Skip to main content

Best MDM for shared devices in Europe (2026)

Shared device MDM compared: 8 solutions for shared iPads, Android multi-user and store terminals, with EU hosting, GDPR and NIS2 checked on official docs.

12 min read
Shared devices managed by an MDM in a European warehouse

Shared device MDM is a different job from managing one phone per employee, and most vendor feature lists hide that. A tablet that passes through three shifts has to forget the previous person, restore the next one, and do it in under a minute at the start of a shift. Below: what actually changes technically, the European questions that decide most procurement files, and an honest read on eight solutions as of September 2026.

What a shared device changes for your MDM

One device, one owner, one enrollment. That assumption sits under almost every MDM feature you know: the compliance record, the app assignment, the certificate, the passcode policy. Break it and four things need answers.

  • Sessions. Someone has to sign in, and the MDM has to know who. Either the operating system owns the session (Apple's Shared iPad, Android secondary users) or your identity provider does (Microsoft Entra shared device mode), or you skip identity entirely and run the device as a pooled asset tied to a location.
  • Clearing data between users. This is where deployments fail quietly. Apple erases nothing: it partitions storage per Managed Apple Account, so the previous nurse's files stay in her partition and are simply unreachable. Android's ephemeral users take the other route and delete the whole user at sign-out or reboot. Entra shared device mode does neither by itself, it signals the app that the user changed and the app has to clear its own cache.
  • Apps and data per person. A picker and a supervisor sharing the same scanner may need different apps. Few platforms do per-user app assignment on a shared device well, so in practice you install the union of all apps and gate access inside them.
  • Rotation. Forty devices, 120 people, three shifts. The device is charging in a cabinet at 5 am and on a forklift at 6. Enrollment has to survive a factory reset without a trip to IT, which is why shared fleets lean on Android zero-touch enrollment and Apple's Automated Device Enrollment rather than manual setup.

Worth being blunt about one thing: you do not always need sessions. A lot of what people call shared device management is really a locked-down dedicated device running one app, where the "user" is the store aisle, not a person. That is a much cheaper problem to solve. Decide which one you have before you shortlist anything.

The European criteria that decide the deal

Feature parity between the big UEM platforms is closer than vendors admit. What actually separates them in a European tender is four things, and only the first one usually makes it into the RFP.

Where the console data lives. An MDM console holds your whole estate: every device, its user, its OS version, its patch state, often the installed app list. That inventory is a target by itself. Microsoft documents that Intune's Europe geography uses data centers solely inside the EU and EFTA, but also that the geography is picked from your Microsoft Entra directory country value and cannot be modified later (a migration request can take up to 24 months to complete). Worth checking before you provision, not after.

Sub-processors and the law that reaches them. Under GDPR article 28 your MDM vendor is a processor, and since Schrems II you document the transfer tool for anything leaving the EU. A vendor hosting in Frankfurt on a US-owned cloud is still in scope of that analysis. The SecNumCloud qualification is the only European framework that tests immunity to non-European law directly, including the provider's ownership structure, which is why it shows up in French hospital and defense supplier tenders.

NIS2 for essential sectors. NIS2 never mentions MDM. It asks for asset inventory, access control, MFA, cryptography and patch management, plus an early warning within 24 hours of a significant incident. If you run shared tablets in health, water, transport or manufacturing, that 24-hour clock is the spec: when a device disappears from a ward, can you say today who last signed in, whether storage was encrypted, and whether the wipe confirmed?

Support in the language of the people calling. Unglamorous and decisive. A warehouse supervisor in Lyon or Bologna filing a ticket at 6 am does not want a US time zone. Ask for the support hours by region and the languages of the console itself, not just of the sales deck.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

The eight solutions side by side

Hosting below reflects what each vendor states on its own documentation pages in September 2026. Where we could not verify a claim on an official page, it says so rather than guessing.

