Mobile smart devices are something that employees rely on every day, but they can open up new vulnerabilities on a network.
Monitoring remote devices with a Mobile Device Management (MDM) solution is essential for managing remote devices like smartphones and tablets from one location.
MDM solutions are invaluable tools for granting administrators visibility over employee devices.
Our list includes solutions for Windows, Linux, and Mac that provide content management, OS updates, email management, and device location tracking for mobile smart devices.
Here is our list of the eleven best MDM solutions:
- ManageEngine Mobile Device Manager Plus EDITOR’S CHOICE Mobile device management solution for device management that supports Windows, Mac OS, Chrome OS, iOS, and Android. A complete enterprise device management package with both on-premises and cloud-based versions. Start the 30-day free trial.
- Kandji (FREE TRIAL) A cloud-based service that reaches out to devices through agents and specializes in Apple devices. Start a 14-day free trial.
- VMWare Workspace ONE Mobile device management solution that can configure policies for devices remotely, automatically deploy applications, and more.
- BlackBerry Unified Endpoint Management Endpoint management solution design that supports Windows 10, Mac OS, iOS, Android, and Chrome OS.
- Citrix Endpoint Management MDM solution that supports Windows 10, Mac OS, iOS, tvOS, iPadOS, Android, Android Enterprise, Chrome OS, and Citrix.
- SOTI MobiControl Endpoint management software that supports Windows XP, Windows CE, Mac OS, iOS, and Android.
- IBM MaaS360 Enterprise mobility management solution with real-time data usage monitoring, application updates, endpoint device malware detection, and more.
- Cisco Meraki Includes a container system to deliver apps to user-owned devices and also has loss protection procedures.
- Miradore Mobile Device Management A Cloud-based device manager in both free and paid versions.
- Jamf Now A cloud-based service that only manages iOS devices.
- SimplySecure A cloud-based MDM that covers iOS and Android mobile devices and portable storage.
The best MDM solutions
What should you look for in a mobile device management system for your business?
We reviewed the market for mobile device management software and analyzed tools based on the following criteria:
- An option to set up a fleet of devices in bulk
- Device tracking
- Device blocking and wiping functions
- Device performance monitoring
- Options for IoT device management
- A free trial or a free demo for a risk-free assessment opportunity
- Value for money in a system that provides a full mobile device management service at a fair price
With these selection criteria in mind, we identified a number of systems that perform onboarding, tracking, and monitoring of mobile devices.
ManageEngine Mobile Device Manager Plus is a free MDM solution that can monitor desktop computers, laptops, smartphones, and tablets. The software supports multiple operating systems including Windows, Mac OS, Chrome OS, iOS, and Android. Through the customizable dashboard you can monitor mobile smart device status, giving you complete visibility over the connected devices your employees bring to work.
- Supports Windows, Mac OS, Chrome OS, iOS, and Android.
- Remote devicecontrol
- Device scanning
- Out-of-the-box reports
The mobile asset management experience offered by ManageEngine Mobile Device Manager Plus is very comprehensive. The dashboard also enables you to view additional information on devices including device owners, installed applications, and more. You can schedule regular device scans to keep this information updated.
If there are any problems with a device you can use remote troubleshooting to take control of the device and find the root cause of the issue in real-time. The administrator can use a remote chat to communicate with the end-user of the device. The chat can also be used to issue security commands.
- Designed to work right away, features over 200 customizable widgets to build unique dashboards and reports
- Leverages autodiscovery to find, inventory, and map new devices
- Uses intelligent alerting to reduce false positives and eliminate alert fatigue across larger networks
- Supports email, SMS, and webhook for numerous alerting channels
- Integrates well in the ManageEngine ecosystem with their other products
- Is a feature-rich tool that will require a time investment to properly learn
ManageEngine Mobile Device Manager is recommended to enterprises who want a free mobile device management solution. The software’s free for up to 25 devices. ManageEngine Mobile Device Manager Plus is available on-premises (for Windows) and in the cloud. For pricing information, you must request a personalized quote from the company directly. You can download the 30-day free trial.
