Apple MDM Software: A Practical Guide for Teams Managing Macs Without a Mac Admin

An independent guide to Apple MDM software for 2026. Jamf, Intune, Mosyle, Iru and Hexnode compared on real published pricing, plus what an MDM will never tell you.

James Carter James Carter • • 25 min read

TL;DR

  • What it is: Apple MDM software enrolls, configures and secures Macs, iPhones and iPads from one console, using the management framework Apple builds into the operating system.
  • When you don't need it yet: under about fifteen Macs, in one office, with somebody technical nearby. Set them up by hand and spend the money elsewhere.
  • The core jobs: enroll a device before the person opens it, push settings and apps, prove encryption and patch state, and wipe it when somebody leaves.
  • The market splits three ways: Apple-only specialists, cross-platform suites that also do Windows, and the free tiers that are genuinely free until a specific ceiling.
  • Decision rule: pick on your fleet mix and who administers it, not the feature grid. A Mac-only shop and a Microsoft shop with forty Macs need different answers.
  • The outcome: a new starter opens the box, signs in, and has a working configured machine without a support ticket.

The Week the Macs Stopped Being Manageable

Somebody in security asks a simple question. How many of our Macs have FileVault on, and can you prove it by Thursday.

You open a spreadsheet. It has 63 rows, which is wrong, because payroll says 71 people have company laptops. Four of the rows have no serial number. One says "Sarah's old one, returned?" with the question mark typed by somebody who has also now left. You can answer the FileVault question for maybe two thirds of the fleet, and only by asking people on Slack.

That's the moment Apple MDM stops being an IT preference and becomes a thing you have to buy. Not when the fleet hits a round number. When somebody asks you to prove something about every device at once and you can't.

So the real problem isn't configuration. Configuration is the easy part and always has been. The problem is that a Mac you never enrolled is a Mac you cannot see, cannot prove anything about, and cannot wipe when its holder stops answering email. This is what Apple MDM software is supposed to fix, and the platforms differ mostly in how much else they try to do at the same time.

Worth separating two things that get merged in every vendor conversation. There is the question of whether a device is configured correctly, and the question of whether you know the device exists at all. MDM answers the first one completely and the second one only for devices already enrolled. A tool cannot report on something it has never met.

That distinction decides which product you should be shopping for, and it is the single most useful thing to settle before you book a demo. Teams who skip it buy a good MDM and then spend a quarter confused about why the original problem is still there.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

When You Don't Actually Need Apple MDM Yet

Under fifteen Macs, one office, somebody technical nearby. Hand-configuring a laptop takes about forty minutes and you do it a few times a year. An MDM costs money and takes a week to set up properly. The maths genuinely does not work yet.

When friction starts showing. The signal is usually a new starter waiting. Somebody joins on Monday, their machine isn't ready until Wednesday, and the reason is that one person had to physically touch it. If that's happened twice this quarter, you're past manual.

When it becomes a liability. SOC 2 and ISO 27001 both want evidence about device state, not assurances. The first time an auditor asks for an encryption report and you produce a spreadsheet somebody maintains by hand, you have learned what this costs.

The edge case that forces it. Remote hiring. A Mac you ship to somebody in another country is a Mac you will never physically touch again. Without zero-touch enrollment, that person configures their own security settings, which means your security settings are whatever a non-technical new starter felt like doing on their first morning.

There is a fifth case that does not fit the progression, and it arrives without warning: an acquisition. Inheriting forty Macs configured by somebody else's standards, with somebody else's admin accounts on them, is a different problem from managing your own fleet badly. Most of those machines cannot be put into automated enrollment retrospectively, so you are choosing between a wipe-and-rebuild programme and running two standards indefinitely. Budget for the first one.

Five Questions IT Asks at 11pm

"Can I enroll a Mac I will never physically touch?" Yes, through Apple Business and automated device enrollment, but only if the Mac was bought through a channel that supports it. A machine someone bought at a retail store cannot be added to automated enrollment later, and that trips up more teams than any other single thing here.

"Will this work on the four Windows laptops we also own?" Depends entirely on which platform you pick. Apple-only specialists do Macs beautifully and ignore everything else. Cross-platform suites cover both and are usually weaker on the Mac-specific details that Mac users notice immediately.

"What does it actually cost at our size?" Anywhere from nothing to several thousand a year for the same fleet, and the published numbers are not comparable because some price per device and others per user. A company with 40 people and 60 devices pays very differently under those two models.

