Glossary
MDM server
An MDM server is the backend that enrolled devices talk to: it stores your policies and app assignments, sends commands to iPhones, Android devices, Windows PCs and Macs through each platform's push service, and records what every device reports back. For an IT team it's the piece that decides whether you host and patch that backend yourself or rent it as a SaaS console.
How it works
Every enrolled device holds a record of one server: its URL, a certificate, and a push token. When you queue a command in the console, the server doesn't contact the device directly. It asks the platform's push service to wake it. For Apple devices that's APNs, and the server needs an Apple push certificate issued through the Apple Push Certificates Portal and renewed every year. For Android Enterprise, Google's Android Management API and Firebase Cloud Messaging carry the signal. Windows uses OMA-DM over HTTPS with the Windows Notification Service for the wake-up.
Once woken, the device connects out to the server and pulls its queue: install this app, apply this restriction, report your inventory. The traffic is always device-initiated, which is why MDM works through corporate firewalls and on cellular without any inbound port. Apple devices need to reach APNs on port 5223 or 443; block that on your guest Wi-Fi and enrollment mysteriously stalls.
The server also holds the trust anchors. Enrollment issues a device identity certificate, and on Apple the server address is baked into the enrollment profile. Change the hostname and every device needs to re-enroll.
Why it matters for a fleet
The classic decision is on-premises versus SaaS. Ten years ago many fleets ran their own MobileIron or Workspace ONE server in the datacenter. That gave control over the data location but also meant patching the server, renewing the APNs certificate before it expired (miss it and every Apple device goes silent), and scaling the database when the fleet grew. Most vendors now push customers to their cloud, and Microsoft Intune has never offered anything else.
What you should still ask a SaaS vendor is where the server runs and under which law. The MDM server holds the map of your estate: serial numbers, users, installed apps, compliance failures. That inventory is a target in itself.
Availability matters more than people assume. If the server is down, devices keep working with their last policy, but you can't wipe a stolen phone or push an urgent fix. Ask for the uptime history, not the SLA.
How Appaloosa handles it
Appaloosa is the MDM server, delivered as SaaS: you register it as an MDM server in Apple Business Manager, connect Android Enterprise and Windows Autopilot, and devices enroll against it without any infrastructure on your side. The server and your data are hosted in France on SecNumCloud-qualified infrastructure, and the push certificates, database and updates are Appaloosa's job, not yours. Platform coverage is detailed on the mobile device management page.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →Ready to try Appaloosa? Start free