The Addigy agent software installed on your Mac collects plenty of meaningful data that you can use to make decisions about your fleet or debug issues. Other data is what Apple makes available through their MDM framework. All this adds up to dozens of pieces of device data that we call Device Facts.
Facts are a great tool for reporting various information about your machines and can be used to filter the devices list or trigger an alert to notify you or run a remediation script.
You can collect custom information about your Macs by creating a Custom Fact.
Default Facts List
Below is a list of facts collected from the Addigy agent or MDM along with their descriptions.
| Device Fact Name | Description |
|---|---|
| 32-Bit Application Paths |
Retrieves a list with the paths of the 32 Bit applications.
Key: 32_bit_applications Collector: agent |
| Active Users |
Retrieves a list of user account names on the Mac. It filters out
user accounts with UniqueIDs less than 500, which are typically system
accounts or service accounts.
Key: active_users Collector: agent |
| Addigy Splashtop Installed |
Checks if the Splashtop streamer is installed. Returns true if it
is installed and false if it is not found.
Key: addigy_splashtop_installed Collector: agent |
| Admin Users |
A list of users who have administrative privileges on a Mac.
Key: admin_users Collector: agent |
| Agent Version |
Retrieves the version of the Addigy agent.
Key: agent_version Collector: agent |
| Bandwidth Saved (GB) |
Retrieves the amount of bandwidth (in gigabytes) fetched from other
peers in the network.
Key: bandwidth_saved_gb Collector: agent |
| Bandwidth Served (GB) |
Retrieves the amount of bandwidth (in gigabytes) served served to
other peers in the network.
Key: bandwidth_served_gb Collector: agent |
| Battery Capacity Loss Percentage |
Retrieves information about the battery capacity of a Mac. Calculates
the battery percentage by subtracting the maximum capacity from the
design capacity and dividing it by the design capacity.
Key: battery_capacity_loss_percentage Collector: agent |
| Battery Charging |
The charging status of a Mac. It is 'true', if the device is currently
charging, otherwise it is 'false'.
Key: battery_charging Collector: agent |
| Battery Cycles |
The cycle count of the battery on a Mac. The cycle count represents
the number of times the battery has been charged and discharged.
If the cycle count is not available, it shows 0. Most modern Macs
have a maximum of 1000 cycles. Review Apple's Documentation for more
details https://support.apple.com/en-us/HT201585.
Key: battery_cycles Collector: agent |
| Battery Failures |
If the value is 0, it means that the battery has not permanently
failed. Otherwise, it contains the status code indicating the permanent
failure of the battery.
Key: battery_failures Collector: agent |
| Battery Percentage |
Retrieves current battery percentage of a Mac.
Key: battery_percentage Collector: agent |
| Battery Temperature(Fahrenheit) |
The current temperature of the battery of a Mac in fahrenheit. It
is '0' if the temperature value is not available.
Key: battery_temperature_fahrenheit Collector: agent |
| Battery Temperature(Celsius) |
Retrieves the temperature of the battery on a Mac in celsius. If
the temperature is not available, it returns 0. Otherwise, it converts
the temperature from a raw value to Celsius and returns the result.
Key: battery_temperaturecelsius Collector: agent |
| Bluetooth MAC |
The Bluetooth MAC address of the Mac.
Key: bluetooth_mac Collector: agent |
| Build Version |
The build version of the macOS system. If the build version is not
found, 'n/a' is printed instead.
Key: build_version Collector: agent |
| Crashplan Days Since Last Backup |
The number of days that have passed since the last completed backup
in CrashPlan.
Key: crashplan_days_since_last_backup Collector: agent |
| Current User |
Retrieves the username of the currently logged-in user on a Mac.
If there is no user logged in, it returns an empty string.
Key: current_user Collector: agent |
| Device Chip Type |
The type of chip used by the device.
Key: device_chip_type Collector: agent |
| Device Model Name |
The model name of a Mac. If the model name is found, it is printed
to the console. If the model name is not found, an error message
is printed.
Key: device_model_name Collector: agent |
| Device Name |
The hostname of the Mac. If a hostname is found, it is printed to
the console. If no hostname is found, an error message is displayed.
Key: device_name Collector: agent |
| Display On |
Checks if a display is connected to a Mac and if the display is asleep
or turned off. If no display is found, it returns 'false'. If the
display is asleep or turned off, it also returns 'false'. Otherwise,
it returns 'true' indicating that a display is connected and turned
on.
Key: display_on Collector: agent |
| Displays Serial Number |
The serial numbers of the displays connected to a Mac.
Key: displays_serial_number Collector: agent |
| Enrolled Via ADE |
Determines whether the device was enrolled via Automated Device Enrollment.
If the macOS version is 10.12.3 or earlier, it returns 'false'.