"How long until it's actually running?" A week of real work for a first deployment, if you have Apple Business sorted. Longer if you don't, because that setup involves a verified domain and a federated identity decision that nobody enjoys making under time pressure.

"Can I wipe a laptop when somebody stops replying?" Yes, if the device is enrolled and still checks in. If it has been offline for three months in a drawer, the remote wipe command sits in a queue waiting for a device that may never connect again. This limitation is the single most misunderstood thing about MDM.

What Apple MDM Actually Does

Apple MDM is not a product category Apple sells. It's a framework Apple builds into macOS, iOS and iPadOS, which third-party platforms talk to. That matters because it sets a floor and a ceiling. Every vendor can do roughly the same core things, because they all use the same Apple framework. What they compete on is everything around it: the console, the automation, the reporting, the app packaging, and how much hand-holding the setup needs.

The four jobs that matter:

Enrollment. Getting the device under management. The good version is automated device enrollment through Apple Business, where a Mac enrolls itself during setup, before anybody can skip it. The weak version is asking a human to install a profile, which works right up until somebody declines.

Configuration. Pushing settings, Wi-Fi, certificates, restrictions and applications. This is the part that is genuinely similar across vendors, because Apple defines what is possible.

Compliance evidence. Reporting on encryption, OS version, patch state and installed software. This is where platforms diverge sharply, and it's the part auditors care about.

Offboarding. Remote lock, remote wipe, and removing company data. Powerful when it works, useless against a device that stopped checking in months ago.

There is a fifth job that no vendor lists because none of them do it: knowing the device exists before any of the other four can happen. Enrollment assumes a device you already know about. Everything downstream inherits that assumption, which is why an MDM dashboard showing full compliance is a statement about a subset, not about your company.

The Free Tier Is Real, and Where It Stops

Most "free" software in this market is a trial with a longer name. Apple MDM is the exception, and anyone shopping here should know it before they talk to a salesperson.

Mosyle Business FREE covers up to 30 devices at no cost, with no billing requirement. That is a real free tier with real functionality, not a crippled demo. For a 25-person Mac shop, it may genuinely be the correct answer, and a vendor telling you otherwise is selling.

Fleet publishes an open source device management platform you can self-host. Free in licence terms, which is not the same as free. Somebody runs the server, applies updates and takes backups, and that person's time is the actual price.

Where free stops is fairly predictable. You cross the device ceiling. You need a support contract with somebody who answers. Or you need an integration, usually to an identity provider or an HRIS, that the free tier does not include. Until one of those three things happens, paying is optional.

The ceiling is the one that catches people, because 30 devices is fewer people than it sounds. A company of 22 where everybody has a laptop and eight people also carry a company iPhone is already at 30. Count devices, not headcount, and count the phones, because teams routinely forget them and then discover the limit mid-deployment.

And be honest about the support question. A free tier with community support is fine while things work and expensive the week they do not, particularly if the person who set it up has left and nobody else understands the configuration. That risk is worth more than the licence fee for some teams and nothing at all for others, which is why it is a judgement rather than a rule.

So test the free tier first if you are under the ceiling. The worst outcome is that you learn exactly which paid feature you actually need, which makes the eventual purchase much better informed.

Six Apple MDM Platforms, Reviewed

Jamf Pro

Best for: Mac-heavy organisations that want the deepest Apple management available and have somebody to run it.

Why teams choose it: Jamf has been doing Apple management longer than almost anyone and it shows in the depth. If a thing is possible on a Mac, Jamf can probably do it, and the community knowledge around it is enormous. For an organisation where Macs are the primary platform and the stakes are high, this is the safe choice.

Where it struggles: It assumes an administrator. Teams expecting to configure it in an afternoon are consistently surprised, and smaller companies often buy more capability than they will ever use. Jamf does not publish pricing, so comparison requires a sales conversation.

A useful test: if nobody in your organisation has written a configuration profile or read an Apple deployment guide before, Jamf will be a steep first week. That is not a criticism of the product. It is the cost of depth, and teams who have that skill in house generally consider it money well spent.

Microsoft Intune

Best for: Organisations already standardised on Microsoft 365 with a minority of Macs.

