> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Devices

> Track employee device compliance — encryption, screen lock, OS updates, and security agent enrollment.

The Devices page tracks all employee endpoints — laptops, desktops, and mobile devices — and monitors their security compliance status. Auditors need evidence that company devices meet baseline security requirements, and this module provides it.

## What Devices is for

SOC 2 and ISO 27001 require you to demonstrate that employee devices are secured — encrypted hard drives, screen locks enabled, OS up to date, and security agents installed. The Devices module tracks all of this in real time, either through a device agent or MDM integration.

## How device data is collected

Devices are registered in two ways:

* **DSALTA Device Agent** — Employees install a lightweight agent on their device through the employee portal. The agent reports device configuration data to DSALTA without collecting personal data or browsing history.
* **MDM Integration** — Connect **JumpCloud** to pull device data automatically for all managed devices.

## Viewing your devices

The device list is split into two sections:

**Monitored Devices** — Devices that are assigned to an employee. The table shows the owner, OS version, the PW / HD / AV / SL check columns and the Last Check date, and a device stays on this tab whatever its Last Check date says.

**Unmonitored Devices** — Devices that are waiting to be assigned to an employee. Assignment is the only thing that decides which tab a device appears on. JumpCloud-synced devices arrive here, because the sync reports each system without an owner email; use the row's ⋮ menu → **Assign to User** to link one to an employee, which moves it to Monitored, or **Forget this Device** to remove it.

For each monitored device, DSALTA tracks:

| Check                     | Description                                                                                                       |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Hard Drive Encryption** | Whether disk encryption is enabled (BitLocker on Windows, FileVault on macOS)                                     |
| **Screen Lock**           | Whether automatic screen lock is configured with a reasonable timeout                                             |
| **OS Version**            | The operating system and version string the device reported, shown with a platform icon                           |
| **Password Manager**      | Whether a password manager application is installed                                                               |
| **Antivirus**             | Whether antivirus or endpoint protection software is active                                                       |
| **Owner**                 | The employee the device is assigned to — the value that decides whether it appears under Monitored or Unmonitored |
| **Last Check-In**         | When the device last reported its status                                                                          |

## Working with devices

When a device check fails (e.g., encryption is not enabled), that column shows a red ✗ in the device list. Tell the employee directly — their portal covers onboarding tasks, policies, security trainings and the Device Monitor install step.

To resolve a failing device check:

1. Identify the failing check from the ✓/✗ icons in the Monitored table's PW, HD, AV and SL columns. Clicking a row opens the assigned employee's profile panel.
2. Contact the employee so the setting is applied on the machine — the device agent reports the new value at its next check-in. JumpCloud-synced rows carry disk encryption from JumpCloud's FileVault/BitLocker status, and their screen lock, antivirus and password manager columns report ✗ on every device the sync creates.
3. Once the employee's device meets the requirement, the next check-in updates the status automatically.

A device stays on the Unmonitored tab until someone links it to an employee. Assign it from the row's ⋮ menu → **Assign to User**; it moves to Monitored as soon as the owner is set. This is also how JumpCloud-synced devices get an owner.

## Integrations that feed Devices

One integration syncs devices into DSALTA:

| Integration   | What syncs                                                                                                                           |
| ------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| **JumpCloud** | Every system in your JumpCloud org — device name, serial number, OS and version, and disk-encryption status (FileVault / BitLocker). |

To connect an integration, go to **Integrations** in the DSALTA sidebar.

## Related pages

* [People & Groups](/guides/data-library/people)
* [Access Reviews](/guides/data-library/access-reviews)
* [Integrations](/integrations/overview)
