Mobile Device Management tools (MDM tools) provide an automated method to manage mobile devices that are owned by your business and also those user-owned devices that you want to allow to access your network.
Some MDM tools are integrated into full Unified Endpoint Management (UEM) service that can also manage desktop setups. As the use of mobile devices for system access by employees out in the field increases, MDM software becomes more important for most businesses. This is not just an extra system management tool that only interests large corporations; small businesses and startups need MDM software as well.
Here is our list of the eight best MDM software tools:
- N-able N-central EDITOR’S CHOICE A suite of system administration tools for IT departments and managed service providers that includes a mobile device management module. Suitable for both company equipment and user-owned devices, this MDM system installs on a bare metal server. Start a 30-day free trial.
- ManageEngine Mobile Device Manager Plus (FREE TRIAL) Manages Windows, macOS, Chrome OS, iOS, and Android mobile devices. It is available for installation on-premises or as a cloud service.
- Citrix Endpoint Management MDM tool that supports devices running Windows, macOS, iOS, tvOS, iPadOS, Android, Android Enterprise, Chrome OS, and Citrix.
- SOTI MobiControl Onboarding, secure access, and content delivery to devices running Windows XP, Windows CE, macOS, iOS, and Android.
- VMWare Workspace ONE Creates a virtual app set for mobile devices that can be removed instantly.
- BlackBerry Unified Endpoint Management Endpoint management software that covers desktops and mobile devices.
- IBM MaaS360 A cloud-based enterprise mobility management (EMM) solution that manages desktops, mobile devices, and IoT equipment.
- Cisco Meraki A cloud-based service that creates secure, containerized applications and data access for mobile devices.
Businesses that are run by a lead consultant and see most of their workers permanently at client sites need MDM tools more than they need network monitoring systems. Lightweight businesses that operate as a virtual office can use MDM software to manage access by remote workers as a replacement for the office network. As many of the best MDM tools are cloud-based, these services can be used as the entire IT infrastructure for a distributed business model.
The Best MDM Software Tools
Given the wide range of business cases that MDM serves, we have built a list of MDM software that should cater to all needs.
N-able N-central is a Remote Monitoring and Management suite (RMM) that can be used by an IT department to monitor several sites or by a Managed Service Provider (MSP) to provide support to clients.
One of the tools in the RMM bundle is an MDM software package. It’s capable of managing Bring Your Own Device (BYOD) environments as well as corporate fleets of mobile devices. The MDM tool manages the entire lifecycle of mobile usage for access to corporate facilities.
The first facility you will need in the MDM software is its onboarding system. This enables you to create a standard device configuration that can be rolled out en masse or applied to a single new device. The service can be set up as an invitation that allows an authorized user to access the onboarding procedure when convenient. It is also possible for a systems administrator to set up a device manually through the MDM tool.
During the device’s service life, the MDM software provides device location tracking, application control for corporate devices, remote security management, locking, and wiping. Reporting functions provide per device activity and resource utilization records.
N-able N-central is delivered for on-premises installation. The MDM software has a modified version of CentOS Linux included in it, so it installs on a bare metal server. You can get a 30-day free trial of N-central, which also includes network and endpoint management and security systems.
N-able N-central is our top pick for an MDM tool. It comes as part of a bundle of system management software. As well as onboarding, tracking, and controlling mobile devices, N-central includes network management, patch management, backup and restore, network topology mapping, Endpoint Detection and Response (EDR), anti-virus software, and remote access systems.
Get a 30-day free trial: n-able.com/products/n-central/trial
Operating system: Bare metal server
The Mobile Device Manager Plus system from ManageEngine is a standalone MDM tool that can also be integrated with other infrastructure management modules that are available from the vendor. This MDM software enables the management of mobile devices running Windows, macOS, Chrome OS, iOS, and Android.
The Mobile Device Manager Plus offers a very comprehensive choice of mobile management strategies. These include containerized delivery for user-owned devices, mobile content management strategies that track access to files through mobile devices and prevent unauthorized copies. It also provides device tracking, and security management facilities, such as remote locking, wiping, and PIN management, and app management and control.
