Data collection
The Oneleet Agent collects data from your device for continuous monitoring and security. The data collected includes:
System information
Section titled “System information”- Computer name
- CPU brand
- Hardware model
- Hardware serial
OS information
Section titled “OS information”- OS name
- OS version
- OS architecture
- Local user accounts and permissions, including which accounts are able to unlock FileVault
- Active and enabled network filters
Firewall status
Section titled “Firewall status”Firewall is a network security system that monitors and controls incoming and outgoing network traffic. We check the status of the firewall and installed network filters to ensure that a firewall is enabled.
Gatekeeper status
Section titled “Gatekeeper status”Gatekeeper is a security feature in macOS that helps protect your Mac from malicious software. We check the status of Gatekeeper to ensure that it is enabled.
System Integrity Protection status
Section titled “System Integrity Protection status”System Integrity Protection (SIP) is a macOS security feature that protects system files and processes from modification, including by accounts with administrator access. We check the status of SIP to ensure that it is enabled.
The Oneleet Agent devices have System Integrity Protection enabled monitor evaluates macOS devices running agent version 2.3.6 or newer that report SIP status. It passes when SIP is enabled and fails when SIP is disabled. Windows and Linux devices, older agents, and devices whose SIP status can’t be read are marked as Not applicable. A not-applicable result doesn’t confirm that SIP is enabled.
To re-enable SIP, ask the device owner to start the Mac in macOS Recovery:
- Apple silicon: shut down, then hold the power button until startup options appear. Choose Options, then Continue.
- Intel: restart and immediately hold Command (⌘) + R.
Authenticate if prompted, then choose Utilities > Terminal, run csrutil enable, and restart. The agent reports the updated status on its next check-in. This monitor has no automatic fix.
FileVault status
Section titled “FileVault status”FileVault is a disk encryption program in macOS that helps protect your data. We check the status of FileVault for your main disk drive to ensure that it is enabled.
Screenlock status
Section titled “Screenlock status”Screenlock is a security feature that requires a password to unlock your device. On macOS, the device must require a password within 10 minutes of inactivity, both on battery and on the power adapter.
In System Settings > Lock Screen, the earlier enabled timer for turning off the display or starting the screen saver, plus Require password after screen saver begins or display is turned off, must total 10 minutes or less on each power source. A timer set to Never doesn’t trigger locking. A screen saver that meets the limit allows either display-off timer to exceed 10 minutes or be set to Never. For example, a 5-minute screen saver with an immediate password requirement passes even with a 30-minute power adapter display timer; without that screen saver, the same display timer fails.
If the agent can’t read a usable screen-lock timer, the check fails and reports that it couldn’t verify the settings. Sign in to the Mac and run the agent check again. Contact support if the read failure persists.
Storage information
Section titled “Storage information”The storage volumes mounted on your device, including the device name, mount point, total capacity, and available free space.
MDM enrollment
Section titled “MDM enrollment”We check whether the device is enrolled in a Mobile Device Management (MDM) service, and if so, the enrollment server’s URL, whether enrollment happened through Apple’s Device Enrollment Program, and whether the user approved it. A Mac can hold only one MDM enrollment at a time, so this tells you which devices are already managed by another product and therefore cannot be enrolled into Oneleet MDM.
System information
Section titled “System information”- Computer name
- CPU brand
- Hardware model
- Hardware serial
OS information
Section titled “OS information”- OS name
- OS version
- OS architecture
- Local user accounts and permissions
Firewall status
Section titled “Firewall status”Firewall is a network security system that monitors and controls incoming and outgoing network traffic. We check the status of the firewall to ensure that it is enabled.
Antivirus status
Section titled “Antivirus status”Antivirus software detects and removes malware. We read the antivirus products registered with the Windows Security Center, along with Microsoft Defender’s running mode and real-time protection state, to determine whether an antivirus is enabled. A third-party antivirus counts, so devices protected by another vendor’s product pass without running Defender.
BitLocker status
Section titled “BitLocker status”BitLocker is a disk encryption program in Windows that helps protect your data. We check the status of BitLocker for your main disk drive to ensure that it is enabled.
Screenlock status
Section titled “Screenlock status”Screenlock is a security feature that requires a password to unlock your device. We check the status of screenlock to ensure that it is enabled and set to a minimum threshold.
Storage information
Section titled “Storage information”The logical drives on your device (such as C:), including the drive name, total capacity, and available free space.
System information
Section titled “System information”- Computer name
- CPU brand
- Hardware model
- Hardware serial
OS information
Section titled “OS information”- OS name
- OS version
- OS architecture
- Local user accounts and permissions
Firewall status
Section titled “Firewall status”Firewall is a network security system that monitors and controls incoming and outgoing network traffic. We check supported Linux firewall managers and rulesets, including UFW, firewalld, nftables, and iptables, to determine whether a firewall is enabled.
Disk encryption status
Section titled “Disk encryption status”Disk encryption is a security feature that helps protect your data. We check the status of disk encryption for your main disk drive to ensure that it is enabled.
Storage information
Section titled “Storage information”The storage volumes mounted on your device, including the device name, mount point, total capacity, and available free space.
Application inventory
Section titled “Application inventory”If application inventory is available for your organization, an administrator can enable it in Settings → General → Application inventory. The Oneleet Agent then collects installed application names, versions, and available icons on Windows, macOS, and Linux devices, along with available application metadata such as publisher and installation location. On Linux, the inventory covers desktop application launchers rather than every installed package.
To view the latest reported inventory, open Devices, select a device, and choose Apps. Search by application name or version, or select Export to download the displayed applications as a CSV file. Applications without a reported name are omitted; a missing version is shown as Unknown, and an unavailable icon uses a generic application icon.
Select an application to open its installation details and see when the agent last observed the inventory. Installed version, installation scope, architecture, installation path, and application identifier are marked Not reported when unavailable. Publisher, package type, maintainer, executable path, and desktop launcher details appear only when reported. Separate installations can appear as separate rows even when their names and versions match.
Inventory appears after the agent next reports it. If the device is waiting for inventory, make sure it’s online and running the latest agent. The collection timestamp shows when the inventory was checked, so an offline device’s list can be out of date.
Disabling application inventory hides the Apps tab and stops collection after the agent receives the updated configuration. An organization with inventory disabled can’t retrieve the stored inventory through the application inventory API.
Additional data on MDM-managed devices
Section titled “Additional data on MDM-managed devices”Devices in organizations using Oneleet MDM report additional device inventory data on top of the data listed above:
Battery health (macOS and Windows)
Section titled “Battery health (macOS and Windows)”The battery’s factory design capacity and current maximum charge capacity, along with a computed battery health percentage. This helps track battery degradation across managed hardware.
iCloud accounts (macOS)
Section titled “iCloud accounts (macOS)”The iCloud accounts configured for each local user account, including the iCloud account ID (the email address used to sign in) and whether the account is currently signed in. This helps verify that managed devices are only associated with approved iCloud accounts.