macOS Device Control policies frequently asked questions (FAQ)

Applies to:

This article provides answers to frequently asked questions about Device Control capabilities in Microsoft Defender for Endpoint.

Questions | Answers

How do I know whether the machine is Device Control enabled, and what is the Default Enforcement?

Answer: Run mdatp device-control policy preferences list to see all the iOS policies on this machine:

Shows how to run mdatp device-control policy preferences list to see if a device is Device Control enabled.

How do I know whether the policy has been delivered to the client machine?

Answer: Run mdatp device-control policy rules list to see all the iOS policies on this machine:

Shows how to run mdatp device-control policy rules list to determine whether a policy has been configured on the endpoint.

Answer 2: Run mdatp device-control policy groups list to see all the iOS groups on this machine:

Shows how to see all of the iOS groups on the device.

See also

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.