Secure your Iru surface
Apple device posture, blueprint assignment drift, and encryption state across the fleet. We don’t connect to Iru to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.
Iru was previously known as Kandji. Both names refer to the same platform, and this integration is unchanged.
Book a Demo[01] What This Surface Exposes
Where Iru goes wrong
Iru goes wrong through silent failure: a library item that fails to apply repeatedly is a control you believe you have and do not.
- Devices assigned to blueprints that no longer match their role
- FileVault enabled without key escrow
- Library items failing to apply repeatedly without anyone noticing
- Devices running OS versions past security support
- Enrolment gaps between purchased hardware and managed hardware
[02] What We Secure
What we watch, catch and fix on Iru
On Iru we surface persistent library item failures as findings, and reconcile blueprint assignment against each device's actual role.
- Blueprint assignment reconciled against device role and user
- Encryption and key escrow verified per device
- Persistent library item failures surfaced as findings, since a control that keeps failing is a control you do not have
- OS currency tracked against Apple's support behaviour
- Purchase-to-enrolment reconciliation to catch unmanaged hardware
[03] Where It Lands
Where Iru lands in your registers
Every managed device becomes an asset register entry with its owner, encryption state, and OS currency. Access reviews cover the accounts bound to it, and the risk register carries what an unpatched or unencrypted endpoint actually exposes given the data that person handles. The gap that matters most is the device your MDM has never seen — we reconcile against your directory and HR record to find it.
[04] How We Engage
On Iru specifically
On Iru, we correct blueprint assignment and drive remediation of failing library items. Fleet-wide OS upgrade campaigns and unmanaged device recovery we project-manage.
Platform licence
Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.
- Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
- Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
- Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
- Unlimited integrations and unlimited users, with anything missing built within two weeks
Managed service
Every tool you connect through Konfirmity comes under our care, with our team doing the work.
- Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
- Incident response led by us, with containment coordinated with your team
- Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
- Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it
[05] Iru FAQs
What Iru access does Konfirmity need?
Konfirmity needs a read-only API token covering device inventory, blueprints and library item status. That is enough to assess posture, encryption state and configuration drift across the Apple fleet.
Is this the same product as Kandji?
Yes. Kandji rebranded to Iru, and both names refer to the same Apple device management platform. The integration is unchanged, and existing connections continue to work exactly as before.