Key: enrolled_via_dep Collector: agent |
| Ethernet MAC Address |
MAC address of the Ethernet interface on a Mac. It first checks if
there is an Ethernet interface and if so, it retrieves the MAC address.
If there is no Ethernet interface, it checks for a LAN interface
and retrieves the MAC address if found.
Key: ethernet_mac_address Collector: agent |
| Files Served |
The number of files served by the device through LANCache.
Key: files_served Collector: agent |
| FileVault Enabled |
The status of FileVault on a Mac. It is 'true' if FileVault is enabled,
otherwise it is 'false'.
Key: filevault_enabled Collector: agent |
| Firewall Allowed Applications |
A list of applications that are allowed to make all connections if
the firewall on a Mac is enabled and set to limit incoming connections
to specific services and applications.
Key: firewall_allowed_applications Collector: agent |
| Firewall Block All Incoming Connections |
If the firewall is set to 'Block all incoming connections', it returns
'true'. Otherwise, it returns 'false'.
Key: firewall_block_all_incoming_connections Collector: agent |
| Firewall Blocked Applications |
The list of blocked applications if the firewall is enabled.
Key: firewall_blocked_applications Collector: agent |
| Firewall Enabled |
True if the firewall is set to 'Limit incoming connections to specific
services and applications' or 'Block all incoming connections', false
otherwise.
Key: firewall_enabled Collector: agent |
| Firewall Stealth Mode Enabled |
True if the firewall is in stealth mode, false otherwise.
Key: firewall_stealth_mode_enabled Collector: agent |
| Firmware Password Allow Orams |
Checks if option ROMs are enabled on a Mac. Option ROMs are firmware
extensions that provide additional functionality to the device's
hardware. If the script is 'true', it means that option ROMs are
allowed and enabled. If it is 'false', it means that option ROMs
are not allowed or not enabled.
Key: firmware_password_allow_orams Collector: agent |
| Firmware Password Exists |
If the firmware password is enabled, it will print 'true', otherwise
it will print 'false'.
Key: firmware_password_exists Collector: agent |
| Free Disk Percentage |
The fact calculates the percentage of free disk space on the Mac.
The result is rounded to the nearest whole number.
Key: free_disk_percentage Collector: agent |
| Free Disk Space (GB) |
Retrieves the total free space in gigabytes. Free Disk Space value
does not include the total purgable space that can be reclaimed by
normal macOS operations. The final result is the total free space
rounded up to the nearest whole number. * (See footnote at the bottom
of the article)
Key: free_disk_space_gb Collector: agent |
| Gatekeeper Enabled |
Determines the status of Gatekeeper on a Mac. Gatekeeper is a security
feature that helps protect the system from running malicious software.
If enabled, Gatekeeper is currently active and will block the execution
of unsigned or unidentified applications.
Key: gatekeeper_enabled Collector: agent |
| Has MDM |
Checks if the device is enrolled in the Addigy MDM (Mobile Device
Management) system.
Key: has_mdm Collector: agent |
| Has MDM Profile Approved |
Checks if the Mac is enrolled in Addigy MDM and if the user has approved
the enrollment profile. If it is not enrolled, it returns 'false'.
If the macOS version is 10.12.3 or earlier, it returns 'true'.
Key: has_mdm_profile_approved Collector: agent |
| Has Wireless |
Checks if there is a wireless network interface on the Mac. If a
wireless port is found, it returns 'true', otherwise it returns 'false'.
Key: has_wireless Collector: agent |
| Host Name |
The hostname of the device.
Key: host_name Collector: agent |
| Addigy Identity Installed |
Checks if Addigy Identity is currently installed on the device.
Key: identity_installed Collector: agent |
| Addigy Identity Users |
Retrieves the usernames of all users on a Mac that have logged in
with their IDP.
Key: identity_users Collector: agent |
| Installed Profiles |
Retrieves a list of configuration profiles installed on a Mac.
Key: installed_profiles Collector: agent |
| Apple Intelligence Compatibility |
Is Apple intelligence compatible with the device.
Key: is_apple_intelligence_compatible Collector: agent |
| Is MDM Client Stuck |
Checks if a Mac has an Addigy MDM profile installed and if the MDM
client is stuck. It does this by searching for the presence of the
Addigy MDM profile in the system configuration profile data and by
checking the latest log entry for the MDMClientStuck flag. If both
conditions are met, it returns true; otherwise, it returns false.
Key: is_mdm_client_stuck Collector: agent |
| Is MDM Identity Certificate Installed |
Checks if a Mac has an Addigy MDM profile installed and if an Addigy
MDM identity certificate is present. It returns 'true' if both conditions
are met, and 'false' otherwise.
Key: is_mdm_identity_certificate_installed Collector: agent |
| Is MDM Software Update Stuck |
Checks if MDM is stuck processing a software update command.
Key: is_mdm_softwareupdated_stuck Collector: agent |
| macOS Sequoia Support |
Returns 'true' if the device is eligible to be upgraded to Sequoia.
