Platform

Everything an MDM should do, for four platforms

BusiMDM manages company-owned Windows PCs, Macs, iPhones, iPads and Android devices using the management features built into each one. Here is what that gives you.

Enrolment

Devices are managed from first boot, without a technician touching them.

WindowsmacOSiOS & iPadOSAndroid
  • Apple Automated Device EnrolmentiPhone, iPad and Mac assigned in Apple Business Manager enrol supervised during Setup Assistant, with the screens you choose skipped.
  • Android zero-touchFully managed Android devices enrol from the zero-touch portal or a QR code, with Managed Google Play ready before anyone signs in.
  • Windows auto-enrolmentYour existing Windows PCs enrol themselves through Group Policy. They stay joined to your domain and keep their existing policies alongside.
  • Bulk and re-enrolmentAssign hundreds of serials at once. Wiped or replaced devices pick up the same policy automatically.
  • An identity per deviceEach device gets its own certificate so it can prove who it is. Nothing is shared between devices, so nothing can be copied.
  • Enrolment codes that expireEnrolment codes are single-use and short-lived, so an old one can't be used to add a rogue device.

Policy and configuration

Decide the settings once. BusiMDM applies them using each platform's own built-in management, so nothing extra runs on the device.

WindowsmacOSiOS & iPadOSAndroid
  • Network and certificatesWi-Fi, VPN and the certificates they need, in place before the user reaches the desktop.
  • Security settingsPasscode and password rules, BitLocker and FileVault encryption, firewall and screen lock.
  • RestrictionsCamera, AirDrop, USB, app stores, sharing and account controls, tuned per platform and per group.
  • OS updatesDeferral windows, deadlines and forced restarts outside working hours, with the posture visible per site.
  • Kiosk and single-app modeLock a tablet or counter device to one app, or curate the home screen layout and wallpaper.
  • Changes you approved, and only thoseEvery set of settings is approved and signed on your own network before it goes anywhere. Anything unsigned, expired or older than what a device already has is refused.

App delivery and self-service

One signed catalogue for every platform, and a self-service store that gets IT out of the install queue.

WindowsmacOSiOS & iPadOSAndroid
  • Windows self-service storeStaff install, update and remove approved apps without admin rights. A small BusiMDM service does the privileged work, and only for apps on the approved list.
  • Any Windows installerUse Chocolatey, winget or your own MSI and EXE installers. They all sit behind the same approval.
  • Apple appsAssign App Store apps through Apps and Books with no Apple ID on the device. Deploy enterprise apps and app configuration.
  • Managed Google PlayApprove, assign and configure Android apps from the same console.
  • Admin rights for one task, not foreverGive a user or a device temporary admin rights for one job, with an offline code for sites without connectivity. Standing local admin for the few who genuinely need it.
  • Access requestsUsers request apps that aren't yet approved. Approvers see who, what and why, and one click publishes.

Compliance engine

Set the rules once. BusiMDM checks every device against them, every time it checks in.

WindowsmacOSiOS & iPadOSAndroid
  • Rules in plain termsEncryption on. Operating system at or above a version. Passcode set. Seen in the last so many days. A particular app present, or absent.
  • Continuous evaluationEvery check-in re-evaluates. State changes land in dashboards and alerts within minutes.
  • Remediation firstNon-compliant devices can be pushed the missing policy, prompted, or given a deadline before any access is withdrawn.
  • Microsoft 365 accessDevices that pass keep their access. Devices that don't lose it until they're fixed, using the Microsoft 365 controls you already have.
  • Grace and exceptionsGrace periods per rule. Documented exceptions with an owner and an expiry, never a silent exemption.
  • EvidenceEvery evaluation is stored with the inputs it saw, so an audit question has an answer.

Remote actions

The commands that matter most are the ones with the most guardrails.

WindowsmacOSiOS & iPadOSAndroid
  • Lock and lost modeLock a device and show a message and callback number. On iPhone, iPad and Android, see where it is while it's lost.
  • Wipe and retireFull wipe for a lost device. Retire to remove management and corporate data before a device is handed on.
  • Recovery-key rotationRotate a BitLocker or FileVault key remotely after a reveal or a staff change.
  • App removalRemove a managed app and its data from one device or a group.
  • One device, one command, short lifeEach command names one device and expires in 15 minutes. It can't be redirected to another device or run twice.
  • Two people for bulk actionsAnything that targets many devices, or the whole estate, needs a second administrator to approve it first.

Recovery-key escrow

BitLocker and FileVault keys you can retrieve when a laptop won't boot, and nobody else can.

WindowsmacOS
  • Encrypted before it leaves the deviceRecovery keys are encrypted on the device so that only your own system can read them. The cloud stores them but cannot open them.
  • Revealed only on your own networkA key is only ever decrypted inside your own BusiMDM server, by an administrator you've given that permission.
  • Every reveal loggedWho, which device, when and why, written to the audit trail before the key is shown.
  • Rotate after useRotate the key once it has been revealed so the old one is worthless.

Inventory and reporting

Every device, every site, one query.

WindowsmacOSiOS & iPadOSAndroid
  • Hardware and OSModel, serial, OS build, storage, battery health and warranty where the vendor exposes it.
  • SoftwareInstalled applications and versions on every platform. Find every device with an out-of-date browser in one search.
  • CertificatesWhich identity and network certificates each device holds, and when they expire.
  • Smart groupsDynamic groups from any inventory attribute drive policy and app assignment.
  • Dashboards and exportsCompliance, enrolment, update posture and open actions per site. CSV export and a read API.
  • Audit trailAn append-only record of every administrative action and every command delivered.

Identity, roles and audit

Administrators sign in with your Microsoft account. Roles decide who can do what.

WindowsmacOSiOS & iPadOSAndroid
  • Microsoft sign-inYour existing multi-factor authentication and sign-in rules apply to the BusiMDM console too.
  • Role-based accessSeparate who can author, approve, release and reveal. Scope roles to sites or device groups.
  • Second-approver workflowsBulk actions and escrow reveals can require two people.
  • Everything loggedEvery change, approval and command, with who did it and when. Export it to your security tooling if you have any.
Platform matrix

What each platform gets

Each platform is managed through its own built-in tools, so what's possible follows what Apple, Microsoft and Google allow. Here is where the lines are.

CapabilityWindowsmacOSiOS & iPadOSAndroid
Sets itself up out of the boxYes, via Group PolicyYes, via Apple Business ManagerYes, via Apple Business ManagerYes, via Android zero-touch
OwnershipCompany-owned, domain-joinedCompany-owned, supervisedCompany-owned, supervisedCompany-owned, fully managed
How it's managedWindows built-in management plus the BusiMDM app storeApple built-in managementApple built-in managementAndroid Enterprise
Policy and restrictionsYesYesYesYes
App deliverySelf-service store: Chocolatey, winget, MSI and EXEApps and Books, enterprise appsApps and Books, enterprise appsManaged Google Play
Disk encryption and escrowBitLocker, escrowedFileVault, escrowedBuilt-in device encryptionBuilt-in device encryption
Microsoft 365 access controlYesYesYesYes
Lock, wipe and retireYesYesYesYes
Lost mode with locationNoNoYesYes
Kiosk and single-app modeAssigned accessNoYesYes
Temporary admin rightsYesNot neededNot applicableNot applicable
Personally owned (BYOD)NoNoNoNo

Company-owned devices only. BusiMDM does not manage staff's personal phones and laptops, by design.

Want to see it on your estate?

Tell us your platforms and device count and we'll set up a walkthrough on your own tenant, not a demo estate.

Request details