device trust. * **Bring your own sign-in, when you need it.** People normally sign in to Iru directly. You can also let them sign in through a provider you already run, such as Google Workspace or Microsoft Entra ID. That path is useful when you use Iru Identity as an authentication layer into the Iru platform rather than your primary identity provider, or to ease a migration onto Iru Identity. ## How the pieces fit together ```mermaid theme={null} flowchart LR subgraph sources["Sources of truth"] hr["HR system"] file["User import"] end subgraph iru["Iru Identity"] dir["Directory
users and groups"] pol["Access policies"] apps["Connected apps"] end people["Your people
sign in with a passkey"] idp["Existing provider
(optional · migration)"] saas["Your applications"] hr --> dir file --> dir people --> pol idp -. "optional sign-in" .-> pol dir --> pol pol --> apps apps --> saas ``` ## Who this is for This documentation is for IT administrators and security operators who configure Iru Identity in the Iru dashboard. It covers what you configure in the product and what Iru does on your behalf. Pages about end-user behavior call that out explicitly. Iru Identity itself is for the admin who is tired of bolted-on legacy identity systems, mystery-meat policy engines, authentication flows held together with redirects and folklore, and security products that somehow make the secure path feel like the least reliable one. It is for teams that want identity to feel modern, direct, and operationally sane. Teams that care deeply about security, but do not believe strong security has to mean brittle user experiences, buried configuration, unclear failure states, or a permanent dependency on tribal knowledge. Iru Identity is built around phishing-resistant authentication, trusted devices, clear activation flows, and policy behavior that administrators can actually reason about. The goal is not to take an old identity model, sand down the edges, add a nicer dashboard, and call it innovation. The goal is to make identity cleaner at the foundation: fewer inherited assumptions, fewer strange exceptions, fewer places where everyone quietly agrees not to touch the thing because nobody remembers why it works. These docs are written in that same spirit. They explain what the product does in practice: what each setting means, what happens when you change it, what users experience, and what Iru handles behind the scenes. Where behavior depends on policy, device state, application configuration, or administrator action, we call that out directly. Iru Identity is for organizations that want identity to be secure, understandable, and built for the way modern teams actually operate, not for the way legacy systems wish the world still worked. Iru Identity is a new product with a long future ahead of it. We're grateful to build alongside customers who believe workforce identity can be clearer, stronger, and better than what came before. ## Get started Stand up single sign-on for your first application in a few guided steps. Learn the core objects (users, groups, applications, policies, and connections) and how they relate. See how identities, sign-in, and provisioning flow through Iru Identity. Add people, organize them into groups, and shape their profiles. Iru Identity features move through Iru's release stages as they mature. When a capability is in an early stage, the page or section says so. See [Iru release stages](/en/iru/platform-overview/iru-release-stages) for what each stage means. # Quickstart Source: https://docs.iru.com/en/identity/getting-started/quickstart Go from an empty Iru Identity tenant to a working single sign-on launch for your first app: add users, assign access, and test the sign-in flow end to end. This quickstart walks through the shortest path to a working sign-on: add a user, group them, connect an application, grant access, protect it with a policy, and verify the experience. Each step links to a deeper guide when you want more detail. You need administrator access to your Iru tenant to follow these steps. If you manage admins separately, see [Administrators & roles](/en/identity/administration/administrators-and-roles). ## Before you begin You can add users by hand, import them from a file, or sync them from a connected HR system. For this quickstart, adding one user by hand is enough. To bring in your whole organization later, see [Importing users](/en/identity/directory/importing-users) and [Directory Sync](/en/identity/directory/directory-sync). Most applications support either SAML or OIDC for single sign-on. Have the app's documentation handy, or use a ready-made [application template](/en/identity/applications/application-templates) so the fields are filled in for you. ## Set up your first sign-on In **Directory → Users**, create a user with a name and email address. Use an address the user can actually receive mail at, so they can complete their invitation. The user's profile holds the attributes that policies and apps can use later. Learn more in [Users](/en/identity/directory/users). In **Directory → Groups**, create a group and add your user to it. Assigning access to groups instead of individuals keeps things manageable as you grow. See [Groups](/en/identity/directory/groups). In **Apps**, add an application. Choose a template from the catalog when one exists, or configure a custom SAML or OIDC app. Iru gives you the sign-on details to enter in your app, and you enter the details your app provides back into Iru. See [Add an application](/en/identity/applications/applications-overview). Assign the group you created to the application. Everyone in the group now has access; from then on you manage who can reach the app by changing the group's membership. See [Assigning access](/en/identity/applications/assigning-access). In **Policies → Authentication policies**, create a policy and attach it to your app to control **device trust** (for example, requiring a managed, encrypted device for a sensitive app. A passkey or Iru Access is already required for every sign-in, so you do not configure that here. See [Authentication policies](/en/identity/authentication/authentication-policies). Sign in as your test user and open the app dashboard. Your application appears as a tile; selecting it signs the user straight in. See [End-user experience](/en/identity/administration/end-user-experience). To exercise device trust and the full sign-in experience, install **Iru Access** on your test device and register it; see [Authenticators](/en/identity/authentication/authenticators). ## What you just built ```mermaid theme={null} flowchart LR user["Test user"] --> group["Group"] group --> assign["Assigned to app"] policy["Authentication policy"] --> assign assign --> app["Single sign-on"] ``` You now have a user who belongs to a group, a group that is granted an application, and a policy that governs how they sign in. Adding more users or apps is a matter of repeating the parts you need. ## Next steps Import your full user list or sync it from your HR system so the directory stays current on its own. Let users sign in with Google Workspace, Microsoft Entra ID, or another provider you already run. Provision and deprovision accounts in your apps automatically as access changes. Add risk and device trust conditions so access adapts to context. # System architecture Source: https://docs.iru.com/en/identity/getting-started/system-architecture Understand how identities, sign-in, and provisioning flow through Iru Identity, and the architectural guarantees that protect data and isolate tenants. Iru Identity is the identity layer between your people, the systems that know about them, and the applications they use. Below is how sign-in, provisioning, and access decisions flow through that layer. ## The identity layer ```mermaid theme={null} flowchart LR subgraph people["Your people"] emp["Employees and contractors"] end hr["HR system
(who exists)"] idp["Existing provider
(optional · migration)"] subgraph iru["Iru Identity"] dir["Directory"] engine["Policy engine"] prov["Provisioning"] end subgraph apps["Where people work"] saas["Your applications"] end hr -->|"sync people"| dir emp -->|"sign in with a passkey"| engine idp -. "optional sign-in" .-> engine dir --> engine engine -->|"allowed access"| saas dir --> prov prov -->|"accounts"| saas ``` Iru Identity is **your identity provider**. Your people sign in to Iru directly, typically with a passkey or the Iru Access app, and Iru vouches for who they are to every connected app, sending each one a signed statement of identity using the SAML or OIDC standard it supports. Iru can **also act as a relying party** to an identity provider you already operate: it hands sign-in off to that provider and continues the session once the provider confirms the user. This is a secondary path, meant for two situations: * **Signing in to the Iru platform with an existing provider.** Every Iru tenant uses Iru Identity to manage admins and keep users in sync, but not every organization uses it as their full identity provider. When Iru Identity is the authentication layer into Iru and its products, users can sign in with the provider you already run. * **Easing a migration.** While you move onto Iru Identity as your identity provider, users can keep signing in through their current provider during the transition. ## How sign-in works ```mermaid theme={null} sequenceDiagram participant U as Person participant A as Application participant I as Iru Identity participant P as Connected provider U->>A: Open the app A->>I: Ask Iru to authenticate alt Direct sign-in (default) I->>U: Prompt for a passkey or Iru Access U-->>I: Prove identity else Federated sign-in (auth layer or migration) I->>P: Hand off to your existing provider P-->>I: Confirm the user end I->>I: Evaluate the authentication policy alt Policy passes I-->>A: Issue single sign-on A-->>U: Grant access else Policy fails I-->>U: Deny and explain why end ``` Every sign-in to a connected app is checked against that app's authentication policy. A strong authenticator is always required; the policy then evaluates device trust before access is granted. Iru records the decision in the [activity log](/en/identity/administration/activity-log). ## How provisioning works Provisioning keeps your directory and your apps aligned with reality, in two directions. People enter the directory from a source of truth: ```mermaid theme={null} flowchart LR hr["HR system"] -->|"scheduled sync"| dir["Directory"] file["User import"] -->|"on upload"| dir manual["Manual entry"] --> dir dir -->|"attributes drive"| groups["Group membership"] ``` A connected HR system syncs users on a schedule, a file import brings in a batch at once, and you can always add users by hand. As profiles arrive, [Auto Groups](/en/identity/directory/auto-groups) update their membership automatically. Access changes flow out to connected applications: ```mermaid theme={null} flowchart LR dir["Directory"] -->|"assigned access"| prov["Provisioning"] prov -->|"create or update"| app["App account"] prov -->|"remove on offboarding"| app ``` When you assign someone to an app that supports provisioning, Iru creates and updates their account there. When access is removed, Iru can remove the account. Iru keeps a history of these syncs so you can confirm what happened. See [Provisioning](/en/identity/applications/provisioning). ## Iru Access **Iru Access** is the Iru app users install on their computer or mobile device. It plays two roles at once: * **Authenticator:** it holds a device-bound, passkey-style credential users use to sign in, unlocked by the device's biometric or screen lock. * **Device agent:** it reports the device's health signals to Iru, which your [device-trust](/en/identity/authentication/device-trust) policies can require. Because it's both, a single app gives users fast, phishing-resistant sign-in and gives you device posture for access decisions, with no separate agent to deploy. ## Device trust signals The Iru Access agent on each device reports device health (such as whether the device is encrypted and healthy) to Iru, where your authentication policies can use it. A policy can then require a known, healthy device before granting access. See [Device trust](/en/identity/authentication/device-trust). ## Guarantees that protect your tenant Authentication has to stay trustworthy. Here's what Iru does to protect it: Your directory, apps, and settings live in your own tenant. One organization's data is never visible to another. The identity statements Iru sends to your apps are signed so each app can confirm they genuinely came from Iru and were not altered in transit. Authenticators such as passkeys are stored and verified so that the secret needed to sign in never has to be shared with the apps you use. Information is protected in transit between your people, Iru, and your apps, and while it is stored. For how credentials and sessions are protected, and how to think about data and privacy, see [Security and privacy](/en/identity/security/security-and-privacy). ## Where to go next Review the objects referenced above and how they relate. Connect an identity provider your people already sign in with. Decide who can sign in to each app and what they must prove. Connect the apps your users sign in to. # Authentication architecture Source: https://docs.iru.com/en/identity/security/authentication-architecture How Iru makes sign-in phishing-resistant, signs and replay-proofs every request, and establishes verifiable SSO trust with rotating keys. Authentication is the part of Iru that has to be hardest to fool. Below are the cryptographic foundations: how users prove who they are without a shareable secret, how requests are signed and replay-proofed, and how the trust Iru extends to your apps is verifiable and rotates safely. ## Phishing-resistant sign-in Iru is built around **passkeys (WebAuthn/FIDO2)** and device-bound credentials. There is no password to phish, reuse, or breach. A passkey is cryptographically scoped to Iru's exact origin. A credential minted for Iru simply won't produce a valid signature on a look-alike phishing domain. Iru stores only the **public** key, the authenticator's provenance (AAGUID), and a signature counter. The private key never leaves the user's device, so there's nothing on the server to steal. Sign-in requires discoverable (resident) credentials and captures authenticator attestation at enrollment, so Iru knows the kind of authenticator in use. The Iru Access app holds its keys in the device's secure hardware (the **Secure Enclave** on Apple, the **TPM** on Windows) and proves possession on every request with a per-credential signature. Secure Enclave / TPM key custody is a property of the Iru Access app on the device; the server verifies the device-bound public-key signature on each call. ## Proving the device is genuine Beyond proving *who* is signing in, Iru can verify *what* they're on. Apple **DeviceCheck** validates that a request comes from a genuine, untampered Apple device, and the check is **fail-closed**. Bypassing it requires deliberate configuration. On Windows, TPM signals reported by Iru Access feed device-trust posture decisions. See [Device trust](/en/identity/authentication/device-trust). ## Every request is signed and replay-proofed Requests from the Iru Access app and integrations aren't just bearer-token authenticated. They're **signed**, and bound so a captured request can't be reused. | Mechanism | Standard | What it does | | --------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **HTTP Message Signatures** | RFC 9421 | Signs the method, path, authority, and key request components, so any tampering in transit invalidates the request. Schemes: `ed25519`, `ecdsa-p256-sha256`, `rsa-v1_5-sha256`. | | **Content-Digest** | RFC 9530 | A SHA-256/512 digest binds the signature to the exact request body. | | **Single-use, time-boxed proofs** | - | Signatures carry a `created`/`expires` window (max \~10 min, ≤5s clock skew) and a **nonce stored with a uniqueness constraint**. A replayed nonce is rejected. | | **DPoP** | RFC 9449 | Sender-constrained, proof-of-possession tokens bound to a client-held key (with `htm`/`htu`/`ath` binding and per-proof JTIs). A stolen bearer token is useless without the private key. | The Iru Access app additionally pins the TLS certificate of the service it talks to (an agent-side control), so it won't trust an intercepting proxy. ## Verifiable SSO trust, with safe key rotation When Iru acts as your identity provider, the statements it sends your apps are **signed** so each app can verify they genuinely came from Iru and weren't altered. SAML responses and assertions are signed with XML Signature; assertions can additionally be **encrypted** to the service provider. OIDC ID tokens are JWS-signed. Iru supports modern algorithms (RSA/ECDSA with SHA-256 or stronger, AES-GCM content encryption, and RSA-OAEP key wrapping), selectable per integration to match what each service requires. Iru publishes its public keys and metadata at standard endpoints: a **JWKS** document, OAuth Authorization Server Metadata (RFC 8414), and OpenID Connect Discovery. Relying parties configure and refresh keys automatically. Signing keys rotate on a **30-day** schedule with a **24-hour overlap**: a new key takes over while the previous one keeps verifying in-flight tokens, then expires rather than being deleted. Key types include ECDSA P-256/384/521 and RSA-2048. This limits the blast radius of any single key with no interruption to your apps. ## Encryption and sessions * **In transit:** all traffic is protected with TLS; session cookies are `Secure`, `HttpOnly`, and `SameSite`. * **At rest:** sensitive fields are encrypted with **AES-256-GCM** using a key supplied at runtime from a managed secret store. * **Sessions:** sign-in sessions are short-lived with a sliding inactivity window; longer-lived flows use rotating refresh tokens with one-time code challenges (PKCE `S256`) and replay detection. Sessions can be revoked **globally, per user, or per authenticator**, so a lost device or compromised account can be cut off immediately. See [Credentials and sessions](/en/identity/security/credentials-and-sessions). ## Where to go next The services, regions, and infrastructure behind this. How each tenant's data stays separate and auditable. The passkeys and Iru Access app users use day to day. Configure the signing and encryption a specific app receives. # Credentials and sessions Source: https://docs.iru.com/en/identity/security/credentials-and-sessions How Iru Identity protects the credentials users sign in with and the sessions they hold, and how to end access immediately when you need to. Two things stand behind every user who reaches an app through Iru: the **credential** they used to prove who they are, and the **session** that keeps them signed in afterward. Here's how Iru protects both, and how you cut someone off when you need to. ## How credentials are protected Users prove who they are with **authenticators**, and a **passkey** is the primary one. Passkeys are designed to resist phishing, which is the most common way credentials are stolen. A passkey keeps the secret that proves identity bound to the user's device. Signing in proves they hold it without ever transmitting the secret itself, so there is nothing reusable for an attacker to capture. A passkey only works when the user is genuinely signing in to Iru. A look-alike phishing page cannot trigger it, because the passkey is tied to the real Iru sign-in and will not respond to an impostor. What Iru keeps to verify an authenticator is protected while it is stored, and is never enough on its own to impersonate the user. Users manage their own authenticators in self-service. If someone loses access to theirs, an administrator can reset them so the user can register a new one. See [Users](/en/identity/directory/users). Which authenticators users may register, and which a policy will accept for a given app, is up to you. See [Authenticators](/en/identity/authentication/authenticators) and [Authentication policies](/en/identity/authentication/authentication-policies). ## What an application receives (and what it never sees) When a user reaches an app through Iru, the app learns who they are without ever learning how they proved it. This separation is what keeps a single stolen credential from spreading across your apps. A signed statement that confirms who the user is, plus the profile details you chose to map into that app's sign-on. Because the statement is signed, the app can verify it really came from Iru and was not tampered with. The user's passkey or any other authenticator secret. Apps never hold the means to prove the user's identity, so a breach of one app cannot be replayed against Iru or your other apps. You decide which profile attributes are shared with each application, so an app sees only the details it needs to identify the user. See [Assigning access](/en/identity/applications/assigning-access). ## How sessions are protected After a successful sign-in, Iru establishes a session so the user isn't asked to prove themselves again on every click. Sessions are protected so they can't be borrowed or stretched indefinitely. A session does not last forever: it ends after a period of inactivity and again at a maximum age, after which the user signs in and the governing policy is evaluated afresh. The session length presented to a connected app is configurable per [SAML app](/en/identity/applications/saml-applications) and per [application role](/en/identity/applications/roles-and-bundles). Signing in to a connected app runs through that app's authentication policy, so a sensitive app can require a trusted device even when the user is already signed in to Iru. (A passkey or Iru Access is required for every sign-in either way.) See [Authentication policies](/en/identity/authentication/authentication-policies) and [Device trust](/en/identity/authentication/device-trust). A user's active sessions can be ended, which forces them to sign in again before they can continue. This is how you cut off access even when someone is already signed in. ## Ending access immediately When access needs to stop, you don't have to wait for a session to expire. Pick the action that matches the situation; each one is recorded in the [activity log](/en/identity/administration/activity-log). | Action | What it does | Reversible? | | --------------------------- | ---------------------------------------------------------------------------------------------------------------- | ------------------------------------------------ | | **End sessions** | Ends the user's active sessions so they must sign in again. | Yes; they can sign in again if still active. | | **Suspend the user** | Blocks all sign-in while preserving the record and history. Existing access is cut and new sign-ins are refused. | Yes; reinstating restores their previous status. | | **Remove access to an app** | Revokes an assignment; for apps that support provisioning, the account there can be removed too. | Yes; reassign to restore. | | **Remove the user** | Deletes the directory record entirely. | No; this cannot be undone. | **Ending a session inside a connected app depends on the app.** Ending sessions and suspending a user stop further sign-ins **through Iru** right away. Whether a user's *existing* session inside a connected app also ends is up to that app and its protocol: * Apps that check with Iru on each access stop letting the user in at the next check. * For apps provisioned with [SCIM](/en/identity/applications/provisioning), suspending or unassigning the user sends a **deactivate** (the account's `active` flag set to `false`) or a **delete** to the app. Whether that immediately ends the app's active sessions is determined by how the app handles that signal. * Some apps keep an existing session until it expires unless they support session revocation or single logout. To cut someone off as completely as possible, **suspend the user** and **end their sessions**, and rely on each app's deprovisioning to remove downstream access. Suspending a user is the surest single action to cut someone off everywhere at once: it stops new sign-ins and existing access stays blocked until you reinstate them. Removing a user is permanent; suspend instead if there is any chance they will return or you need their history. See [Users](/en/identity/directory/users). If you suspect a credential is compromised rather than the user, reset the user's authenticators and end their sessions. They keep their account but must register a fresh authenticator before signing in again. ## How a compromised credential is contained The pieces above work together so that one stolen credential can't cascade: 1. Passkeys give attackers nothing reusable to phish in the first place. 2. Apps never receive the means to prove identity, so a breached app can't be replayed against Iru. 3. If something does go wrong, suspending the user and ending their sessions cuts access immediately, and every step is recorded for review. ## Where to go next The full security and privacy posture, expressed as plain guarantees. Choose which authenticators users register and use. What users see when they sign in through Iru. Suspend, reinstate, reset authenticators, and manage users in your directory. # Multi-tenant isolation Source: https://docs.iru.com/en/identity/security/multi-tenant-isolation How Iru keeps every organization's data separate, enforced in the database engine with row-level security, and every change tamper-evident. Iru Identity is multi-tenant: many organizations share the same service. The most important property of that design is that **one tenant can never see or touch another's data**. Iru enforces this in the database engine itself, not just in application code, so even a bug in a query cannot cross the boundary. ## Isolation enforced by the database Every table that holds tenant data carries a `tenant_id` and is protected by **PostgreSQL row-level security (RLS)**: * The table has RLS **enabled and forced** (`FORCE ROW LEVEL SECURITY`), so the policy applies to every role. There is no privileged path around it. * A single policy governs both reads and writes: rows are visible (`USING`) and writable (`WITH CHECK`) only when their `tenant_id` matches the tenant of the current request. ```sql theme={null} -- The shape every tenant table shares ALTER TABLE app. ENABLE ROW LEVEL SECURITY; ALTER TABLE app.