Key: is_sequoia_ready Collector: agent |
| macOS Sonoma Support |
Returns 'true' if the device is eligible to be upgraded to Sonoma.
Key: is_sonoma_ready Collector: agent |
| Java Vendor |
Checks if Java is installed on a Mac and determines whether it is
an Oracle or Apple Java installation. The script then outputs 'Oracle',
'Apple', or 'Not Available'.
Key: java_vendor Collector: agent |
| Java Version |
Retrieves the version of Java installed on a Mac. It shows 'n/a'
if Java is not available.
Key: java_version Collector: agent |
| Kernel Panic |
Checks if there is a kernel panic log in the system log file. If
there is a kernel panic log, it returns true; otherwise, it returns
false.
Key: kernel_panic Collector: agent |
| LANCache Size (bytes) |
The total size, in bytes, of all files in the directory /Library/Addigy/download-cache/downloaded.
Key: lan_cache_size_bytes Collector: agent |
| Last Reboot Timestamp |
The timestamp of the last time the Mac was booted (reported in Epoch
time).
Key: last_reboot_timestamp Collector: agent |
| Local IP |
Retrieves the IP address of the Mac by querying the network interfaces.
It shows 'n/a' if no IP address is found.
Key: local_ip Collector: agent |
| Locales |
The preferred language settings for the currently logged-in user
on the Mac.
Key: locales Collector: agent |
| LocalHost Name |
Retrieves the local hostname of a Mac. The local hostname is the
name that the device uses to identify itself on the local network.
If no local hostname is found, an error message is displayed.
Key: localhost_name Collector: agent |
| macOS Version |
The OS version of the Mac. The value is 'n/a' if the OS version is
not available.
Key: mac_os_x_version Collector: agent |
| Malwarebytes Account ID |
The account ID associated with the Malwarebytes Endpoint Agent Daemon
exists on the Mac. The value is an empty string if the agent or account
ID is not found.
Key: mb_endpoint_account_id Collector: agent |
| Malwarebytes Version |
The fact checks if the Malwarebytes Endpoint Agent Daemon is installed
on the Mac. It returns 'n/a' if it is not found.
Key: mb_endpoint_agent_version Collector: agent |
| Malwarebytes Machine ID |
The machine ID for the Malwarebytes Endpoint Agent Daemon installed
on the Mac.
Key: mb_endpoint_machine_id Collector: agent |
| Malwarebytes Nebula Machine ID |
The Nebula Machine ID for the Malwarebytes Endpoint Agent Daemon
installed on the Mac.
Key: mb_endpoint_nebula_machine_id Collector: agent |
| Malwarebytes |
Checks if the Malwarebytes Endpoint Agent is installed on the Mac.
Key: mb_oneview_installed Collector: agent |
| MDM Update Eligibility |
Indicates that the device can be updated through MDM.
Key: mdm_update_eligibility Collector: agent |
| Microsoft Company Portal Version |
Returns the version of the Microsoft Company Portal application installed
on the Device.
Key: microsoft_company_portal_version Collector: agent |
| OS Platform |
The OS Platform of the device.
Key: os_platform Collector: agent |
| Peer Count |
The number of LANCache peers available to the device.
Key: peer_count Collector: agent |
| Policy Execution (seconds) |
Calculates the most recent execution time in seconds of the Addigy
Policier binary.
Key: policy_execution_seconds Collector: agent |
| Privileged MDM |
Returns 'true' for Silicon-based devices that are enrolled manually
and have the ability to do Automatic Software Updates. This setting
must be set manually in the RecoveryOS. Returns 'false' otherwise
Key: privileged_mdm Collector: agent |
| Processor Speed (GHz) |
Returns the CPU speed in GHZ. It will show 'n/a' if the CPU speed
cannot be determined.
Key: processor_speed_ghz Collector: agent |
| Processor Type |
Returns the name of the processor installed on the device. Returns
'n/a' if the processor name cannot be determined.
Key: processor_type Collector: agent |
| Product Description |
Product Description or 'n/a' if it cannot be determined.
Key: product_description Collector: agent |
| Product Name |
Retrieves the model name of the device.
Key: product_name Collector: agent |
| Remote Desktop Enabled |
Returns 'true' if Remote Desktop is enabled, otherwise returns 'false'.
Key: remote_desktop_enabled Collector: agent |
| Remote Login Enabled |
Checks if remote login is enabled on a Mac.
Key: remote_login_enabled Collector: agent |
| Serial Number |
The serial number of the device.
Key: serial_number Collector: agent |
| SMART Failing |
Returns 'true' if the status SMART (Self Monitoring Analysis and
Reporting Technology) is "Failing", otherwise return 'false'. This
only verifies the internal drives.
Key: smart_failing Collector: agent |
| Software Update Device ID |
Software Update Identifier is used internally to detect new software
updates.