SolutionShared device approachEuropean hosting (per official docs)Best fit
Microsoft IntuneEntra shared device mode (iOS, iPadOS, Android) plus Android dedicated and Shared iPadEurope geo in EU/EFTA data centers only; geo fixed at provisioningMicrosoft 365 shops with frontline licenses
Jamf ProShared iPad, Apple onlyServers in the US, UK, Germany, Japan, Australia; data at rest stays in the instance regionApple-only estates, hospitals
SOTI MobiControlAndroid dedicated and multi-user, rugged OEM depthEU cloud hosting offered and on-premises still available; exact regions not publishedLogistics, rugged scanners
ScalefusionAndroid multi-user, kiosk, Shared iPadData centers in Ireland, the Netherlands, Germany and the US; EU customer data kept in EUMid-size mixed fleets
Hexnode UEMAndroid kiosk and multi-app, Shared iPadAWS across EU and US locations, instance assigned by location or on requestBudget-sensitive mixed fleets
Samsung Knox ManageKnox-specific shared and kiosk configurationsTwo global servers, US and EU; region chosen at tenant creationSamsung-standardized fleets
Ivanti Neurons for MDMAndroid dedicated and shared configurationsNot stated on a public page we could verify; ask in writingExisting Ivanti estates
AppaloosaShared iPad with Managed Apple Accounts, kiosk, pooled devices by role or siteHosted in France on SecNumCloud-qualified infrastructureEuropean retail, field teams, regulated mid-market

How each one actually handles shared devices

Microsoft Intune

The widest coverage of the eight, because Microsoft owns both halves of the problem. Entra shared device mode gives one sign-in and one sign-out across every app that supports it, on iOS, iPadOS and Android. Intune pushes Microsoft Authenticator with shared device mode turned on, and on iOS it also enables the Enterprise SSO plug-in.

The catch is app support. If an app does not implement shared device mode through MSAL, the user gets none of the benefit and the app keeps its cached data. Your line-of-business app needs development work, and that work is on you. Microsoft also notes third-party MDMs can set up shared device mode on Android, so you are not locked into Intune to use it.

On hosting, Intune is honest in its docs and the detail matters: your geography follows your Entra directory country and you cannot change it afterwards.

Jamf Pro

If your shared fleet is iPads and nothing else, Jamf is the deepest Shared iPad implementation on the market, and hospitals are where that shows. Ward tablets that stay with the room instead of the nurse, Managed Apple Accounts federated to Entra ID, Apple's own configuration surfaced without translation layers.

It does one platform. That is the whole trade. Add Android scanners to the same project and you are buying a second tool. Jamf's security overview lists servers in the United States, the United Kingdom, Germany, Japan and Australia, with data at rest staying in the hosting region. Germany covers most EU requirements; the UK is a third country for transfer purposes, so check which region your instance landed in.

SOTI MobiControl

Built for rugged hardware and it shows in places no one else bothers with: Zebra and Honeywell scanner settings, per-OEM firmware control, scripting that survives gloves and cold storage. European logistics operators run it for a reason. SOTI also still sells an on-premises build, which is the blunt instrument for a data residency requirement you cannot negotiate.

It is heavier to operate than the mid-market tools, and the console shows its age next to Scalefusion. SOTI advertises EU cloud hosting, but we could not find a public page naming the exact regions, so put that question in writing during procurement.

Scalefusion

The best-documented hosting story of the non-European vendors. Its security documentation names the data centers (Ireland, the Netherlands, Germany and the United States) and states that EU customer data stays in EU data centers, alongside ISO/IEC 27001:2022 certification and SOC 2 Type 2. Android multi-user and kiosk work well, Shared iPad is supported, and the console is pleasant.

Cloud only, so self-hosting and air-gapped networks are out. The company is Indian-owned with EU hosting, which satisfies GDPR residency but not a sovereignty requirement that tests ownership.

Appaloosa

Our own position, stated plainly. Appaloosa's shared device management handles Shared iPad with a Managed Apple Account per person, kiosk mode on Android and supervised iPadOS, and pooled devices tied to a site or a role rather than a named owner. The whole platform is hosted in France on SecNumCloud-qualified infrastructure, and the published price is 3.49 euros per device per month on Business (50 device minimum) or 5.49 on Enterprise (100 minimum), with a 14-day trial and no credit card. Console and support exist in French, English, German and Spanish.

Two limits worth saying out loud. Appaloosa does not document per-user Android secondary profiles: its Android shared story is a dedicated device plus kiosk plus a clean reset through zero-touch, which covers scanners and store terminals but not a warehouse that genuinely needs separate persistent Android user sessions. And Appaloosa itself holds no ISO 27001 certification; the SecNumCloud qualification belongs to the hosting provider, not to us. Anyone telling you otherwise is selling.