FORCE ROW LEVEL SECURITY; CREATE POLICY tenant_access_policy ON app.
FOR ALL USING (tenant_id = current_setting('iru.tenant_id')) WITH CHECK (tenant_id = current_setting('iru.tenant_id')); ``` This is applied uniformly and at scale (**hundreds of tables**, each with forced RLS and an identical read-and-write policy), not just to a privileged few. Because the boundary lives in the database, a query that forgets to filter by tenant simply returns nothing from another tenant. The engine refuses to show or change rows outside the active tenant. ## The tenant context travels with every request ```mermaid theme={null} flowchart LR req["Request to
tenant.subdomain"] --> mw["Resolve tenant
(reject if unknown)"] mw --> tx["Open DB transaction"] tx --> setl["SET LOCAL iru.tenant_id = …
+ instigator + correlation id"] setl --> rls["RLS policy reads
the same setting"] rls --> data[("Only this tenant's rows")] ``` 1. The tenant is resolved from the request's subdomain in middleware. If it can't be resolved, the request is **rejected before it ever reaches a handler**. 2. For each database transaction, Iru sets the tenant (along with the acting user and a correlation/trace id) as a **transaction-scoped** setting (`SET LOCAL`). Because it's scoped to the transaction, it cannot leak to the next request that reuses a pooled connection. 3. The RLS policy reads that exact setting, so the security boundary is the same value the application set, established transactionally on every connection. ## Least privilege, so audit history can't be rewritten The database role the application runs as can read and write **live** data, but it holds only **read** access to the **audit schema**. Even if application SQL were somehow abused, it has no grant to modify or delete audit history. The trail is protected at the privilege layer, independent of any application logic. Referential integrity is tenant-scoped too: foreign keys are composite (`tenant_id` + id), so a record can only ever reference another record **in the same tenant**. ## Every change is journaled (append-only) Iru keeps a complete, tamper-evident history of changes to tenant data. Every mutable table has a mirror **audit (journal) table** written by a database trigger on insert, update, and delete. Each entry records **what** happened (the action), **who** (both the acting database principal and the authenticated user), **when**, a **correlation/trace id** tying it to the originating request, and the **full before/after state** of the row. The trail is protected three independent ways: the trigger only ever *inserts* journal rows; the application's database role has **read-only** access to the audit schema; and the trigger runs with definer rights. There is no path for the application to alter or erase an audit record. A standing consistency check compares every live table's columns against its audit table and fails if any column is missing, so new fields can't quietly escape the audit trail. Schema migrations are themselves versioned, checksum-verified, and journaled. ## Sensitive fields get an extra layer On top of isolation, particularly sensitive values are **encrypted at the field level with AES-256-GCM** (authenticated encryption) before they're stored, and decrypted only when read by the application. Encryption keys are supplied at runtime from a managed secret store, never from code or the database. ## How this fits the bigger picture Isolation works hand in hand with **regional data residency**: each region has its own database, and a tenant's queries only ever run against its region's database (see [Platform architecture](/en/identity/security/platform-architecture)). Within that database, RLS keeps each tenant separate. The regions, planes, and infrastructure this isolation runs on. How sign-in and API requests are made phishing-resistant and tamper-proof. The audit trail, surfaced for admins to review. The guarantees these mechanisms add up to. # Platform architecture Source: https://docs.iru.com/en/identity/security/platform-architecture How Iru Identity is built: a two-plane service architecture across isolated regions, engineered for data residency, reliability, and observability. Iru Identity is a cloud service built to be the trustworthy center of your access. Below is how the service is built and what that means for reliability and isolation. ## Two planes, separated by job The platform is split into two independently deployed services that share a common, layered core. Keeping privileged provisioning apart from per-tenant request traffic shrinks the blast radius of each. ```mermaid theme={null} flowchart TB subgraph cp["Control plane"] tprov["Tenant lifecycle
(create / delete)"] jwks["Public key publication (JWKS)"] tmpl["App-template sync"] end subgraph tp["Tenant API"] iam["Per-tenant IAM API"] work["Background provisioning workers"] end cp -->|"provisions"| tp people["Your admins & people"] --> tp apps["Your apps"] --> tp ``` | Plane | Responsibility | Why it's separate | | ----------------- | ---------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Control plane** | Creating and deleting tenants, publishing signing keys, syncing the application-template catalog. | A small, privileged surface kept away from customer request traffic. Tenant operations require a token compared in constant time; the template-sync credential is fetched per request from a managed secret store so rotations take effect immediately. | | **Tenant API** | The customer-facing identity and access API, plus background workers that provision accounts to your apps. | The high-traffic surface your people and apps actually use, with provisioning handled out-of-band so a slow downstream app never blocks sign-in. | ## A disciplined, layered core Both services are built in Go on a layered architecture with a one-directional dependency rule. A separately enforced **platform** tier sits below the product layers and owns tenant isolation and identity primitives. **Foundation** stays dependency-free for shared infrastructure utilities that do not carry tenant context. Tenant isolation and identity spine: database access, sessions, tenant and region resolution, actor, logging, and public URL handling. This tier is reviewed and enforced separately so isolation stays out of ordinary product code. Shared infrastructure utilities that depend on nothing above them (for example crypto and tracing). Tenant-scoped concerns live in platform, not here. Business logic per entity (users, applications, policies…). Depends on platform and foundation, not on usecase or REST. Orchestrates multiple domain services for complex flows. HTTP handlers and middleware, the only layer that speaks the wire. The layering is a documented, **review-enforced** convention (backed by linting and directory structure), not a compiler-guaranteed invariant. We call that out honestly rather than overclaiming. Testing follows the same discipline: pure business logic is unit-tested without mocks, and behavior is validated by **integration tests that run against a real PostgreSQL database**, so tests exercise the same row-level security and audit behavior that runs in production, not a stubbed approximation. ## Hosting and hardening Iru Identity runs on **AWS**, with a security-hardened deployment: Services run on AWS Fargate as non-root with a **read-only root filesystem**, **no-new-privileges**, and all Linux capabilities dropped. The application connects to managed **PostgreSQL (Amazon RDS)** using short-lived **IAM authentication tokens**. There is no static DB password to leak. Credentials and signing keys are injected from a managed secret store at runtime, never committed to the repository or stored in the database in plain text. Container images are scanned for vulnerabilities in the CI pipeline before they can ship. Static assets are served through a CDN (Fastly), and short-lived preview environments for testing run on Google Cloud Run. ## Two regions, real data residency Iru Identity operates in **two isolated regions (United States `us-east-2` and European Union `eu-central-1`)**, and residency is enforced in code, not by convention. ```mermaid theme={null} flowchart LR req["Request"] --> mw["Resolve tenant
from subdomain"] mw --> reg{"Tenant's
region?"} reg -->|"US"| usdb[("US database")] reg -->|"EU"| eudb[("EU database")] reg -->|"unknown"| rej["Rejected"] ``` * Every tenant is **pinned to a region**, stored on the tenant record. * The database layer holds **separate connection pools per region** and routes every transaction by the tenant's region. A request whose region can't be resolved is **rejected**. It never silently falls back to another region. * Region-specific data operations (such as seed data) are gated so they can't run against the wrong region. The result: an EU tenant's data is read and written only against EU infrastructure. See [Multi-tenant isolation](/en/identity/security/multi-tenant-isolation) for how isolation continues *inside* each regional database. ## Built to stay up, and to be observable A dependency-free liveness endpoint lets the orchestrator probe without touching the database or auth. On shutdown, services stop accepting traffic and flush tracing, error reporting, and database connections in order. Connection pools are tuned and bounded, ping their database at startup, and **fail fast** if it's unreachable rather than serving broken requests. Account provisioning to your apps runs through an **outbox and reconciliation** loop in cancellation-aware background workers, so downstream changes are retried until they succeed instead of being lost. Requests are traced with **OpenTelemetry** from HTTP through application code down to the SQL query, and structured logs are correlated by tenant and trace ID. Errors are captured centrally with sampling to balance fidelity and cost. Schema changes are embedded, version-ordered, and **checksum-verified** (a changed, already-applied migration is a hard failure). A standing checker proves every table's audit journal stays in sync with its live schema. ## Where to go next How row-level security and append-only auditing keep every tenant's data separate and tamper-evident. Phishing-resistant sign-in, signed requests, and how SSO trust is established. The guarantees these mechanisms add up to. The customer-facing view of how identities and sign-in flow. # Security and privacy Source: https://docs.iru.com/en/identity/security/security-and-privacy Iru Identity's security and privacy posture, expressed as plain guarantees about how your tenant, your sign-ins, and your data are protected. Iru Identity sits at the center of who can reach your applications, so it is built to be trustworthy by default. Here are plain guarantees about what Iru does for you. For the engineering behind them, follow the architecture deep-dives: Two-plane services, AWS hosting, and two-region data residency. Row-level security and append-only auditing in the database engine. Phishing-resistant sign-in, signed requests, and rotating SSO keys. ## What protects your tenant Your directory, applications, policies, and settings live in your own tenant. One organization's data is never visible to another, and access decisions in one tenant cannot affect another. The identity statements Iru sends to your applications are signed, so each app can confirm a sign-on genuinely came from Iru and was not altered along the way. An app will reject anything that does not carry Iru's valid signature. Passkeys are the primary way users prove who they are. The secret that proves identity stays bound to Iru and the user's device and is never handed to the apps they sign in to, which removes the credential a phishing page would try to steal. Information is protected while it travels between your people, Iru, and your apps, and while it is stored. Administration is governed by roles, so each administrator has only the access their job requires. See [Administrators & roles](/en/identity/administration/administrators-and-roles). Significant events (sign-in decisions, changes to users and access, and administrative actions) are written to an activity log you can review and filter. See [Activity log](/en/identity/administration/activity-log). ## The trust boundary Iru is the gatekeeper between the users who originate in your upstream systems and the applications they reach. Everything inside the boundary is isolated to your tenant; everything that crosses it does so under a guarantee above. ```mermaid theme={null} flowchart LR subgraph outside["Outside the boundary"] people["Your people"] idp["Connected providers
and HR systems"] apps["Your applications"] end subgraph iru["Your Iru tenant"] direction TB dir["Directory"] policy["Authentication policies"] log["Activity log"] end people -->|"phishing-resistant sign-in"| iru idp -->|"federated sign-in and synced people"| iru iru -->|"verifiable, signed single sign-on"| apps iru -.->|"encrypted in transit and at rest"| iru ``` For a fuller picture of how identities, sign-in, and provisioning flow through Iru, including the role Iru plays for your apps. See [System architecture](/en/identity/getting-started/system-architecture). ## Adaptive protection at sign-in Strong credentials are only part of the story. Every sign-in to a connected app is evaluated against that app's authentication policy before access is granted, and a policy can demand more when the situation warrants it. Every sign-in requires a phishing-resistant authenticator (a passkey or Iru Access), so there are no passwords to steal or replay. Policies can require that a user is on a known, healthy device before access is granted. Policies can take the risk of a sign-in into account and ask for more assurance, or deny access, when something looks unusual. Decide which authenticators your users may register and which a policy will accept. ## Your data, under your control Iru holds the directory and settings needed to run identity, sign-on, and provisioning for your organization, and no more than that. Beyond the built-in profile fields, you choose which custom attributes to keep on your people, and you can mark them required or unique. Store what your policies, app mappings, and groups actually need, and leave out what they don't. See [Schema](/en/identity/directory/schema). The profile and activity data Iru holds is used to run sign-in, evaluate policies, provision accounts, and produce your activity log. Those are the functions that make Iru work for you. An application only receives the profile details you map into its sign-on. You decide which attributes are shared with each app, so a given app sees only what it needs to identify the user. See [Assigning access](/en/identity/applications/assigning-access) and [Provisioning](/en/identity/applications/provisioning). Iru Access makes this commitment to your people directly: on first launch it shows what it shares with their organization (sign-in, device type and security posture, coarse location from the public IP) and what it never touches (their personal content). Point your team to [Your privacy](/en/identity/end-user/your-privacy). ## Removing access quickly When someone should no longer have access, Iru lets you act immediately, and the change is recorded. Suspending a user blocks their sign-in while preserving their record and history, so it is reversible if they return. Existing sessions can be ended, so access is cut even where someone is already signed in. Removing access can remove the matching account in apps that support provisioning, not just block future sign-on. Suspending a user is the fastest way to cut off a user across everything at once. Reach for it the moment access should stop; you can always reinstate them later. ## Compliance and data residency Iru Identity is operated as part of the wider Iru platform's security and compliance program. For your organization's specific requirements: * **Attestations and reports:** request Iru's current compliance reports and attestations through the [Iru Trust Center](https://trust.iru.com) or your Customer Success Manager. * **Data residency and retention:** confirm where your tenant's data is stored and how long it is retained with your Customer Success Manager. ## Where to go next How passkeys and sessions are protected, and how to end sessions and suspend users. Decide who can sign in to each app and what they must prove first. Govern who can manage Iru, and with how much access. Review significant events and the outcomes of sign-in decisions. # Import Administrators via CSV Source: https://docs.iru.com/en/iru/access/import-administrators-via-csv Bulk invite administrators to Iru with a CSV file. Download the sample, review required columns and roles, then import from Access. Use **Import via CSV** when you need to invite more than one administrator at a time. Prepare a CSV with the required columns, or start from the sample file in the import dialog. For a single invitation, see [Invite New Team Members](/en/iru/access/invite-new-team-members) or [Admins and Access](/en/endpoint/getting-started/foundation/admins-and-access). Invitations expire after 24 hours. If 24 hours pass before an account is created, an existing administrator or account owner must resend the invitation from **Access**. See [How to Resend Invitations](/en/iru/access/invite-new-team-members#how-to-resend-invitations). ## Import administrators via CSV In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. Open the **Admin and authentication** tab if it is not already selected. Next to **+ Administrator**, click the caret. Click **Import via CSV**. Access Admin and authentication page with Import via CSV open from the caret next to + Administrator In the **Import administrators via CSV** dialog, click **Download sample.csv** to get a template you can edit. Drag your CSV into the upload area, or choose **click to browse** and select the file. Then click **Import**. Import administrators via CSV dialog with Download sample.csv and drag or browse upload area Expand **CSV column format** in the dialog for required and optional columns, accepted role values, and language values. Import administrators via CSV dialog with CSV column format expanded showing required columns and accepted role and language values ## CSV column format Column names are case-sensitive. Match the sample file headers exactly. The downloaded **sample.csv** uses this header order and includes one example row: ```csv theme={null} firstName,lastName,email,upn,role,language Alex,Smith,alex.smith@example.com,,admin,en_US ``` Leave `upn` blank to have Iru fill it from the email, as in the sample row. ### Required columns | Column | Description | | ----------- | ------------------------------------------------------------------------------ | | `firstName` | First name | | `lastName` | Last name | | `email` | Email address for the invitation | | `role` | Access level. Must be one of the [accepted role values](#accepted-role-values) | ### Optional columns | Column | Description | | ---------- | ------------------------------------------------------------ | | `upn` | User principal name. If blank, Iru fills this from the email | | `language` | Preferred language. If blank, defaults to `en_US` | ### Accepted role values Values must match exactly (lowercase, hyphenated where shown): | Value | Access level | | ----------------- | --------------- | | `admin` | Admin | | `help-desk` | Help Desk | | `auditor` | Auditor | | `standard` | Standard | | `secrets-auditor` | Secrets Auditor | For what each level can do, see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). ### Accepted language values Values are case-sensitive. If `language` is blank, Iru uses `en_US`. | Value | Language | | -------- | ----------------------- | | `en_US` | English (US) | | `en_GB` | English (UK) | | `es_419` | Español (Latinoamérica) | | `de` | Deutsch | | `ja_JP` | 日本語 (日本) | # Invite New Team Members Source: https://docs.iru.com/en/iru/access/invite-new-team-members Invite new team members to your Iru account. Send email invitations, assign roles, and configure access permissions for administrators and collaborators. ### About Inviting Team Members New members of the Admin Team can be invited under **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). This allows you to grant access to other administrators who can help manage your Iru environment. User creation and team member changes are recorded on the [Unified Activity](/en/iru/platform-overview/unified-activity). Invitations expire after 24 hours. If 24 hours pass before the account is created, an existing administrator or account owner must resend the invitation from **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). ### How to Invite New Team Members To invite one team member at a time, use the steps below. To invite several administrators from a spreadsheet, see [Import Administrators via CSV](/en/iru/access/import-administrators-via-csv). In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. Screenshot of the account menu with Access option highlighted Click **New user** on the top right of the Access page. Fill in the required user information fields and choose an appropriate [access level](/en/iru/access/team-member-role-permissions) for the new team member. Click **Submit** to send the invitation. ### How to Resend Invitations If an invitation has expired, you can resend the invitation under **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). In the sidebar, click the **Account Menu Button**, then select **Access**. Screenshot of the account menu with Access option highlighted Click **Resend invite** next to the user who needs a new invitation. # Iru Account Recovery Source: https://docs.iru.com/en/iru/access/iru-account-recovery Recover access to your Iru account when locked out. Reset passwords, restore two-factor authentication, and regain admin access through support channels. ### About Login and Account Recovery To help users regain access, you can send them an authentication registration request so they can register a new passkey, or manage and reset their authenticators. For the full steps, see [Send Authentication Registration Request](/en/iru/access/passkeys-and-social-login#send-authentication-registration-request) and [Manage Passkeys for Team Members](/en/iru/access/passkeys-and-social-login#manage-passkeys-for-team-members) in **Passkeys & Social Login**. Recovery options also depend on how the user signs in (social login vs. passkey), as below. ### If You Sign In with Google or Microsoft (Social Login) If you use Google or Microsoft to sign in to Iru, reset your password with that provider: * [Office 365](https://support.office.com/en-us/article/i-forgot-the-username-or-password-for-the-account-i-use-with-office-eba0b4a2-c0ae-472c-99f6-bc63ee2425a8) * [Google](https://support.google.com/accounts/answer/41078?co=GENIE.Platform%3DDesktop\&hl=en) ### If You Sign In with a Passkey If you use a [passkey](/en/iru/access/passkeys-and-social-login#passkeys) to sign in, use your credential manager (e.g., 1Password, Apple Passwords) to authenticate at the Iru login page. If you no longer have access to your passkey, an Account Owner must send you an [authentication registration request](/en/iru/access/passkeys-and-social-login#send-authentication-registration-request) so you can register a new passkey. Account Owners can also [manage or reset authenticators for