Skip to main content

Glossary

MDM

MDM (Mobile Device Management) is the software an IT team uses to enroll, configure, secure and monitor smartphones, tablets and laptops from one console. It talks to the operating system directly, so policies apply whether or not the user cooperates.

How it works

Every modern OS ships with a management channel built in. Apple has had one since iOS 4 in 2010, Google added Android Enterprise with Android 5.0, and Windows exposes its own set of configuration service providers. An MDM server plugs into that channel. Once a device is enrolled, the server sends commands (install this app, require a 6-digit passcode, turn on encryption) and the OS executes them without asking the user.

The device also reports back. Model, OS version, installed apps, whether the passcode is set, whether the device is jailbroken or rooted. That inventory is what makes compliance checks possible.

Enrollment is the step that matters most. It can be manual (the user scans a QR code or installs a profile), or automated through Apple Business Manager, Android zero-touch or Windows Autopilot, in which case the device is managed from its first boot.

Why it matters for a fleet

Past 30 or 40 devices, doing things by hand stops working. Nobody can update settings on 200 phones one at a time, and nobody can be sure a lost tablet had encryption switched on.

MDM answers three questions you'll be asked after an incident: which devices do we have, what state are they in, and can we wipe this one right now. It also shortens onboarding. A new hire gets a phone that configures itself in minutes instead of an afternoon with the helpdesk.

There's a trade-off. Full device management on a personal phone is intrusive, which is why the BYOD variants (work profile on Android, User Enrollment on iOS) exist. Pick the mode that matches who owns the device.

How Appaloosa handles it

Appaloosa is an MDM platform for iOS, iPadOS, Android, Windows and macOS. You enroll devices through Apple Business Manager, Android zero-touch or Windows Autopilot, then apply security policies (passcode, encryption, compliance rules), push public and private apps, and lock devices into kiosk mode when needed. Remote wipe and TeamViewer-based remote support are available from the same console. The whole thing is hosted in France on SecNumCloud-qualified infrastructure.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

Ready to try Appaloosa? Start free

Frequently asked questions

Does MDM let my employer read my messages or see my photos?
On a fully managed corporate device, IT can see installed apps and device state, not message content. On a personal device enrolled with a work profile or User Enrollment, the personal side is invisible to the MDM by design. Apple and Google document exactly what each mode exposes.
What's the difference between MDM and an antivirus?
An antivirus scans for malicious code. MDM configures and controls the device itself: enrollment, passcode rules, app deployment, encryption, remote wipe. Many teams run both, but MDM is the layer that makes the device manageable in the first place.
Can I manage devices without buying them through a reseller?
Yes. Manual enrollment works on any device via QR code or profile install. Automated enrollment (Apple Business Manager, Android zero-touch) requires devices bought from an authorized channel, but Apple Configurator can add existing iPhones to ABM afterwards.