Hexnode UEM

Good value, broad platform coverage, and a kiosk implementation that handles multi-app lockdown without much fighting. Hexnode documents hosting on AWS across EU and US locations, with the instance assigned by your location or on request, which is less specific than Scalefusion's disclosure. Fine for a retail chain, thinner for a NIS2 essential entity that has to name the region in an audit.

Samsung Knox Manage

If your fleet is Samsung and will stay Samsung, Knox Manage reaches hardware controls that generic MDMs get to through OEMConfig. Samsung's documentation is clear that there are two global servers, US and EU, and the region follows what you pick when the tenant is created. Standardizing on one vendor's hardware is a real constraint, though, and mixed Apple estates push you elsewhere.

Ivanti Neurons for MDM

Capable, and usually the answer when Ivanti already runs your endpoint estate. Shared and dedicated Android configurations are there. We could not verify European hosting regions on a public Ivanti page, which is not an accusation, just a gap you should close with a written answer before signing.

What we would pick by sector

Retail. Store tablets are usually pooled assets, not personal ones. Kiosk plus a location-scoped device identity beats per-user sessions, and the thing that matters is a clean reset when a device comes back from a broken store. Appaloosa, Scalefusion or Hexnode all fit; Intune only really earns its place if the staff already have Microsoft 365 frontline licenses.

Healthcare. Shared iPad with Managed Apple Accounts, full stop. Per-user partitions are what lets a nurse open her own notes on a ward tablet without seeing the previous shift's. Jamf if you are Apple-only and have the budget; Appaloosa if French or EU hosting is a hard requirement and the estate is mid-size.

Logistics. Rugged Android, three shifts, scanners that take abuse. SOTI for depth on Zebra and Honeywell hardware, or Scalefusion if you want Android multi-user with clearer EU hosting. This is the one sector where persistent Android secondary users genuinely pay off, because drivers keep route data between shifts.

Manufacturing. Workshop tablets are dedicated devices wearing a shared-device costume: one MES or quality app, gloves, no keyboard. Lock it to the app and stop there. NIS2 scope is the reason to care about hosting here, since much of manufacturing landed in scope that NIS1 left out.

FAQ

Can you run Shared iPad without Apple Business Manager?

No. Shared iPad requires a supervised iPad enrolled through Automated Device Enrollment, which means it was assigned to your MDM in Apple Business Manager or Apple School Manager, plus a Managed Apple Account per user. Switching a device into or out of Shared iPad erases it, so there is no in-place conversion of a personal iPad. Apple's storage floor is 32 GB, and anyone running this in production will tell you to buy 128 GB or more so partitions do not force a slow iCloud round trip at sign-in.

What is the difference between a multi-user Android device and a dedicated device?

A dedicated device is locked to one app or a small set, with the MDM as device owner and Android's lock task mode hiding the rest of the system. Multi-user adds identity on top: Android's documentation distinguishes secondary users, whose apps and data persist between sessions, from ephemeral users, which the system deletes at sign-out or reboot. Delivery drivers want the first, a public lobby kiosk wants the second.

Does GDPR require an MDM hosted in Europe?

No, and any vendor claiming it does is overselling. GDPR requires a documented transfer tool and a risk assessment for personal data leaving the EU, which EU hosting simply removes the need for. Sovereignty requirements are a separate matter: French public bodies and several NIS2-scoped tenders ask for SecNumCloud, and that is a qualification granted to a named offering at a named version, never to a company as a whole. Ask which offering is qualified and until when.

The shortlist gets short fast once you separate pooled devices from true per-user sessions, then filter on hosting you can name in an audit. If your fleet is shared tablets or phones passed between frontline teams and you want the console and the data in France, start with our mobile device management platform and a 14-day trial.

See the full platform Explore Appaloosa

Ready to deploy MDM?

Get started today with unrestricted access to our platform and help from our product experts.

Get Started

Alternatively, contact sales.

Free 14-day trial
Cancel anytime, no questions asked.
Expert Support
Get customized and expert onboarding to get started.