Skip to content

Data collection

The Oneleet Agent collects data from your device for continuous monitoring and security. The data collected includes:

  • Computer name
  • CPU brand
  • Hardware model
  • Hardware serial
  • OS name
  • OS version
  • OS architecture
  • Local user accounts and permissions, including which accounts are able to unlock FileVault
  • Active and enabled network filters

Firewall is a network security system that monitors and controls incoming and outgoing network traffic. We check the status of the firewall and installed network filters to ensure that a firewall is enabled.

Gatekeeper is a security feature in macOS that helps protect your Mac from malicious software. We check the status of Gatekeeper to ensure that it is enabled.

System Integrity Protection (SIP) is a macOS security feature that protects system files and processes from modification, including by accounts with administrator access. We check the status of SIP to ensure that it is enabled.

The Oneleet Agent devices have System Integrity Protection enabled monitor evaluates macOS devices running agent version 2.3.6 or newer that report SIP status. It passes when SIP is enabled and fails when SIP is disabled. Windows and Linux devices, older agents, and devices whose SIP status can’t be read are marked as Not applicable. A not-applicable result doesn’t confirm that SIP is enabled.

To re-enable SIP, ask the device owner to start the Mac in macOS Recovery:

  • Apple silicon: shut down, then hold the power button until startup options appear. Choose Options, then Continue.
  • Intel: restart and immediately hold Command (⌘) + R.

Authenticate if prompted, then choose Utilities > Terminal, run csrutil enable, and restart. The agent reports the updated status on its next check-in. This monitor has no automatic fix.

FileVault is a disk encryption program in macOS that helps protect your data. We check the status of FileVault for your main disk drive to ensure that it is enabled.

Screenlock is a security feature that requires a password to unlock your device. On macOS, the device must require a password within 10 minutes of inactivity, both on battery and on the power adapter.

In System Settings > Lock Screen, the earlier enabled timer for turning off the display or starting the screen saver, plus Require password after screen saver begins or display is turned off, must total 10 minutes or less on each power source. A timer set to Never doesn’t trigger locking. A screen saver that meets the limit allows either display-off timer to exceed 10 minutes or be set to Never. For example, a 5-minute screen saver with an immediate password requirement passes even with a 30-minute power adapter display timer; without that screen saver, the same display timer fails.

If the agent can’t read a usable screen-lock timer, the check fails and reports that it couldn’t verify the settings. Sign in to the Mac and run the agent check again. Contact support if the read failure persists.

The storage volumes mounted on your device, including the device name, mount point, total capacity, and available free space.

We check whether the device is enrolled in a Mobile Device Management (MDM) service, and if so, the enrollment server’s URL, whether enrollment happened through Apple’s Device Enrollment Program, and whether the user approved it. A Mac can hold only one MDM enrollment at a time, so this tells you which devices are already managed by another product and therefore cannot be enrolled into Oneleet MDM.

If application inventory is available for your organization, an administrator can enable it in Settings → General → Application inventory. The Oneleet Agent then collects installed application names, versions, and available icons on Windows, macOS, and Linux devices, along with available application metadata such as publisher and installation location. On Linux, the inventory covers desktop application launchers rather than every installed package.

To view the latest reported inventory, open Devices, select a device, and choose Apps. Search by application name or version, or select Export to download the displayed applications as a CSV file. Applications without a reported name are omitted; a missing version is shown as Unknown, and an unavailable icon uses a generic application icon.

Select an application to open its installation details and see when the agent last observed the inventory. Installed version, installation scope, architecture, installation path, and application identifier are marked Not reported when unavailable. Publisher, package type, maintainer, executable path, and desktop launcher details appear only when reported. Separate installations can appear as separate rows even when their names and versions match.

Inventory appears after the agent next reports it. If the device is waiting for inventory, make sure it’s online and running the latest agent. The collection timestamp shows when the inventory was checked, so an offline device’s list can be out of date.

Disabling application inventory hides the Apps tab and stops collection after the agent receives the updated configuration. An organization with inventory disabled can’t retrieve the stored inventory through the application inventory API.

Devices in organizations using Oneleet MDM report additional device inventory data on top of the data listed above:

The battery’s factory design capacity and current maximum charge capacity, along with a computed battery health percentage. This helps track battery degradation across managed hardware.

The iCloud accounts configured for each local user account, including the iCloud account ID (the email address used to sign in) and whether the account is currently signed in. This helps verify that managed devices are only associated with approved iCloud accounts.