Proactive Device Health
Compliance drift < 3% workspace-wide
IT hears about a laptop problem the moment it becomes urgent — during a customer call, before a board meeting, at 4pm on a Friday. The signals were always there in the MDM console: failing SMART data, battery cycles past life expectancy, disk 98% full, macOS three major versions behind. Nobody looked. Reactive support means the fix is always at the worst possible time.
An hour-by-hour walkthrough.
Step by step.
- 01
Pull nightly telemetry from every MDM
Read device inventory + health telemetry from Jamf / Intune / Kandji / Workspace ONE / Fleet. Normalise to a common device record with health-score inputs.
Jamf · Intune · Kandji · Workspace ONE · Fleet - 02
Score against health thresholds
Compute a multi-factor score. Green: all normal. Yellow: one or more signals in caution range but not urgent. Red: signal past failure threshold or urgent security posture issue. Yellow triggers a friendly nudge; red triggers an urgent ticket.
Health model · Threshold config - 03
DM the user with a plan + approvals
User DM lists the signals, the plan Ivy has drafted, and the one-click approvals. Never runs disruptive actions without approval. Emergency-only exception: security posture failures (unencrypted disk on lost device) execute immediately with post-hoc notification.
Slack · Teams · MDM · Approval flow - 04
Schedule the fixes off-hours
OS upgrades, disk cleanups, cache flushes queue for the user's off-hours from their calendar. Hardware issues (battery, keyboard) route to IT ops for swap-slot booking with the user's availability.
MDM · Google Calendar · IT ticketing - 05
Weekly IT-ops digest + fleet health rollup
Weekly rollup: fleet health by device model, top failure modes, replacement pipeline forecast (batteries, laptops approaching end-of-life). Feeds hardware budgeting + refresh planning.
Analytics · Slack digest · Asset lifecycle tool
What you connect to make this run.
Jamf · Intune · Kandji · Workspace ONE
read+writeRead: device inventory, hardware telemetry, OS version, security posture, encryption. Write: scheduled OS upgrades, remediation scripts, policy pushes. Nightly poll + on-demand for high-signal events.
CrowdStrike · SentinelOne · MDM security posture
readSecurity agent heartbeat, encryption status, patch level, exploit protection. A missing EDR heartbeat is a red signal — the device is either lost, wiped, or the agent is broken.
Slack · Teams · Google Calendar
read+writeUser DM with plan + approvals. Read calendar for off-hours scheduling. Never runs disruptive actions in-hours; user always sees the plan before execution.
Asset lifecycle · Hardware ordering
read+writeReplacement forecasting from health trends. Auto-open orders for batteries, laptops within refresh window. Feeds finance forecasting + inventory management.
Before and after, honestly.
Playbooks that pair with this one.
Answers about this playbook.
Won't nightly telemetry pulls affect battery life?
MDMs run continuous background telemetry regardless — Ivy just consumes what's already emitted. No additional agent overhead on the device.
What if users decline the recommended fixes?
Declined once = respected. Declined three times on the same signal = escalates to the user's manager as a coaching moment (usually the user needs a swap, not a fix). Security posture issues override user decline with policy-level enforcement.
How does it handle BYOD or unmanaged devices?
BYOD devices have limited telemetry; Ivy scores what MDM sees (email posture, VPN checks) and nothing more. Unmanaged devices don't get monitored — enrolling is the prerequisite.
Can we exclude specific device populations from proactive nudges?
Yes — device tag filters. Lab machines, kiosks, and shared devices typically excluded from user DMs but included in IT-ops digest. Executives can opt into higher-touch (dedicated IT ops rep instead of DM).
How is this different from what MDMs already do?
MDMs report; Ivy reasons + acts. MDM dashboard tells you 40% of the fleet is behind on OS; Ivy schedules the upgrades user-by-user off their calendars, chases the approvals, verifies success, and rolls up the fleet health for planning.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.