Why teams choose it: It is frequently already paid for. Intune Plan 1 capabilities are included with Microsoft 365 E3 at $39.00 per user per month and E5 at $60.00, and Plan 2 is $4.00 per user per month standalone. If you hold those licences, adding Mac management is a configuration exercise rather than a purchase.

Where it struggles: Mac support is real but visibly second to Windows. Features arrive later, some Apple-specific capabilities are shallower than the specialists, and Mac-literate staff tend to notice. If Macs are your primary platform, this is the wrong tool bought for the right financial reason.

Mosyle

Best for: Apple-only teams that want capable management without enterprise pricing.

Why teams choose it: The free tier covers 30 devices with no billing requirement, and paid plans start at $1.00 per device per month for Business Premium, $1.50 for iOS and iPadOS Fuse, and $3.00 for macOS Fuse, each with a 30-licence minimum billed annually. For a small Apple shop the value is hard to argue with.

Where it struggles: Apple only, which is the trade. The console is less polished than Jamf's and the depth runs out earlier on complex deployments. Organisations that grow into mixed fleets usually migrate away eventually.

The migration point is worth planning for rather than discovering. If your hiring plan implies Windows machines within two years, starting on an Apple-only platform means a move later, and moving MDM is genuinely disruptive because devices have to be unenrolled and re-enrolled. Knowing that at the start changes whether the free tier is a bargain or a deferred cost.

Iru (formerly Kandji)

Best for: Teams that want strong Apple management with automation built in rather than scripted.

Why teams choose it: Its pre-built compliance and remediation library does work that other platforms expect you to script yourself, which is worth a great deal to a team without a dedicated Mac admin. Following its rebrand from Kandji in October 2025 it also covers Windows and Android, so it is no longer Apple-only.

Where it struggles: It does not publish pricing, so budgeting requires a sales call. And the brand change is recent enough that a lot of the comparison material you will find online still says Kandji, which makes research needlessly confusing.

Hexnode UEM

Best for: Mixed fleets wanting published per-device pricing.

Why teams choose it: Pricing is on the website, which in this market is unusual enough to be a feature. Pro is $2.20 per device per month, Enterprise $3.20, and Ultimate $4.70, with a 14-day trial and a 15-device start. Cross-platform coverage is genuinely broad.

Where it struggles: Breadth costs depth. On Apple-specific capability it sits behind Jamf, Mosyle and Iru, and teams whose fleet is overwhelmingly Mac usually feel that gap within a quarter.

Scalefusion

Best for: Teams managing shared, kiosk or rugged devices alongside laptops.

Why teams choose it: Strong handling of the awkward cases, including shared iPads and single-purpose devices, with pricing from $2 per device per month on Essential, billed annually with a ten-device minimum. Device-centric pricing suits fleets where device count is lower than headcount.

Where it struggles: The Mac experience is competent rather than excellent. If your problem is a hundred MacBooks held by software engineers, the specialists will serve you better.

What Each One Actually Costs

Pricing in this market is deliberately hard to compare, so here is what each vendor publishes on its own site, with the gaps named rather than estimated.

Platform Published price Model Free tier
Mosyle $1.00 to $3.00 per device/month Per device, 30 minimum, annual Yes, up to 30 devices
Scalefusion From $2 per device/month Per device, 10 minimum, annual Trial only
Hexnode UEM $2.20 / $3.20 / $4.70 per device/month Per device, from 15 14-day trial
Microsoft Intune $4.00 per user/month (Plan 2) Per user Included with M365 E3 and E5
Jamf Pro Not published Quote Trial only
Iru (formerly Kandji) Not published Quote Trial only

Two things in that table matter more than the numbers.

Per device versus per user is not a detail. A company of 50 people where everybody has a laptop and half also have a company phone is 75 devices. Under per-device pricing you pay for 75. Under per-user you pay for 50. Depending on which way your fleet leans, the same headline rate can differ by half.

Not published means budget for a sales cycle. Jamf and Iru are both credible platforms and both require a conversation before you know the number. That is a real cost in calendar time if you are trying to decide this quarter.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
All Macs, small team, tight budget Under 30 devices One office or hybrid Nothing is managed at all Mosyle free tier
All Macs, growing, no Mac admin 30 to 150 Distributed Setup time per hire Iru (formerly Kandji)
Mac-primary, high compliance stakes 150+ Any Audit evidence and depth Jamf Pro
Microsoft shop with some Macs Any Any Already paying for Intune Microsoft Intune
Mixed Apple, Windows and Android 50 to 500 Distributed One console for everything Hexnode UEM
Shared, kiosk or rugged devices Any On site Devices without a single owner Scalefusion
Devices exist but nobody knows where Any Remote-first The register, not the management An asset platform, not an MDM

Most teams sit in two rows at once. Start with the row describing what broke most recently, not the one describing your ambitions.