team members](/en/iru/access/passkeys-and-social-login#manage-passkeys-for-team-members) in **Passkeys & Social Login**. On macOS, if you are prompted for a passkey but the prompt does not include the passkey you previously created, open **System Settings > Privacy & Security > Passkeys Access for Web Browsers** and turn on access for the browser you are using. Then close and re-open your browser and try authenticating again. Identity app users see the same tip in [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). ### Related Articles Register passkeys, manage team member authenticators, and configure social login How passkeys and Iru Access work for Iru Identity application sign-in End-user guide for passkeys, backup devices, and lost-device recovery Alternative authentication methods for Iru Endpoint tenant access # Modify or Remove Team Members Source: https://docs.iru.com/en/iru/access/modify-or-remove-team-members Change roles or remove team members from your Iru account. Update permissions, transfer ownership, and revoke access for departing administrators. ### About Team Member Management Team Members are users who have access to the Iru Web App. Administrators can adjust the access level, edit details, and remove other Team Members (suspend first, then delete). When using SSO to sign into Iru, the team member's account must be created in the Access settings under Admin Team to sign into the Iru web app. ### How It Works Team member management allows administrators to control access levels, edit user details, and transfer account ownership within the Iru platform. Changes to team members are recorded on the [Unified Activity](/en/iru/platform-overview/unified-activity). To help a team member regain access (for example, if they lost their passkey), use **Manage authenticators** in Access. See [Passkeys & Social Login](/en/iru/access/passkeys-and-social-login). ### Change a Team Member's Account Permissions In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Account menu with Access option highlighted On the **Access** page, under **Team Members**, select the **Access Level** drop-down for the user in the **Role** column, then choose the level you want. ### Edit a Team Member's Details In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Access** option in the menu. Account menu with Access option highlighted Click the **ellipsis** (⋮) next to the Team Member you wish to edit. From the ellipsis (⋮) menu, select **Edit user**. Edit the first or last name of the Team Member in the displayed text fields, then click **Save**. ### Delete a Team Member You must **suspend** a user before the **Delete user** menu option is available. In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Access** option in the menu. Account menu with Access option highlighted Click the **ellipsis** (⋮) next to the user you want to remove. From the ellipsis (⋮) menu, select **Suspend user**. If you suspended the wrong user, or you want to restore access without deleting them, click the **ellipsis** (⋮) next to that user, then select **Unsuspend user**. Click the **ellipsis** (⋮) next to the same user again. From the ellipsis (⋮) menu, select **Delete user**. When you delete an Admin user, **API tokens they created are not removed**; those tokens **stay active** until someone revokes them in **Access** on the **API tokens** tab. To cut off API access from that person’s integrations, revoke or rotate those tokens there. Anyone with permission to open **Access** can manage **every** tenant API token (permissions, rename, revoke); you do not need to be the creator. The bearer secret is only shown **once** at creation, so other admins cannot copy it later unless it was shared with them then. See **[Iru API Overview](/en/endpoint/api/iru-api-overview#considerations)** under **Removed administrators and API tokens**. Their **display name** may no longer appear on some historical activity in the Iru Web App after the user is deleted, while token lifecycle and API access follow the behavior above. ### Transfer Account Ownership The Account Owner can transfer ownership to any admin on their Iru team. In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Access** option in the menu. Account menu with Access option highlighted Click the **ellipsis** (⋮) on the right-hand side of the admin to whom you wish to assign ownership, then select **Make Account Owner**. # Passkeys & Social Login Source: https://docs.iru.com/en/iru/access/passkeys-and-social-login Sign in to Iru using passkeys or social login providers. Set up passwordless authentication with biometrics, security keys, or Google and Apple accounts. ### About Passkeys and Social Login Passkeys and social login provide straightforward ways to configure access to your Iru tenant. Users can create their own passkeys, or use their existing Google or Microsoft account to access your tenant. While they're easy to configure, they do have inherent limitations compared to configuring a [Single Sign-On](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) authentication method. If you're looking to [Require Authentication](/en/endpoint/enrollment/configure-require-authentication-for-enrollment#manual-enrollment) for enrollment, passkeys and social login can only be used for manual enrollments. This article covers passkeys for signing into **Iru Endpoint** and managing authentication under **Access**. For passkeys your people use to sign into **Iru Identity** applications, see [Authenticators](/en/identity/authentication/authenticators) and [Manage authenticators](/en/identity/end-user/manage-authenticators). ### How Passkeys and Social Login Work **Passkeys** use standards-based technology that eliminates shared secrets, making them resistant to phishing attacks. When a user registers a **passkey**, it's stored in their credential manager and can be synced across their devices. During login, the credential manager authenticates the user without requiring a password. **Social login** allows users to authenticate using their existing Google or Microsoft accounts. For Microsoft Social, authentication matches users based on their User Principal Name (UPN) in Microsoft Entra ID, not just their email address. Google Social and Microsoft Social can be limited to specific domains for additional security. ### Passkeys Designed to replace traditional passwords, passkeys offer a more secure and user-friendly way to sign into websites and applications. You can see Apple's [About the security of passkeys](https://support.apple.com/en-us/102195) and [Use passkeys to sign in to websites and apps on iPhone](https://support.apple.com/guide/iphone/use-passkeys-to-sign-in-to-websites-and-apps-iphf538ea8d0/ios) pages for more information. #### Send Authentication Registration Request Admins and Account Owners can send authentication registration requests to users so they can register a passkey. In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click the **Access** option in the menu. Account menu with Access option highlighted Click the **ellipsis** (⋮) next to the user you would like to send the authentication registration request to. From the ellipsis (⋮) menu, select **Manage authenticators**. Click the **Send Authentication Registration** button. Click the **Accept** button in the invitation email. Click the **Passkey** button under the **Register a Passkey** section. Follow the prompts for your preferred credential manager to register the passkey. You can now choose the **Passkey** button at the Iru login page. Choose your passkey from your credential manager to authenticate. #### Register a New Passkey You can register additional passkeys for your account without an administrator sending a registration request. You may register multiple passkeys per user account. In the sidebar, click the **Account Menu Button**, then select **My Account**. Left navigation with user name and My Account option In the My Account page, click **Authenticators**. Click the **+ Authenticator** button. If you see a notice that you cannot add additional authenticators without an existing one, contact an administrator to send a registration link as described in the [Send Authentication Registration Request](/en/iru/access/passkeys-and-social-login#send-authentication-registration-request) section. In the Add authenticator dialog, click the **Passkey** button. Follow the prompts to save the passkey in your preferred credential manager. When prompted, authenticate using an existing passkey. If your existing passkey is stored in a different credential manager, select it from that credential manager when prompted. Follow the prompts to complete the passkey registration. #### Credential Managers It's important to save your passkeys in a way that allows you to access them across multiple devices. Most popular credential managers, such as 1Password and Apple's Passwords app, support saving and synchronizing passkeys. When registering passkeys, if the expected credential managers do not prompt to save the passkey, check the settings of the related app or browser extension to ensure that prompts to save passkeys are enabled. If you have multiple credential manager browser extensions enabled, you may need to disable the other extensions to avoid conflicts. On macOS, if you are prompted for a passkey but the prompt does not include the passkey you previously created, open **System Settings > Privacy & Security > Passkeys Access for Web Browsers** and turn on access for the browser you are using. Then close and re-open your browser and try authenticating again. Identity app users see the same tip in [Accessing your apps](/en/identity/end-user/accessing-your-apps#find-and-open-an-app). #### Manage Your Passkeys You can suspend or delete your registered passkeys. In the sidebar, click the **Account Menu Button**, then select **My Account**. Left navigation with user name and My Account option In the My Account page, click **Authenticators**. Click the disclosure triangle (⌄) to the right of the authenticator you would like to suspend. Click **Suspend authenticator** to temporarily disable the authenticator. You must suspend an authenticator before you can delete it. Now that the authenticator is suspended, you can click **Delete authenticator** to completely remove it. Click **Yes, delete** to complete deleting the authenticator. You can also click **Unsuspend authenticator** if the wrong authenticator was suspended. #### Manage Passkeys for Team Members You can suspend, delete, and reset all of the registered passkeys for team members. In Iru Endpoint, in the sidebar, click the **Account Menu Button**. Click the **Access** option in the menu. Account menu with Access option highlighted Click the **ellipsis** (⋮) next to the user you would like to manage. From the ellipsis (⋮) menu, select **Manage authenticators**. If you want to remove all passkey registrations from a user, click the **Reset all** button. This action will remove all authenticators for the given user. Registering a new authenticator will be required to log in. See [Iru Account Recovery](/en/iru/access/iru-account-recovery) for recovery options. Click the disclosure triangle (⌄) to the right of the authenticator you would like to suspend. Click **Suspend authenticator** to temporarily disable the authenticator. You must suspend an authenticator before you can delete it. Now that the authenticator is suspended, you can click **Delete authenticator** to completely remove it. Click **Yes, delete** to complete deleting the authenticator. You can also click **Unsuspend authenticator** if the wrong authenticator was suspended. ### Social Login **Social login** allows users to authenticate using their existing Google or Microsoft accounts without needing to configure complex [Single Sign-On](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) authentication methods. There are two social login options available in Iru: Microsoft Social and Google Social. #### Limit Authentication to Domain For Google Social and Microsoft Social, you can optionally limit authentication to one or more domains. This allows you to restrict social logins to your organization's specific domains. Another level of security you can add after limiting to specific domains is to enable Multi-Factor Authentication for the social login platforms. Learn more about using MFA for signing in with Google Workspace and Office 365: * [Google 2-Step Verification](https://www.google.com/landing/2step/) * [Set up 2-step verification for Office 365](https://support.office.com/en-us/article/set-up-2-step-verification-for-office-365-ace1d096-61e5-449b-a875-58eb3d74de14) To use a social login method for Require Authentication during enrollment, you'll need to limit that method to specific domains. See [Configure Require Authentication for Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment#manual-enrollment) for more information. #### Microsoft Social When using the Microsoft Social authentication method, the match between the user in Iru and the user in Microsoft is based on the User Principal Name (UPN). This is an important distinction because a user's email address and UPN could be different. In cases where the email address in Microsoft Entra ID matches the email of the user in Iru, it will still fail if the UPN of the related user in Microsoft Entra ID does not match. ### Manage Tenant Authentication You can either allow or disallow Passkey, Google Social, and Microsoft Social tenant authentication methods individually. You cannot disallow the authentication method that was used to access your current session. ### Related Articles Help team members regain access when they lose a passkey or authenticator Configure SSO and manage Passkey, Google Social, and Microsoft Social tenant authentication How passkeys and Iru Access work for Iru Identity application sign-in End-user guide for passkeys, Iru Access, and backup devices # Team Member Role Permissions Source: https://docs.iru.com/en/iru/access/team-member-role-permissions Reference guide for Iru team member roles and permissions. Compare access levels for Account Owner, Admin, Standard, Help Desk, Auditor, and more. ### About Team Member Roles Invite team members from **Access**: in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Access**. The account owner has full access like an administrator, but other administrators cannot remove that person or strip the role. The first account owner is created when the tenant is set up; ownership can later transfer to another admin. To change or remove users, see [Modify or Remove Team Members](/en/iru/access/modify-or-remove-team-members). ### Access Levels #### Account Owner Full access to all functionality. Other team members cannot delete the Account Owner. When creating your Iru account, the first team member has 24 hours to activate their account via email. #### Administrator Full access to all functionality. Accounts with this role can be deleted by other administrators. Additional administrators have 24 hours to activate their Iru account via email. If 24 hours pass before the account is created, an existing admin must [resend the invitation](/en/iru/access/invite-new-team-members#how-to-resend-invitations) from **Access**. #### Standard Same permissions as Administrator accounts without access to Settings. #### Help Desk No access to Settings and read-only access to Blueprints and Library Items. Help Desk users can run all device actions, including deleting a device. #### Auditor Limited **read-only** access to the Iru Web App. #### Secrets Auditor Limited **read-only** access to the Iru Web App plus the ability to read: * macOS FileVault recovery keys * Activation lock bypass codes * Recovery lock password * Device unlock PIN ### Permissions Overview | Category | Permission | Owner | Admin | Standard | Help Desk | Secrets Auditor | Auditor | | ------------------------ | ---------------------------- | ----- | ----- | -------- | --------- | --------------- | --------- | | Configuration | Manage Blueprints | ✅ | ✅ | ✅ | Read Only | Read Only | Read Only | | | Manage Parameters | ✅ | ✅ | ✅ | Read Only | Read Only | Read Only | | | Manage Library Items | ✅ | ✅ | ✅ | Read Only | Read Only | Read Only | | | Manage Enrollment Portal | ✅ | ✅ | ✅ | Read Only | Read Only | Read Only | | Device Management | Enroll Devices | ✅ | ✅ | ✅ | ✅ | Read Only | Read Only | | | Manage Devices | ✅ | ✅ | ✅ | ✅ | Read Only | Read Only | | | Manage User Assignments | ✅ | ✅ | ✅ | ✅ | Read Only | Read Only | | | Device Tags | ✅ | ✅ | ✅ | ✅ | Read Only | Read Only | | | Device Notes | ✅ | ✅ | ✅ | ✅ | Read Only | Read Only | | Basic Device Actions | Send Blank Push | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Set Device Name | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Renew MDM Profile | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Reinstall Agent | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Unlock User Account | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Sensitive Device Actions | Lock Device | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Erase Device | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Restart Device | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Shutdown Device | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Set Auto Admin Password | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Delete User Account | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | | Delete device record | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Device Secrets | Access Device Secrets | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | | Settings & Integrations | Company Settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | | User Management | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | | Integrations | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | | Apple Integrations | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | | Self Service Settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | | API Token | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | | Iru AI | Access Iru AI | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | Documentation & Support Q\&A | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | Endpoint Management Agent | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | Vulnerability Agent | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | EDR Agent | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | Compliance Agent | ✅ | ✅ | ✅ | ✅ | ✅ | Limited | | | Trust Center Agent | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | | | Recommendations | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ | | | Execute Iru AI Actions | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ | | Ownership | Account Permanence | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | | | Transfer Account Ownership | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | **Limited (Auditor):** The Compliance agent runs, but control definitions are withheld. Linked actions and artifacts are still available. This matches **Auditor** access under [Compliance Permissions](/en/compliance/compliance-permissions) (**View controls** is off). Iru AI does not grant access beyond what the role already has in the web app. Device secrets (such as FileVault recovery keys) are not available through Iru AI for any role. When a question falls outside a role's access, Iru AI says so and answers from documentation instead of returning partial data. For agent coverage and org-level enablement, see [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview). For Compliance-only roles, see [Compliance Permissions](/en/compliance/compliance-permissions#iru-ai). ### Web App Authorization & Session Duration For security, team members must re-authenticate their Iru Web App session on a schedule, regardless of role. * Sign in at least once every 24 hours. * After 60 minutes of inactivity, the session ends automatically. ### Related Articles * [Compliance Permissions](/en/compliance/compliance-permissions): roles and permissions in Iru Compliance, including Compliance-only roles that align with the access patterns above. * [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview): how Iru AI agents work and how to enable Iru AI for the organization. # Iru AI Overview Source: https://docs.iru.com/en/iru/iru-ai/iru-ai-overview Overview of Iru AI features for intelligent device management. Learn about AI-powered insights, automated recommendations, and natural language queries. Iru AI is Iru's intelligent assistant that provides AI-powered insights, natural language querying, and automated recommendations for device management across your entire fleet. ## About Iru AI Iru AI is a system of specialized agents that span all of the Iru products: identity & access, endpoint security & management, and compliance automation. Iru AI delivers insights, actions, and answers through a unified interface, making device management more intuitive and efficient. ## How Iru AI Works Iru AI is available to all Iru customers, and enabled by default. Ask a question in the chat, and Iru AI routes the request to the agent that owns the relevant data. Iru AI provides two primary ways to interact directly with the system: through the chat interface and through Insights in Home. When you ask Iru AI a question, you'll receive both a summary view of your requested information and a link to the detailed data for deeper analysis, where you can view full table representations with all relevant attributes. Iru AI also proactively brings relevant items to your attention via Insights, helping you optimize your configurations and ensure your devices, users, and applications are managed to your satisfaction. Insights have corresponding actions that you can authorize via the same interface. ### What each agent does | Agent | What it covers | | ----------------------- | ---------------------------------------------------------------------------- | | Endpoint Management | Devices, Blueprints, Library Items, and Prism data | | Vulnerability | Vulnerability summaries, CVE detail, and remediation status | | EDR | Threat detections, classifications, and affected devices | | Compliance | Frameworks, controls, actions, artifacts, and sources | | Trust Center | Security questionnaire content and responses | | Recommendations | Suggests Library Items to add, based on the fleet | | Actions | Executes an action you authorize, such as creating a Library Item | | Documentation & Support | Answers from Iru documentation; available to every role that can open Iru AI | Which agents a team member can reach depends on their role. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) and [Compliance Permissions](/en/compliance/compliance-permissions#iru-ai). ## Iru AI Capabilities ### Natural Language Queries Ask questions about your device fleet in natural language: * "What versions of Zoom are installed across my devices?" * "Which OS versions are installed?" * "Which devices have FileVault turned off?" * "Which devices have Activation Lock enabled?" * "Show me devices that haven't checked in recently" ### Proactive Insights Iru AI proactively detects opportunities to improve your tenant's configurations based on: * Known best practices that Iru recommends to all customers * ML models that highlight suggestions based on organizations similar to yours * Real-time analysis of your device fleet status ### Automated Actions Insights are designed to be actionable with clear calls-to-action in each recommendation card. When you click an insight's action button, Iru AI will: * Show a preview of the action it's about to take * Allow you to approve, reject, or learn more * Execute approved actions automatically * Provide links to newly created objects ### Cross-Platform Intelligence Iru AI delivers unified insights across Apple, Windows, and Android devices, providing: * **Detailed Analysis**: Access detailed device data through conversational interfaces * **Actionable Intelligence**: Recommendations with one-click approval and execution * **Universal Access**: Chat interface available from anywhere in the platform ## Accessing Iru AI ### Top Navigation Bar Wherever you are in the Iru platform, you can start chatting with Iru AI by clicking the AI icon in the top right corner of the screen. ### Home Dashboard If you're in Home, you can start chatting with Iru AI by clicking into the chat interface at the bottom of the page. ### Universal Search You can click Universal Search or press **Cmd + K** (Mac) / **Ctrl + K** (Windows) to open the search modal, then click the "Ask Iru AI" button to pass your query to Iru AI. ## Managing Iru AI Access ### Account Owner Controls [Account Owners](/en/iru/access/team-member-role-permissions) can enable or disable Iru AI for the entire organization on the **Iru AI** tab in **Organization**. When Iru AI is off, the Iru AI chat interface and Insights are hidden, and team members can't open Iru AI from the top nav or Universal Search. Certain AI-powered features such as control generation for [Iru Compliance](/en/compliance/getting-started-with-compliance) and [Adaptive Compliance](/en/compliance/adaptive-compliance) control update recommendations can still rely on Iru AI to function properly. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Organization** in the menu. Screenshot of the account menu with Organization option highlighted Select the **Iru AI** tab. Use the toggle to enable or disable Iru AI for the tenant. ### User Permissions Two things must both be true for a team member to use Iru AI: 1. **Iru AI is enabled for the organization** (see [Account Owner Controls](#account-owner-controls) above). 2. **The team member's role reaches at least one agent.** Every role that can open Iru AI can ask documentation and support questions. Product data (devices, vulnerabilities, EDR, Compliance, and Trust Center) is scoped by role. Iru AI grants no access a role does not already have in the web app. When a question falls outside a role's access, Iru AI says so and answers from documentation instead of returning partial data. For the full permission matrices, see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) and [Compliance Permissions](/en/compliance/compliance-permissions#iru-ai). ## Privacy and Data Considerations Iru AI is designed to protect your privacy. Each interaction with Iru AI is a standalone session, and no previous conversations are logged or retained. Regarding data handling, we adhere to high standards for privacy and security. We hold [ISO 42001](https://www.iso.org/standard/81230.html) certification, which ensures our AI processes comply with strict guidelines for maintaining data privacy. Your data is stored securely within Iru's infrastructure. Iru AI only accesses a limited portion of your data, just what's necessary to answer your question. If you don't use Iru AI, it won't access your data. When working with large language models (LLMs), they do not store, use for training, or retain any of your data. ## Best Practices * **Regular monitoring**: Use Iru AI Insights to regularly monitor your device fleet and identify optimization opportunities * **Natural language queries**: Ask questions in natural language rather than trying to construct complex filters * **Review recommendations**: Regularly review Iru AI Insights and take action on recommended improvements * **Audit actions**: Monitor [Unified Activity](/en/iru/platform-overview/unified-activity) to audit any Iru AI actions taken in your environment ## Considerations When the chat interface is opened to full-width and you click into another page, you'll be navigated there but won't be able to see the new page until you reduce to drawer-width or close the chat interface altogether. # Prism Data Analytics Source: https://docs.iru.com/en/iru/iru-ai/prism-data-analytics Use Prism in Iru to query and visualize device fleet data. Build custom reports, filter by attributes, and export results for analysis. Prism is Iru's device data collection and analytics platform. It gathers inventory and configuration data from your fleet and feeds [Iru AI](/en/iru/iru-ai/using-iru-ai), so you can ask questions about your devices and get recommendations based on that data. ## About Prism Prism stores the device data Iru AI uses to answer questions and surface recommendations. Collection and organization happen in Prism. Iru AI then makes that data available in conversation and through proactive insights. ## Prism Data Categories Prism organizes device data into these categories: General information about your enrolled devices. Device and user Activation Lock status, bypass code escrow, and related settings for iOS, iPadOS, visionOS, and macOS devices. Built-in macOS application firewall status, including block all incoming, stealth mode, logging, allow signed applications, and firewall unloading. Firewall exceptions are not included here; they will ship later in their own category. Application inventory for iOS, iPadOS, tvOS, visionOS, and macOS devices, including source, signature, Team ID, and install or download state. On Mac, the Iru Agent also records each app's last-opened date and timestamp. Cellular details for iOS and iPadOS devices, including dual-SIM Slot 1 and Slot 2 data such as carrier, roaming, personal hotspot, IMEI, ICCID, and EID. Installed certificates on macOS, iOS, iPadOS, and tvOS devices, reported with common name and whether each is an identity certificate. Screensaver path and interval, clock display, and hot corners per user account on macOS devices. FileVault status on macOS devices, including recovery key type, escrow status, regeneration needed, and next scheduled rotation. Gatekeeper status and mode on macOS, plus Gatekeeper, Opaque, XProtect, and MRT versions. Gatekeeper exceptions will arrive later as a separate category. All installed profiles on Apple devices, including profiles not installed by Iru Endpoint, with managed, removable, signed, encrypted, and removal passcode attributes. Installed kernel extensions and their status on macOS devices. Launch agents and daemons on macOS devices, including load and disabled state, domain, program arguments, and the local user for user agents. Local users on macOS devices, including Administrator or Standard type, Secure Token, FileVault User, Volume Owner, Mobile Account, and Home Folder Secured. Core macOS security settings such as System Integrity Protection (SIP), Authenticated Root Volume, Bootstrap Token, and Secure Boot. Installed system extensions on macOS devices, including state, MDM Managed, Team ID, and version details. Transparency, Consent, and Control (TCC) entries on macOS devices, including service, application, Allowed or Denied status, and status reason (User Set, System Set, or MDM Policy). ## Using Prism Open **Devices**, then select the **Prism** tab. Prism Devices category view with sidebar categories, filters, columns, and CSV export controls ### Global Filters Use the **Device** and **Blueprint** filters to narrow Prism results across all categories. Categories that do not apply to the filtered platform may be grayed out. For example, FileVault grays out when you filter to iOS devices. #### Device Filter by platform. Options include: * **Apple**, with nested choices for **Mac**, **iPhone**, **iPad**, **Apple TV**, and **Vision** * **Windows** * **Android** Select one or more platforms, then use **Reset** to clear the Device filter. #### Blueprint Filter by Blueprint. Search Blueprints, choose **Select all**, or select individual Blueprints. Use **Clear** to remove Blueprint selections. ### Expand and Collapse Table View Click **Expand table view** to hide the Prism category sidebar and give the table more room. Click **Collapse table view** to show the sidebar again. Prism Expand table view control above the Devices table ### Manage Tags From the Devices page (including Prism), open the ellipsis menu and select **Manage tags** to search for, add, edit, or delete tags for your tenant. For full steps, see [Tags for Devices](/en/endpoint/devices/device-record-management/tags-for-devices#managing-tags). ### View Settings Use **View settings** to choose which attributes appear in the table for the current category. Click **View settings**. Prism View settings control above the Devices table Search for a specific attribute if you have one in mind. Click **Hide all** to turn off all optional columns. Uncheck individual columns to hide them from the table. Click and drag the **drag-and-drop** icon to reorder columns. Click **Show all** to turn on all columns. Check items in the hidden list to show them in the table again. Click **X** to close **View settings**. Prism View settings panel for searching, showing, and hiding table columns ### CSV Export Export the contents of the category you are viewing. Click **Export CSV**. Select **Current View** or **All Attributes**: * **Current View**: Includes only the data currently visible in the table, plus any applied filters. * **All Attributes**: Includes all data for this category, even columns that are not visible in the table. Click **Start export**. Prism Export CSV dialog with Current View and All Attributes options ### Add Filters Use **+ Filter** to narrow the table by any attribute in the category. For example, in FileVault you can show devices where the recovery key is not escrowed. Click **+ Filter**. Search for the attribute you want to filter on. Select the filter from the list. Choose the status or value for the filter. Click **Apply**. Prism Add Filter workflow showing search, Recovery Key Escrowed filter, status options, and Apply ### Remove a Filter Click the **X** on an applied filter to remove it. Prism applied filter chip with X control to remove the Recovery Key Escrowed filter ### Attribute Values Prism attributes appear in one of these states: * **Value**: A returned value such as a boolean (true/false, yes/no, on/off), string, or number * **Empty**: The attribute applies, but no value is present. For example, a launch daemon with no program arguments * **Null**: The attribute does not apply to the device platform. For example, application signature on iOS, because Apple does not expose application signing information over the MDM protocol ### Cross-Category Shared Attributes These attributes appear in every Prism category: | Attribute | Description | | ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Device ID** | The unique identifier for the enrolled device | | **Device Name** | The name of the enrolled device. Links to the device record | | **Device Family** | The device platform family, such as Mac, iPhone, iPad, or Windows | | **Device User ID** | The unique identifier for the assigned device user | | **Device User** | The assigned user of the device record. Links to the user record | | **Device User Email** | The email address of the assigned device user | | **Blueprint ID** | The unique identifier for the assigned Blueprint | | **Blueprint Name** | The assigned Blueprint for the device. Links to the Blueprint record | | **Tags** | Tags applied to the device | | **Asset Tag** | The asset tag value on the device record, if set | | **Device Serial Number** | The device serial number | | **First Seen** | The first time Prism recorded this row of data | | **Last Updated** | The last time this row was updated in Prism | | **Last Collected** | The last time the data was collected | | **Last Changed** | The last time the data was collected and the values differed from the previous collection. For example, FileVault status was collected and changed to On. | ## Collection Frequency This table shows how often Prism collects each type of data, and which method it uses. | **Data** | **Source** | **Collection Frequency** | **Compatibility** | | ------------------------------- | --------------------------------- | --------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | | **Devices** | Agent/MDM | 24 Hours (Apple platforms)
Daily (Windows)
When something changes on the device (Android) | Apple, Windows, Android | | **Activation Lock** | MDM | 24 Hours | iOS, iPadOS, visionOS, macOS | | **Application Firewall** | Agent/MDM | 15 Minutes / 24 Hours | macOS | | **Apps** | Agent/MDM | 24 Hours (iOS, iPadOS, tvOS, visionOS)
Near-instant (macOS) | iOS, iPadOS, tvOS, visionOS, macOS | | **App Last Opened** | Agent | Daily (at agent check-in) | macOS | | **Cellular** | MDM | 24 Hours | iOS, iPadOS | | **Certificates** | MDM | 24 Hours | macOS, iOS, iPadOS, tvOS | | **Desktop & Screensaver** | Agent | 15 Minutes | macOS | | **FileVault** | Agent/MDM | 15 Minutes | macOS | | **Gatekeeper & XProtect** | Agent | 15 Minutes | macOS | | **Installed Profiles** | MDM | 24 Hours | iOS, iPadOS, tvOS, visionOS, macOS | | **Kernel Extensions** | Agent | 15 Minutes | macOS | | **Launch Agents & Daemons** | Agent | 15 Minutes | macOS | | **Local Users** | Agent | Hourly | macOS | | **Startup Settings** | MDM | 24 Hours | macOS | | **System Extensions** | Agent | 15 Minutes | macOS | | **Transparency Database** | Agent | 15 Minutes | macOS | | **Security Patch Level** | MDM | Status report sent upon attribute change | Android | | **API Level** | MDM | Status report sent upon attribute change | Android | ## Platform-Specific Data Collection * Device model and specifications * Serial number and UDID * Storage capacity and usage * Battery health and status * Operating system version and build * Installed applications and versions * Mac app last-opened date/timestamp (daily from the agent; macOS updates as apps are used) * System extensions and kernel extensions * Launch agents and daemons * FileVault encryption status * Gatekeeper and XProtect status * Activation Lock status * Installed security profiles * Local user accounts, including Secure Token, FileVault User, Volume Owner, Mobile Account, Home Folder Secured, and logged-in state * Desktop and screensaver settings per user account, including screensaver path/interval and hot corners * Device model and manufacturer * Serial number and device identifiers * Storage capacity and usage * Processor architecture * Network information * Operating system name, version, and edition * OS build and Update Build Revision (UBR) * Full software version * Agent installation status and version * Device model and specifications * Storage capacity and usage * Network connectivity status * Android version and API level * System updates and patches * Installed applications in the work profile * Application versions and sources * Work profile configuration * Security patch level * Device compliance status * Work profile security settings * Certificate and encryption status ## Data Collection Methods The Iru Agent gathers data by: * **System APIs**: Reading system information and status directly * **File system monitoring**: Tracking changes to system files and configurations * **Process monitoring**: Watching running processes and services * **Event logging**: Collecting system events and security logs MDM protocols gather data by: * **Device queries**: Requesting specific device information * **Status reports**: Receiving automatic status updates * **Command responses**: Collecting data returned from MDM commands * **Profile information**: Reading data from installed configuration profiles ## Privacy and Security Iru protects Prism data with: * **Encryption**: Data is encrypted in transit and at rest * **Access controls**: Access controls limit who can view device data * **Audit logging**: Data access is logged and auditable * **Data retention**: Retention policies you can configure Prism data collection aligns with: * **GDPR**: European data protection regulations * **CCPA**: California consumer privacy laws * **SOC 2**: Security and availability standards * **ISO 27001**: Information security management ## API Access Prism was built API-first. Anything you can do in the web app is also available through the [Iru API](/en/endpoint/api/iru-api-overview). With the Prism API, you can: * Query any category with any subset of filters * Request a CSV export of any category and retrieve the result set asynchronously ## Best Practices Check Prism often enough to catch security issues and compliance gaps before they linger. Use fleet data in Prism when you change device management policies. Treat FileVault, Gatekeeper, TCC, and related categories as early signals for hardening work. Use Prism to confirm devices still meet your compliance requirements. ## Troubleshooting **Possible causes:** * Device offline or not checking in * Agent not running * Network connectivity issues **Solutions:** * Confirm the device is online * Verify the agent is running * Test network connectivity **Possible causes:** * Platform limitations * Agent version mismatch * Permission issues **Solutions:** * Confirm the category is available for the device platform * Update the agent to the latest version * Verify required permissions **Possible causes:** * Timing of the last collection cycle * System state changing during collection * Agent sync problems **Solutions:** * Wait for the next collection cycle * Force a device check-in * Restart the agent if needed # Using Iru AI Source: https://docs.iru.com/en/iru/iru-ai/using-iru-ai Use Iru AI to ask questions about your device fleet in natural language. Get instant answers about compliance status, device health, and configurations. Iru AI provides two main ways to interact with your device management data: through the chat interface for direct queries and through Insights for proactive recommendations. ## Chat Interface ### About Chat with Iru AI You can talk directly with Iru AI from anywhere on the platform. Get clear, natural language answers and guidance that evolves with every interaction. Iru AI's chat interface provides instant access to device insights and recommendations. ### Opening the Chat Interface #### Top Navigation Bar Wherever you are in the Iru platform, you can start chatting with Iru AI by clicking the AI icon in the top right corner of the screen. #### Home Dashboard If you're in Home, you can start chatting with Iru AI by clicking into the chat interface at the bottom of the page. #### Universal Search You can click Universal Search or press **Cmd + K** (Mac) / **Ctrl + K** (Windows) to open the search modal, then click the "Ask Iru AI" button to pass your query to Iru AI. ### Managing the Chat Interface Once the chat interface is open, you can: * **Expand to full-width** for a larger view of the conversation * **Reduce to drawer width** to keep it accessible while browsing other pages * **Close it completely** when you're done * **Create new chats** and access your chat history to revisit previous conversations ### Chat Features #### Natural Language Queries Ask Iru AI questions in natural language about your device fleet. For example, you can ask "Show me devices that haven't checked in recently," "Which devices have FileVault disabled?" or "What versions of Chrome are installed across my fleet?" #### Contextual Responses Iru AI provides summary views of your requested information along with links to detailed Prism reports with all underlying data. You'll also get actionable insights and recommendations for improving your device management, and Iru AI can ask clarifying questions to provide better answers. #### Session Management Each chat session is independent and privacy-focused. No previous conversations are logged or retained, and your conversations are not used to train AI models. ## Iru AI Insights ### About Iru AI Insights Iru AI proactively detects opportunities to improve your tenant's configurations and presents them as actionable insights. These recommendations are based on known best practices that Iru recommends to all customers, as well as ML models that highlight suggestions based on organizations similar to yours. ### What Are Insights? Iru AI Insights are designed to be actionable with clear calls-to-action in each recommendation card. They help you optimize configurations, enhance security, ensure compliance, and make device management processes more efficient. ### Accessing Insights Insights are only available in the Home dashboard. The insights section can be collapsed or expanded. Who can view and act on insights depends on the permissions in their role (for example, **Recommendations** and **Execute Iru AI Actions**). See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). Insights are updated regularly based on your current configuration. ### Authorizing Actions When you click the call-to-action for an insight, Iru AI opens a new chat to begin acting on that insight. Iru AI displays a preview of the action it's about to take, including what will be changed, which devices or settings are affected, and expected outcomes. You can approve the action by clicking "Yes," reject it by clicking "No," learn more by clicking the relevant link, or ask Iru AI to adjust the configuration before applying. Once you click "Yes," Iru AI executes the approved action, provides a link to the newly created object or modified configuration, and updates the insight status. ### Activity Logs All Iru AI actions are logged for audit purposes. Authorized actions are recorded in the Activity log, so you can track what changes were made and when, providing full visibility into Iru AI's automated actions. Activity logging for Iru AI actions is coming as a fast follow to the initial release. ### Managing Insights #### Snoozing Insights Individual insights can be snoozed if you don't want to act on them immediately. Click the snooze option on any insight card, choose how long to snooze the insight, and it will reappear after the snooze period. #### Insight Categories Insights are organized into categories such as: * **Security** - Recommendations for improving security posture * **Compliance** - Suggestions for meeting compliance requirements * **Performance** - Optimizations for better device performance * **Management** - Improvements to device management processes ## Best Practices * **Be specific**: Ask specific questions to get more targeted results from Iru AI * **Use natural language**: Don't worry about technical syntax - Iru AI understands natural language * **Follow up**: Ask follow-up questions to dive deeper into topics of interest * **Review recommendations**: Consider Iru AI's suggestions and take action when appropriate * **Review regularly**: Check your insights dashboard regularly for new recommendations * **Understand before acting**: Read the action preview carefully before approving changes * **Use learn more**: Click "Learn more" to understand the reasoning behind recommendations * **Monitor results**: Track the impact of approved actions on your device fleet * **Audit actions**: Review the Activity log to see what changes Iru AI has made ## Considerations **Chat Interface Navigation**: When the chat interface is opened to full-width and you click into another page, you'll be navigated there but won't be able to see the new page until you reduce to drawer-width or close the chat interface altogether. **User Access Levels**: Which agents and actions a team member can use depends on their role, and Iru AI must be enabled for the organization. