Look up devices
Find devices
Find devices
@Find DevicesInput fields:serialNumber- device serial number.macAddress- device MAC address, for example00:0c:29:05:43:b6.deviceName- device name to search for.model- device model, for exampleMacBook AiroriPhone 15.platforms- one or more platforms to filter by:Mac,iPad,iPhone,AppleTV,Android,Windows.user- name of the device owner, for exampleArt Vandelay.
devices- array of matching devices. Each device includesdeviceId,deviceName,serialNumber,model,platform,osVersion,lastCheckIn,user(email and name),assetTag,blueprintName,mdmEnabled,agentInstalled, andtags.
- Find all devices assigned to a user
- Look up a device by serial number before running a remote action
- Filter devices by platform to scope a compliance review
- Identify a device by name when a serial number is not available
When a user asks about their devices, use @Find Devices to search by their name. If they mention a serial number or device name, include it in the search. Summarize each device found: model, OS version, and last check-in time.
Get device details
Get device details
@Find Devices.Tool name: @Get Device DetailsInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.
iruDeviceDetails- a device detail object with sections:general(model, OS, assigned user, blueprint),mdm(enabled status, supervision, last check-in),activationLock,filevault(encryption status, key escrow),kandjiAgent(version, last check-in),hardwareOverview(processor, memory, serial number),volumes(disk usage and encryption),network(MAC address, IP addresses),recoveryInformation(recovery lock, firmware password),securityInformation(remote desktop),users(local accounts),installedProfiles, andtags.
- Retrieve hardware specs and serial number for an asset record
- Check FileVault status and whether the recovery key is escrowed
- Confirm configuration profiles are installed on a device
- Look up the device’s current network address
When a user asks for details about a specific device, use @Find Devices to locate it, then use @Get Device Details to return hardware information, MDM status, and installed profiles. Highlight any issues such as disabled MDM or missing FileVault encryption.
Get device apps
Get device apps
@Find Devices.Tool name: @Get Device AppsInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.
apps- array of installed apps. Each app includesappName,bundleId,version,source, andpath.
- Verify whether a required app is installed before approving access
- Check which version of an app a user is running
- Audit apps on a device flagged in a security review
When a user asks whether a specific app is installed on their device, use @Find Devices to locate the device, then use @Get Device Apps to check. Report the app name and version if found, or confirm it is not installed.
Get device activity
Get device activity
@Find Devices.Tool name: @Get Device ActivityInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.limit- maximum number of items to return. Defaults to 50 and cannot exceed 50.offset- number of items to skip for pagination.
iruDeviceActivities- array of activity items. Each item includesactionType,createdAt,details,computer(device name at the time of the event),blueprint, anduser(who performed the action).totalCount- total number of activity events on the device.limit,offset- the values used for this page of results.
- Review recent MDM commands sent to a device
- Check when a device was enrolled or re-enrolled
- Identify who changed a device’s blueprint or name
- Audit device history during a security review
When a user asks what has happened recently on their device, use @Find Devices to locate it, then use @Get Device Activity to return the most recent events. Summarize the action types and dates in the reply.
Get device status
Get device status
@Find Devices.Tool name: @Get Device StatusInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.
libraryItems- each item’sname,type,status,reportedAt, andlog.parameters- each security parameter’sname,category,subcategory, andstatus.
- Check whether required apps and scripts are installed and passing
- Identify failing compliance parameters before an access approval
- Review the status of all configuration profiles on a device
- Confirm a device meets security requirements
When a user reports a compliance issue or is denied access, use @Find Devices to locate their device, then use @Get Device Status to check library item and security parameter status. List any items that are failing or pending and describe next steps.
Troubleshoot devices
Perform daily check-in
Perform daily check-in
@Find Devices.Tool name: @Perform Daily Check-inInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.
- Force a compliance remediation to run without waiting for the next scheduled check-in
- Apply a blueprint change to a device right away
- Resolve a pending policy application for a Windows device
When a user says their device is not picking up a recent policy or compliance change, use @Find Devices to locate the device, then use @Perform Daily Check-in to trigger an immediate check-in. Tell them to allow a few minutes for the changes to apply.
Send blank push
Send blank push
@Find Devices.Tool name: @Send Blank PushInput fields:iruDeviceId(required) - the Kandji device ID, obtained from@Find Devices.
- Wake a device that has not checked in recently
- Force a device to pick up a stuck MDM command
- Verify MDM connectivity is working
When a device has not checked in and MDM commands are stuck, use @Find Devices to locate the device, then use @Send Blank Push to prompt it to reconnect. Follow up by checking @Get Device Activity to confirm the check-in arrived.
Setup
Install Iru integration
Configure agent
Create rules
Test tools
Best practices
- Find the device first. All tools except
@Find Devicesrequire a device ID. Have the agent call@Find Devicesbefore any other Iru tool, and confirm the right device when multiple results come back. - Chain read tools before write tools. Use
@Get Device Statusor@Get Device Detailsto confirm a device’s state before triggering@Perform Daily Check-inor@Send Blank Push. - Use compliance status to gate access approvals. Call
@Get Device Statusas part of an access request workflow to check that required library items are passing before approving. - Check management status before troubleshooting. Use
@Get Device Detailsto confirm MDM is enabled and the Kandji agent is installed before suggesting remediation steps. - Prefer
@Perform Daily Check-inover@Send Blank Pushfor policy gaps. A daily check-in applies the full Kandji logic; a blank push only prompts the device to call home, which is useful for connectivity issues but does not re-run policies on its own.