# Shangri-La Rasa Ria centralizes control across 500+ endpoints with ManageEngine Mobile Device Manager Plus ## Key benefits ![ ](https://www.manageengine.com/products/desktop-central/case-study/images/case-study-benefits-icon-6.svg) PDPA-aligned audit and compliance reporting ![ ](https://www.manageengine.com/products/desktop-central/case-study/images/case-study-benefits-icon-25.svg) Centralized device control from a single console ![ ](https://www.manageengine.com/products/desktop-central/case-study/images/case-study-benefits-icon-19.svg) Reduced IT workload through automation Shangri-La Rasa Ria is a luxury resort based in Tuaran, Sabah on the island of Borneo in Malaysia. Shangri-La Rasa Ria’s IT team is responsible for more than 500 Windows endpoints spread across the resort. With a lean team of four members, operational efficiency and control are not optional—they are required to keep day-to-day operations running. ![shangri-la-logo](https://cdn.manageengine.com/sites/meweb/images/mobile-device-management/images/shangri-la-logo.png) **Industry** Accommodation and hospitality **Location** Tuaran, Sabah, Malaysia **Company Size** Mid-size **Competitors tried** Microsoft Intune [Download PDF](https://www.manageengine.com/sites/meweb/images/mobile-device-management/shangri-la-case-study.pdf) ## Business challenges ### No central visibility or control across the device fleet. Prior to the introduction of ManageEngine Mobile Device Manager Plus, Shangri-La’s mobile device management (MDM), including device configuration, was completely manual. The team faced challenges such as inconsistencies in security configurations, software updates, and application management, which became increasingly difficult to handle with a small team. ### Inconsistent security settings and software versions. The IT team had no single point of visibility into the state of devices across the organization, including which devices were online, what software was installed on them, or whether they were meeting baseline security standards. Identifying a lost or misplaced device required manual checking, and knowing whether a device was compliant with internal policies was largely guesswork. Because each device was manually configured, security settings and software versions varied widely, and catching those inconsistencies consumed more time as the fleet grew. ### Regulatory exposure under Malaysia’s PDPA with no audit trail. As a hospitality organization that handles guest data, Shangri-La Rasa Ria is bound by the Personal Data Protection Act (PDPA) of Malaysia. Demonstrating compliance requires documented evidence of how data is protected across devices. With no audit trail, producing that evidence was a manual and incomplete exercise. > **"Before we had proper mobile device management in place, every device was configured individually. There was no way to see the full picture from one place. Security settings were inconsistent, software versions were out of sync, and if a device was lost or misused, we had limited options to respond quickly."** > — Halim Bin Timbang, Senior IT Officer, Shangri-La Rasa Ria ## Evaluating the market The IT team evaluated ManageEngine Mobile Device Manager Plus and Microsoft Intune. After reviewing them, Mobile Device Manager Plus stood out on the factors that mattered most to a lean IT team with a wide operational footprint: | Decision factor | What it meant for Shangri-La Rasa Ria | |---|---| | Ease of use and deployment | The small IT team needed a platform that could be set up and operated without weeks of onboarding or dedicated MDM expertise. | | Automation and policy enforcement | The team needed to transform manual configuration and automate device setup, updates, and policy application. | | Application management | The team wanted to control what apps could run on which devices, push updates quietly, and block unauthorized installs from a single console. | | Compliance and audit readiness | Rather than manual record-keeping, the team required a platform with built-in audit logs and reporting to provide documented evidence of PDPA compliance. | ## Adopting Mobile Device Manager Plus Shangri-La Rasa Ria adopted Mobile Device Manager Plus for its endpoint estate, replacing a fragmented, manual approach with centralized, policy-driven device management. ### Centralized management across all sites The IT team can now see the status of all managed devices from one console, including what software is installed, whether policies are being enforced, and when devices were last active. Device inventory, configuration status, and compliance posture data are available when needed without contacting individual staff or physically visiting sites. Simplified device enrollment allows new devices to be brought under management quickly and consistently, rather than requiring hands-on IT configuration for each device. ### Kiosk mode and application restrictions Shangri-La Rasa Ria uses kiosk mode and device restriction profiles to restrict company devices to only approved business apps. Employees are not authorized to install software without approval, change device settings outside of their role, or use company devices for any purpose other than their operational role. This has cut down on the number of support requests related to configuration drift and unauthorized app installs. Because devices are set up correctly from the start and locked to their intended profile, the volume of ad hoc IT intervention has dropped significantly. > **"Kiosk mode changed how we think about device deployment. We set the policy once, lock the device to the approved apps, and it stays that way. We are not chasing down unauthorized installs or reconfiguring devices that staff have changed. That alone has made a real difference to how much time the team spends on day-to-day support."