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) and [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview#managing-iru-ai-access). **Review Before Acting**: Insights are based on current best practices and ML analysis of similar organizations. Always review recommendations before approving automated actions. # Access to Iru Support Source: https://docs.iru.com/en/iru/iru-support/access-to-iru-support Contact Iru Support for technical assistance with your account or devices. Learn about support channels, response times, and how to submit a support ticket. Iru Support will be closed from December 24, 2026 to January 1, 2027 so our team can rest over the holiday period. Live chat with a human will be unavailable during this time. We will continue to monitor email at [support@iru.com](mailto:support@iru.com) and the [Support Customer Portal](/en/iru/iru-support/support-customer-portal). During this time, we will review incoming requests and respond to incidents and other issues that need more immediate attention. Support is available to users with access to the Iru Web App who meet the eligibility requirements described in the [Team Members](#team-members) section below. The following sections cover available support channels and access levels. ### Contacting Support #### Support Channels ##### Available 24/7 * **Support AI**: Available via the chat bubble in the upper right corner of the Iru Web App * **Knowledge Base**: Available at [docs.iru.com](https://docs.iru.com/), includes overviews of all areas of Iru and frequently asked questions ##### Available 24/5 * **Iru Support Engineers**: Available via the chat bubble in the upper right corner of the Iru Web App, [support@iru.com](mailto:support@iru.com), or the [Support Customer Portal](/en/iru/iru-support/support-customer-portal). #### Regional Support Business Hours Support Engineers operate in the US, UK, and Australia with the following local business hours: * **United States**: Monday-Friday 6:00 AM - 9:00 PM EST/EDT * **United Kingdom**: Monday-Friday 7:00 AM - 4:00 PM GMT/BST * **Australia (Sydney)**: Monday-Friday, local time. Hours follow New South Wales daylight saving (AEST/AEDT). * **8:00 AM - 5:00 PM** on **Australian Eastern Standard Time (AEST)**: from the end of daylight saving in April through the start of daylight saving in October (Australian winter). * **9:30 AM - 6:30 PM** on **Australian Eastern Daylight Time (AEDT)**: from the start of daylight saving in October through the end of daylight saving in April (Australian summer). ### Team Members Support is available to users signing in with a verified work email domain that is associated with your organization's Iru tenant or an approved managed service provider (MSP) acting on your behalf. For security and data-protection reasons, we do not provide support to accounts that use personal or free email providers (including, but not limited to, @gmail.com, @yahoo.com, @outlook.com, @hotmail.com, @live.com, @msn.com, @aol.com, @icloud.com, @me.com, @protonmail.com, @zoho.com, @gmx.com, @mail.com), even if those addresses are added as team members in an Iru tenant. Administrators can be invited in **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). See [Modify or Remove Team Members](/en/iru/access/modify-or-remove-team-members). ### End Users Users of enrolled devices should contact their IT Admin for support. For security and privacy reasons, Iru only provides support to users listed in the team in **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**). ### Code of Conduct We value our customers and treat them with the utmost respect and courtesy. We expect the same in return. Disrespectful behavior, including but not limited to offensive language, personal insults, harassment, or threats, will not be tolerated. ### Iru Support Holiday Schedule #### 2026 | Date | Holiday | Region | | --------------------------------------- | --------------------------- | ---------- | | Thu, January 1 | New Year's Day | US, UK, AU | | Mon, January 19 | Martin Luther King Jr. Day | US | | Mon, January 26 | Australia Day | AU | | Mon, February 16 | Presidents' Day | US | | Fri, April 3 | Good Friday | UK, AU | | Mon, April 6 | Easter Monday | UK, AU | | Mon, April 27 | Anzac Day | AU | | Mon, May 4 | Early May Bank Holiday | UK | | Mon, May 25 | Memorial Day | US | | Mon, June 8 | King's Birthday | AU | | Fri, June 19 | Juneteenth | US | | Fri, July 3 | Independence Day (observed) | US | | Mon, August 31 | Summer Bank Holiday | UK | | Mon, September 7 | Labor Day | US | | Mon, October 5 | Labour Day | AU | | Thu, November 26 | Thanksgiving Day | US | | Fri, November 27 | Day after Thanksgiving | US | | Thu, December 24 – Fri, January 1, 2027 | Winter Wellness Week | US, UK, AU | | Fri, December 25 | Christmas Day | US, UK, AU | | Mon, December 28 | Boxing Day | UK, AU | # Service Level Agreement Source: https://docs.iru.com/en/iru/iru-support/service-level-agreement Review the Iru service level agreement (SLA) for uptime guarantees, response times, and support commitments. Understand coverage tiers and escalation paths. ### Iru Service Commitment Iru is committed to 99.9% availability of our services. Downtime does not include unavailability due to force majeure or due to planned downtime with at least 24 hours prior notice to customer. ### Maintenance Iru will provide all Account Owners with 24 hours prior notice through our [status page](https://status.kandji.io) for any platform maintenance. Iru will not be considered to be unavailable for any outage that results from any maintenance. Services will not be considered unavailable for any outage due to any customer-provided items such as customer software or custom scripts. Services will not be considered unavailable due to any network unavailability or bandwidth limitations. ### Support Services * In-App chat support through each customer tenant * Detailed Knowledge Base is located 24/7 at docs.iru.com * Email support at [support@iru.com](mailto:support@iru.com) ### Technical Support Commitment
Support Chat Support Portal Email
Business Hours (Sunday 22:30 - Saturday 01:00 UTC) 24 / 5 24 / 5 24 / 5
Trial Access
Customer Access
Initial Response Time \< 30 minutes \< 4 hours \< 4 hours
To provide world-class support, Iru Support and Solutions teams require [auditor-level access](/en/iru/access/team-member-role-permissions) to all customer tenants. ### Remedies This SLA provides Iru customers sole and exclusive remedy related to any Iru Endpoint failure to meet our service commitment. If Iru Endpoint fails to meet the 99.9% availability stated herein (calculated monthly), Customer will receive the following credit: for every 60 minutes of downtime, the customer will receive a credit equal to 2.5% of Customer's monthly fee for the affected Iru Endpoint Services. However, Customer's maximum total credit in any calendar month shall not exceed 100% of the fees for the affected Iru Endpoint Services paid by Customer and attributable to that month. To receive service credits, Customer must submit a written request to [support@iru.com](mailto:support@iru.com) and provide documented proof of the downtime within thirty (30) days of the downtime. # Status Page Source: https://docs.iru.com/en/iru/iru-support/status-page Monitor Iru platform status and service health on the status page. Check for incidents, scheduled maintenance, and subscribe to real-time status notifications. If you believe you are having issues with Iru there can be many factors, including but not limited to internet speeds, cloud service providers, and Iru internal systems. To provide transparency around the Iru system status we have created a status page that you can visit and subscribe to. All subscribers will be immediately notified of any changes to Iru's system status, as well as proactively notified of any planned outage for maintenance. Our status page is located at [https://status.kandji.io](https://status.kandji.io). Our support team is available to answer any questions our customers may have, so please [contact us](/en/iru/iru-support/access-to-iru-support) with any questions. # Support Customer Portal Source: https://docs.iru.com/en/iru/iru-support/support-customer-portal Access the Iru Support customer portal to view and manage your support tickets. Track issue status, add comments, and review resolution history. The Iru Support Customer Portal allows customers to open new support tickets, communicate with support, and check the status of existing support requests. ### Signing In To use the Support Customer Portal, you must be a [Team Member](/en/iru/access/team-member-role-permissions) with at least Auditor level access to the Iru Web App. Open our [Knowledge Base](/en/endpoint/getting-started/getting-started). You can start from any page in the Knowledge Base, including this article. Click the **Support** button near the top right of the page. Choose **Sign in with Kandji.io** or **Sign in with Iru.com**. When prompted, enter the subdomain (e.g., **accuhive** when the full domain of your tenant is **accuhive.iru.com**), then authenticate with your web app credentials. ### Viewing Tickets The **Tickets** page shows current ticket activity. From here, you can: * View ticket identifiers * View ticket subjects. Open a subject to read the thread with support or add a reply. * View the status of your support tickets Any [Team Member](/en/iru/access/team-member-role-permissions) included in communications for a ticket will have access to that ticket in their portal. ### View All Tickets Associated with Your Tenant By default, web app team members only have access to tickets they created. [Account Owners](/en/iru/access/team-member-role-permissions) may request visibility to all tickets associated with their company tenant, for themselves and/or any other web app team members, by contacting support via chat, support portal, or email at [support@iru.com](mailto:support@iru.com). ### File a Support Ticket Click **Submit a Ticket** near the top right of the page to open a new ticket with **Iru Support**. * **Requester** (required): The email address support uses for replies. It is prefilled for your account. * **Cc**: Add other people who should receive ticket messages; use **Hide CC** when you do not need this field. * **Issue Summary** (required): A short title for the request. * **Device Serial(s)**: Optional; enter serial numbers when the ticket is about specific devices. * **Full Details** (required): The main description. The editor supports formatting such as bold, lists, links, images, and code snippets. * **Attachments**: Optional files such as screenshots or logs; add or remove them before you submit. Each upload cannot exceed **20 MB**. If you need to share a larger file, say so in **Full Details** so **Iru Support** can help you transfer it another way. # Account Menu Source: https://docs.iru.com/en/iru/platform-overview/account-menu Open the Account Menu Button at the bottom of the Iru sidebar to reach Access, Billing, Organization, Integrations, Partner portal, My Account, and other tenant settings. ### About the Account Menu The **Account Menu Button** is at the bottom of the left sidebar in the Iru web app. It shows your name and email. Click it to open a menu of tenant-wide settings and account options that are not tied to a single product area (Endpoint, Identity, or Compliance). Account menu open at the bottom of the left navigation showing Access, Billing, Organization, Integrations, and other options Throughout this documentation, paths such as **Account Menu Button → Access** mean: click the **Account Menu Button**, then select **Access** from the menu. ### How to Open the Account Menu In the sidebar, click the **Account Menu Button** at the bottom of the left navigation. ### Menu Options | Menu item | What it opens | | --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Access** | Authentication, SSO, passkeys, team members, and API tokens. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) and [Passkeys & Social Login](/en/iru/access/passkeys-and-social-login). | | **Billing** | License counts, usage, and plan details. See [Billing Page](/en/iru/platform-overview/billing-page). | | **Organization** | Tenant profile, device domains, Endpoint platform settings, and organization resources. See [Getting Started with Compliance](/en/compliance/getting-started-with-compliance) and [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). | | **Integrations** | Directory services, SSO integrations, Apple platform settings, and third-party connectors. See [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) and [Apple Integrations Overview](/en/endpoint/settings/apple-integrations/apple-integrations-overview). | | **Partner portal** | MSP parent tenant management: child tenant list, provisioning, and creation. See [Partner Portal Page](/en/iru/platform-overview/partner-portal-page). | | **Customize sidebar** | Show or hide Endpoint, Identity, and Compliance sections in the left navigation. See [Customize Sidebar](/en/iru/platform-overview/upgrade-to-iru#customize-sidebar). | | **Getting started** | Onboarding tasks by product area. See [Getting Started](/en/endpoint/getting-started/getting-started) and [Getting Started with Compliance](/en/compliance/getting-started-with-compliance). | | **My Account** | Your profile, authenticators, and notification preferences. See [My Account Profile Settings](/en/endpoint/settings/user-preferences/my-account-profile-settings). | | **Sign out** | End your current session. | Depending on your permissions, you may not see **Access**, **Billing**, **Organization**, **Integrations**, or **Partner portal** in the account menu. **Partner portal** appears only for **Account Owners** and **Administrators** on an MSP parent tenant. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for which roles can open each option. While you are in the [Partner portal](/en/iru/platform-overview/partner-portal-page), the account menu includes **Home**. Click **Home** to return to your MSP parent tenant. ### Related Navigation Some features moved out of the account menu in the Iru interface. You can find them here instead: * **Activity**: Pulse icon in the top right navigation bar. See [Activity Page](/en/endpoint/devices/activity-page) and [Unified Activity](/en/iru/platform-overview/unified-activity). * **Alerts**: Bell icon in the top right navigation bar. See [Global Alerts](/en/endpoint/devices/global-alerts). * **Enrollment**: Bottom of the Endpoint section in the left sidebar. See [Getting Started](/en/endpoint/getting-started/getting-started). For a full list of interface changes after the Kandji-to-Iru transition, see [Upgrade to Iru](/en/iru/platform-overview/upgrade-to-iru). # Billing Page Source: https://docs.iru.com/en/iru/platform-overview/billing-page Manage your Iru subscription and billing details. View invoices, update payment methods, change plans, and monitor license usage from the billing page. ### About the Billing Page On the **Billing** page, you can review license counts, usage, and utilization by product. If you have questions about licensing or you're over your limit, use the **Contact sales** button in the bottom right to talk to sales about more licenses or your plan. For what you’ll see in the app when you’re near or over a limit, see [License Limits](/en/iru/platform-overview/license-limits). ### How to Get to the Billing Page In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Billing**. Screenshot of the account menu with Billing option highlighted ### License Management The **License management** table has four columns: * **Item**: The product or platform row. * **In use**: Licenses currently in use. * **License count**: Your limit for that row. * **Utilization**: How much of that limit is in use, as a percentage. Rows are grouped by category: * **Device Management**: macOS, Windows, Android, and Mobile. * **Endpoint Detection & Response**: EDR licenses by platform. * **Vulnerability Management**: Vulnerability management licenses by platform. * **Compliance**: Items such as ISO 27001, SOC 2, Trust Center, and Seats. * **Identity**: **Monthly Active Users (MAU)** with in use, license count, and utilization. Billing page showing License management table and Contact sales button in the bottom right Use the table to see how close you are to your limit in each area. At 100% usage, see [License Limits](/en/iru/platform-overview/license-limits) for in-app behavior such as notices and Blueprint editing. ### Requesting More Licenses or Plan Changes To request more licenses or change your plan, click **Contact sales** in the bottom right on the Billing page. In the sidebar, click the **Account Menu Button**, then select **Billing**. Screenshot of the account menu with Billing option highlighted On the Billing page, click the blue **Contact sales** button in the bottom right. In the Contact sales modal, select one or more products: * **Endpoint**: Endpoint security and management for Apple, Windows, and Android devices: Endpoint Management, Endpoint Detection & Response, Vulnerability Management. * **Identity**: Workforce identity and access management: Workforce Identity. * **Compliance**: AI-native compliance automation: Compliance Automation, Customer Trust. Click **Submit** to send your request. The sales team will follow up. If you still need help, [contact Iru Support](/en/iru/iru-support/access-to-iru-support). # Iru Brand Update Source: https://docs.iru.com/en/iru/platform-overview/iru-brand-update Learn about the Iru brand update including the new name, visual identity, and what has changed. Understand the transition timeline and impact on your account. ## About the Iru Brand Update As of **April 8, 2026**, Kandji branding has been updated to Iru across key admin, enrollment, and endpoint surfaces. Use this article as a quick reference for what changed, what stayed the same, and what IT teams should review. As of **April 8, 2026**, endpoint app branding updates are in place. Some changes may continue to roll out gradually by environment. ## What Changed * The Kandji bee icon is replaced by the Iru jellyfish in user-facing surfaces. * App names now use Iru branding (for example, Kandji Self Service is now Iru Self Service). * Manual enrollment portal branding now uses Iru. * Self Service item deep links for macOS use the **`iru-self-service://`** URL scheme for new links you create or share from the current app. Existing **`kandji-self-service://`** links keep working. See [Deep-Linking Self Service Items](/en/endpoint/settings/self-service/self-service-for-macos#deep-linking-self-service-items) for the URL format and how sharing works. * Docs and screenshots now reflect Iru naming in updated articles. ## Name Changes at a Glance | **Area** | **Before** | **After** | **Notes** | | ------------------------------------- | -------------------------------------------- | ---------------------------------- | ---------------------------------------------------- | | Agent app (user-facing) | Kandji Agent | Iru Agent | App branding update | | Self Service app (user-facing) | Kandji Self Service | Iru Self Service | App branding update | | Enrollment portal (manual enrollment) | Kandji branding | Iru branding | Applies to macOS and Windows enrollment portal flows | | Product mark / icon | Bee | Jellyfish | User-facing visual identity | ## Logo Icon Comparison Use this quick visual comparison to recognize the logo change from Kandji to Iru. | **Kandji icon** | **Iru icon** | | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- | | Kandji logo icon for light modeKandji logo icon for dark mode | Iru logo icon for light modeIru logo icon for dark mode | You may see logo variations across the platform, including light and dark color treatments and both flat and dimensional styles. These are expected and all represent the same Iru brand. ## What Did Not Change Some internal identifiers still use Kandji-prefixed values for compatibility. You may still see these in logs, system tools, and some on-disk names. * Unified Logging subsystem identifiers remain under `io.kandji.*`. * Some bundle identifiers remain under `io.kandji.*`. * Some launchd labels and plist names remain Kandji-prefixed. * Certain on-disk names can still include Kandji (for example, some utilities or legacy file names). * API endpoints remain unchanged. Tenants migrated to Iru can use either `https://subdomain.api.kandji.io/api/v1` or `https://subdomain.api.iru.com/api/v1`. Any existing scripts or integrations using the `api.kandji.io` URL will continue to work without modification. ## Where You See the Updates * **Admin web app:** Navigation and UI branding now use Iru. * **Endpoint apps (macOS):** Agent and Self Service now use Iru naming and visuals. * **Endpoint apps (iOS, iPadOS, and visionOS):** The **Iru Self Service** App Store app replaces **Kandji Self Service**. * **Endpoint apps (Windows):** User-visible app naming and enrollment-related text now use Iru branding. * **Manual enrollment portal:** Portal branding now uses Iru for macOS and Windows enrollment flows. ## Actions for IT Admins Review and update internal references that still use old app names: * Scripts that check app/process names * Automation workflows and device management utilities * Internal runbooks and SOP documentation * User communication templates and onboarding guides If your logic uses user-facing names, update it to Iru names. If your logic uses internal identifiers, verify whether Kandji-prefixed values still apply before changing automation. ## Related Articles Learn how the platform transition works and what to expect during upgrade. Understand the role of the agent and MDM in device management. Review command-line actions and operational workflows for the agent. Configure and manage the Self Service app experience for macOS users. Configure Self Service behavior and user experience on Apple mobile platforms. Set up Apple enrollment workflows and requirements in Iru Endpoint. Set up Windows enrollment workflows and requirements in Iru Endpoint. ## Need Help? If you need help validating whether a specific path, label, or identifier should be updated, contact [Iru Support](/en/iru/iru-support/access-to-iru-support). # Iru Overview Source: https://docs.iru.com/en/iru/platform-overview/iru-overview Overview of the Iru platform for Apple, Windows, and Android device management. Learn about Endpoint, Identity, Compliance, and AI product capabilities.
## What is Iru?
**Kandji is now Iru.**
Kandji logo icon for light mode Kandji logo icon for dark mode Iru logo icon for light mode Iru logo icon for dark mode

Iru is the security and IT platform trusted by the world’s fastest-growing companies to protect their people, apps, and devices. Built for the AI era, it brings identity, device management, and compliance together in one system, simplifying operations and giving teams back time and control.