ManageEngine Mobile Device Manager Plus is a complete enterprise mobile management package that comes in both on-premises and cloud-based versions. Include a configuration manager for single or mass device set up and there is also a self-enrollment app that you can use for your device enrollment program. You can also set different policies for business-owned and user-owned devices.
Get 30 Day Free Trial: manageengine.com/mobile-device-management/
OS: Windows 7 or higher, Windows Server 2008 or higher
Kandji.io specializes in the management of Apple devices. This includes desktop Macs and mobile devices. The fleet management features in the package include onboarding systems and update management.
- Macs and mobile devices
- Onboarding features
- Data privacy standards compliance
The setup for a group of devices is planned in a system called Blueprints. You can create the same Blueprints for different models of mobile devices because the features that you include in one of these plans relate to the applications and access rights, which sit on top of the operating system and aren’t hardware dependent. You don’t have to apply the same Blueprint to all devices, so you can create different plans for different groups of users.
User accounts can be acquired from third-party apps, so you can import the accounts that you have already set up in systems, such as Slack or Okta. This allows you to easily create a single sign-on environment for all of your mobile devices, also coordinating access rights to on-premises Macs.
- Integrates with third-party systems to create a single sign-on environment
- Allows the creation of Blueprints, which are software profiles for groups of devices
- Lets users switch between on-premises Macs and mobile devices
- Automated the update of software and operating systems
- Won’t manage devices running Windows, Linux, or Android.
You set up an account on the Kadji website and then download an agent onto each of the devices that you enroll in the service, so there are both cloud and on-device elements to this system. The starting price for the package is $399 per month for up to 100 devices. You can get a 14-day free trial, which starts with a system demo to assess the Kandji service.
VMWare Workspace ONE is a mobile device management tool that can be used to remotely manage devices. With VMWare Workspace One you can configure devices in bulk with the Apple Device Enrollment Program, Know Mobile Enrollment, and Android zero-touch enrolment.
- Configure devices on bulk
- Automatically deploy applications
- Use onboarding workflow to add new devices
To manage devices, you can configure policies that determine restrictions and assign them to devices. You can distinguish between devices and assign them based on the operating system or ownership type. Ownership types are divided into BYO (Bring Your Own) and corporate-owned so you can tell which devices are company-owned and which are owned by employees.
The platform also enables you to automatically push applications to devices. This means you can purchase applications in bulk and deploy them efficiently without wasting any time. When it comes to adding new devices, users can enter credentials into an onboarding workflow to join the management solution.
- Supports platforms like Apple Enrollment as well as Android Zero Touch
- Great for both managed devices as well as BYOD environments
- Can build workflows and policies with little platform knowledge
- Can take some time to explore the product
VMWare Workspace ONE is suitable for enterprises of all sizes and comes with a range of pricing options, due to its seven editions. Prices start at $1.66 (£1.33) per device and $3.00 (£2.40) per user. You can try the 30-day free trial to manage up to 100 devices.
Workspace One is a cloud-based service and you can get a 30-day free trial.
BlackBerry Unified Endpoint Management is an endpoint management solution designed for monitoring the Internet of Things (IoT) devices. Through one centralized user interface, you can view an overview of devices, users, and applications in use throughout your network. The tool supports operating systems including Windows 10, Mac OS, iOS, Android, and Chrome OS.
- Manage device policies
- Supports iOS, Android, Chrome OS, Windows, and Mac OS
- Activate uses with a QR code (iOS and Android only)
- Available on-Premises and in the cloud
Managing policies with BlackBerry Unified Endpoint Management is very easy. You can manage policies, users, groups, and applications from the console. Tasks you can complete including assigning apps to user accounts, distributing applications to containers, and configuring native apps.
Onboarding new users is also incredibly efficient, with the option to activate new devices via QR code for iOS and Android users. Groups can also be linked with Active Directory to automatically onboard new users. There is also the option to set aside work activities from personal ones with multiple activation types such as Work and Personal devices and Work Only.
