Skip to main content
Enrolled Devices cover — one glance, one outlier. Once a campaign starts producing enrollments, Devices in the Frontegg Portal (https://portal.frontegg.com/<environment>/agen/shielded/devices) is where the fleet lives. Every Mac that completed enrollment appears here, whichever way it was installed — MDM push or install command.

Device states

The counters across the top are the fastest read on fleet health. They are mutually informative, so learn what each one actually measures:
Syncing is the state that surprises people. A Mac deployed by MDM enrolls and starts pulling policy before anyone logs in — that is working as intended. It moves to Online at the first GUI login, when the extensions activate.
A large, persistent Syncing count means Macs are being imaged but never logged into. A large Offline count usually means devices left the fleet without being offboarded.

The device list

Bundle is the column to watch during a policy change: it tells you whether a rule you just published has actually reached the fleet, rather than whether you published it. A device stuck on an old revision is not enforcing your latest rules, no matter what the Frontegg Portal shows centrally. Endpoint is the column to watch during an upgrade — mixed versions here are normal mid-rollout and should converge.

A single device

Click any row. The detail view is the answer to “what is this Mac doing, and is it healthy?”: This is the view to open when a developer reports “AgenShield blocked me” — the Activity tab shows the exact action and the rule that decided it.

Revoke versus offboard

These do different things and are not interchangeable. Revoke is the containment action — a lost or compromised Mac you want cut off from your policy immediately. Offboard is the lifecycle action — someone left, or the machine is being reassigned.
With a connected MDM, removing a device from its group by hand in Intune or Entra does neither of these cleanly. MDMs run scripts when a device is added to a group, never when it is removed — so a manual removal leaves AgenShield installed and merely unmanaged. Use Offboard in the Frontegg Portal. See Microsoft Intune.
On an unmanaged Mac, the end user can remove AgenShield with the campaign’s uninstall command, which carries no token and is safe to hand out — see Install and uninstall.

What to check in the first week

1

Enrollments match your MDM group

Endpoints in the Frontegg Portal should converge on the size of the group you assigned. A persistent gap is usually a profile that never landed.
2

Syncing is draining

Macs should move from Syncing to Online as people log in. A stuck count means imaged-but-unused machines, or extensions that never activated.
3

Bundle revisions are converging

After you publish a policy change, watch the Bundle column catch up. This is the honest measure of whether a rule is live.
4

Nothing unexpected is quarantined

Quarantined devices receive no policy. Confirm every one was intentional.

Next

Rules and policy

Now that devices are reporting, decide what they are allowed to do.

Telemetry

Read what your agents are actually doing before you write a single rule.