Key: software_update_device_id Collector: agent |
| Splashtop ID |
The UUID is a unique identifier assigned to the Splashtop Streamer
application, which is used for remote desktop access.
Key: splashtop_id Collector: agent |
| Splashtop Installation Date |
Retrieves the installation date of the Splashtop application on a
Mac.
Key: splashtop_installation_date Collector: agent |
| Splashtop Version |
Retrieves the version number of the Splashtop Streamer application
installed on a Mac.
Key: splashtop_version Collector: agent |
| System Integrity Protection Enabled |
Returns 'true' if System Integrity Protection (SIP) is enabled and
'false' if disabled. SIP is a security feature that protects critical
system files and processes from being modified or tampered with.
Key: system_integrity_protection_enabled Collector: agent |
| System Version |
Retrieves the system version of a Mac.
Key: system_version Collector: agent |
| Third-Party Agents |
Lists the files in the '/Library/LaunchAgents/' directory on a Mac.
The files in this directory are used to configure and manage user-specific
processes that are launched automatically when a user logs in.
Key: third_party_agents Collector: agent |
| Third-Party Daemons |
The fact lists the launch daemons present in the /Library/LaunchDaemons/
directory of a Mac. The files in this directory are used to configure
and manage system wide processes that are launched automatically
when the device starts up.
Key: third_party_daemons Collector: agent |
| Third-Party Kernel Extensions |
A list of kernel extensions (kexts) installed on a Mac. It filters
out the built-in Apple kexts.
Key: third_party_kernel_extensions Collector: agent |
| Time Machine Days Since Last Backup |
The last time in days that a Time Machine backup was performed on
a Mac.
Key: time_machine_days_since_last_backup Collector: agent |
| Timezone |
Retrieves the current timezone of the Mac.
Key: timezone Collector: agent |
| Tmp Size (MB) |
The fact calculates the size of the /private/tmp directory in megabytes.
Key: tmp_size_mb Collector: agent |
| Total Disk Space (GB) |
The total disk space in gigabytes.
Key: total_disk_space_gb Collector: agent |
| Total Memory (GB) |
Retrieves the total memory in gigabytes. It rounds up the calculated
total memory to the nearest whole number.
Key: total_memory_gb Collector: agent |
| UDID |
Retrieves the UDID (Universally Unique Identifier) of a Mac. The
UDID is a unique identifier assigned to each device and can be used
to identify and track the device.
Key: udid Collector: agent |
| Uptime (days) |
Retrieves the number of days that the Mac has been running. If the
device has been running for less than a day, it returns 0. Otherwise,
it returns the number of days.
Key: uptime_days Collector: agent |
| Used Memory (GB) |
The amount of used memory on a Mac in gigabytes rounded to the nearest
whole number. It retrieves information about pageable internal memory,
purgeable memory, wired down memory, and memory occupied by the compressor.
Key: used_memory_gb Collector: agent |
| Warranty Days Left |
The number of warranty days left on the device. It will return 'n/a'
if the warranty has already expired.
Key: warranty_days_left Collector: agent |
| Wifi MAC Address |
Retrieves the MAC address of the Wi-Fi interface on a Mac. The MAC
address is a unique identifier assigned to the network interface
card (NIC) of the device. It is used to identify the device on a
network.
Key: wifi_mac_address Collector: agent |
| Xcode Installed |
Checks if Xcode Command Line Tools or Xcode is installed on a Mac.
Key: xcode_installed Collector: agent |
| Battery Health |
The device’s battery health. Available in iOS 17 and later on iPhone
only (iPad returns unsupported), and macOS 14.4 and later on Apple
silicon Mac computers. Possible Values: non-genuine, normal, service-recommended,
unknown, unsupported
Key: battery_health Collector: ddm |
| Agent ID |
The Addigy Agent ID is a unique identifier assigned to an Apple device
by Addigy.
Key: agentid Collector: server side |
| Audit Execution (seconds) |
Audit Execution (seconds) refers to the amount of time it takes for
an audit process to be executed. This metric measures the speed and
efficiency of the audit process, with a lower number indicating faster
execution.
Key: audit_execution_time_seconds Collector: server side |
| Microsoft Entra Device IDs |
Azure AD Device IDs is a list of unique identifiers assigned to devices
that are registered with Azure Active Directory. These device ids
are used to uniquely identify and manage devices within an organization's
Azure AD environment.
Key: azure_ad_device_ids Collector: server side |
| Microsoft Entra User IDs |
Azure AD User IDs refers to a list of unique identifiers assigned
to users in Azure Active Directory. These user IDs are used to authenticate
and authorize users to access various resources and services within
the Azure ecosystem.
Key: azure_ad_user_ids Collector: server side |
| Client IP |
The IP address of the device that is accessing a network or server.
