Check out MSP Central: The complete IT platform for MSPs

GET ACCESS

Everything you need to deliver MDM at scale

A complete mobile device management platform built for MSPs. Manage every stage of the device lifecycle across all your client organizations from a single multi-tenant console.

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
Endpoint_Central_MSP_Features

Device Management

Manage the full device lifecycle: enroll, configure, secure, and retire devices across client organizations from one console.

background

Automated provisioning

Bring devices to a work-ready state the moment they power on with zero-touch enrollment via Apple Business Manager, Android ZTE, Samsung Knox, and Windows Autopilot across all client accounts.

Learn more →

background

Smart management policies

Define group-based and role-based device settings with reusable policy templates. Apply uniform standards across hundreds of clients or tailor rules per organization.

Learn more →

background

Device restrictions

Enforce per-client restrictions on hardware buttons, network interfaces, storage, browsers, and apps. Disable cameras, USB, and Bluetooth based on client compliance requirements.

Learn more →

background

Remote commands

Execute lock, restart, shut down, ring, and wipe commands on devices across any client account. Trigger actions manually or automatically based on compliance violations.

Learn more →

background

Contextual deprovisioning

Perform corporate or complete wipes when employees leave, devices are lost, or compliance is breached. Automate retirement actions based on predefined rules per client.

Learn more →

Device Enrollment

Enroll devices in bulk via zero-touch, QR code, or self-enrollment with two-factor authentication across all client organizations.

background

Zero-touch enrollment

Auto-enroll corporate devices via Apple Business Manager, Android Zero-Touch Enrollment, Samsung Knox, and Windows Autopilot. Devices become managed the moment they power on.

Learn more →

background

BYOD self-enrollment

Enable employees to enroll their personal devices through branded self-service portals, email invitations, or SMS links, complete with privacy disclosures and two-factor authentication.

Learn more →

background

Bulk enrollment for new clients

Rapidly onboard entire device fleets when you win a new account. Import device details via CSV and bring hundreds of endpoints under management in minutes.

Learn more →

background

Client-specific enrollment policies

Assign unique enrollment rules, authentication methods, and ownership types per client organization. Ensure each account's devices meet the right management profile from day one.

Learn more →

background

Multi-platform support

Enroll iOS, Android, Windows, macOS, Chrome OS, and tvOS devices from one unified console. Support corporate, BYOD, and shared device ownership models across all platforms.

Learn more →

App Management

Silently install, update, and remove store and in-house apps across all client organizations from one console.

background

Silent app distribution

Deploy store and in-house apps in IPA, APK, MSIX, APPX, and MSI formats. Distribute silently and automatically across client device fleets without user intervention.

Learn more →

background

App configuration & permissions

Preconfigure app settings and permissions per client before deployment. Ensure apps are production-ready the moment they land on devices with no end-user setup required.

Learn more →

background

Self-service app catalog

Curate a self-service portal per client with approved store and in-house apps. Empower employees to browse and install apps on their own, reducing support tickets for your MSP team.

Learn more →

background

Blocklist & mandate apps

Meet client compliance, productivity, and security requirements by blocking prohibited apps or mandating the presence of critical apps on all managed devices.

Learn more →

background

Managed app updates

Test updates in staging channels before mass deployment across client accounts. Silently roll out approved versions at scheduled times to minimize end-user disruption.

Learn more →

Profile Management

Create reusable profiles and policies for Wi-Fi, VPN, passcodes, and restrictions, then deploy them across client organizations.

background

Network connectivity profiles

Configure VPN, Wi-Fi, APN, proxy, and certificate settings per client. Ensure devices connect securely to the right networks from the moment they enroll.

Learn more →

background

Device restriction policies

Apply client-specific restrictions on cameras, network sharing, app installs, and USB access. Maintain compliance without impacting legitimate device functionality.

Learn more →

background

Data loss prevention policies

Disable copy/paste, screenshots, and cloud syncing between personal and corporate workspaces. Enforce granular DLP rules per client to protect sensitive data.

Learn more →

background

Web content filtering

Define client-specific website allowlists and blocklists for corporate devices. Filter malicious and non-productive content to boost security and workplace productivity.

Learn more →

background

Reusable policy templates

Build once, deploy everywhere. Create profile templates and reuse them across multiple client accounts, significantly reducing onboarding time for new clients.

Learn more →

Email Management

Configure, secure, and control corporate email on client devices with containerization, conditional access, and ActiveSync policies.

background

Automated email configuration

Push email profiles to devices during enrollment so they're inbox-ready immediately. Configure Exchange, Microsoft 365, and Google Workspace accounts per client organization.

Learn more →

background

Conditional access

Block unmanaged and non-compliant devices from accessing Exchange and Microsoft 365 mailboxes. Ensure only authorized endpoints connect to client email infrastructure.

Learn more →

background

Email data loss prevention

Restrict copy/paste, screenshots, and attachment sharing from email apps. Apply DLP policies per client to keep sensitive communications from leaking outside managed channels.

Learn more →

background

Secure email attachments

Force attachments to open in the built-in secure viewer. Prevent forwarding to unapproved apps and block downloads to unmanaged storage across client devices.

Learn more →

background

Certificate-based authentication

Enable passwordless email access with enterprise certificates and SSO. Eliminate password fatigue for end users while strengthening security across all client accounts.

Learn more →

Security Management

Enforce passcode, encryption, and device lock policies across corporate and BYOD devices to protect client data from threats.

background

Passcode & encryption enforcement

Mandate strong passcodes, biometric locks, and full-disk encryption on all client devices. Define complexity, length, and expiry rules to meet each client's security standards.

Learn more →

background

Lost device protection

Remotely lock, locate, ring, and wipe lost or stolen devices across any client account. Trigger automated actions when devices leave geo-fenced boundaries.

Learn more →

background

Jailbreak & root detection

Identify compromised devices in real time and automatically trigger compliance actions, from restricting access to corporate resources to initiating a complete wipe.

Learn more →

background

Geo-fencing

Create virtual perimeters around client offices, warehouses, or job sites. Mark devices as non-compliant and trigger security actions when they leave approved boundaries.

Learn more →

background

BYOD containerization

Separate corporate data from personal data on employee-owned devices. Manage only the work container while respecting end-user privacy across all client BYOD fleets.

Learn more →

Kiosk Mode

Lock devices to single-app or multi-app kiosk mode with custom home screens and automated lockdown policies across clients.

background

Single-app kiosk

Restrict devices to run a single designated app for dedicated use cases like POS terminals, digital signage, patient check-in kiosks, or customer feedback stations.

Learn more →

background

Multi-app kiosk

Allow access to a curated set of apps while locking down everything else. Ideal for client environments where employees need limited apps for their specific role.

Learn more →

background

Custom home screen layout

Design branded home screens with approved app icons, wallpapers, and folder arrangements per client. Deliver a consistent, distraction-free device experience.

Learn more →

background

Web kiosk & autonomous kiosk

Lock devices to specific websites or allow autonomous operation with scheduled lockdown windows. Perfect for retail displays, libraries, and interactive client installations.

Learn more →

background

Kiosk exit controls

Secure kiosk mode with password-protected exit mechanisms. Define technician-only escape codes so end users cannot break out of the locked-down environment.

Learn more →

Remote Troubleshooting

Remotely view, control, and troubleshoot client mobile devices in real time with built-in support for 25+ OEMs at no extra cost.

background

Remote view & control

Access client devices remotely and perform operations in real time. Mirror device screens, navigate apps, and resolve issues without needing physical access or end-user involvement.

Learn more →

background

Unattended remote access

Troubleshoot devices even when no end user is available. Enable unattended access for field devices, kiosks, and rugged endpoints deployed in client environments.

Learn more →

background

File transfer & chat

Transfer files to and from client devices during remote sessions. Communicate with end users via built-in messaging for real-time issue resolution and guided walkthroughs.

Learn more →

background

Multi-OEM support

Connect to devices from 25+ manufacturers including Samsung, LG, Honeywell, Zebra, and Kyocera using built-in remote capabilities. No third-party agents or licenses required.

Learn more →

background

Session recording & audit

Record every remote session for supervision, training, and audit purposes. Maintain a full trail of technician actions per client account for compliance and accountability.

Learn more →

Asset Management

Scan and track hardware details, installed apps, certificates, and compliance status across every client's device fleet.

background

Comprehensive inventory

Maintain granular asset details including installed apps, certificates, restrictions, device identifiers, and hardware specs with periodic automated scans across all client fleets.

Learn more →

background

Real-time location tracking

Monitor device locations in real time across client organizations. View location history, set up geo-fences, and locate lost devices with precision GPS tracking.

Learn more →

background

Lost & stolen device actions

Lock, reset passcodes, locate, or wipe lost and stolen devices across any client account. Activate lost mode on iOS to display custom recovery messages on the lock screen.

Learn more →

background

Automated asset reports

Generate scheduled, per-client inventory reports in PDF, CSV, or XLS. Drag and drop columns, mask PII fields, and automate delivery to client stakeholders.

Learn more →

background

Help desk integration

Surface asset data directly inside ServiceDesk Plus, ServiceNow, and Zendesk tickets. Enable technicians to perform MDM actions without leaving the help desk console.

Learn more →

Content Management

Distribute, secure, and manage corporate documents across client devices with built-in DLP and granular access controls.

background

Over-the-air document distribution

Push documents, presentations, spreadsheets, images, and media files to client devices silently over the air. Support all major file formats without requiring email or USB.

Learn more →

background

Group-based content automation

Cluster devices by client, department, or role and automatically provision the right documents. New devices added to a group instantly receive all assigned content.

Learn more →

background

Content synchronization

Update documents on the admin console and push changes instantly to all targeted devices. Ensure client employees always work with the latest approved versions.

Learn more →

background

Document security & DLP

Prevent documents from being shared, copied, or backed up to unauthorized services. Apply DLP policies per client to protect confidential business content.

Learn more →

background

Secure document viewer

View distributed content inside the built-in secure vault. No third-party apps or cloud copies needed. Revoke access remotely when employees leave or devices are retired.

Learn more →

Audit & Reports

Generate out-of-the-box and custom reports on compliance, rooted devices, blocklisted apps, and more across client fleets.

background

Out-of-the-box reports

Access pre-built reports for common scenarios: rooted/jailbroken devices, blocklisted apps, non-compliant endpoints, and inactive devices across all client organizations.

Learn more →

background

Custom report builder

Create custom reports with drag-and-drop column selection. Filter by client, device group, OS, or compliance status and export in CSV, PDF, or XLS formats.

Learn more →

background

Scheduled automated delivery

Schedule reports to run at daily, weekly, or monthly intervals and auto-deliver them to client stakeholders via email. Maintain consistent reporting cadence without manual effort.

Learn more →

background

Real-time compliance alerts

Receive instant notifications when devices across client accounts violate compliance policies: jailbreaks, unauthorized apps, encryption disabled, or inactive check-ins.

Learn more →

background

Admin audit logs

Maintain a complete record of all technician and admin actions per client account. Track who did what, when, and on which device for compliance and incident investigation.

Learn more →

Rugged Device Management

Manage the full lifecycle of ruggedized devices, AOSP endpoints, and IoT hardware across all client organizations.

background

Non-traditional enrollment

Enroll rugged and AOSP devices that lack Google Play Services using QR code, NFC bump, or zero-touch methods. Support devices from Honeywell, Zebra, Datalogic, and more.

Learn more →

background

OEMConfig for 22+ vendors

Leverage deep, vendor-specific configurations via OEMConfig for Samsung, Honeywell, Kyocera, Datalogic, Zebra, and more. No custom scripting or manual setup required.

Learn more →

background

Remote control for field devices

Troubleshoot devices deployed in warehouses, delivery routes, and factory floors remotely. Use built-in unattended access when no operator is available.

Learn more →

background

Firmware & OS update management

Schedule custom firmware updates (FOTA) during non-work hours to avoid disrupting client operations. Control OS update rollouts to prevent untested patches from reaching the field.

Learn more →

background

Rugged kiosk lockdown

Lock rugged devices to curated apps for retail, warehouse, and logistics use cases. Prevent end-users from altering device settings or accessing unauthorized functionality.

Learn more →

Shared Device Management

Configure devices shared by multiple users, delivering a fresh, personalized workspace per session across client sites.

background

Shared Apple devices

Set up Shared iPad with Managed Apple IDs or federated Entra ID credentials. Deliver personalized user sessions on iPads shared across shifts in client environments.

Learn more →

background

Shared Android devices

Enable directory-integrated sign-in on shared Android devices with automatic data purge on sign-out. Ensure each user gets a clean workspace for their shift.

Learn more →

background

User-based provisioning

Deliver different apps, configurations, and permissions based on who signs in, not which device they pick up. Tailor the experience per role across client shift workers.

Learn more →

background

Streamlined SSO sign-in

Federate with SAML-based identity providers for one-tap sign-in on shared devices. Reduce friction for frontline workers across client healthcare, retail, and logistics sites.

Learn more →

background

Automated session cleanup

Purge user data, app caches, and browsing history automatically between sessions. Guarantee a fresh device state for the next user without manual intervention.

Learn more →

Admin App

Lock, wipe, locate, and troubleshoot client devices on the go with the MDM admin app for iOS and Android.

background

Real-time fleet monitoring

Initiate device scans and view fleet health, compliance status, and enrollment stats across all client organizations, directly from your mobile phone.

Learn more →

background

Security actions on the go

Lock devices, change or clear passcodes, and activate lost mode from anywhere. Respond to security incidents immediately without needing access to a desktop console.

Learn more →

background

Device location tracking

View real-time and historical device locations across all client accounts from your phone. Locate lost devices and verify geo-fence compliance while on the move.

Learn more →

background

Remote commands

Execute restart, shut down, ring alarm, and corporate/complete wipe commands directly from the admin app. Handle critical situations from anywhere, anytime.

Learn more →

background

Command history & audit trail

Review a complete log of all remote actions issued per device. Maintain accountability and trace every technician action across client accounts from your mobile.

Learn more →

Integrations

Connect with helpdesk, analytics, and asset management tools via native connectors and REST APIs to unify MSP operations.

background

ITSM & help desk

Integrate with ServiceDesk Plus, ServiceNow, and Zendesk to execute MDM actions directly from help desk tickets. Reduce context switching and resolution time for technicians.

Learn more →

background

Analytics & reporting

Connect with Analytics Plus for AI-powered dashboards and consolidated reports across all client organizations. Gain actionable insights beyond built-in reporting.

Learn more →

background

Directory services

Sync users and groups from Active Directory, Microsoft Entra ID, Okta, Google Workspace, and Zoho Directory. Automate user provisioning and deprovisioning across client accounts.

Learn more →

background

Zero-touch enrollment platforms

Integrate with Apple Business Manager, Android Zero-Touch, Samsung Knox, and Windows Autopilot for seamless out-of-box enrollment across client device fleets.

Learn more →

background

REST APIs & webhooks

Build custom integrations with the MDM REST API. Automate device actions, pull asset data, and trigger workflows in your existing MSP tools via webhooks and API calls.

Learn more →

Manage your clients' devices while they focus on their business

Start your free 30-day trial. No credit card required.