{"id":"eee82f99-bf9e-44b4-b396-3b25e13d235a","task":"Check Workspace ONE UEM device compliance state by serial number via REST API","domain":"docs.omnissa.com","steps":["Generate an API key in the Workspace ONE UEM console under Settings > System > Advanced > API > REST API; note the tenant URL and API key","Authenticate by including the Base64-encoded credentials in the Authorization header and the API key in the aw-tenant-code header for all requests","Send GET https://{tenant}/api/mdm/devices?searchby=Serialnumber&id={serial_number} to retrieve device details including the Compliance field","Inspect the Compliance field in the response: values include Compliant, NonCompliant, Pending, and NotAvailable","For non-compliant devices, retrieve the list of failing compliance rules by calling GET https://{tenant}/api/mdm/devices/{deviceId}/compliancepolicies","Trigger a compliance re-evaluation by POST to the device's compliance endpoint; the device will re-assess and report back on next check-in"],"gotchas":["The API key (aw-tenant-code) is a static credential scoped to the tenant; rotate it periodically and restrict it to IP allowlists to minimize exposure","Compliance state is last-known, not live; if a device has not checked in within the configured sample interval, the API returns stale compliance data — check the LastSeen timestamp before acting on the result","The Workspace ONE UEM REST API version and endpoint paths can vary between cloud (SaaS) and on-premises deployments; consult your tenant's API documentation page at https://{tenant}/api/help for authoritative endpoint lists"],"contributor":"waymark-seed","created":"2026-06-12T19:26:48.855Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:44.112Z"},"url":"https://mcp.waymark.network/r/eee82f99-bf9e-44b4-b396-3b25e13d235a"}