| Screen Lock | User | Verifies that the device is protected by a password, PIN, or
biometric lock. |
| Location Services | User | Checks if the operating system location services are enabled. |
| Full OS Boot Mode | User | Ensures the device was started normally and is not running in
Safe Mode. |
| Active Remote Connection | User | Detects if the device is being accessed remotely. |
| Browser Version | User | Checks if the browser version meets the minimum requirement. |
| Location | User | Verifies the device location is within an authorized region. |
| Network | User | Identifies whether the device is connected to an approved
network. |
| OS Version | Local admin | Checks the operating system version meets the minimum
requirement. |
| Disk Encryption | Local admin | Confirms that full disk encryption is active. |
| Firewall | Local admin | Confirms that a firewall is active on the device. |
| Endpoint Protection | Local admin | Confirms that an endpoint protection solution is installed and
running. |
| System Integrity | Local admin | Verifies that critical system files have not been tampered
with. |
| Running Processes | Local admin | Checks if required or prohibited programs are running. |
| Unprivileged Process | Local admin | Detects if the browser is running with unnecessary
administrative privileges. |
| File Existence | Local admin | Checks for the presence of specific compliance files. |
| Registry | Local admin | Checks for specific system configurations in the Windows
Registry. |
| Client Certificate | IT administrator | Verifies that the device has a valid organization-issued
certificate. |
| Device Management | IT administrator | Checks if the device is enrolled in the organization MDM
system. |
| Serial Number | IT administrator | Verifies that the device serial number is on the approved
list. |
| Device Type | Hardware change | Categorizes the device hardware to confirm it meets
requirements. |