The last row is the one people get wrong, and it deserves its own section.

Apple Business Is Not Optional

Every platform above depends on Apple Business, and it's the step teams consistently underestimate.

One naming change first, because it is recent enough to cause confusion. Apple retired Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026 and replaced all three with a single free platform called Apple Business, available in more than 200 countries and regions. Vendor onboarding guides and internal runbooks that still say Apple Business Manager mean this.

The change is more than cosmetic. Apple Business now includes Apple's own built-in mobile device management at no cost, with Blueprints for configuring groups, device settings and apps. For a small Apple fleet with straightforward requirements that is worth trying before paying for anything, because it may be enough on its own. It does not remove the case for a dedicated platform once you need policy depth, third-party patch management or compliance reporting, but it does move the point at which paying becomes necessary.

Apple Business is Apple's free portal for organisations. It does two jobs that matter: automated device enrollment, so a Mac enrolls itself during first setup rather than relying on somebody installing a profile, and volume app purchasing. Without it, your MDM is running in a weaker mode and you have no way to stop a user skipping enrollment.

Setting it up involves verifying a domain you own, deciding how it federates with your identity provider, and linking your hardware resellers so purchased devices appear automatically. None of that is difficult. All of it involves waiting on somebody else, which is why it takes longer than the hour it looks like.

The federation decision deserves a moment of thought rather than a quick click. Federating Apple Business with your identity provider means people sign in to Apple services with their work account, which is usually what you want, but it also captures existing personal Apple IDs that use a company email address. Those users get prompted to change their Apple ID, which generates support tickets from people who have been using that address for years.

None of that is a reason to avoid federation. It is a reason to announce it before you switch it on, which costs an email and saves a week of confusion.

And there's one rule worth knowing before you buy anything. Devices have to be purchased through Apple directly or through a reseller enrolled in the programme to appear in automated device enrollment. A Mac bought at a retail store, or secondhand, or on a company card in an emergency, cannot be added later. You can still manage it, but only with user-approved enrollment, which a user can decline.

The emergency purchase is how this rule bites most teams. Somebody's laptop dies on a Thursday, a manager buys a replacement locally to keep them working, and nine months later that machine is the one device nobody can auto-enroll. One of those is an annoyance. A habit of them creates a permanent second tier in your fleet.

The fix is procedural rather than technical: route every purchase through an enrolled reseller, and give managers a fast path that does not involve a retail shop. If you cannot make that work, at least keep a list of the devices bought outside the channel, so the gap in your enrollment numbers has a known explanation rather than looking like a failure.

So audit how you actually buy hardware before you choose a platform. Teams that discover this rule after deployment end up running two enrollment processes forever.

Where Teams Get Apple MDM Wrong

The mistake How it shows up What fixes it
Buying before Apple Business exists Enrollment depends on users cooperating Set up Apple Business first, then pick a platform
Choosing on feature count Paying for depth nobody uses Choose on fleet mix and who administers it
Assuming remote wipe always works A dormant laptop ignores the command Treat wipe as best effort, not a guarantee
Buying retail Macs Devices that cannot be auto-enrolled Route all purchasing through an enrolled reseller
Mistaking MDM for an asset register Only devices that check in are visible Run a register alongside the MDM
Underestimating setup A two-week deployment booked as two days Budget a week of real work, minimum

The third row is worth sitting with, because it is the most common misunderstanding in this category and the most expensive.

Remote wipe is not a magic button. It is a command placed in a queue, which executes the next time the device contacts the MDM server. For a laptop in daily use, that is immediate. For a laptop that somebody put in a drawer when they resigned four months ago, the command waits indefinitely. If the device never connects again, it never wipes, and your compliance report will happily show the wipe as pending forever.

There's a second-order problem that follows from it. Because the pending state looks like progress, nobody escalates. A row saying wipe pending reads as in hand, and reviews skip past it. Months later somebody asks how many ex-employee devices still hold company data, and the honest answer is that nobody knows, because the system was reporting the queue rather than the outcome.

