
czos7 (czos7) asked a question.
Hi,
I have noticed a number of devices that are showing as unencrypted in the Okta Mobility Management area. What defines an unencrypted device? What occurs to make a device enrolled but unencrypted? How can it be re-encrypted?
Thanks,
Tom

Tom,
Okta leverages the existing MDM framework Apple and Android provide, so we are not creating an encrypted tunnel for communication between apps or adding an extra security layer. When you look at the settings for OMM to protect data between managed and unmanaged (personal) apps, we are just turning on a data protection flag that the platform provides in their framework. For encryption on the device, this again ties into the OS on the device. For example, when a passcode is defined on an Android device, this automatically turns on encryption. For Android for Work, this is turned on during the enrollment into Android for Work. Hence, from an auditing perspective, you would need to review how Apple and Android protect this data flow between apps within their MDM framework. This is also the same for how encryption is enabled since this is done at the OS level for both platforms. In short, we are just looking into this framework and turn on flags to enable or disable pre-existing settings they provide. As to why your specific devices as showing unencrypted, we would need to look into the devices itself, could be an issue with a passcode not being set, could be an issue where a mobile device is rooted or jailbroken. If you need us to further investigate this please open a full support case by emailing support@okta.com
Thank you