- Sleek highly customizable interface
- Cross platform support with Windows, Mac OS, Linux, Android and iOS
- Available on premise and as a cloud service
- Would like to see more options for mobile security
- Better suited for enterprise networks
BlackBerry Unified Endpoint Management is a solid MDM solution that’s available on-premises and in the cloud. To view the pricing information you need to request a quote from the sales team directly. You can start the free trial.
Citrix Endpoint Management is one of the top MDM solutions that enable users to monitor devices, applications, and platforms from one console. With Citrix Endpoint Management you can monitor Windows 10, Mac OS, iOS, tvOS, iPadOS, Android, Android Enterprise, Chrome OS, and Citrix.
- Remote monitoring & device management
- Machine learning and Analytics
- Integrations with Azure Active Directory and Okta
The software has been built to assist the user in monitoring user behavior. Citrix Endpoint Management uses user context controls based on role, location, or device to ensure that sensitive data isn’t compromised. The solution is intelligent, with machine learning and analytics to help identify high-risk user behavior.
- Supports a wide range of monitoring environments from Windows 10 to Citrix
- Monitors user behavior to identify insider threats and block high-risk users proactively
- Best suited for large environments that have to support multiple types of devices
- Better suited for enterprise networks
Citrix Endpoint Management is worth considering at if you’re looking for cross-platform device management, with compatibility with Citrix infrastructure. To view pricing information you need to contact the sales team directly for a quote. You can request a demo.
SOTI MobiControl is an endpoint management solution that can monitor devices from over 170 vendors in one location. Devices supported by SOTI MobiControl include Windows XP, Windows CE, Mac OS, iOS, and Android.
- Remote viewing
- Remote control
- Integrations with Apple DEP, Android zero-touch enrolment, Samsung KME, Windows Autopilot, and Zebra StageNow
- Use scripts to execute management actions
When monitoring devices users can choose between remote viewing or remote control to take control of devices for a more hands-on approach to performance issues. There is also a chat that enables the administrator to communicate with the end-user of the device.
The software can also be used for mobile content management to secure files and web content. Through the SOTI Hub app, you can upload Microsoft Office files and determine which users have access to the resources. The application is very useful for managing access to files to ensure that only relevant employees can view sensitive information.
The application management capabilities of SOTI MobiControl are also very useful. Administrators can control what applications are permitted through blacklists and whitelists. Blacklisting non-work applications help ensure that teams stay productive.
- Supports over 170 different vendor devices
- Allows technicians to manage devices and even remotely control them
- Supports access auditing
- Best suited for MSPs and larger networks
SOTI MobiControl is recommended for teams looking for MDM solutions with clear connected visibility with remote control capabilities. However, you must request pricing information from the company directly. You can start the 30-day free trial.
IBM MaaS360 is an enterprise mobility management solution that supports Windows, Mac OS, Android, and iOS devices. With IBM MaaS360 you can monitor the data usage of devices in real-time and deploy updates to mobile applications from one centralized location. Application updates can be deployed to Windows and Mac OS devices for apps like Java, Adobe, Flash, Apple iTunes, and more.
- Real-time data usage monitoring
- Malware detection and remediation
- 24/7/365 customer support
- Single sign-on to web and cloud apps
The device security features included with IBM MaaS360 are one of its greatest assets. The device platform can detect and remediate malware on endpoints. Being able to detect malware on devices provides you with an extra layer of mobile security that helps prevent endpoints from being compromised and putting your data at risk.
If you’re looking to monitor IoT devices then IBM MaaS360 is a natural choice. The platform can monitor Google Android, Android Things, Microsoft Windows 10, and Windows IoT devices to deploy security policies to protect the devices from causing security risks.