** > — Halim Bin Timbang, Senior IT Officer, Shangri-La Rasa Ria ### Geotracking and remote wipe With Mobile Device Manager Plus' geotracking functionality, the IT team now can track the location of any managed device. If a device is stolen or misplaced, the team can find it quickly, even without waiting for staff to report it. For devices that are lost, stolen, or compromised, remote lock and remote wipe capabilities give the team an immediate response option. ### Silent app deployment and OS update management App deployments and software updates across 500+ devices no longer require IT staff to touch each machine. From the central console, the team can deploy approved apps and push OS updates to the entire fleet using the App Repository and silent push capabilities. The IT team can schedule updates based on usage reports to ensure devices are up to date without disrupting day-to-day business operations. ### Security policy enforcement and PDPA compliance Mobile Device Manager Plus enforces consistent security policies on all managed devices, removing the inconsistency caused by manual configuration. Encryption settings, password requirements, Wi-Fi access controls, and application restrictions cannot be changed at the device level by end users, as these are all policy enforced. The platform maintains comprehensive audit logs for PDPA compliance, tracking device status, policy enforcement actions, app installations, and access events. Today, Shangri-La Rasa Ria can pull compliance documentation on demand from a single dashboard, rather than manually gathering records from disparate sources. ### Lower IT workload and faster response times The transition to centralized management has reduced the day-to-day burden for all areas of device management for Shangri-La Rasa Ria’s IT team. The device setup that was previously manual for each endpoint is now standardized in an enrollment process that’s faster and consistent. Remote troubleshooting through Mobile Device Manager Plus means that issues on devices at any site can be diagnosed and resolved from the central console. The team no longer needs to travel to a site or wait for a device to be brought in to identify and fix a problem. For a small team managing endpoints across the resort, that change in how support works has a direct and meaningful effect on how the team spends its time. Kiosk mode's role in preventing unauthorized app installations and configuration changes has reduced the number of support requests generated by device drift. Devices that stay in their intended state generate fewer incidents, and fewer incidents means less reactive work for the team. > **"We can now show exactly what controls are in place across every device and pull an audit report without any manual preparation. For PDPA compliance, that kind of ready documentation makes a real difference when you need to demonstrate what your organization is doing to protect guest data."** > — Halim Bin Timbang, Senior IT Officer, Shangri-La Rasa Ria ## Results and impact Since deploying ManageEngine Mobile Device Manager Plus, the IT team at Shangri-La Rasa Ria has observed continual improvements in device security, operational efficiency, and compliance-readiness. | Challenges before | Outcomes after | |---|---| | No central overview of device status, location, or configuration. | Single-console view of all 500+ managed devices, their status, installed apps, and policy compliance. | | Every device set up manually with different security settings and software versions. | Standardized enrollment and policy application ensures each device is built to the same baseline the moment it joins the fleet. | | No way to restrict app installs or prevent unauthorized use of devices. | Kiosk mode and restriction profiles lock down devices to approved apps, preventing unauthorized installs and misuse. | | No quick or safe way to respond to stolen or compromised devices. | With remote lock and remote wipe capabilities, the team can respond immediately when an incident is reported. | | App deployments and updates required manual, device-by-device effort. | Silent app push and update scheduling deploy software across the full fleet from a single console, without interrupting operations. | | PDPA compliance evidence was difficult and time-consuming to compile. | On-demand audit-ready reports and compliance dashboards are available with no manual record assembly required. | | Configuration drift and ad hoc requests placed a high workload on IT. | Automated policies minimize support ticket volume and devices stay configured without constant manual fixing. | > **"The IT workload has gone down noticeably since we deployed Mobile Device Manager Plus. Remote troubleshooting means we are not driving to sites for every issue. Devices are staying in the configuration we set for them. And when something goes wrong, we can act on it immediately from the console."** > — Halim Bin Timbang, Senior IT Officer, Shangri-La Rasa Ria ## Looking ahead Shangri-La Rasa Ria has moved from reactive, manual device management to a centralized, policy-driven model that gives the IT team genuine control over its endpoint estate. The team can now manage the fleet at a scale that would have been impossible before, with 500+ devices consistently configured, monitored, and secured from a single console. As Shangri-La Rasa Ria grows its operations and its device count increases, Mobile Device Manager Plus provides a foundation that scales. New devices can be enrolled and configured quickly, policies can be pushed to the full fleet from one place, and compliance documentation remains available at any point without preparation. ### Features ![kiosk-mode](https://www.manageengine.com/ems/images/icon/case-study-compliance.svg) Kiosk mode ![geotracking-remote-wipe](https://www.manageengine.com/ems/images/icon/case-study-remote-control.svg) Geotracking & remote wipe ![app-deployment](https://www.manageengine.com/ems/images/icon/case-study-patch-management.svg) Silent app deployment ## Results - Single-console visibility across all 500+ managed devices - Standardized enrollment and consistent security baselines - Kiosk mode and restriction profiles preventing unauthorized installs - On-demand PDPA audit-ready reports with lower IT workload ## About Mobile Device Manager Plus Mobile Device Manager Plus is available both as a standalone enterprise mobility management platform and as a core capability integrated within Endpoint Central. As a standalone solution, it serves to secure, monitor, and manage smartphones, tablets, laptops, and rugged devices across all major operating systems. When utilized within Endpoint Central, it bridges traditional desktop management and security with mobile device management into a single console through a unified agent. Recognized as a Gartner® Peer Insights™ Customers’ Choice in the Voice of the Customer for Unified Endpoint Management Tools, ManageEngine powers 30 million devices across 35,000 organizations worldwide.