Desktop Central Architecture

ManageEngine Desktop Central, in addition to managing desktops and servers, also supports managing your Mobile Devices from a central point. It allows you to perform Policy Management, Profile Management, Asset Management, App Management and Security Management of mobile devices.

Desktop Central MDM Architecture

Figure 1: MDM Architecture of Desktop Central


The advantages of using the MDM architecture of Desktop Central include the following:

  • Agentless, Over-the-Air (OTA) Management
  • Uses Apple's Push Notification Service/ Android GcM for communication
  • Profiles and Policies gets deployed immediately
  • All communications to and from the mobile device is secured.


  1. Any communication from Desktop Central to the device is routed through Apple Push Notification service (APNs) via TCP port 2195 for iOS devices and through GCM via TCP port 80 for Android Devices
  2. As per Apple IOS MDM protocol, all iOS devices maintain a dedicated TCP connection with APNs at TCP Port 5223. Destkop Central leverages this to wake up a device using APNs.
  3. Device communicates with Desktop Central Server for available instructions at port 8383 using a secured connection.
  4. Executes the instructions and reports back to Desktop Central Server with the status/data at port 8383 securely.

For the above setup to work, the following should be done

  • Assuming users' mobility, Desktop Central Server should be reachable via public IP address. You should NAT your internal IP of Desktop Central Server to a public IP to enable this. If all the devices managed are within the LAN, this requirement is not needed.

Ports Details

TCP Ports that needs to be opened at Desktop Central Server

8383 - Used for secured communication between the agent and the Desktop Central

TCP Ports that needs to be opened for managing iOS devices

2195 - Should be open for the Desktop Central Server to reach the APNs. Host address:

5223 - If the mobile device connects to the internet through the WiFi, then this
port should be opened. For better security, you can restrict these connections on
the IP range If all the managed devices have access to cellular data
network, this requirement is not needed.

TCP Ports that needs to be opened for managing Android devices

443 - Used for secured communication between the Desktop Central server and the GCM

Port numbers 5228, 5229, 5230 should be open on the fire wall, If the mobile device
connects to the internet through WiFi. This enables communication between the mobile
devices and the GCM.