Skip to content
English
  • There are no suggestions because the search field is empty.

Troubleshooting Security Policy Automations in Senturo

Diagnose and resolve the most common issues with building, activating, and running automations.

Overview

Most automation problems fall into a few predictable categories: an automation that won't save or activate, one that's active but never seems to fire, actions that don't apply to every device, or schedules and compliance counts that don't behave as expected. This guide walks through those issues in the order you're likely to hit them — from building an automation to running it across your fleet — with the cause and the fix for each.

If you're new to automations, the Understanding Security Policy Automations overview and the How to Create a Security Policy Automation walkthrough provide the background these fixes assume.


Building and Activating

The Save & Activate button is unavailable. One or more pre-save checks haven't been met. Open the Summary panel and review the Pre-Save Checks list: an automation needs a name, one trigger (and, for geofence triggers, a selected geofence), at least one action, at least one device group, and a schedule type. Complete any item marked with an ✕, and the button becomes available once all checks pass.

A geofence trigger won't let me finish. Geofence triggers require a specific geofence to be selected. Open the trigger's geofence picker and choose an existing geofence, or create one with the + button. See Creating and Managing Geofences.

I need the automation to respond to more than one condition. Each automation has exactly one trigger. To respond to several conditions, create a separate automation for each. You can point them all at the same device groups and actions.


Triggers and Firing

My automation is Active but nothing happens. Work through these in order: confirm the status is Active (not Draft or Paused); confirm the current time falls within the automation's schedule; confirm the affected devices are in one of the selected device groups; and confirm the trigger condition is actually being met. The non-compliant count on the card shows how many in-scope devices currently meet the trigger — if it's 0, no device is in breach right now.

The non-compliant count looks wrong for my trigger. The count reflects devices currently violating the trigger condition, updated live as devices move in and out of that condition. A number that changes on its own is expected behavior, not a fault. See Managing Automation Compliance and Statuses.


Actions

An MDM Integration action is unavailable or fails to run. Actions such as Jamf Lock, Jamf Lost Mode, Microsoft Intune Lock, Meraki Lock, Meraki Wipe, and Google Disable require the corresponding integration (Jamf Pro, Microsoft Intune, Cisco Meraki, or Google Admin Console) to be connected in Senturo with the necessary permissions, and the target device must be managed by that platform.

An action didn't apply to some devices. Some actions are platform-specific. Take Screenshots for example are supported on Windows, macOS, and ChromeOS, but not on iOS/iPadOS or Android; MDM actions apply only to devices managed by that MDM. Devices on unsupported platforms skip the action. See the Automation Actions reference for platform support.

My actions ran in the wrong order. Actions run from top to bottom in the order listed in the Then Do section. Reorder them with the up and down arrows on each action — for example, place Set Missing Mode above Senturo Lock so the device escalates to real-time tracking before it locks.

A destructive action ran and no one was notified. Notifications aren't automatic. Add Send Email to Administrator to any automation that includes Wipe Files on Device, Meraki Wipe, Google Disable, or other high-impact actions so an administrator is informed whenever they run.


Devices

The automation is affecting the wrong devices, or too many. Review the device groups selected in the For Devices section. Confirm you selected the intended groups and didn't inadvertently include everything with Select all. Remember that unassigned devices fall under Ungrouped, which can be large.


Scheduling

I can't activate — the Schedule check is incomplete. A schedule type must be chosen. Open the Active schedule dialog, select Always On or Custom Schedule, configure it if needed, and click on Done.

The automation doesn't run when I expect it to. For a Custom Schedule, confirm the current day is enabled under Active days and that the current time falls within a defined Time window. Because each device applies the schedule in its own local time, check the time on the device, not on your own machine.

The automation runs at the wrong time for devices in other locations. This is usually a timezone expectation. You set schedule times in your local timezone, but devices apply them in their own local time — so an 08:00–15:30 window runs during those local hours wherever the device is. This is by design and keeps a single schedule correct fleet-wide. See Scheduling Automations.


Compliance and Statuses

A high non-compliant count. This simply means many in-scope devices currently meet the trigger condition. It's a live indicator of devices in breach, not an error — confirm the scope and trigger are what you intended.

I paused an automation, but it still shows non-compliant devices. The non-compliant count reflects how many devices currently meet the trigger condition, independent of whether the automation is running. Pausing stops the actions, not the count.

I can't find an automation in the list. Check the status filter chips — a newly saved draft appears under Draft, not Active. Use the search field to find it by name, and clear the type filter to widen results.


Conclusion

Most automation issues trace back to one of a handful of causes: an incomplete pre-save check, a status that isn't Active, a schedule or timezone expectation, a platform or MDM prerequisite, or a misunderstanding of the live non-compliant count. Working through the relevant section above resolves the large majority of them; anything that remains is worth escalating.


FAQs

Q: Why is the Save & Activate button greyed out even though my automation looks complete? A: An automation can't be activated until every pre-save check passes. Check the Pre-Save Checks list in the Summary panel for the item still marked with an ✕ — commonly a missing name, an unselected geofence, or no schedule type.

Q: My automation is Active but not doing anything — what should I check first? A: Confirm the current time is within the schedule, the devices are in a selected group, and the trigger is actually being met. The non-compliant count shows how many in-scope devices currently meet the trigger.

Q: Why did an action work on some devices but not others? A: Likely platform support. Take Screenshots for example aren't available on iOS/iPadOS or Android, and MDM actions only apply to devices managed by that MDM.

Q: The schedule seems to run at the wrong time — is it broken? A: Almost always this is timezone behavior. Devices apply the schedule in their own local time, so the window runs during those local hours on each device. This is intended.

Q: Does a high non-compliant count mean something is wrong? A: No. It's a live count of devices currently meeting the trigger condition. Whether that number is expected depends on your policy and your fleet.