So set a threshold. Any wipe pending beyond thirty days stops being an MDM matter and becomes a recovery matter, which means somebody contacting a person rather than a dashboard waiting for a device.

What an MDM Will Never Tell You

An MDM knows about devices that check in. That is the whole of its visibility, and it is a smaller claim than it sounds.

It does not know about the MacBook in a drawer since March. It does not know about the laptop somebody bought on expenses and never mentioned. It does not know what any of them cost, when the warranty ends, or whether the one assigned to a leaver ever physically came back. Those are asset management questions, and an MDM is not an asset management system even when its dashboard looks like one.

This matters because the two get conflated constantly during buying decisions. A team with a device-recovery problem buys an MDM, deploys it properly, and discovers the problem is untouched: they now have excellent configuration control over the devices they already knew about, and exactly as little visibility as before over the ones they didn't.

The practical answer is to run both and be clear about which answers which question. An MDM tells you the state of a device that is online. An asset register tells you the device exists, who holds it, what it cost and whether it came back. Platforms like RemoAsset sit on the asset side, handling procurement, delivery, retrieval and the register, with MDM enrollment happening on delivery rather than replacing the MDM itself. Neither category substitutes for the other, and any vendor suggesting otherwise is overselling.

The test for which one you need is a question, not a feature comparison. Ask what broke last quarter. If the answer is that a machine was misconfigured, unpatched or missing encryption, that is MDM. If the answer is that a laptop never came back, or an audit found hardware nobody had recorded, that is the register, and an MDM will not touch it.

Most companies past about fifty people eventually need both, and the order matters less than the clarity. What costs money is buying one while describing the other's problem.

What to Put in Writing Before You Buy

Artefact Why it matters When
Device count, split by platform and by user Per-device and per-user pricing differ sharply Before any vendor call
How hardware is purchased today Retail purchases cannot be auto-enrolled Before any vendor call
Who administers this day to day Jamf and Mosyle assume very different skill levels Before shortlisting
Your compliance evidence requirements Reporting depth is where platforms genuinely differ Before demos
Apple Business status Everything depends on it Before deployment
What happens to a dormant device Wipe is best effort, and policy should say so Before the first offboarding

The first row prevents the most common budgeting error. The second prevents the most common deployment surprise.

Questions to Ask Before You Commit

On enrollment. Can we auto-enroll every device we own today? A bad answer is probably.

On pricing model. Is this per device or per user? A bad answer is it depends.

On Mac depth. Which Apple features lag your Windows support? A bad answer is none.

On dormant devices. What happens to a wipe command for a laptop that never reconnects? A bad answer is it wipes.

On setup. How long to a first managed device, realistically? A bad answer is same day.

On exit. How do we get our configuration out if we leave? A bad answer is a vague one.

What Getting This Wrong Costs

The first cost is the deployment that stalls. A team buys a capable platform, discovers Apple Business was a prerequisite rather than a nice-to-have, and spends three weeks on domain verification and federation decisions while the licences run. Nothing is broken. Nothing is working either.

The second cost is paying enterprise prices for a small fleet. This happens when the shortlist is built from feature comparisons rather than from fleet shape. A 40-device Apple-only company does not need what a 4,000-device mixed enterprise needs, and the gap between a free tier and a quoted enterprise contract for that same fleet can be most of an annual tooling budget.

The third cost is the quietest. You deploy MDM, you get a dashboard that says 63 devices are compliant, and you treat that as the whole picture. It isn't. It's the state of the devices the system knows about, and if your register was wrong before, it is still wrong now, just behind a better interface. The audit that eventually catches this is harder than the one you would have failed before, because now there's a system that was supposed to have solved it.

There is a fourth, and it only shows up at renewal. Pricing models that looked similar at 40 devices diverge sharply at 300, particularly between per-device and per-user vendors, and a fleet that grows in phones rather than laptops moves the number in a direction nobody modelled. Ask every vendor for the figure at your projected size as well as your current one, and get both in writing, because the second number is the one you will actually be paying.

So ask the diagnostic question before the demos start. Are you solving a configuration problem, a compliance evidence problem, or a visibility problem? Those have three different answers, and only the first two are MDM.

When You Are Ready to Go Further

Start with Apple Business, before you shortlist anything. It's free, every platform depends on it, and it's the step most likely to add two weeks you didn't plan for. Verify the domain, decide the federation question, and link your reseller.