By replacing fragmented tools with a single platform, Iru enables your teams to spend less time chasing tickets and more time improving the business. Iru's products include: Apps, policies, and enrollment for Apple, Windows, and Android. Prevent, detect, and contain threats on Mac and Windows. Find software risk on Mac and Windows and close patching gaps. Passwordless access with device-bound passkeys and live posture. Agents and a shared context layer across identity, endpoint, and compliance. Map controls to evidence and stay ready for audits. Public trust page for certifications, reports, and security posture.
## Iru Endpoint Iru provides unified endpoint management and security across Apple, Windows, and Android devices. Manage and protect every device with a single, low-overhead agent. ### Endpoint Management Provision work-ready devices with the right apps, settings, and security controls. Automate onboarding, app updates, and policy enforcement so teams move faster across Apple, Windows, and Android. ### Endpoint Detection & Response Defend against advanced and emerging threats. Prevent, detect, and contain attacks in real-time through a single, low-overhead agent across Mac and Windows. Real-time behavioral analysis, Iru AI, and our leading in-house research team ensure that unknown threats are stopped before lateral movement occurs. ### Vulnerability Management Gain full visibility into software risks across Mac and Windows with enhanced vulnerability detection. Iru’s autonomous remediation closes the gap between app vulnerability discovery and patching. **Docs:** [Getting Started](/en/endpoint/getting-started/getting-started) covers foundation, Blueprints, enrollment, and Endpoint guides. ## Iru Identity Iru delivers workforce identity and access management that pairs stronger security with a dramatically better user experience. ### Workforce Identity Iru is a truly passwordless identity & access management solution with one-step multifactor authentication, using device-bound passkeys. Iru’s extensible trust fabric spans users, devices, and apps, and links them with live device posture and authenticator lineage. It enforces device security policies at sign-in and maintains auditable records. **Docs:** [Identity overview](/en/identity/getting-started/overview) covers workforce identity concepts (product areas may vary by subscription). ## Iru AI Iru AI unites specialized agents across identity & access, endpoint security & management, and compliance automation. Iru AI is built around the Iru Context Model, a unified context layer that maps users, apps, devices, posture, policy, and events. Iru AI turns that live context into insights, actions, and audit-ready evidence. **Docs:** [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview) ## Iru Compliance Iru provides adaptive compliance automation that’s fully powered by Iru AI while also unblocking deals with a Trust Center. ### Compliance Automation See rigid frameworks turn into tailored controls with clear tasks ready to execute against. Iru AI collects, validates, and maps evidence, keeping teams continuously audit-ready. Draft and publish security policies in [Policies Management](/en/compliance/policies-management). When integrations or policies change, [Adaptive Compliance](/en/compliance/adaptive-compliance) proposes updates to control and action text for your review before anything is applied. ### Trust Center Meet procurement and legal needs with a public Trust Center. Share certifications and reports, gate sensitive docs with NDA workflows, and show real-time security posture to speed up sales. **Docs:** [Getting Started With Compliance](/en/compliance/getting-started-with-compliance) · [Policies Management](/en/compliance/policies-management) · [Adaptive Compliance](/en/compliance/adaptive-compliance) · [Sources Management](/en/compliance/sources-management) · [Trust Center Management](/en/compliance/trust-center/trust-center-management)
## The Iru Advantage Iru Endpoint, Identity, and Compliance share context through the Iru Context Model. Users, devices, apps, posture, and policy sit in one layer, so identity policies can apply on the device, device posture can inform sign-in, and compliance can reuse those same facts as evidence. For IT and security teams, this means getting back the time and control that's been lost to tool sprawl and manual processes. Instead of constantly switching between different consoles and trying to piece together what's happening, you have a unified view and intelligent automation. Your organization gains stronger security through advanced machine learning and contextual insights, improved productivity with automation, happier employees with a better end-user experience, and peace of mind with ongoing compliance assurance. Ready to see how Iru can transform your security and IT operations? Contact [sales@iru.com](mailto:sales@iru.com) to schedule a demo. # Iru Product Updates Source: https://docs.iru.com/en/iru/platform-overview/iru-product-updates Stay current with Iru product updates and new feature releases. Browse the changelog for recent improvements, bug fixes, and platform enhancements. The **Iru Product Updates** page lists feature releases and product improvements. You can read updates in the browser, subscribe by email for specific areas of the product, or follow the site with an RSS reader. The **Iru Product Updates** page is hosted at [https://www.iru.com/updates/](https://www.iru.com/updates/). ## Email Subscriptions On the **Iru Product Updates** page, choose **Subscribe to Updates** and enter your email address. You can select which kinds of product update emails you want to receive: * Agent * Auto Apps * Vulnerability Management * Endpoint Security * Device Management You can change your preferences or unsubscribe using the controls in those messages. In **Iru Endpoint**, you can also turn optional [weekly status emails](/en/endpoint/settings/user-preferences/my-account-profile-settings#weekly-status-emails) on or off for your account. Those messages summarize activity for your tenant and are separate from the product update categories above. ## RSS Feed To follow updates in an RSS reader, use the English feed URL: [https://updates.iru.com/feed-en](https://updates.iru.com/feed-en) If you have questions about a release or your tenant, [contact Iru Support](/en/iru/iru-support/access-to-iru-support). ## Related Articles Check Iru system status, subscribe to status notifications, and review incidents and maintenance. See how features move through release stages and what each stage means for your organization. See how the Iru platform fits together across Endpoint, identity, and compliance. Follow Endpoint setup from foundation through enrollment, including where to find Iru Product Updates links. Update your profile photo, preferences, and optional weekly status emails in Iru Endpoint. # Iru Release Stages Source: https://docs.iru.com/en/iru/platform-overview/iru-release-stages Understand Iru feature release stages including Beta, Early Access, and General Availability. Learn what to expect at each stage and how to provide feedback. We regularly introduce new product features in stages, with varying levels of availability and support. Some features may skip certain stages in the release process. ### Early Access (EA) We will, from time to time, invite select customers to test new features before they are available to all customers. The objective is to gather real-world feedback and refine the feature while it's still in development. Features in Early Access are designed to be functional, but their implementation and behavior may change before they reach later release stages. Therefore, we recommend using these features only on testing devices, not production devices. Participants in the Early Access program can access support through a dedicated ticket portal, where they can report issues and provide feedback. We also provide private documentation for these features, separate from our main support knowledge base. ### Preview Features in Preview are available to all our customers and are generally ready for production environments. However, some details of their implementation may still change. The Preview phase aims to expose new features to a broader audience for feedback and real-world testing. These features are clearly marked in the Iru user interface to indicate that minor changes may still occur. Preview features are supported through standard support channels and documented in the support knowledge base. ### Generally Available (GA) Features labeled as Generally Available (GA) are accessible to all customers and suitable for production environments without any additional requirements. Our Support Engineering team fully supports these features. Please note that some GA features may be available separately. ### Reference Table | **Support Type** | **Early Access (EA)** | **Preview** | **Generally Available (GA)** | | --------------------------- | --------------------- | ----------- | ---------------------------- | | Available for all customers | | **✓** | **✓** | | Chat Support | | **✓** | **✓** | | Email Support | **✓** | **✓** | **✓** | | Portal Support | **✓** | **✓** | **✓** | | Feature Requests Accepted | **✓** | **✓** | **✓** | # License Limits Source: https://docs.iru.com/en/iru/platform-overview/license-limits Understand Iru license limits and device count thresholds. Learn how licenses are consumed, what happens when you exceed limits, and how to upgrade your plan. ### About License Limits When your tenant is near or over its license count, Iru shows notices in the web app. You can still edit Blueprints and use the platform. This article describes those notices and where to check license usage. For licensing questions or when you're over your limit, use the [Contact sales](/en/iru/platform-overview/billing-page#requesting-more-licenses-or-plan-changes) button in the bottom right on the [Billing Page](/en/iru/platform-overview/billing-page). For a high-level product summary, see [Iru Overview](/en/iru/platform-overview/iru-overview). ### License Count Visibility Open the [Billing Page](/en/iru/platform-overview/billing-page) to compare licenses in use to your plan and spot when you're approaching or at a limit. ### When You're Near or Over Your Limit **Blueprint editing**\ You can edit Blueprints at any time, even when your tenant is at or over its license count. As of March 18, 2026, Blueprint editing is no longer locked when your tenant is at or over its license count. **Notices**\ Iru surfaces a notice about license usage. How often it appears depends on usage: | **Usage** | **When the notice appears** | | ----------------------------------- | ------------------------------------------------ | | **90%** of your license count | Once when you log in | | **100%** or over your limit | On every page load | ### Device Limit Exceeded If you're over your licensed device limit, Iru may show a dialog titled **Device limit exceeded**. It says you're over your licensed limit and asks you to contact your Customer Success Manager (CSM). If the dialog looks wrong or you don't know your CSM, click **View details** to open the [Billing Page](/en/iru/platform-overview/billing-page), then **[Contact sales](/en/iru/platform-overview/billing-page#requesting-more-licenses-or-plan-changes)** in the bottom right to reach sales. The dialog lists affected platforms, such as Android, Mobile, macOS, and Windows. Each over-capacity row shows a warning when utilization is above 100%. Device limit exceeded dialog with platform list over 100% utilization and View details button On the [Billing Page](/en/iru/platform-overview/billing-page), review limits in the **License management** table, then use **Contact sales** in the bottom right if you need to follow up. ### Share Feedback To suggest changes to license limits or notifications, use [feature requests](/en/endpoint/settings/submit-feature-requests-and-ideas). If you still need help, [contact Iru Support](/en/iru/iru-support/access-to-iru-support). # Partner Portal Page Source: https://docs.iru.com/en/iru/platform-overview/partner-portal-page Manage MSP child tenants from the Partner portal. View tenant details, provision products, create tenants, and open customer environments from the Partner dashboard. ### About the Partner Portal If your organization is an MSP parent tenant, the **Partner portal** is where you view and manage child customer tenants from one place. You can see which products are enabled per tenant, adjust provisioning, create new tenants, and open a child tenant to work in that environment. Child tenants still use separate sign-in. Opening a child tenant takes you to that tenant's URL; you authenticate there like any other Iru tenant. **Partner portal** appears in the [Account Menu](/en/iru/platform-overview/account-menu) only for **Account Owners** and **Administrators** on an MSP parent tenant. Other roles do not see it. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). ### How to Open the Partner Portal In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Partner portal**. You land on the **Partner dashboard**, which lists your parent tenant and every child tenant under your MSP account. Partner dashboard listing parent and child tenants with Search and Create tenant ### Return to the Parent Tenant While you are in the Partner portal, use **Home** in the Account Menu to return to your MSP parent tenant. In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu). Click **Home**. Account Menu open in the Partner portal showing Home and Sign out ### Partner Dashboard The **Partner dashboard** is the main view in the Partner portal. Use **Search** to filter tenants by name. Each row shows: * **Tenant name** and **subdomain URL** (for example, `customer.iru.com`) * **Parent** label on your MSP parent tenant row * **Product icons** for provisioned products. Icons appear in color when a product is enabled for that tenant and grey when it is off: * [Endpoint management](/en/endpoint/getting-started/getting-started) * [Endpoint detection & response](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) * [Vulnerability management](/en/endpoint/vulnerability-management/vulnerability-management-overview) * [Compliance](/en/compliance/getting-started-with-compliance) * [Identity](/en/identity/getting-started/overview) * [Trust Center](/en/compliance/trust-center/trust-center-management) * **Details** and **Tenant** buttons Click **+ Create tenant** in the top right to add a new child tenant. If you have no child tenants yet, the dashboard shows an empty state with the same **Create tenant** action. ### Open a Child Tenant On the **Partner dashboard**, locate the child tenant you want to open. Click **Tenant** on that row. Iru opens the child tenant in your browser. Sign in to that tenant if you are not already authenticated there. If you manage multiple tenants in separate tabs, child tenant browser tabs show the tenant name in the tab title (for example, **Iru | customername**). You can also open a tenant from the **Organization details** drawer. Click **Details** on a row, then click **Go to tenant** in the drawer header. ### View and Edit Tenant Details On the **Partner dashboard**, click **Details** on a tenant row. The **Organization details** drawer shows: * **Organization name** * **Company locale** (editable dropdown) * **Subdomain** (read-only; this URL is how users access the tenant and cannot be changed) * **Provision products**: Toggles for products your parent tenant has available: * [Endpoint management](/en/endpoint/getting-started/getting-started) * [Endpoint detection & response](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) * [Vulnerability management](/en/endpoint/vulnerability-management/vulnerability-management-overview) * [Compliance](/en/compliance/getting-started-with-compliance) * [Trust Center](/en/compliance/trust-center/trust-center-management) * [Identity](/en/identity/getting-started/overview) Organization details drawer with organization name, company locale, subdomain, and provision product toggles Adjust **Organization details** toggles as needed, then click **Save details**. On **Confirm changes**, review the summary of added and removed products. Type the tenant's subdomain into the **Enter tenant subdomain** field. Confirm changes dialog with product change summary and Enter tenant subdomain field Click **Confirm changes**. Whether you can edit and save tenant details depends on your role on the MSP parent tenant. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions). ### Create a Tenant On the **Partner dashboard**, click **+ Create tenant**. In **Tenant information**, fill in: * **Account owner**: Select an administrator from your parent tenant * **Organization name** * **Desired subdomain**: The tenant URL uses this value with `.iru.com`. It cannot be changed after creation. * **NFR (not-for-resale) license** (optional): Creates a complimentary demo tenant capped at 10 enrolled devices. Your parent tenant has a limited number of NFR licenses. When no NFR licenses remain, this option is disabled. Create tenant dialog on Tenant information with account owner, organization name, desired subdomain, and NFR license option Click **Save and continue**. In **Client information**, enter the client's details: * **Title** * **Customer email** * **First name** * **Last name** If you selected **NFR (not-for-resale) license**, this section is skipped. Create tenant dialog on Client information with title, customer email, first name, and last name fields Click **Save and continue**. In **Product provision**, turn on the products this tenant needs. Available toggles match the products provisioned on your parent tenant: * [Endpoint management](/en/endpoint/getting-started/getting-started) * [Endpoint detection & response](/en/endpoint/endpoint-detection-response-edr/endpoint-detection-and-response-edr-overview) * [Vulnerability management](/en/endpoint/vulnerability-management/vulnerability-management-overview) * [Compliance](/en/compliance/getting-started-with-compliance) * [Trust Center](/en/compliance/trust-center/trust-center-management) * [Identity](/en/identity/getting-started/overview) Create tenant dialog on Product provision with product toggles enabled Click **Save and continue**. Confirm the summary for **Organization information**, **Client information**, and **Product provision**. Use **Edit** on any section to go back and change it. Create tenant confirmation summary with organization information, client information, product provision, and Create tenant button Click **Create tenant** to provision the child tenant, or **Cancel** to discard. The new tenant appears on the **Partner dashboard** after creation. Open it with **Tenant**, or adjust products and locale from **Details**. ### Considerations The Partner portal is available only from your MSP parent tenant. You cannot open it from a child tenant's account menu. Each child tenant has its own sign-in. The Partner portal links you to child tenant URLs; it does not share a single session across tenants. You can enable only products that your parent tenant has provisioned. Child tenant toggles cannot exceed what the parent tenant supports. NFR tenants are for demonstration use and are limited to 10 enrolled devices. Your parent tenant receives five NFR licenses in total. The create-tenant form shows how many you have left. ### Related Articles Open **Partner portal** or return to your parent tenant with **Home**. Which roles can access the Partner portal and manage tenants. Add administrators who can be assigned as account owners for new tenants. Review license usage on your parent tenant. # Unified Activity Source: https://docs.iru.com/en/iru/platform-overview/unified-activity View and filter activity across Iru Endpoint, Detections, Vulnerabilities, and Compliance in one unified timeline. Search events and review actors. Preview ### About Unified Activity **Unified Activity** is a cross-product timeline of actions across Iru. See what happened, who performed the action, when it occurred, and which product recorded the event. Unified Activity is in **Preview** and is available alongside the current [Activity Page](/en/endpoint/devices/activity-page), which continues to show Endpoint activity. Unified Activity is supported through standard support channels, but some details may change before General Availability. See [Iru Release Stages](/en/iru/platform-overview/iru-release-stages) for details. ### How It Works Activity from **Endpoint**, **Detections**, **Vulnerabilities**, and **Compliance** appears in one feed, sorted with the most recent events first. Scroll down to load additional events. Each row includes **Activity**, **User**, **Timestamp**, and **Category** columns. When a product supplies a formatted description, that text appears in the **Activity** column. ### Access Unified Activity Click the **Activity** icon (pulse icon) in the top right navigation bar. Activity icon in the top right navigation bar Use the search field and filters at the top of the page to narrow the feed. Filter by **Date**, **User**, **Category**, or **Activity type**, and combine them with search as needed. See [Search and Filter Activity](#search-and-filter-activity) for details on each filter. ### Review Activity Details Click any row to expand it and read its fields. The **details** view opens by default. When the activity type provides them, you see formatted fields such as changes, related objects, and other context for that event. Click an activity row to expand it. Review the **details** view, including changed fields, related objects, and other context for that activity type. Expanded activity row showing the default details view Click **Show JSON** to open the raw event record for that activity. Expanded activity row with Show JSON button The expanded row shows every field logged for that event. Click **Show details** to return to the standard **details** view. Activity row with JSON payload expanded Some activity types include an **action menu** (**…**). Click it to open a related **Device** record, **Library Item**, vulnerability entry, or other page tied to that event. Activity row action menu with option to go to the related vulnerability entry ### Search and Filter Activity Use the search field and filters at the top of the Activity page to narrow the timeline. Search and filters work together. Search activity descriptions and underlying event details. Filter activity by time range: * Last 24 hours * Last 48 hours * Last 7 days * Last 30 days * Custom date range Filter by users who have access to your tenant. The list includes administrators and other team members. To add users, see [Invite New Team Members](/en/iru/access/invite-new-team-members). Filter by