Key: client_ip Collector: server side |
| FileVault Key Escrowed |
Indicates whether the FileVault key for the Apple device has been
escrowed. If the value is true, it means that the FileVault key has
been stored securely by MDM, allowing for recovery of the key if
it is lost or forgotten. If the value is false, it means that the
FileVault key has not been escrowed and recovery of the key would
not be possible.
Key: filevault_key_escrowed Collector: server side |
| Identity Email |
The email address associated with a user in their IDP.
Key: identity_email Collector: server side |
| Identity Employee Department |
The department of an employee in an organization within the IDP.
It is used to identify the specific department that an employee belongs
to within the organization.
Key: identity_employee_department Collector: server side |
| Identity Employee Hire Date |
The date when an employee was hired, as fetched from the IDP. It
is used to track the length of an employee's tenure with the company
and can be used for various HR and administrative purposes.
Key: identity_employee_hire_date Collector: server side |
| Identity Employee Type |
Refers to the type of employee within an organization within the
IDP.
Key: identity_employee_type Collector: server side |
| Identity Job Title |
The job title associated with a user within the IDP.
Key: identity_job_title Collector: server side |
| Identity Mobile Phone |
The phone number associated with the logged in user within the IDP.
Key: identity_mobile_phone Collector: server side |
| Identity Office Location |
The Office Location associated with the logged in user within the
IDP.
Key: identity_office_location Collector: server side |
| Identity Password Set Date |
The date when the password for was last set within the IDP. This
date is important for security purposes as it helps track when the
password was last changed.
Key: identity_password_last_set_date Collector: server side |
| Identity Provider Name |
The name of the service or platform that is used for user authentication
and authorization. It could be a third-party service like Azure,
Google or Okta.
Key: identity_provider_name Collector: server side |
| Identity Usage Location |
The geographic location where the user logged in with their IDP.
Key: identity_usage_location Collector: server side |
| Identity User Display Name |
The name of the user associated with the IDP. It is typically used
for displaying the user's name in various applications and settings
on the device.
Key: identity_user_display_name Collector: server side |
| Identity Username |
The unique username associated with a the IDP. It is used for various
purposes such as signing in.
Key: identity_username Collector: server side |
| Compliant |
The fact is describing whether an Apple device is compliant with
its associated Benchmarks.
Key: is_compliant Collector: server side |
| Last Online |
Date of the last time that the device connected to Addigy Services.
It can be useful for tracking the activity or usage patterns of a
device, or for determining if a device is currently online or offline.
Key: last_online Collector: server side |
| Mac UUID |
A unique identifier assigned to each Apple device. It is a string
of alphanumeric characters that can be used to uniquely identify
a specific Apple device.
Key: mac_uuid Collector: server side |
| Online |
Returns true if device is online and connected to Addigy Services
and false otherwise.
Key: online Collector: server side |
| Policy ID |
The Policy ID shows the a legacy single policy assignment for the
device. Now that devices can be assigned to multiple policies you
should use the 'Policy IDs' fact for a more accurate view of the
device's policy assignments.
Key: policy_id Collector: server side |
| Policy IDs |
Policy IDs refer to a list of Policies that the device is assigned
to.
Key: policy_ids Collector: server side |
| Registration Date |
Returns the date that the device was registered with Addigy.
Key: registration_date Collector: server side |
| Malwarebytes Last Scan |
Returns date when last Malwarebytes scan was performed on the Apple
device. It provides information about the most recent scan conducted
by Malwarebytes to detect and remove any potential malware or malicious
software from the device.
Key: mb_endpoint_last_scan Collector: mbov |
| Malwarebytes Suspicious Activity Count |
A numerical value that represents the number of suspicious activities
detected by the Malwarebytes software on an Apple device. This count
indicates the level of potential security threats or malicious activities
that have been identified and blocked by Malwarebytes.
Key: mb_endpoint_suspicious_activity_count Collector: mbov |
| Malwarebytes Suspicious Activity Detected |
Indicates whether Malwarebytes has detected any suspicious activity
on the Apple device. If the value is true, it means that Malwarebytes
has detected suspicious activity, while a value of false means that
no suspicious activity has been detected.
Key: mb_endpoint_suspicious_activity_detected Collector: mbov |
| Active Managed Users |
Active Managed Users refers to the number of users who are currently
enrolled in MDM.
Key: active_managed_users Collector: mdm |
| Authenticated Root Volume Enabled |
Indicates whether the authenticated root volume feature is enabled
on the Apple device. When enabled, the device verifies the integrity
of the operating system at startup to ensure it has not been tampered
with or modified.
Key: authenticated_root_volume_enabled Collector: mdm |
| Awaiting Configuration |
The fact is describing whether an Apple device is currently in the
process of being configured. If the value is true, it means that
the device is awaiting configuration in Setup Assistant. If the value
is false, it means that the device has already been configured.
