Every device accounted for, wherever it is.

Enrol it before it touches data, keep it configured and patched while it works, and take the data back the day the person leaves. That is the whole job, and most estates only do the first part.

— The situation

The asset register was accurate on the day it was made.

Laptops get issued and reissued. Phones get replaced under warranty. Contractors bring their own machines and connect to the same Wi-Fi as everyone else. Somewhere in that estate is a device three OS versions behind, holding a cached copy of something it should not, belonging to a person who resigned in March.


MDM makes the register a live system instead of a document, and gives you a remote wipe you have actually tested.

— Capabilities

What you get.

Zero-touch enrolment

A device out of the box joins the estate with the right profile before the user opens anything, on both corporate-owned and BYOD paths.

Configuration profiles

Wi-Fi, VPN, certificates, mail and restrictions pushed by group, so a new joiner is productive without a build ticket.

Patch and OS control

Update rings, deferral windows and enforcement, with visibility on what is behind and by how long.

Application management

Push required apps, block prohibited ones, and run a private catalogue for the internal tools.

Remote lock and wipe

Full wipe on a company device, selective wipe of corporate data on a personal one. Tested during deployment, not during the incident.

Compliance posture

Encryption, passcode, jailbreak and patch state reported per device, with automatic quarantine when a rule is broken.

Work / personal separation

Corporate data in a managed container on BYOD, so personal photos are never in scope for a wipe.

Loss and recovery

Location on managed devices, lock screen messaging, and an activation lock that survives a factory reset.

— Deployment

How it lands.

Platform Enrolment Ownership model
Android Zero-touch, QR, Android Enterprise Fully managed, work profile, dedicated device
iOS & iPadOS Automated Device Enrolment, user enrolment Supervised corporate, BYOD user enrolment
Windows Autopilot, Azure AD join, bulk provisioning Corporate-owned, co-managed with existing tooling
macOS Automated Device Enrolment Corporate-owned, supervised
— Protective DNS

The day
someone leaves.

Most breaches of this kind are not sophisticated. They are a laptop that was never collected and never wiped. The exit process should be one action, not a chase.

How many devices are on your network that nobody enrolled?

Scroll to top