- Built with enterprises in mind
- Good fit for those looking to monitor IoT devices
- Can detect and defend against malware
- Best suited for MSPs and larger networks
IBM MaaS360 is one of the easiest to use tools on this list, with a high-quality console for managing devices that would suit the needs of enterprises of all sizes. IBM MaaS360 pricing starts at $4 (£3.25) per device per month and $8 (£6.50) per user per month. You can start the 30-day free trial.
Cisco Meraki covers the management of laptops and desktops as well as smartphones and tablets. This management console of this system is very attractive and includes a map showing the locations of all of your company’s managed devices. However, it can’t manage IoT or wifi-enabled office equipment, such as printers. It will communicate with devices running Windows, macOS, Windows Phone, iOS, Android, Chrome OS and Samsung Knox.
Underpinning the MDM is a secure communication channel that is encrypted by AES with a 256-bit key. The app communication is protected by a VPN, which is applied on a per-app basis.
Configuration can be varied according to device type, user profile, or ownership model. These groups of devices can be configured in bulk, but there is always the possibility of individual configuration. Users with their own devices can enroll to get included in the network. The delivery method for apps and data files is called Backpack. The central administrator creates a bundle of files and then sends out access permissions to groups, individuals, or the entire network. These bundles will go out to user-owned devices once they have enrolled and been included in a user group.
Lost or stolen mobile phones can have all of their rights revoked and can be locked or wiped remotely. Meraki automatically tracks mobile plan usage, so excessive activity can be identified from live reports and stolen devices can be cut off from the phone and data services immediately.
- Protects communications with AES-256 bit encryption
- Supports BYOD enrollment
- Supports remote wipes for stolen devices
- Would like to see better data visualizations
- Does not support IoT devices
Related post: Best Cisco Network Monitoring Tools
The Miradore Mobile Device Management package is an online service and it is free of charge. Miradore actually has three levels of service, with the two higher plans available for a fee. Those paid plans consist of the Business Edition, which costs $1 per device, and the Enterprise Edition, which costs $2 per device. All plans can manage Windows 10 and macOS computers and mobile devices running iOS and Android.
With the free MDM you get just about all of the device security features available on all Miradore plans. These include end-to-end encryption and remote control functions. Those remote access functions allow you to lock or wipe a lost device, reset its password, or even bypass any hardware password set by the user. You can make the device sound an alarm, which is useful to help a user to locate a misplaced device or to deter a thief.
A map in the dashboard shows exactly where all of your devices are located. The device can send notifications of any status changes to the control console.
The configuration process with Miradore is enrollment-based. That is, you don’t configure all the devices, but you invite each user to set up the device with the Miradore client to access your network. Those configurations can include secure email apps, wifi protection, and a VPN service. The VPN is only available for iOS devices.
If you want to include mobile application management, sign up for the enterprise plan. Containerization, which partitions user-owned devices to only allow company-approved apps access to business resources, is reserved for the Enterprise plan. The creation of business policies to enforce different usage procedures according to device type/ownership is only available with the Enterprise package.
A lot of functionality included with the standard plans of the other MDMs in this list are reserved for Mirador’s most expensive package. However, even the most expensive Miradore plan with all the MAM and security extras of the other plans is still one of the cheapest options on this list.
- Offers three flexible pricing options
- Encrypts communications via VPN
- Provides security features as an add on
- Offers a wide range of features that can take time to fully explore
Jamf Now is a mobile device management system that only controls iOS devices. This is a cloud-based system that is priced per device. The service is free for the first three devices.
The setup process for devices revolves around “blueprints.” Each blueprint represents a standard configuration. You can create groups of devices and allocate a different blueprint to each. Configuration of those groups of devices can then be commanded, setting up all of them in bulk.
An alternative method for device inclusion is the enrolment process. This requires a device owner to create an account for the network by accessing a custom enrollment page. Once signup is complete, the configuration of the device initiates, giving user-owned devices the same level of security accorded to business-owned devices.