Key: awaiting_configuration Collector: mdm |
| Bootstrap Token Allowed For Authentication |
Refers to a feature in Apple devices that allows the use of a bootstrap
token for authentication. A bootstrap token is a cryptographic token
that is used to securely authenticate a device with an external service
or system. This feature enhances the security and authentication
capabilities of Apple devices. The value returned is the bootstrap
token itself.
Key: bootstrap_token_allowed_for_authentication Collector: mdm |
| Bootstrap Token Required For Kernel Extension Approval |
Indicates whether a bootstrap token is required for kernel extension
approval on an Apple device. If the value is true, it means that
a bootstrap token is required. If the value is false, it means that
a bootstrap token is not required.
Key: bootstrap_token_required_for_kernel_extension_approval Collector: mdm |
| Bootstrap Token Required For Software Update |
Indicates whether a bootstrap token is required for software updates
on the Apple device. If the value is true, it means that a bootstrap
token is required. If the value is false, it means that a bootstrap
token is not required.
Key: bootstrap_token_required_for_software_update Collector: mdm |
| Carrier Settings Version |
The software version that is specific to a particular carrier and
is installed on an iPhone. It includes settings and configurations
that are necessary for the device to connect to the carrier's network
and access certain features, such as cellular data and voice calling.
Key: carrier_settings_version Collector: mdm |
| Cellular Technology |
The technology used in Apple devices to connect to cellular networks
and access the internet. It allows users to make phone calls, send
text messages, and use data services while on the go, without relying
on Wi-Fi connections.
Key: cellular_technology Collector: mdm |
| Current Carrier |
The mobile network operator that a specific Apple device is currently
connected to. This information is useful for determining the network
coverage and services available to the device, as well as for troubleshooting
network-related issues.
Key: current_carrier_network Collector: mdm |
| Current MCC |
The Mobile Country Code of the current network that an Apple device
is connected to. The MCC is a unique identifier assigned to each
country or region, and it is used to determine the country or region
of the mobile network that the device is currently using.
Key: current_mcc Collector: mdm |
| Current MNC |
MNC (Mobile Network Code) is a unique identifier assigned to a mobile
network operator. It is used to identify the network that an Apple
device is currently connected to.
Key: current_mnc Collector: mdm |
| Data Roaming Enabled |
Indicates whether data roaming is enabled on the Apple device. If
data roaming is enabled, the device can connect to cellular networks
outside of its home network and use data services while roaming.
Key: data_roaming_enabled Collector: mdm |
| Days Since Last Cloud Backup |
The number of days that have passed since the last cloud backup of
an Apple device. This backup includes data such as photos, contacts,
and app settings, which can be restored in case of device loss or
damage.
Key: days_since_last_cloud_backup Collector: mdm |
| EAS Device Identifier |
A unique identifier assigned to an Apple device that is used for
Exchange ActiveSync (EAS) communication. It allows the device to
securely connect and synchronize with an Exchange server, enabling
features such as email, calendar, and contacts syncing.
Key: eas_device_identifier Collector: mdm |
| Ethernet MA CS |
The Ethernet Media Access Control (MAC) sublayer and Carrier Sense
(CS) mechanism. This technology is used in Apple devices to control
access to the Ethernet network and ensure that multiple devices can
share the network without causing collisions or data loss.
Key: ethernet_ma_cs Collector: mdm |
| External Boot Level |
The boot level of an Apple device that is connected to an external
source, such as a computer. It indicates whether the device is currently
booting up or has successfully booted up from the external source.
Key: external_boot_level Collector: mdm |
| Firmware Password Change Pending |
Whether a firmware password change is pending. If the value is true,
it means that a firmware password change is pending. If the value
is false, it means that there is no pending firmware password change.
Key: firmware_password_change_pending Collector: mdm |
| Hardware Encryption Capability (iOS only) |
Refers to the ability of iPhones to encrypt data using hardware-based
encryption. This means that the encryption process is performed by
dedicated hardware components within the device, which provides faster
and more efficient encryption compared to software-based encryption
methods. This capability enhances the security of data stored on
iPhones, protecting it from unauthorized access.
Key: hardware_encryption_caps Collector: mdm |
| Hardware Model |
The specific model of an Apple device, such as iPhone X or MacBook
Pro. It is a unique identifier that distinguishes one device from
another and is often used for compatibility and support purposes.
Key: hardware_model Collector: mdm |
| Has Unlock Token |
Indicates whether the Apple device has an unlock token. An unlock
token is a unique identifier that allows the device to be unlocked
and accessed by the user.
Key: has_unlock_token Collector: mdm |
| iCCID |
The iCCID is a unique identifier for a SIM card in an Apple device.
It stands for Integrated Circuit Card Identifier and is used to identify
the SIM card and establish a connection with the cellular network.
