# Auditing Compliance Last Updated On: 23 Jul 2026 19 minutes read This page explains how to group compliance policies, configure audit scans, and interpret compliance results at the target group, computer, and policy levels in Endpoint Central. ## Grouping Policies for Audit The first step in creating a compliance audit is to group the policies against which you want to audit a specific group of target systems for compliance. > **Note** > Compliance audits only run on target systems whose OS matches that of the policies. It is recommended to group policies based on OS in order to effectively map them to targets belonging to the same OS. To create a policy group: 1. Navigate to **Compliance → Policy Groups**. 2. If you are just starting out and have not created a Policy Group yet, click **View Compliance Policies**. This opens a wizard displaying all available policies along with details such as the category, OS platform, and total number of rules against which targets will be scanned. > **Note** > Once a policy group is created, the **View Compliance Policies** button changes to **Create Policy Group**. 3. Give a meaningful name to the Policy Group. 4. Select the policies you want to group together for audit. Clicking on a policy reveals a detailed breakdown. Refer to [this document](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/understanding-compliance-policies.html) to learn more about the policies supported and how they are structured. 5. Click **Create Group**. The created group will be listed under the **Policy Groups** section. Click the created policy group to view the policies included in it. You can use filters to view policies by Deprecation Status and OS platform. Deprecated policies refer to obsolete policies superseded by their latest upgraded version — they appear greyed-out in the console. Endpoint Central immediately supports the superseded version of all deprecated policies. When you map target system groups to this policy group, they will appear under the **Mapped Target Groups** section. Under **Built-in Templates**, policy group templates built by consolidating policies based on OS and profile levels are readily available. Click a template to view the policies included in it. To use a template policy group for audit, click the **Add to Policy Groups** button against the desired template. These templates will now be available under Policy Groups and can be used for audits. ## Configuring a Compliance Audit Once you have created a policy group, you need to link it to a target custom group where the compliance scan will run. Navigate to **Compliance → Map and Audit Targets → Create Audit**. A new window will open for creating the audit: - Under **Target Group**, choose the custom group where you want to run the compliance check. - Under **Map Policy Groups**, select the policy group you have created under the **Map Policy Groups against which the target should be audited** option. - Under **Schedule Scan**, select the scan **Frequency** (daily is recommended so that any deviations from compliance can be tracked easily) and set the **Start at** date. - If you want to configure notifications regarding this CIS compliance audit, enable the **Enable Notifications** checkbox. After configuring these settings, click **Create Audit and Scan Now** to run the compliance scan immediately, or click **Create Audit** to run the compliance scan in the subsequent refresh cycle. ![Compliance Audit configuration window showing Target Group, Map Policy Groups, Schedule Scan, and Enable Notifications options](https://www.manageengine.com/products/desktop-central/help/images/vm15.png) Once an audit scan has been scheduled for a target group, it will appear in the table in the **Map and Audit Targets** view. Systems belonging to the target group will then be periodically assessed for compliance against all rules in the mapped policies based on the schedule. The resulting overall compliance percentage will be displayed for each target group. The overall compliance percentage indicates the percentage of systems that are secure (systems that achieved a compliance percentage of at least 90%) out of the total systems scanned in the target group. **Overall compliance percentage** = Number of secure systems (systems that achieved a compliance percentage of at least 90%) / Total scanned systems × 100 > **Note** > Only scanned systems — not all systems — are considered for overall compliance percentage, because new systems may be added to the custom group in the future. If the audit scan runs before this addition, those new machines will not be audited for compliance until the next scheduled scan. If a system is offline during a scheduled scan, the compliance percentage will reflect only the results of the last scan before this scheduled scan. The compliance scan for this system will occur in the subsequent refresh cycle, after which the compliance percentage will be updated accordingly. ## Inside the Target Group ![Target group compliance view showing compliance status, breakdown of computers by health, and table of scanned computers](https://www.manageengine.com/products/desktop-central/help/images/vm12.png) At the top, you can see the name of the target group, who scheduled the audit, and its scan schedule. You can edit the schedule by clicking **Modify Schedule**. ### Compliance Status This section indicates the number of computers that need attention (computers whose individual compliance is below 90%) out of total scanned computers. According to Endpoint Central, systems that have achieved a compliance of at least 90% are considered secure. The compliance percentage displayed here is the same as the overall compliance percentage of the target group. ### Breakdown of Computers by Health Computers are classified in this section by health based on their compliance percentage. | Compliance Percentage of the Systems | Health Status | |---|---| | Below 10% | Vulnerable — indicates vulnerable computers | | 10% — 50% | Poor Compliance — indicates systems with poor compliance | | 50% — 90% | Moderate Compliance — indicates systems whose compliance can be improved | | Above 90% | Secure — indicates secure computers | ### The Table View The table below lists all computers belonging to this target group. Details such as OS platform, scanned and yet-to-scan policies, and compliance percentage for each computer are available here. If the audit is modified after a scan to map a new policy group, these