Then count honestly. Devices by platform, devices per person, how many were bought outside your normal channel. That count determines which pricing model favours you and whether the free tiers are even in scope, and it takes an afternoon.

Then trial two platforms, not five. One specialist and one cross-platform, chosen on your fleet mix rather than a feature grid. A week with each tells you more than a month of comparison tables, because the thing that separates these products is how they feel to administer, and no table captures that.

HROpsLab publishes independent comparison work across HR and IT tooling. We sell nothing, we take no vendor money, and we publish no paid placements. Every price in this guide was taken from the vendor's own pricing page, and where a vendor publishes nothing, we say so rather than estimating.


Frequently Asked Questions

What is Apple MDM software?

Apple MDM software manages Macs, iPhones and iPads through the mobile device management framework Apple builds into its operating systems, letting one administrator enroll devices, push settings and applications, enforce security policies like disk encryption, report on compliance, and remotely lock or wipe a device. Apple provides the framework rather than the product, which is why platforms like Jamf, Mosyle, Iru and Intune can all do broadly the same core things and compete instead on the console, the automation, the reporting depth and how much setup work they expect from you.

Is there genuinely free Apple MDM software?

Yes, and this category is unusual in that respect. Mosyle Business FREE covers up to 30 devices with no billing requirement and real functionality rather than a crippled demo, and Fleet publishes an open source platform you can self-host at no licence cost, though somebody still has to run the server and take backups. For an Apple-only team under 30 devices the free option may genuinely be correct, and the honest advice is to try it before paying, because the worst outcome is learning exactly which paid feature you actually need.

What happened to Kandji?

Kandji rebranded to Iru on 22 October 2025, and kandji.io now redirects to iru.com. The platform also expanded beyond Apple to manage Windows and Android devices, so it is no longer the Apple-only product most published comparisons describe. This matters when you research the category because a great deal of material still uses the old name, and you may read two reviews of what you think are different products when they are the same one.

Jamf or Intune, which should we pick?

Pick Jamf if Macs are your primary platform, the stakes are high and you have somebody to administer it properly, because its Apple depth is the deepest available and the community knowledge around it is enormous. Pick Intune if you are already standardised on Microsoft 365 and Macs are a minority of your fleet, because Intune Plan 1 capabilities come with E3 and E5 licences you may already hold, making Mac management a configuration exercise rather than a purchase. The trade is real either way: Intune's Apple support is genuinely second to its Windows support, and Mac-literate staff notice.

Do we need Apple Business as well?

Effectively yes, and it is free. Apple Business is the platform that replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect on 14 April 2026, and it is what enables automated device enrollment, letting a Mac enroll itself during first setup rather than depending on somebody installing a profile they could decline. It also handles volume app purchasing and now carries Apple's own built-in device management at no cost, which smaller fleets should try before buying anything. Setting it up involves verifying a domain, making a federation decision about your identity provider, and linking your hardware resellers, none of it difficult but all of it dependent on other people, which is why it takes longer than it looks and should be done before you shortlist platforms.

Can we manage a Mac somebody bought at a retail store?

You can manage it, but not through automated device enrollment, and that distinction matters. Devices must be purchased through Apple directly or through a reseller enrolled in the programme to appear in automated enrollment, and a machine bought retail, secondhand or on a company card in an emergency cannot be added to it afterwards. Such devices can still be enrolled with user approval, which means the user can decline, so audit how your organisation actually buys hardware before choosing a platform rather than discovering this during deployment.

Will remote wipe always work?

No, and treating it as a guarantee is the most expensive misunderstanding in this category. Remote wipe is a command placed in a queue that executes the next time the device contacts the MDM server, so for a laptop in daily use it is effectively immediate, while for one that has sat in a drawer since somebody resigned months ago the command simply waits, possibly forever. Your compliance report will show the wipe as pending indefinitely, which is why offboarding policy should treat wipe as best effort and pair it with physically recovering the device.

Does MDM replace asset management software?

No, and conflating them causes real problems during buying decisions. An MDM knows about devices that check in, so it can tell you the configuration and compliance state of machines it already knows about, but it cannot tell you about the laptop in a drawer, the one bought on expenses and never registered, what any of them cost, or whether a leaver's device actually came back. Those are asset register questions, and teams with a device-recovery problem who buy an MDM typically deploy it successfully and find the original problem completely untouched.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →