# How to manage devices in isolated network using ME MDM? Last updated: July 24, 2026 Manage devices in isolated, air-gapped, offline, or closed network environments using ManageEngine MDM; environments differ by internet access and isolation level, with enrollment methods, app management, and restrictions varying by environment type. Ensure robust data protection and compliance of managed devices using ManageEngine MDM in isolated network environments such as Closed Networks, Air-Gapped Networks, Offline Device Management and Private Network Deployments. These isolated environments differ in terms of internet accessibility and levels of isolation. Accordingly the enrollment methods, app management capabilities and, restrictions for the managed devices vary across each setup. the following section provides a comparison of all these isolated network types. ## Comparison of Isolated Network Environments | | Air-Gapped Network | Offline Device Management | Closed Network | Private Network Deployment | |---|---|---|---|---| | Internet Access | None (physical separation) | None (Devices temporarily disconnected during management tasks) | Limited or None (controlled outbound access) | Has Internet, but access restricted to within the organization’s private infrastructure. | | Isolation Level | High — total physical and logical isolation | Low — temporary isolation only | Moderate — connected internally, but restricted from public access | Medium — isolated from public internet, but internal cloud or VPN-based access possible | | MDM Server (On-Premise/Cloud) | [On-Premise](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/configuring_mdmp_on_premises.html) | | [On-Premise](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/configuring_mdmp_on_premises.html) Preffered, can be cloud if Internet allowed | [On-Premise](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/configuring_mdmp_on_premises.html) or Private Cloud | | Supported Platform | Android | | Android, If the Internet is available, then iOS | | | Use Case | Defense, nuclear research, or classified environments requiring total isolation | Remote field operations, ships, or testing labs where the Internet is not available always | Government, healthcare, banking environments needing security with limited cloud dependence | Corporates maintaining private data centres or internal clouds with secure, restricted connectivity | ## Steps to Manage Devices in an Isolated Network ### Manage devices in a Network Without Internet Connection 1. Only Android devices can be managed in a Network without Internet Connection. 2. Begin the device management by Installing the Mobile Device Manager Plus on an [on-premises server](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/configuring_mdmp_on_premises.html). Ensure that all communication between devices and the MDM server happens over the intranet (LAN). 3. **Self Service app (previously ME MDM app) Settings on ME MDM Console**: Navigate to Enrollment->Android->Self Service app (previously ME MDM app). Configure the Mode of Communication and Self Service app (previously ME MDM app) distributing as described below: - For **Configure Mode of Communication** Choose "Periodic" as Communication Type. Periodic mode is an alternative to Immediate Mode and is the preferred mode of communication between the MDM server and mobile devices, when there is limited public internet access within your organization, or if there is no access to Google apps and/or services. For detailed information on Communication Types, visit our [Configure Mode of configuration](https://www.manageengine.com/mobile-device-management/help/enrollment/customize_me_mdm_app.html#Direct_Mode) guide. - For **Self Service app (previously ME MDM app) Distribution Settings** choose "Corporate Network" to proceed with the Self Service app (previously ME MDM app) distribution to the managed devices. This steps is essential because the devices will be managed in the closed network and the Self Service app (previously ME MDM app) can not be installed from the Playstore. 4. **Enrollment Methods**: For enrolling devices, follow the below enrollment methods: - Generate enrollment configurations such as [Invite Enrolments (QR codes/URL)](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_enrollment_by_email_invite.html), [Self Enrolment tokens](https://www.manageengine.com/mobile-device-management/help/enrollment/mdm_byod.html) from the MDM console to enroll and manage the devices. - Load the Enrollment Profiles using [Device Owner Provisioning using USB / Wireless Debugging](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_device_owner_provisioning_adb.html). 5. **App Management**: For managing and distributing apps in the closed network host the required enterprise apps on the Self Service app (previously ME MDM app) repository. For Hosting Enterprise Apps, refer our [Android Enterprise Apps](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html) guide. For updating the enterprise apps for Android refer our [Enterprise Android App update](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_multi_app_version_management.html#updating_android_enterprise_apps) guide. Sync devices with the internal server for app and patch updates. 6. **Profiles**: Configure the [Android Profiles](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_configuration_profiles_for_android.html) such as passcode enforcement, Wi-Fi/VPN configurations, restrictions, etc. and distribute to the managed devices or groups from the ME MDM Console. 7. **Monitor Managed Devices**: On the MD MDM Console, Navigate to Inventory and view/monitor the managed devices. Refer our [Device Information](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_viewing_device_information.html) guide for detailed information. 8. **Reports**: On the ME MDM console, Navigate to Reports to generate device usage, compliance [reports](https://www.manageengine.com/mobile-device-management/help/reports/reports.html) within the internal environment. ### Manage devices in a Network has Internet Connection 1. When the network has an Internet connection, you can manage the devices either using ManageEngine Mobile Device manager On-Premise or using the Cloud. 2. **On-Premises**: Ensure you have allowed the given [Ports](https://www.manageengine.com/mobile-device-management/faq.html?help#g1) and [Domains](https://www.manageengine.com/mobile-device-management/faq.html?help#g2) which are required for the MDM to manage the mobile devices. 3. **Enrollment**: For enrollment, use device provisioning tools such as [Apple Configurator](https://www.manageengine.com/mobile-device-management/help/enrollment/enroll_ios_devices_using_apple_configurator.html), [Samsung Knox tools](https://www.manageengine.com/mobile-device-management/help/enrollment/knox_mobile_device_management.html), or [Android Zero-touch with restricted connectivity](https://www.manageengine.com/mobile-device-management/help/enrollment/android_zero_touch_enrollment.html), etc. 4. **App Repository**: On the ME MDM console, navigate to App Mgmt->App Repository and add the required [Apps](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_app_management.html) from the Play Store or the App Store. Configure the [iOS Enterprise Apps](https://www.manageengine.com/mobile-device-management/help/app_management/ios_enterprise_app.html) and [Android Enterprise Apps](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html) as required. Once Apps are added to the App repository, distribute them to the managed devices. Visit our [Self Service app (previously ME MDM app) repository](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html) guide for the detailed information. 5. **Profiles**: To enhance the security and Compliance policies, configure the [Android](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_configuration_profiles_for_android.html) and [iOS](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_configuration_profiles.html) profiles and distribute to the managed devices. 6. **Monitor Managed Devices**: On the MD MDM Console, Navigate to Inventory and view/monitor the managed devices, refer our [Device Information](https://www.manageengine.com/mobile-device-management/help/asset_management/mdm_viewing_device_information.html) guide for detailed information. 7. **Reports**: On the ME MDM console, Navigate to Reports to generate device usage, compliance [reports](https://www.manageengine.com/mobile-device-management/help/reports/reports.html) within the internal environment. ## Frequently asked questions ### Which isolated network environments does ME MDM support? Four types are supported: Air-Gapped Networks (total physical isolation, no internet), Offline Device Management (devices temporarily disconnected during management tasks), Closed Networks (limited or no outbound internet access), and Private Network Deployments (internet available but restricted to the organization's private infrastructure). ### Can I manage iOS devices in an isolated network? Only Android devices can be managed in an air-gapped or offline network with no internet connection. iOS devices can be managed only in a Closed Network or Private Network Deployment, and only if internet access is available. ### How do I enroll devices when there's no internet connection? Use Invite Enrollments (QR codes/URL) or Self Enrollment tokens generated from the MDM console, or load enrollment profiles using Device Owner Provisioning over USB or wireless debugging. ### How can I distribute the Self Service app if devices can't reach the Play Store? Set the Self Service app distribution setting to "Corporate Network" so the app is distributed directly instead of through the Play Store, which isn't reachable in a closed network.