Skip to main content

Glossary

Endpoint management

Endpoint management is the discipline of enrolling, configuring, securing and keeping up to date every device that touches company data, from smartphones and tablets to laptops, desktops and rugged scanners, through one console. For an IT team it means a single inventory and a single set of rules instead of one tool per operating system.

How it works

The word "endpoint" comes from network security, where it names anything at the end of a connection: a phone, a PC, a printer, a barcode scanner. Endpoint management took the tooling that grew up around mobile devices (MDM) and extended it to laptops and desktops, which Gartner started calling Unified Endpoint Management in 2018.

Under the hood, each operating system exposes its own management channel. Apple's MDM protocol dates from iOS 4 in 2010 and now covers macOS as well. Google ships Android Enterprise on every certified Android device since Android 5.0. Windows 10 and 11 answer OMA-DM commands through configuration service providers. An endpoint management console speaks all of those protocols and hides the differences behind one policy model: a passcode rule written once lands as a restriction payload on an iPhone, a policy on Android and a CSP on Windows.

The daily loop is the same everywhere. A device enrolls, gets its baseline (encryption on, screen lock, Wi-Fi, certificates), receives its apps, then checks in on a schedule so the console knows its OS version, its compliance state and when it was last seen.

Why it matters for a fleet

Most European organizations run a mixed estate: iPhones for managers, Android in the field, Windows laptops for finance and a few MacBooks in engineering. Managing that with Jamf for Apple, a Google console for Android and group policy for Windows means three inventories that never agree on how many devices you own.

That disagreement shows up at the worst moment. When an auditor asks whether every laptop is encrypted, or when a device is stolen and someone has to find it in the right tool at 6 pm on a Friday.

One console also changes the economics of policy. Writing a rule three times means it drifts three ways within a year. Writing it once, then watching the compliance report, is what keeps a 500-device fleet manageable by two people.

There's a trade-off to be honest about. Microsoft Intune goes deep on Windows and Jamf goes deep on macOS. A single console that covers everything won't match either on their home platform. For fleets where phones and tablets outnumber PCs by five to one, that's usually the right trade.

How Appaloosa handles it

Appaloosa manages iOS, iPadOS, Android, Windows and macOS from one console: enrollment through Apple Business Manager, Android zero-touch, Samsung Knox Mobile Enrollment or Windows Autopilot, then compliance policies evaluated continuously, an enterprise app store with public and private apps, kiosk mode and remote wipe. Devices report OS version, encryption state and last check-in into one inventory, hosted in France on SecNumCloud-qualified infrastructure. The platform coverage is laid out on the mobile device management page.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

Ready to try Appaloosa? Start free

Frequently asked questions

What's the difference between endpoint management and MDM?
MDM was built for phones and tablets and works through the management channel each mobile OS provides. Endpoint management widens the scope to laptops, desktops and any other device that touches company data, usually from the same console. In practice most vendors now sell endpoint or unified endpoint management and still call the mobile part MDM.
Do I need endpoint management if I already use Intune for Windows?
If Intune covers your Windows estate well and your phones are few, you may not. The question becomes harder when Android field devices, iPads and Macs grow. At that point you either accept several consoles or move to one tool that handles all platforms at a level good enough for your rules.
How often do managed devices report back to the console?
It depends on the platform and the vendor. Apple devices respond to push notifications and typically check in within minutes; Android Enterprise devices sync on a schedule plus on push; Windows devices poll on a fixed interval, often every 8 hours. Treat check-in age as a compliance signal: a device silent for a week is unknown, not compliant.