Security features extend to connection policies. It is possible to enforce VPN usage by installing a VPN system that has a kill switch to prevent unprotected connections. It is also possible to limit the list of WiFi systems that the device is permitted to connect to. The MDM tool includes its own secure email server, clients, and delivery system.
The MDM tool includes mass automated setup or individual on-demand enrolling and it also allows remote access for manual configuration or troubleshooting by technicians. MDM software is able to manage laptops, smartphones, and tablets.
ManageEngine Mobile Device Manager Plus is available for on-premises installation on Windows or it can be accessed as a cloud service. Both versions can be accessed on a 30-day free trial.
Citrix Endpoint Management is a total unified endpoint management solution. It integrates an MDM tool, called XenMobile, which used to be marketed separately by Citrix. The mobile device management features of this endpoint management system provide the tools to implement a wide range of mobile access strategies, including BYOD.
The total endpoint management system covers desktops, laptops, tablets, and smartphones. It can communicate with the Windows 10, macOS, iOS, tvOS, iPadOS, Android, Android Enterprise, Chrome OS, and Citrix operating systems.
As it is a Citrix product, the MDM tool is particularly adept at implementing virtualizations, enabling companies to use a thin-client architecture that enables each user to log in to any device and get the same desktop and file storage access. The thin-client model is just one option for systems administrators with this MDM tool.
Apps and data access can be set up to follow the user or stick to the device. Such flexibility in access methods creates security weaknesses as it allows external access from any location or device. To combat this, Citrix Endpoint Management includes an AI-based user behavior modeling system. This is able to identify genuine users and spot compromised accounts being used by intruders.
Under a managed device scenario, administrators are able to enroll, patch, and manage all types of devices. The service includes remote access for troubleshooting, location tracking, remote locking, and wiping. Apps can be delivered to BYOD devices in a containerized form of virtualization enabling complete separation of corporate access rights and data from the user’s own device.
SOTI MobiControl is a full support system for mobile devices as well as an MDM tool. It includes help technician facilities such as remote desktop and remote access for troubleshooting and bug fixing. With the MobiControl MDM software, systems administrators can watch over devices running Windows XP, Windows CE, Mac OS, iOS, and Android.
The SOTI system includes a range of pre-configured channels for delivering content to mobile devices. It isn’t necessary to configure the entire device and it isn’t even necessary to give mobile device users full access to the corporate system. A facility called SOTI Xtreme Hub enables administrators to make files available for sharing over mobile devices. Version control and control over actions, such as editing and copying are also built-in.
The SOTI Xtreme Hub app can also enable access to intranet facilities that deliver services to employees on mobile devices without giving them full system access. This is an application management service that can allocate a set menu of apps to different groups, individual users, or device types. Company-owned devices can be controlled to block users from installing their own apps and the service can also block access to BYOD device owners if they already have a banned app on their phone, tablet, or laptop.
Other features of SOTI MobiControl include rapid onboarding and self-service enrollment by invitation and security features, such as tracking, locking, and wiping. The SOTI MDM software installs on Windows Server. You can experience SOTI MobiControl on a 30-day free trial.
Like Citrix, VMWare is a leader in virtualization, so it is a strong rival in the field of thin-client solutions for mobile device access. Workspace ONE is a unified endpoint management system, so it includes desktops as well as laptops, smartphones, and tablets.
The Workspace ONE MDM tool offers a virtual desktop to all users, across devices. This standardizes user access across devices. All data and apps are really held on a central server and only a view of the desktop is transmitted to the user. VMWare Workspace One can be accessed from Windows, macOS, iOS, and Android devices.
Onboarding is very simple with the virtualization model. The systems administrator just has to create an image of a standard desktop and then grant access to it to each new user. The user installs a portal on the mobile device, which connects to the VM on the server. If a device gets lost or stolen, the administrator simply blocks access to the user profile from that device – there are no passwords or files resident on the remote equipment.