policies will remain unscanned until the next scheduled scan and will be counted as **Yet-to-scan** policies. The compliance percentage of each system indicates the percentage of rules the computer has passed out of the total scanned rules (excluding unscored rules) from all the mapped policies. **Compliance percentage** = Rules passed / (Total scanned rules − unscored rules) × 100 > **Note** > Not all rules from the mapped policies factor into your compliance percentage. Rules are excluded in three cases: > - The rules belong to policies that are yet to be scanned. > - The rules belong to policies that are not applicable to the system — this can happen if the policy is designed for a particular OS that does not match the system's OS. > - The rules are labelled as unscored. While these rules are still counted towards the total rule count of a policy, their outcome will not be factored into the compliance percentage. > > Also, if a policy group mapped to the target is modified after an audit scan to add or remove policies, those changes will not influence the compliance percentage until the subsequent scan. You can also view the compliance status and percentage of a computer on a per-policy basis by clicking on a computer. ## Individual Computer View ![Individual computer compliance view showing compliance status, breakdown of rules by compliance status, and per-policy table](https://www.manageengine.com/products/desktop-central/help/images/vm13.png) ### Compliance Status This section indicates the number of rules the computer has failed to comply with out of the total scanned rules from all the mapped policies. The compliance percentage displayed here indicates the percentage of rules the computer has passed out of the total scanned rules (excluding unscored rules) from all the mapped policies. **Compliance percentage** = Rules passed / (Total scanned rules − unscored rules) × 100 ### Breakdown of Rules by Compliance Status All rules applicable to the computer are classified in this section based on compliance status: - **Failed** — Rules that the computer configurations failed to comply with. - **Error** — Rules that failed to be processed while scanning. - **Unscored** — These rules are counted towards the total rule count of a policy, but their outcome will not be factored into the compliance percentage. According to CIS, rules are either "scored" or "not scored". Scored recommendations are mandatory to achieve [CIS compliance](https://www.manageengine.com/vulnerability-management/cis-compliance.html), and if not met will lower the total benchmark compliance percentage. Recommendations that are not scored have no impact on the compliance percentage. - **Passed** — Rules that the computer configurations successfully comply with. ### The Table View The table below lists all policies mapped to this computer along with the number of rules passed in each policy and the compliance percentage per policy. The compliance percentage for each policy indicates the percentage of rules the computer has passed out of the total scanned rules from that policy. You can use the filter option to view rules based on compliance status. For instance, selecting **Failed** in the compliance status filter displays all failed rules from every policy. Click **View Resolution** next to a failed rule to view the detailed steps to implement the recommended value. You can also view the compliance status of a computer on a per-rule basis by clicking on a policy. ## Individual Policy View ![Individual policy compliance view showing compliance status and breakdown of rules by compliance status for a specific policy](https://www.manageengine.com/products/desktop-central/help/images/vm14.png) ### Compliance Status This section indicates the number of rules the computer has failed to comply with out of the total scanned rules from this particular policy. The compliance percentage displayed here indicates the percentage of rules the computer has passed out of the total scanned rules from the policy. ### Breakdown of Rules by Compliance Status All rules from the policy are classified in this section based on the computer's compliance status: - **Failed** — Rules that the computer configurations failed to comply with. - **Error** — Rules that failed to be processed while scanning. - **Unscored** — These rules are counted towards the total rule count of a policy, but their outcome will not be factored into the compliance percentage. According to CIS, rules are either "scored" or "not scored". Scored recommendations are mandatory to achieve CIS compliance, and if not met will lower the total benchmark compliance percentage. Recommendations that are not scored have no impact on the compliance percentage. - **Passed** — Rules that the computer configurations successfully comply with. ### The Policy Breakdown Table View Refer to [this page](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/understanding-compliance-policies.html) to learn more about how the policy is structured and for a detailed explanation of the terminologies used. For each title, you can view the number of rules the computer has passed. Click on a title to expand and reveal the rules pertaining to it. You can view the compliance status next to each rule. If you click on a rule, the detailed summary, rationale, and **How to Fix** columns will be visible. The How to Fix column offers detailed steps to implement the recommended value for each failed rule. You can also create customized CIS Compliance Reports. Navigate to **Reports → Executive Reports** and choose **CIS Compliance Reports**. Refer to [this page](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/executive-reports-vm.html#CIS) to learn more about creating one. ## Related - [Understanding Compliance Policies](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/understanding-compliance-policies.html) - [Vulnerability Management Overview](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/vulnerability-management-overview.html) - [Preventing Security Misconfigurations](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/preventing-security-misconfigurations.html) - [Executive Reports](https://www.manageengine.com/products/desktop-central/help/vulnerability-management/executive-reports-vm.html) - [CIS Compliance](https://www.manageengine.com/vulnerability-management/cis-compliance.html) - [Reach Out to Support](https://www.manageengine.com/vulnerability-management/request-support.html?cis-req)