Key: iccid Collector: mdm |
| iMEI |
The IMEI (International Mobile Equipment Identity) is a unique identifier
for a mobile device. It is a 15-digit number that is used to identify
and track individual devices, such as iPhones. The IMEI can be found
in the device settings.
Key: imei Collector: mdm |
| Activation Lock Enabled |
Indicates whether the Activation Lock feature is enabled on an Apple
device. Activation Lock is a security feature that prevents unauthorized
users from activating or using a device that has been lost or stolen.
When Activation Lock is enabled, the device requires the user's Apple
ID and password to be entered before it can be activated or used.
Key: is_activation_lock_enabled Collector: mdm |
| Is Activation Lock Manageable |
Describes whether the Activation Lock feature on an Apple device
is manageable or not. If the value is true, it means that the Activation
Lock can be managed, allowing the user to enable or disable it as
needed. If the value is false, it means that the Activation Lock
cannot be managed and is permanently enabled on the device.
Key: is_activation_lock_manageable Collector: mdm |
| Is Apple Silicon |
Indicates whether the Apple device is powered by Apple Silicon or
not.
Key: is_apple_silicon Collector: mdm |
| Cloud Backup Enabled |
Indicates whether cloud backup is enabled on the Apple device. If
the value is true, it means that the device is set up to automatically
backup its data to the cloud. If the value is false, it means that
cloud backup is not enabled and the device's data is not being backed
up to the cloud.
Key: is_cloud_backup_enabled Collector: mdm |
| Location Service Enabled |
Indicates whether the system enabled a device locator service
such as Find My on the device. If the value is true, it has Find
My enabled. If the value is false, Find My is disabled on the device.
Key: is_device_locator_service_enabled Collector: mdm |
| Do Not Disturb Enabled |
Indicates whether the Do Not Disturb feature is enabled on the Apple
device. If the value is true, it means that the Do Not Disturb feature
is currently active and notifications will be silenced. If the value
is false, it means that the Do Not Disturb feature is not active
and notifications will be received as usual.
Key: is_do_not_disturb_in_effect Collector: mdm |
| MDM Activation Lock Enabled |
The fact is describing whether the MDM Activation Lock is enabled
on an Apple device. If the value is true, it means that the Activation
Lock feature is enabled, which requires the user to enter their Apple
ID and password before the device can be activated or used. If the
value is false, it means that the Activation Lock feature is disabled.
Key: is_mdm_activation_lock_enabled Collector: mdm |
| MDM Lost Mode Enabled |
Indicates whether the Mobile Device Management (MDM) Lost Mode is
enabled on the Apple device. Lost Mode is a feature that can be activated
remotely to help locate a lost or stolen device. When enabled, the
device will display a custom message with contact information and
can be tracked using Find My iPhone/iPad/Mac.
Key: is_mdm_lost_mode_enabled Collector: mdm |
| Is Recovery Lock Enabled |
The fact is describing whether the Recovery Lock feature is enabled
on an Apple device. Recovery Lock is a security feature that prevents
unauthorized access to the device by requiring the user to enter
their Apple ID and password before erasing or reactivating the device.
Key: is_recovery_lock_enabled Collector: mdm |
| Is Roaming |
Indicates whether the Apple device has roaming enabled or not.
Key: is_roaming Collector: mdm |
| Is Shared iPad |
Is iPad device a Shared iPad.
Key: is_shared_ipad Collector: mdm |
| Is Supervised |
Indicates whether an Apple device is supervised or not. Supervised
devices have additional management capabilities and restrictions
compared to unsupervised devices.
Key: is_supervised Collector: mdm |
| User Enrollment |
Returns true if the device is enrolled as BYOD (Bring Your Own Device)
otherwise false. User Enrollment allows organizations to securely
manage and separate personal and work data on Apple devices. It provides
a dedicated work profile for business data and apps, while keeping
personal data separate and private.
Key: is_user_enrollment Collector: mdm |
| Languages |
Describes the list of languages supported by an Apple device.
Key: languages Collector: mdm |
| Last Cloud Backup Date |
The most recent date and time when the data on an Apple device was
backed up to the cloud. This backup includes various types of data
such as photos, videos, contacts, messages, and app data. It is important
to regularly back up devices to ensure that data is safe and can
be restored in case of device loss, damage, or software issues.
Key: last_cloud_backup_date Collector: mdm |
| Max Resident Users |
Max Resident Users refers to the maximum number of users that can
be logged in and active on an Apple device at the same time.
Key: maximum_resident_users Collector: mdm |
| MDM Last Connected |
The date when a mobile device management (MDM) solution last connected
to an Apple device. This information is useful for tracking the last
time the device was managed or updated by the MDM solution.
Key: mdm_last_connected Collector: mdm |
| MeId |
Returns the MEID (Mobile Equipment Identifier). MEID is unique identification
number assigned to a Apple devices for activation and registration
purposes.