Remote monitoring of devices can be automated, giving you alerts when risk conditions occur, such as jailbreaking or the installation of unauthorized software. It is possible to display a full inventory of devices on your network in the dashboard. Details include spare storage capacity, a list of installed apps, and the serial number of the device.
Each device can be given a passcode centrally, and it is possible to use two-factor authentication with Jamf Now. You can activate a lost mode, which will lock the device and cause it to signal you its location. You can also wipe devices remotely.
- Leverages a sleek and intuitive dashboard interface
- Uses playbooks and blueprints to templatize device policies
- Can recover lost devices and secure them from data theft
- Only supports iOS devices
Jamf Now is an interesting system and the free service for three devices is very tempting for sole traders, partnerships, and startups on a tight budget. The limitation of the service to just iOS devices may make this option too limited for your business.
SimplySecure is a cloud-based MDM capable of dealing with iOS and Android mobile devices and portable storage. The overall service is called the SimplySecure Management System and it can cover desktops, laptops, mobile devices, and USB storage in these different pricing categories. Simply pay for each device you want to manage. However, the service is charged on a yearly basis, not per month. If you want a monthly price you have to track down a Simply Secure reseller and buy the service from there.
The dashboard for the service is accessed via web browser. Configure your mobile devices remotely and in bulk, applying different policies to groups of devices. Lost devices can be wiped remotely and devices that display suspicious activity can be quarantined.
The service includes device location tracking and you can enforce password protection to add an extra layer of security in case they get mislaid. You may change those passwords remotely to create an instant lock in case of trouble.
All communications within your company network are protected by encryption. Although direct access to apps over the cloud would not be covered by this protection, you can route access through your company server to get the security layer applied to app and data access. Encryption can also be applied to stored data on the device.
This is a lightweight option for small businesses and the delivery by cloud means you don’t have to run a large network or employ a systems administrator to use this service. The ability to include USB memory into the coverage is unique and applies encryption that only you and your employees can decrypt. This is a great solution to the problem of losing confidential data along with a lost USB memory device.
- Supports PCS, laptops, and mobile devices
- Management is accessible via the web browser
- Can alert administrators to suspicious activity
- Better suited for smaller networks
Choosing the right mobile device management system
The growth of mobile device usage and the steady push towards IoT devices has changed the reality of network monitoring. Monitoring mobile devices is now just as important as managing computers. MDM software solutions make the remote network monitoring process easier by allowing one location to monitor all the devices throughout your network.
Our editor’s choice for this article is ManageEngine Mobile Device Manager Plus because it supports enterprises with an easy-to-navigate user interface and a free package. Other choices like AirWatch Workspace ONE and BlackBerry Unified Endpoint Management are also standout alternatives.
Taking a proactive approach to monitoring mobile devices allows you to eliminate potential entry points to your network and keep your data safe. If you’re not already monitoring mobile devices consider investing in a solution.
Mobile Device Management (MDM) Solutions FAQs
Are MDM tools compatible with all types of mobile devices?
The important factor for compatibility between MDM systems and mobile devices is their operating system and not their device type. An MDM that can manage Android devices can interact with smartphones and tablets alike. This is because the command set that the MDM uses to manage devices is operating system dependent.
Why do very few people know about Mobile Device Management?
Mobile devices are thought of as personal property that moves around with the user and MDM software is a corporate service. Many businesses focus on fixed equipment that accesses their network from within their building and don’t realize that the mobile devices that they own can be used to gain access to their data. Businesses are now realizing that they have the right to control any device that uses their network resources even if they are owned by the people that use them.
Will my employees know if we use mobile device management on their phones?
If the phones are owned by the business, the MDM endpoint software that includes tracking, locking, and wiping utilities will already be installed when they are issued to the employee. So, the presence of MDM controls is not obvious. However, it is a good practice to make a usage agreement with the employee before handing over the phone and that should detail permitted usage, rights, and obligations. When a user-owned device is added to the corporate network, the user will need to install an app and that process will include a consent screen that needs to be agreed to before the access software is loaded. This will include details of what the business can do with the employee’s phone.