Fleet health rules
The dashboard’s Fleet health chart sorts every live device into Healthy, Needs attention or Critical using fixed rules. This page spells them out so you know exactly why a device landed where it did.
Who: all roles.
Which devices are counted
Fleet health only counts live devices. These are left out:
- Waiting for device (not enrolled yet)
- Erased
- Retired
The chart’s subtitle shows how many live devices it covers.
The rules
NounDesk checks each device against the rules from top to bottom. The first rule that matches wins, so a device is only ever in one group.
Critical
A device is Critical if any of these is true:
- Google’s security check rates it potentially compromised.
- It’s in Lost mode.
- It’s been Offline (not seen for more than 24 hours) and its compliance is Needs attention.
In the app: “Potentially compromised, in lost mode, or offline for more than 24 hours while non-compliant.”
Needs attention
Otherwise, a device Needs attention if any of these is true:
- Its compliance is Needs attention or Attention.
- Google’s security check rates it at risk.
- It’s been Offline for more than 24 hours.
- It’s Disabled or Erasing….
In the app: “Not compliant, flagged at risk by Google, offline for more than 24 hours, or disabled.”
Healthy
Everything else is Healthy. In the app: “Compliant, no security warning, and seen in the last 24 hours.”
A device that’s Recently offline (last seen within 24 hours) can still be Healthy. A device that has never checked in (Not seen yet) isn’t treated as offline by these rules.
Quick examples
| Device | Result | Why |
|---|---|---|
| Compliant, seen 5 minutes ago | Healthy | No rule matches |
| Compliant, seen 3 hours ago | Healthy | Seen within 24 hours |
| An app still installing (Attention) | Needs attention | Compliance isn’t Compliant |
| Compliant, not seen for 2 days | Needs attention | Offline for more than 24 hours |
| A failed app install (Needs attention), not seen for 2 days | Critical | Offline and non-compliant |
| In lost mode, otherwise fine | Critical | Lost mode |
Using the chart
- Select Healthy to open the devices list filtered to compliant devices.
- Select Needs attention or Critical to open the devices that need attention.
- Open How these are calculated under the chart to see the three rules.
Percentages are rounded so they always add up to 100%.
The dashboard tiles
| Tile | What it counts |
|---|---|
| Total devices | Every device except those Waiting for device, Erased or Retired. |
| Online | Devices seen in the last 15 minutes. |
| Offline | Devices not seen for more than 24 hours, plus devices that have never checked in. Recently offline devices are in neither tile. |
| Compliant | Devices whose compliance is Compliant. |
| Needs attention | Devices whose compliance is Needs attention or Attention. |
| Security risks | See below. |
| Open alerts | Alerts that are open or acknowledged (not yet resolved). |
| Waiting for device | Enrollment codes no device has used yet. This tile only appears when there are some. |
Select a tile to open the matching list.
The Needs attention tile and the Needs attention part of the chart count different things. The tile counts compliance only. The chart also counts offline, at-risk and disabled devices, and moves the most serious ones to Critical.
How “Security risks” is counted
A device counts as a security risk if any of these is true:
- Google’s security check rates it at risk or potentially compromised.
- It’s in Lost mode.
- It has a critical security alert that’s open or acknowledged.
Each device is counted once, however many of these apply. Devices still Waiting for device are never counted. Selecting the tile opens the devices that need attention.