Key: meid Collector: mdm |
| Modem Firmware Version |
Firmware version of cellular modem. The modem is responsible for
managing the device's cellular connectivity and performance, including
features like call quality, data speeds, and network compatibility.
Key: modem_firmware_version Collector: mdm |
| OS Version |
Retrieves the macOS system version information. The value is 'n/a'
if it is not available.
Key: os_version Collector: mdm |
| Passcode Compliant |
Returns 'true' if Passcode is compliant with security requirements
specified by IT admins, otherwise it returns 'false'.
Key: passcode_compliant Collector: mdm |
| Passcode Compliant With Profiles |
Returns 'true' if Passcode is compliant with security requirements
specified by IT admins via MDM Profiles otherwise it returns 'false'.
Key: passcode_compliant_with_profiles Collector: mdm |
| Passcode Lock Grace Period |
The user preference for the number of seconds before a locked screen
requires the device passcode to unlock it. This value is only available
for Shared iPad.
Key: passcode_lock_grace_period Collector: mdm |
| Passcode Lock Grace Period Enforced |
The enforced value for the number of seconds before a locked screen
requires the device passcode to unlock it. If a device has a passcode,
changing PasscodeLockGracePeriod to a larger value doesn't take effect
until the user logs out or removes the passcode. This value is only
available for Shared iPad.
Key: passcode_lock_grace_period_enforced Collector: mdm |
| Passcode Present |
Indicates whether or not the Apple device has a passcode set. If
the value is true, it means that a passcode is present on the device.
If the value is false, it means that no passcode is set.
Key: passcode_present Collector: mdm |
| Personal Hotspot Enabled |
Indicates whether the Apple device has the Personal Hotspot feature
enabled or not.
Key: personal_hotspot_enabled Collector: mdm |
| Phone Number |
The phone number associated with an Apple device.
Key: phone_number Collector: mdm |
| Push Certificate Name |
Push certificate name that a device is associated to.
Key: push_certificate_name Collector: mdm |
| Push Certificate Topic |
Push certificate topic that a device is associated to.
Key: push_certificate_topic Collector: mdm |
| Secure Boot Level |
The level of security implemented in the boot process of an Apple
device. Possible values are 'Full', 'Off', and 'Not Supported'. Full
means that the device will only boot with legitimate and unmodified
OS. Off means that OS integrity will not be verified. Not supported
means that this is an older device that does not support this feature.
Key: secure_boot_level Collector: mdm |
| Sim Carrier |
The mobile network operator that provides cellular service to an
Apple device. It is the company that the device is connected to for
making calls, sending texts, and accessing mobile data.
Key: sim_carrier_network Collector: mdm |
| Subscriber Carrier |
The name of the subscriber carrier network.
Key: subscriber_carrier_network Collector: mdm |
| Subscriber MCC |
The current HotSpot 2.0 subscriber Mobile Country Code (MCC) settings.
Key: subscriber_mcc Collector: mdm |
| Voice Roaming Enabled |
Indicates whether voice roaming is enabled on the Apple device. If
voice roaming is enabled, the device can make and receive phone calls
while connected to a different cellular network than its home network.
Key: voice_roaming_enabled Collector: mdm |
| Available Disk Space (GB) |
Available space is made up of both Free space and Purgeable space.
Represented in GBs* (See footnote at the bottom of the article)
Key: available_disk_space_gb Collector: Agent |
| Available Disk Percentage |
Available space is made up of both Free space and Purgeable space.
Represented in percentage of total disk space
Key: available_disk_space_percentage Collector: Agent |
*There's a small distinction between "Available" and "Free" storage space. "Available" space includes both "Free" space (immediately usable) and "Purgeable" space (reclaimable by macOS). This conflation can be misleading, as the truly usable "Free" space is what ensures smooth operation, particularly for resource-intensive workloads. Always monitor and maintain a minimum of 20GB or more of "Free" space to avoid potential system slowdowns or issues.
Viewing Device Facts
To view Device Facts, you can either navigate to the GoLive > Overview page of a device, or view devices and their device facts by going to the Devices page.
If you would like to see device facts that are not on the default Devices page table view, please reference this article: Customizing the Devices Table
Notes
- Each fact will return one of the following data types:
- String - A collection of words
- Boolean - True or False
- Number - Any positive or negative number
- List - a collection of Strings or Numbers
- You can see what an agent device fact runs by using the cat command and specifying the directory to the fact. The .sh files for the facts are stored in /Library/Addigy/auditor-facts/scripts/
- Example: cat /Library/Addigy/auditor-facts/scripts/device_name
- The Auditor binary is responsible for running device facts.
- A device audit can be manually queued up through two methods:
-
Refresh Data > Device Information (found in GoLive)
- Running this command: sudo /Library/Addigy/auditor
-
Refresh Data > Device Information (found in GoLive)
- Addigy Identity User Attribute information can be found in this article
- These values can be used with the Devices lookup in the Addigy API