product area: * **System**: Tenant * **Product**: Endpoint, Detections, Vulnerabilities, Compliance Filter by specific event types, such as blueprint updates, device changes, detections, or compliance actions. Select multiple types to narrow the feed further. ### Considerations * **Entity-scoped activity**: Device records, Blueprints, and Library Items include **Activity** tabs scoped to that object. Those events also appear in Unified Activity when they match your search and filters. * **Historical Endpoint activity**: Past Endpoint activity is included in Unified Activity. ### Related Articles Current Endpoint activity timeline, available alongside Unified Activity while it is in Preview. Configure cross-account S3 export for the same unified tenant activity shown on this page. # Upgrade to Iru Source: https://docs.iru.com/en/iru/platform-overview/upgrade-to-iru Upgrade your existing Kandji account to the Iru platform. Follow the migration steps, understand what changes, and ensure a smooth transition for your team. Iru is the unified platform that brings together Endpoint, Identity, and Compliance capabilities. It builds on the foundation of Kandji with a fresh interface, enhanced features, and expanded capabilities designed for the complex security and management needs of modern organizations. Apple is still our foundation, and managing Apple devices securely remains a top priority. We're just as committed to building best-in-market Apple solutions, with a dedicated team that's growing and focused only on Apple. The upgrade to Iru brings several important changes to the platform: * **New look and feel**: The navigation interface features updated branding with the Iru logo and jellyfish icon, a new top navigation bar with enhanced search and Iru AI, and a refreshed sidebar design with customizable sections * **New support & knowledge base experience**: Iru Support Chat is available directly from the top navigation bar, and the new Support Knowledge Base is now located at [docs.iru.com](https://docs.iru.com) * **New domain**: Your tenant URL changes from `{{subdomain}}.kandji.io` to `{{subdomain}}.iru.com`, and the Enrollment Portal link moves from `{{subdomain}}.kandji.io/enroll` to `{{subdomain}}.iru.com/enroll` * **New authentication service**: As part of our transition to Iru, we've introduced a new authentication platform that replaces our previous provider. We built it specifically for complex authentication and authorization use cases, and it sets the foundation for advanced features like granular roles, permissions, and fine-grained access controls. * **No impact to end users**: End users don't need to take any action at this time. They'll notice a slightly updated login experience during device enrollment and the new enrollment portal domain, but everything else remains the same. As of **April 8, 2026**, Kandji-branded applications on managed devices have been updated to Iru as part of our transition to Iru. **What changed** * The **bee logo was replaced with the Iru jellyfish** everywhere the Kandji bee was used. * **Application names changed** (for example, "Kandji Self Service" → "Iru Self Service"). * The **manual enrollment portal branding** now uses Iru. **Important notes** * If you have **scripts, automations, or other utilities** that reference Kandji applications **by name**, update those references to the new Iru application names. * This update was applied **automatically to all Iru-managed endpoints**. The change is consistent across customers and **could not be delayed or customized** per device or per tenant. * **Communicate with your end users** about the new name and icon so internal expectations stay aligned. * For additional details on branding changes, see [Iru Brand Update](/en/iru/platform-overview/iru-brand-update). ### User Interface Changes #### Branding and Navigation * **New branding**: The Kandji logo and bee icon have been replaced with the Iru logo and jellyfish icon throughout the platform * **Enhanced search**: The top navigation bar now includes "Search or ask Iru AI" with keyboard shortcut support (⌘K) * **Iru Support Chat**: Access Iru Support Chat via the chat bubble icon in the upper right corner of the top navigation bar, next to Iru AI Navigation bar showing the chat bubble icon for Iru Support Chat in the upper right corner, next to Iru AI * **Updated sidebar**: The left navigation sidebar features a refreshed design with new promotional cards highlighting Identity and Compliance features. #### Account Menu Tenant-wide settings such as **Access**, **Organization**, and **Integrations** now live in the [Account Menu](/en/iru/platform-overview/account-menu). Click the [**Account Menu Button**](/en/iru/platform-overview/account-menu) at the bottom of the left navigation to open it. #### Access Manage authentication, connection settings, passkeys, and session controls. The **API tokens** tab is also available here. After upgrade, the Access page shows your new configuration; you manage connection settings (social login, native SSO, and SAML) and passkey registration. The upgrade card disappears once the upgrade to Iru is complete. #### Customize Sidebar Hide or show Endpoint, Identity, and Compliance sections in the sidebar. Account menu with Customize sidebar option highlighted #### Getting Started An onboarding guide that walks you through initial setup by product area. Use the **Endpoint**, **Identity**, and **Compliance** tabs to see recommended tasks. Tasks are listed as to do or done so you can track progress. #### Relocated Features Several features have moved to new locations: * **Activity**: Pulse icon in the top right navigation bar. See [Activity Page](/en/endpoint/devices/activity-page). **[Unified Activity](/en/iru/platform-overview/unified-activity)** is also available in Preview for a cross-product timeline. * **Alerts**: Bell icon in the top right navigation bar. See [Global Alerts](/en/endpoint/devices/global-alerts). * **Enrollment**: Bottom of the Endpoint menu in the left navigation. See [Getting Started](/en/endpoint/getting-started/getting-started) for enrollment setup. * **Organization**: [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Organization** * **Integrations** and **Apple platform settings**: [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**. See [SCIM Directory Integration](/en/endpoint/integrations/scim/scim-directory-integration) for the Integrations page and [Apple Integrations Overview](/en/endpoint/settings/apple-integrations/apple-integrations-overview) for Apple platform settings. * **Self Service settings**: **Self Service Settings** tab on the Library page. See [Self Service Settings](/en/endpoint/settings/self-service/self-service-settings). ### New Domain Your tenant URL changes from `{{subdomain}}.kandji.io` to `{{subdomain}}.iru.com`, and the Enrollment Portal link moves from `{{subdomain}}.kandji.io/enroll` to `{{subdomain}}.iru.com/enroll`. After you complete the upgrade, you'll need to log in using your new Iru domain. Your old Kandji domain will automatically redirect to the new domain. ### Authentication Improvements and Supported Methods Iru's new authentication platform supports all your existing connection types, plus passkeys: * Custom SAML configurations * Microsoft SSO * Google SSO * Social Login (using email + password + MFA) * Passkeys Replace username + password + MFA for administrators using standard authentication. You get enhanced security with a smoother login experience. ### Impact on Your Users #### For Administrators You'll need to complete the upgrade process when you're ready. After upgrade completes, you'll be signed out and need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`. Your old Kandji domain at `{{subdomain}}.kandji.io` will automatically redirect to the new domain. Once that's done, you'll have access to the new security features and session controls we mentioned earlier. #### For End Users End users don't need to do anything. The main differences they see are: * A slightly updated login experience during device enrollment * The Enrollment Portal link for manual enrollment is now `{{subdomain}}.iru.com/enroll` (replacing `{{subdomain}}.kandji.io/enroll`) Everything else stays the same. ### Frequently Asked Questions You can complete the upgrade when you're ready. The upgrade process is available when you log in to the Iru web app. Switch to the **Upgrade Process** tab above for step-by-step instructions. The upgrade process typically takes just a few minutes, depending on your identity provider and number of connections. End users don't need to take any action. They'll notice a slightly updated login experience during device enrollment and the new enrollment portal domain (`{{subdomain}}.iru.com/enroll` instead of `{{subdomain}}.kandji.io/enroll`). Email [support@iru.com](mailto:support@iru.com) or [contact Iru Support](/en/iru/iru-support/access-to-iru-support) if you need help with the upgrade process or have questions. The upgrade process includes a review step where you can confirm your settings before completing the transition. Ready to upgrade? Switch to the **Upgrade Process** tab above to follow the step-by-step instructions. During the upgrade process, if you get locked out, or have any issues, email [support@iru.com](mailto:support@iru.com) immediately for assistance. When you're ready to upgrade your tenant to Iru, you'll run the upgrade from **Settings** → **Access**. The process walks you through reviewing and reconfiguring your authentication connections for the new platform, then completing the migration. After it finishes, you'll sign back in at your new Iru domain. After you complete the upgrade, all active sessions will end, including your own, and you'll need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`. When you log in to the Iru Endpoint web app, click **Settings** in the left navigation, then select **Access**. You'll see a card prompting you to upgrade to unified authentication. Click **Start migration** to begin. Settings Access page showing the Upgrade to unified authentication card with Start migration button Look over your current authentication setup and configure replacements for SAML, Google, and Microsoft connections. For step-by-step configuration guides for each connection type, please refer to our [Single Sign-On support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on). You're creating a new SSO connection that will replace your existing one. Make sure to either use a new app in your IdP, or update all ACS URLs, Redirect URLs, SSO URLs, and Entity IDs to match the new values. If Standard Authentication isn't enabled, **incorrect configuration could result in getting locked out of your Iru tenant entirely**. Review connections interface showing current authentication setup with options to configure replacements If you currently use email + password + MFA, register a passkey and send passkey invitations to other administrators who also use standard authentication. For more information, see [Passkeys and Social Login](/en/iru/access/passkeys-and-social-login). When finished, click **Continue** to proceed. On macOS, if you or another administrator is prompted for a passkey but the expected one is not listed, open **System Settings > Privacy & Security > Passkeys Access for Web Browsers** and turn on access for the browser in use. Then close and re-open that browser and try authenticating again. If a team member is locked out after a reset, see [Iru Account Recovery](/en/iru/access/iru-account-recovery). Passkey setup interface showing options to register a passkey and send invitations You can click **Back** at any time during the upgrade to return to a previous step and make changes. Review your settings, and click Make changes if needed. Once settings are correct, check the box to confirm, then click **Complete migration** to finish the upgrade. Confirm and complete upgrade interface showing review options and completion button Once complete, all logged-in administrators will be signed out and need to re-authenticate with your new configuration. Log in using your new Iru domain at `{{subdomain}}.iru.com`. Your old Kandji domain at `{{subdomain}}.kandji.io` will automatically redirect to the new domain. The process typically takes just a few minutes, depending on your identity provider and number of connections. If you used **Active Directory Certificate Services (AD CS)** in Kandji, the tenant upgrade does not replace the **legacy** AD CS Connector on your Windows Server. After you sign in to Iru Endpoint, uninstall that Connector on the server, install the **updated** Connector from your **Iru** tenant, and complete registration approval. Follow [Migrating from Kandji to Iru with AD CS](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview#migrating-from-kandji-to-iru-with-ad-cs) in **AD CS Integration: Overview** for the full workflow, including when the integration may still show **Connected** until you remove the legacy package. # HIPAA Compliance Source: https://docs.iru.com/en/iru/regulatory/hipaa-compliance How Iru supports HIPAA compliance for healthcare organizations: security controls, data protection measures, and Iru's role with PHI and BAAs. ### HIPAA Compliance The Health Insurance Portability and Accountability Act (HIPAA) Security Rule defines a series of administrative, technical, and physical security procedures for covered entities to use to assure the confidentiality, integrity, and availability of electronically-protected health information. ### Do I need a Business Associate Agreement with Iru? Iru does not store or manage Protected Health Information (PHI) on behalf of customers. As a result, we do not act as a business associate under HIPAA, and a Business Associate Agreement (BAA) is not required. ### Can Iru help my organization become HIPAA compliant? Yes! As a [CIS partner](https://www.cisecurity.org/partner/iru-inc), Iru can help you employ CIS benchmarks to securely configure workstations used to manage electronic protected health information and be a major component of your HIPAA compliance plan. # Browser Requirements Source: https://docs.iru.com/en/iru/requirements/browser-requirements Review browser requirements for the Iru web application. Check supported browsers, minimum versions, and recommended settings for the best admin experience. ### Browser Requirements The Iru Web App supports the latest version of the following browsers: * Safari * Chrome * Firefox * Edge **Windows Device Enrollment**: You'll need to use Microsoft Edge browser to enroll Windows devices. For more information, see [Microsoft's documentation on Mobile Device Management (MDM) enrollment](https://learn.microsoft.com/en-us/windows/client-management/mdm-enrollment-of-windows-devices#connect-your-windows-device-to-work-using-a-deep-link). ### Browser Extensions While any browser extension may cause issues such as degraded performance, we recommend disabling all ad blockers and translation tools when using the Iru platform. By design, these tools stop certain JavaScript files from loading, which may prevent critical functionality from functioning within the Iru platform. We recommend using a Password Manager extension to generate and store unique and strong passwords for your Iru standard authentication or Single Sign-On (SSO) login credentials. Our recommendations are [1Password](https://1password.com/), [Dashlane](https://www.dashlane.com/), or [LastPass](https://www.lastpass.com/business-password-manager). ### Performance To optimize your experience, we recommend the following device types: * Desktop or portable computers For an optimal experience, be sure to use Iru on a desktop or portable computer. Using Iru on other device types, such as iPad, is not supported. ### Processing Speed Be aware that additional applications, tabs, and browsers use your computer's memory. When you run other applications, this impacts the performance of all other applications, and therefore the Iru platform. When you use one or more 'heavy' applications (e.g., presentations, photo or video editing software) we recommend a minimum of 4GB of memory and upwards. ### Internet Speed Because Iru is a SaaS platform operating in the cloud, the performance is highly dependent on your internet connection. For an optimal experience, we recommend a minimum internet speed of 10Mbps per user. ### Mobile The web version of Iru is currently not optimized for use on mobile or tablet devices. The usage of mobile browsers is not supported at this time. See our [Device Requirements](/en/iru/requirements/device-requirements) article to learn which devices and operating systems support Iru enrollment. # Device Requirements Source: https://docs.iru.com/en/iru/requirements/device-requirements Review device requirements for Iru Endpoint. Check supported operating systems, minimum versions, and hardware specs for Mac, iOS, Windows, and Android. Iru supports managing Apple devices, Windows computers, and Android mobile devices. For a detailed breakdown of supported operating systems and requirements, see the sections below. You can also read our [overview](/en/iru/platform-overview/iru-overview) for more information. ## General Requirements * **Active internet connection** - Required for enrollment, policy updates, and device management * **Hardware compatibility** - All hardware and software combinations must be officially supported by the platform vendor ### Apple Device Support Iru supports management of macOS, iOS, iPadOS, tvOS, and visionOS devices using Apple's Mobile Device Management (MDM) framework and Iru's proprietary agents. **Supported Operating Systems:** * **macOS**: macOS 26 Tahoe, macOS 15 Sequoia, macOS 14 Sonoma * **iOS**: iOS 17 and higher * **iPadOS**: iPadOS 17 and higher * **tvOS**: tvOS 17 and higher * **visionOS**: visionOS 2 and higher ### Apple Device Requirements * All hardware and software combinations must be officially supported by Apple and not virtualized * Iru does not support exploitations of firmware, hardware, or operating systems, or devices running within virtual machines * Iru does not support using a cloned image of a computer that is already enrolled. This includes both physical and virtual devices. When device enrollment or identity tokens are replicated between devices, Iru device enrollment or synchronization failures will occur * Proper network connectivity for MDM communication ### Apple End of Support As of **Wednesday, October 15, 2025**, macOS 12 Monterey, macOS 13 Ventura, and iOS, iPadOS, and tvOS 16 are considered End of Support in Iru, meaning that Iru will no longer add features or bug fixes for these operating system versions. As of **Wednesday, January 21, 2026**, Iru refuses new enrollments from devices running them with the error: `enrolling with management server failed. Unexpected error. (MDMResponseStatus:400)` **End of Support:** * macOS 13 Ventura * macOS 12 Monterey * iOS 16 * iPadOS 16 * tvOS 16 **End of Life:** * macOS 11 and earlier * iOS 15 and earlier * iPadOS 15 and earlier * tvOS 15 and earlier End of Support means that Iru no longer provides support for these operating system versions. End of Life means that Iru no longer allows enrollments or provides support for these operating system versions. A device running an operating system that qualifies as End of Life will receive an error response from enrollment attempts and require an update to a supported operating system to enroll with Iru. ### Apple Considerations * **Apple Silicon vs Intel**: Iru supports both Apple Silicon and Intel-based Macs * **Virtualization**: Virtualized macOS instances are not supported * **Hardware Requirements**: Must meet Apple's minimum system requirements for the supported macOS version * **Device Types**: Supports Mac computers, iPhones, iPads, Apple TVs, and Apple Vision Pro devices ### Apple Troubleshooting **Common enrollment errors and solutions:** **"Device not eligible for enrollment"** * Check if device is running a supported OS version (macOS 14 or higher, iOS 17 or higher, iPadOS 17 or higher) * Verify device isn't already enrolled in another MDM solution * Ensure the device has been removed from Apple Business or Apple School Manager if it was previously enrolled elsewhere **"Profile installation failed"** * Check network connectivity to `*.iru.com` domains * Verify corporate firewall allows MDM traffic on ports 443 and 80 * Ensure device has sufficient storage space (at least 1GB free) * Try enrolling from a different network (home vs corporate) to isolate network issues **"Enrollment timeout"** * Disable VPN during enrollment process * Check if device is behind a proxy that blocks MDM traffic * Verify system date and time are correct on the device **Profile and policy problems:** **"Library items not installing"** * Check device compliance status in Iru dashboard * Verify device is assigned to correct blueprint * Review device logs for specific error messages * Ensure user has necessary permissions for app installations **"Device not checking in"** * Check if device has internet connectivity * Verify MDM profile is still installed (Settings > General > VPN & Device Management) * Look for network restrictions blocking communication with Iru servers * Check if device is in low power mode or has background app refresh disabled **"Settings not applying"** * Verify device meets minimum OS version requirements for specific settings * Check if setting conflicts with existing device configuration * Review device compliance status and any blocking conditions * Ensure proper user permissions for setting changes ### Windows Support Management of Windows is supported with a combination of Microsoft's MDM framework and Iru's proprietary Windows agent which supports app management (installation, upgrade, and uninstall), gathering application inventory from the device, and running custom PowerShell scripts. **Supported Operating Systems:** * **Windows**: Windows 11 24H2 or 25H2 (Pro, Pro Education, Enterprise, Education) ### Windows Requirements * Windows devices must be running Windows 11 24H2 or 25H2 * Local administrator rights required for initial enrollment * Proper network connectivity for MDM and agent communication * Serial numbers: Physical devices include these automatically; virtual machines need them defined ### Windows Troubleshooting **Common enrollment errors and solutions:** **"Access denied" or "Insufficient privileges"** * Ensure user account has local administrator rights during enrollment * Run enrollment command as administrator (right-click Command Prompt > "Run as administrator") * Check if Group Policy is blocking MDM enrollment * Verify Windows edition supports MDM (Pro, Enterprise, or Education required) **"Enrollment failed - Device not supported"** * Verify Windows 11 24H2 or 25H2 is installed (check with `winver` command) * Ensure device meets minimum hardware requirements for Windows 11 * Check if device is running in a virtual machine (some VMs may not support MDM) * Verify TPM 2.0 is enabled and functioning **"Network error during enrollment"** * Check Windows Firewall settings and ensure MDM traffic is allowed * Verify corporate proxy settings don't block `*.iru.com` domains * Disable VPN during enrollment if using corporate VPN **Agent and policy problems:** **"Iru agent not installing or updating"** * Check Windows Event Viewer for installation errors (Windows Logs > Application) * Verify Windows Update service is running and can download updates * Ensure device has at least 2GB free disk space for agent installation * Check if antivirus software is blocking agent installation or updates **"Policies not applying to device"** * Verify device is properly enrolled and shows as "Managed" in Settings > Accounts > Access work or school * Check device compliance status in Iru dashboard * Review Windows Event Viewer for policy application errors * Ensure device is assigned to correct blueprint in Iru **"Device not reporting to Iru"** * Check if Iru agent service is running (Services.msc > "Iru Agent") * Verify network connectivity to Iru servers * Review agent logs in `%ProgramData%\kandji\agent\logs` * Check Windows Defender or other security software isn't blocking agent communication ### Android Support Iru supports management of Android devices using Google's Android Enterprise framework. **Supported Operating Systems:** * **Android**: Android 13 and higher Iru officially supports Android versions that receive security patches from Google. As of now, Google provides security patches for Android 13 and higher. For more information on Google's security patch support, see the [Android Security Bulletins](https://source.android.com/docs/security/bulletin). ### Android Requirements * Android devices must support Android Enterprise * Devices must be compatible with Google Play Services * Proper network connectivity for Google services and Iru management ### Android Troubleshooting **Common enrollment errors and solutions:** **"Device not compatible with Android Enterprise"** * Verify device is running Android 13 or higher * Check if device manufacturer supports Android Enterprise (Samsung, Google Pixel, OnePlus, etc.) * Ensure device isn't rooted or running custom ROM * Verify device has Google Play Services installed and updated **"QR code enrollment fails"** * Ensure device camera can properly scan QR codes * Check if device has sufficient storage space (at least 500MB free) * Verify network connectivity during enrollment process * Try manual enrollment using the Blueprint link if QR code continues to fail **"Google Play Services error"** * Update Google Play Services to latest version * Clear Google Play Services cache and data * Check if device has Google Play Store installed * Verify device isn't running a modified version of Android **Android Enterprise and app management problems:** **"Work apps not installing"** * Check if device is properly enrolled in Android Enterprise * Verify work profile is active (Settings > Work profile) * Ensure Google Play for Work is accessible * Check device compliance status in Iru dashboard **"Device not checking in"** * Verify work profile is enabled and active * Check network connectivity to Google services * Ensure device isn't in battery optimization mode for work apps * Review Android Enterprise app logs for connection errors **"Work profile issues"** * Check if work profile was disabled by user * Verify Android Enterprise policies are properly configured * Ensure device meets minimum requirements for work profile * Check if device storage is full (work profile needs additional space) ## Network Requirements All managed devices require internet connectivity to communicate with Iru services. For detailed network requirements, see [Using Iru on Enterprise Networks](/en/iru/requirements/using-iru-on-enterprise-networks). # Using Iru on Enterprise Networks Source: https://docs.iru.com/en/iru/requirements/using-iru-on-enterprise-networks Configure enterprise network settings for Iru Endpoint. Allow required domains, ports, and IP ranges through firewalls and proxies for MDM communication. Some organizations may create **Enrollment Only** networks or put **Proxies** in place to limit access to the public internet. In these situations, it is important to ensure that your Apple, Windows, and Android devices can communicate with platform services and Iru to complete enrollment and management tasks. When creating firewall rules for these ports, **outbound** traffic will need to be allowed. ## Global Web App Access Regardless of region, all Iru tenants access the web app through a single global domain: `subdomain.iru.com`. The region-specific tables below also list `subdomain.kandji.io` and `subdomain.eu.kandji.io` as web app access domains. These are legacy hostnames that route to the same Iru service. Your data remains isolated within its assigned region. When the app loads, a lookup is performed against a globally available service (the Identity Service) to determine your tenant's region. All subsequent API calls are then routed to region-specific load balancers accordingly. For details on signing in and accessing your tenant, see [Getting Started](/en/endpoint/getting-started/getting-started). ## Required Domains & Ports ### Domains Shared Across All Regions The following domains are required for all tenants regardless of region: | Domain | Ports | Protocol | OS | Description | | ------------------------------ | -------------------------- | ------------------------------- | --------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | | `browser-intake-datadoghq.com` | 443 | TCP | All | Used for release management and platform monitoring | | `events.launchdarkly.com` | 443 | TCP | All | Used for release management and platform monitoring | | `updater.iru.com` | 443 | TCP | All | Used for Iru Access downloads and updates | | `*.c.lencr.org` | 443 | TCP | All | Used for Let's Encrypt certificate validation via Certificate Revocation Lists (CRLs). | ### Region-Specific Domains ### US-Hosted Region Domains | Domain | Ports | Protocol | OS | Description | | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `UUID.web-api.kandji.io``UUID.devices.us-1.kandji.io``UUID.devices.iru.com` | 443 | TCP | All | Used for MDM Check-In and Iru Agent communication. Replace UUID with your tenant's value. See [Determine your unique device domains](#determine-your-unique-device-domains) for how to find your UUID and domains. | | `kandji-prd.s3.amazonaws.com` | 443 | TCP | macOS | Used by macOS devices to download the Iru Agent & Custom Apps uploaded to your Iru tenant | | `iru-prd-managed-library-items.s3.amazonaws.com` | 443 | TCP | macOS | Used by macOS devices to download Auto Apps | | `managed-library.kandji.io` | 443 | TCP | macOS | Used by macOS devices to download Auto Apps | | `subdomain.web-api.kandji.io` | 443 | TCP | All | Used to download Mobile Device Management (MDM) Enrollment Profile | | `subdomain.kandji.io``subdomain.iru.com` | 443 | TCP | All | Used to access the Iru web app | | `subdomain.gateway.kandji.io``subdomain.gateway.iru.com` | 443 | TCP | All | Used by Iru web app to access Iru APIs. | | `*.iot.kandji.io` | 443 | TCP | All | Used for device telemetry communications | | `windows-agent.kandji.io` | 443 | TCP | Windows | Used to install and upgrade the Iru Agent on Windows | | `subdomain.id.iru.com``subdomain.id.connect.iru.com``subdomain.id.devices.iru.com``subdomain.id.gateway.iru.com` | 443 | TCP | All | Access point for the Iru Identity API service serving US tenants. Within the Iru web app, it is used universally across all tenants, independent of Iru Workforce Identity licensing | ### EU-Hosted Region Domains | Domain | Ports | Protocol | OS | Description | | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `UUID.web-api.eu.kandji.io``UUID.devices.eu.kandji.io``UUID.devices.eu.iru.com` | 443 | TCP | All | Used for MDM Check-In and Iru Agent communication. Replace UUID with your tenant's value. See [Determine your unique device domains](#determine-your-unique-device-domains) for how to find your UUID and domains. | | `kandji-prd-eu.s3.amazonaws.com` | 443 | TCP | macOS | Used by macOS devices to download the Iru Agent & Custom Apps uploaded to your Iru tenant | | `iru-prd-eu-managed-library-items.s3.amazonaws.com` | 443 | TCP | macOS | Used by macOS devices to download Auto Apps | | `managed-library.eu.kandji.io` | 443 | TCP | macOS | Used by macOS devices to download Auto Apps | | `subdomain.web-api.eu.kandji.io` | 443 | TCP | All | Used to download Mobile Device Management (MDM) Enrollment Profile | | `subdomain.eu.kandji.io``subdomain.iru.com` | 443 | TCP | All | Used to access the Iru web app | | `subdomain.gateway.eu.kandji.io``subdomain.gateway.eu.iru.com` | 443 | TCP | All | Used by Iru web app to access Iru APIs. | | `*.iot.eu.kandji.io` | 443 | TCP | All | Used for device telemetry communications | | `windows-agent.eu.kandji.io` | 443 | TCP | Windows | Used to install and upgrade the Iru Agent on Windows | | `subdomain.id.iru.com``subdomain.id.eu.iru.com``subdomain.id.connect.iru.com``subdomain.id.connect.eu.iru.com``subdomain.id.devices.eu.iru.com``subdomain.id.gateway.eu.iru.com` | 443 | TCP | All | Access point for the Iru Identity API service serving EU tenants. Within the Iru web app, it is used universally across all tenants, independent of Iru Workforce Identity licensing.

The US id domain is used as a global lookup service to know which region your tenant belongs to, and forward all further traffic to the EU api region. |
## AD CS Integration Network Requirements If you use the Active Directory Certificate Services integration, allow these network paths for AD CS Connector setup and certificate request flow. For full integration context, see [AD CS Integration: Overview](/en/endpoint/integrations/certificate-services/active-directory-certificate-services/active-directory-certificate-services-ad-cs-integration-overview). The **updated** AD CS Connector uses Iru sign-in and **registration URL** approval in the Iru Endpoint web app. It does **not** use Auth0. Use the **Updated AD CS Connector** table for standard allowlists (Iru tenant, Iru tenant API, Iru Identity, `adcsconn`, and internal AD CS CA traffic as listed). Include your Iru web app and any additional Iru Identity destinations from elsewhere in this article where those rows apply to your tenant. If any Windows servers still run the **legacy** connector during migration, also allow the destinations in the **Legacy AD CS Connector** table until those hosts are upgraded and the legacy connector is removed from Iru Endpoint. ### Updated AD CS Connector | Source | Destination | Destination domains | Port | Protocol | Description | | --------------- | ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | AD CS Connector | Iru tenant | `subdomain.iru.com``subdomain.kandji.io``subdomain.eu.kandji.io` | 443 | TCP | Used during initial connector setup for Iru sign-in and **registration URL** approval in the Iru Endpoint web app | | AD CS Connector | Iru tenant API | `subdomain.gateway.iru.com``subdomain.gateway.eu.iru.com``subdomain.gateway.kandji.io``subdomain.gateway.eu.kandji.io``subdomain.clients.us-1.kandji.io``subdomain.clients.eu.kandji.io` | 443 | TCP | Used for API communication between the AD CS Connector and your tenant.

Replace **subdomain** with your tenant subdomain. **Gateway** hostnames match [Region-specific domains](#region-specific-domains).

**Clients** rows are tenant-scoped client API hosts: `subdomain.clients.us-1.kandji.io` for **US Region** tenants and `subdomain.clients.eu.kandji.io` for **EU Region** tenants (same regional split as the tabs above). | | AD CS Connector | Iru Identity | `subdomain.id.iru.com``subdomain.id.eu.iru.com` | 443 | TCP | Used for Iru Identity during sign-in and token flows for the updated connector | | AD CS Connector | AD CS connector service | `adcsconn.kandji.io`
`adcsconn.eu.kandji.io`
| 443 | TCP | WebSocket over TCP. Used for certificate requests between the AD CS Connector and the customer tenant | | AD CS Connector | Windows AD CS CA server(s) in your environment | Internal AD CS CA server FQDN(s) | 135 + dynamic RPC range | TCP | Microsoft DCE/RPC between the connector and issuing CAs when processing certificate requests | Microsoft RPC is not a single fixed high port. Allow **TCP 135** (RPC Endpoint Mapper) to each issuing CA FQDN, and the **Windows dynamic RPC port range** each CA host uses, often the range shown as **RPC Dynamic Ports** in Windows Defender Firewall with Advanced Security on the certificate server. Confirm the range on every issuing CA and mirror it in your firewall or proxy rules. For background, see [Configure RPC dynamic port allocation with firewalls](https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/configure-rpc-dynamic-port-allocation-with-firewalls) on Microsoft Learn. ### Legacy AD CS Connector (migration only) Allow these destinations **only** while at least one Windows server still runs the **legacy** connector (Auth0-based WebView sign-in during setup). When every connector uses the **updated** flow from Iru, remove these allowlist rows. | Source | Destination | Destination domains | Port | Protocol | Description | | --------------- | ----------- | ------------------------------------------------------ | ---- | -------- | ----------------------------------------------------------------------------------------------------------------- | | AD CS Connector | Auth0 | `*.auth0.com` | 443 | TCP | **Legacy connector only.** Multiple subdomains used for initial WebView authentication during connector setup | | AD CS Connector | Auth0 | `auth.kandji.io`
`auth.eu.kandji.io`
| 443 | TCP | **Legacy connector only.** Used when authenticating the AD CS Connector during setup and WebSocket initialization | ## Determine Your Unique Device Domains Your unique device domains are used by enrolled devices to communicate with Iru via the MDM protocol and the Iru Agent. **US region examples:** * `UUID.web-api.kandji.io` * `UUID.devices.us-1.kandji.io` * `UUID.devices.iru.com` **EU region examples:** * `UUID.web-api.eu.kandji.io` * `UUID.devices.eu.kandji.io` * `UUID.devices.eu.iru.com` The UUID is unique to your tenant. You can view your tenant's domains by logging into your tenant and following these steps: In the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu), then select **Organization**. Under **Endpoint**, you will see the **Device Domains** panel. These domains are used by devices for MDM and Agent communication. ### Find Device Domain on a Mac To determine the specific domain being used by an individual Mac computer, run the following command in Terminal: ```bash Terminal icon="terminal" theme={null} system_profiler SPConfigurationProfileDataType | awk -v FS='(https://|/mdm)' '/CheckInURL/ {print $2}' ``` ## SSL/TLS Inspection The macOS Iru Agent uses certificate pinning so it only communicates with trusted servers and so traffic cannot be intercepted and inspected (MITM attack prevention). This may pose a challenge if your network or proxy administrator is decrypting all SSL/TLS traffic by default. Please ask your network administrator to exempt your tenant's device domains from inspection. Please note that even if you deploy your content filter's CA as a trusted root CA to your macOS devices, SSL/TLS inspection will still cause the Iru Agent to not communicate with Iru. ## Platform-Specific Network Requirements ### Apple Required Hosts & Ports Apple devices require access to various Apple services for proper enrollment and management. For Apple's network requirements, see Apple's official guide: [Configure devices to work with APNs](https://support.apple.com/guide/deployment/configure-devices-to-work-with-apns-dep2de55389a/1/web/1.0). | Destination Host | Ports | Purpose | | -------------------------------------- | -------------------------- | ----------------------------------------------------------------------- | | Apple network (`17.0.0.0/8`) | TCP/443 | Device activation and fallback if devices can't reach APNs on port 5223 | | Apple network (`17.0.0.0/8`) | TCP/5223 | Primary communication with Apple Push Notification service (APNs) | | Apple network (`17.0.0.0/8`) | TCP/443 or 2197 | Send notifications from device management service to APNs | ### Windows Required Hosts & Ports Windows devices require access to Microsoft services for proper enrollment and management: | Destination Host | Ports | Purpose | | ---------------------------------------------------------------------------------------------------------------------------------------- | -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `*.notify.windows.com``*.wns.windows.com``login.microsoftonline.com``login.live.com` | TCP/443 | Required for Windows Push Notification Services (WNS). For detailed configuration requirements, see [Microsoft's WNS firewall allowlist documentation](https://learn.microsoft.com/en-us/windows/apps/develop/notifications/push-notifications/firewall-allowlist-config) | Additional URLs may be required for Windows-specific features to function properly. For the full list of Windows endpoints, see [Microsoft's Windows 11 endpoints documentation for non-enterprise editions](https://learn.microsoft.com/en-us/windows/privacy/windows-11-endpoints-non-enterprise-editions) or [Microsoft's Windows 11 endpoints documentation for enterprise editions](https://learn.microsoft.com/en-us/windows/privacy/manage-windows-11-endpoints). ### Android Required Hosts & Ports Android devices require access to Google services for proper enrollment and management. For Android network requirements, see [Google's Android Enterprise network requirements](https://support.google.com/work/android/answer/10513641?hl=en). | Destination Host | Ports | Purpose | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------- | ------------------------------------------------------------------------- | | `play.google.com``android.com``google-analytics.com``googleusercontent.com``*.gstatic.com``*.gvt1.com``*.ggpht.com``dl.google.com``dl-ssl.google.com``android.apis.google.com``*.gvt2.com``*.gvt3.com` | TCP/443
TCP, UDP/5228-5230 | Google Play and updates, app downloads, and Play Store APIs | | `*.googleapis.com``m.google.com` | TCP/443 | EMM/Google APIs/PlayStore APIs/Android Management APIs | | `accounts.google.com``accounts.google.[country]` | TCP/443 | Authentication (use your local top-level domain for \[country]) | | `gcm-http.googleapis.com``gcm-xmpp.googleapis.com``android.googleapis.com` | TCP/443, 5228-5230 | Google Cloud Messaging for EMM Console ↔ DPC communication | | `fcm.googleapis.com``fcm-xmpp.googleapis.com``firebaseinstallations.googleapis.com` | TCP/443, 5228-5230 | Firebase Cloud Messaging for Find Hub and EMM Console ↔ DPC communication | | `connectivitycheck.android.com``connectivitycheck.gstatic.com``www.google.com` | TCP/443 | Android OS connectivity checks for Wi-Fi/Mobile network connections | | `mtalk.google.com``mtalk4.google.com``alt1-mtalk.google.com``alt2-mtalk.google.com``alt3-mtalk.google.com``alt4-mtalk.google.com``alt5-mtalk.google.com``alt6-mtalk.google.com``alt7-mtalk.google.com``alt8-mtalk.google.com``android.apis.google.com``device-provisioning.googleapis.com` | TCP/443, 5228-5230 | FCM connectivity for devices behind organizational firewalls | | `time.google.com` | UDP/123 | NTP server access required during device provisioning |
## TLS Versions and Cipher Suites Per Apple's Platform Security guide, built-in apps and services on macOS, iOS, tvOS, and iPadOS devices will automatically prefer cipher suites with perfect forward secrecy. This is also true in the case where a developer uses a high-level networking API such as CFNetwork. The Iru Agent uses these high-level networking APIs. We encourage you to read Apple's Platform Security Guide to better understand these features, especially the TLS network security section, which can be found [here](https://support.apple.com/guide/security/tls-network-security-sec7b0a3b0b/web). The domains used for MDM and Iru Agent communication are unique to your tenant. See [Determine Your Unique Device Domains](#determine-your-unique-device-domains) for how to find yours. You can inspect your tenant's domains using a tool such as [Qualys SSL Server Test](https://www.ssllabs.com/ssltest/) to understand which ciphers are currently supported by Iru. ### Supported TLS Protocols Iru supports the following TLS protocol versions: | Protocol | Supported | Notes | | ------------------------------- | -------------------------------------- | --------------------------------- | | TLS 1.2 | Yes | Server negotiated using No-SNI | | TLS 1.1 | Yes | | | TLS 1.0 | Yes | Server negotiated using No-SNI | | TLS 1.3 | No | | | SSL 3 | No | | | SSL 2 | No | | ### Cipher Suites * `TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256` * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256` * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA` * `TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384` * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384` * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA` * `TLS_RSA_WITH_AES_128_GCM_SHA256` * `TLS_RSA_WITH_AES_128_CBC_SHA256` * `TLS_RSA_WITH_AES_128_CBC_SHA` * `TLS_RSA_WITH_AES_256_GCM_SHA384` * `TLS_RSA_WITH_AES_256_CBC_SHA256` * `TLS_RSA_WITH_AES_256_CBC_SHA` * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA` * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA` * `TLS_RSA_WITH_AES_128_CBC_SHA` * `TLS_RSA_WITH_AES_256_CBC_SHA` * `TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA` * `TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA` * `TLS_RSA_WITH_AES_128_CBC_SHA` * `TLS_RSA_WITH_AES_256_CBC_SHA` # Home Source: https://docs.iru.com/home Iru documentation hub for device management, identity, compliance, and AI. Find guides, API references, and setup instructions for Apple, Windows, and Android.
# Collapse the stack. Learn the platform.

Get started

Deploy endpoint management, detection & response, and vulnerability management in a single agent across Apple, Windows, and Android. Passwordless workforce identity with device-bound authentication and strong access policies for every app. Automate controls and build an Adaptive Evidence Map so you stay audit-ready and unblock deals with a public trust center.

Popular guides

Learn how Iru's platform fits together. Configure networks for best performance and reliability. How to reach our team and what to include. Submit a support request and track status.

Quick links

See Iru in action. Check system status. Iru security and compliance posture. Latest updates and releases.