Overview
Formal’s Mobile Device Management (MDM) integration allows you to enforce device-based security policies on user connections. By integrating with your organization’s MDM solution, you can ensure that only compliant, managed devices can access protected resources through Formal.How It Works
When users connect through the Formal Endpoint:- The app collects device information (hardware, software, security settings)
- This information is sent to the Connector along with the connection request
- Policies evaluate device attributes via
input.device
Device Information Available
Formal collects comprehensive device metadata that can be used in policies. When MDM integration is enabled, additional compliance data is available throughinput.device.mdm:
Hardware Information
Software Information
MDM Information (When Integration Enabled)
Supported MDM Providers
Formal supports Kandji, Fleet, Jamf Pro, and Mosyle for both endpoint rollout and MDM integrations.Endpoint Rollout
Go to MDM and click Set Up Endpoint Rollout. The dialog walks you through selecting your provider, downloading deployment files, and following setup instructions in your MDM console.Connect Your MDM
Create an MDM integration to sync enrolled devices and their assigned users from your MDM into Formal. Formal uses this list to identify the user behind a device by its serial number, for example when the device attests its identity or signs in without a user login. Option 1: Control Plane- Go to MDM
- Click Create Integration
- Select Kandji, Fleet, Jamf Pro, or Mosyle
- Enter your MDM API credentials
- Click Save
formal_integration_mdm resource with the block for your provider:
Mosyle credentials
Mosyle requires three values:api_url defaults to https://businessapi.mosyle.com. Use https://managerapi.mosyle.com for Mosyle Manager.
Formal reads the assigned user’s email from each Mac’s Mosyle record. A Mac
with no assigned user cannot be mapped to a Formal user, so assign devices to
users in Mosyle before relying on device-based policies or automatic device
login.
Example Policies
Require Secure Boot
Block Jailbroken/Modified Devices
Enforce Activation Lock (macOS)
Require Encrypted Virtual Memory
Conditional Access Based on Device
Monitoring Device Compliance
View device information in session logs:- Navigate to Sessions
- Click on any session
- Review device information in session details
- Filter sessions by device attributes
- Audit which devices are accessing resources
- Identify non-compliant devices attempting connections
- Track OS versions and security settings across your fleet
Best Practices
Require Formal Endpoint
Require Formal Endpoint
Enforce use of the Formal Endpoint for connections that require device
compliance checks. Block direct connections that bypass device verification.
Layer Security
Layer Security
Combine device-based policies with user-based and resource-based policies for
defense in depth.
Grace Periods
Grace Periods
When implementing new device requirements, use dry-run mode first and give
users time to update their devices.
Connect your MDM
Connect your MDM
Connect Kandji, Fleet, Jamf Pro, or Mosyle to sync device compliance data into
Formal. Use endpoint rollout to deploy the Formal Endpoint across your fleet.
Audit Regularly
Audit Regularly
Review session logs to identify devices that frequently fail compliance
checks.
Next Steps
Formal Endpoint
Install the Formal Endpoint
Write Policies
Create device-based policies
Terraform Provider
Configure MDM integrations with Terraform
MDM Integrations
Set up endpoint rollout and MDM integrations