The MDM tool includes security procedures that track the regular devices used to access the system per account and blocks access to any unexpected device in an illogical location.
VMWare Workspace ONE is a cloud-based service and is charged for by subscription per device per month. You can try it on a 30-day free trial.
BlackBerry Unified Endpoint Management covers desktops, laptops, tablets, and smartphones. Managed devices can be running Windows 10, macOS, Chrome OS, iOS, or Android. This MDM tool is also able to manage IoT devices.
BlackBerry gives its users of this MDM software three deployment options: installation on Windows Server, a cloud service, or a software implementation to be hosted on AWS. In each case, the dashboard is accessed through a web browser. It is possible to access the dashboard from anywhere and the devices registered in the MDM tool can be tracked wherever they are in the world.
The management console enables the creation of standard policies and software applications to a group of users, an individual user, or device type. Authorized users of mobile devices initiate access to the service by scanning a QR code. The authorization system can be linked to Active Directory.
BlackBerry UEM allows settings for user-owned devices and the possibility of corporate users switching to personal use. However, there is also the option to jam the device so that it can only host authorized apps. All resource usage on the device is logged.
BlackBerry offers the UEM system for a free trial.
IBM MaaS360 is a cloud-based MDM tool that includes constant usage monitoring of all enrolled devices. This MDM software is hosted in the cloud, so the service bundles processes to run the system and storage space for log data along with the software.
The MaaS360 MDM tool is able to manage laptops, tablets, and smartphones running Windows, macOS, Android, and iOS, plus IoT platforms. All enrolled devices are managed from the dashboard. The settings of those devices are standardized through the creation of policies and group profiles. Once a template has been set up, it can be rolled out to new devices en masse to be acquired through an enrollment process.
The underlying technology of the IBM MaaS360 system relies on containerization. The business apps and data on a device are kept shielded from the operating system of the phone. This is very similar to the virtualization service offered by Citrix and VMWare in their MDM tools. The result of this isolation is that apps and data are very easy to remove should a device get stolen or lost. Getting access to the device does not give access to the menu of corporate access apps.
The management features of this MDM software keep track of the latest available versions of operating systems and software and updates all devices once patches and updates become available. The service also includes malware detection and removal.
The service is charged for by subscription with a rate per user per month. You can explore the system on a 30-day free trial.
Cisco Meraki is a cloud-based service that, like IBM MaaS360, delivers apps to mobile devices through containerization. Users do not get direct access to the corporate system and there are no traces of the connections to be found on the mobile device outside of the company app locker.
Meraki is a UEM and not just an MDM tool – it covers desktop computers as well as laptops, tablets, and smartphones. It manages devices running Windows, macOS, Windows Mobile, iOS, Android, Chrome OS, and Samsung Knox. All communications between the app server and mobile devices are protected by a VPN.
The console is accessed through any standard browser and so is available from anywhere in the world. The screens are attractive and include eye-catching graphics, such as a real-world map that shows the current locations of all enrolled devices.
The systems administrator sets up a series of profiles that serve as a standard configuration with a menu of approved apps. Profiles can be created per device type, per user group, or per individual. A profile can be assigned to one or many devices and rolled out automatically. Meraki also provides a self-enrollment template so that invited users can connect with their own devices.
Each device can be tracked, locked, and wiped through the console and the Meraki service is also able to detect and block unauthorized apps on an enrolled device.
Cisco offers a 14-day free trial of the Meraki MDM software.
Choosing MDM Software
The selection of MDM software starts with a clear knowledge of the business’s operating structure. Not all MDM tools offer the same set of facilities. A unified endpoint management (UEM) system that combines desktop and mobile management might be suitable for businesses that are centered on an office, while an MDM-only approach would be better for businesses that do not have premises.
You might already have a network management system that you are happy with. You may be seeking only to buy a mobile-only management solution to add to that or you might be interested in scrapping all of your current IT infrastructure management systems and starting over.