Which MDM is best for managing Samsung phones and future Windows laptops?

0
1
Asked By MellowPine47 On

Our company currently has no mobile device management, and the phones are essentially unmanaged. We have roughly 50–100 devices, mostly Samsung, and may want to manage Windows laptops later. Cost is important, and we do not currently have Microsoft business accounts, although we do run an Exchange environment.

I have been testing ManageEngine but have run into several problems. The interface has been difficult to navigate, and while the restriction policies seemed workable, self-enrolled devices did not consistently receive the correct applications or connect properly to the managed app store.

My biggest concern involved a personally owned Samsung and OnePlus phone enrolled with a work profile. I was able to use lost mode to lock the entire device rather than just the managed workspace. I am not sure whether this is expected behavior or whether I configured something incorrectly.

Ideally, company-owned phones should be enrolled automatically through the supplier or during setup with a QR code. After the employee signs in with the company account, the required apps and settings should be installed. Those devices need support for lost mode, remote wiping, and remote assistance.

Personally owned phones should use an invitation or QR-code enrollment and create only a managed work profile. The organization should be able to enforce an appropriate password policy, remove the work profile and its data remotely, and keep company data within the managed environment without taking control of the employee's personal device. What products or evaluation approach would you recommend?

3 Answers

Answered By BrightCedar61 On

Separate the company-owned and BYOD policies from the beginning. A company-owned phone can reasonably support full locking, lost mode, remote support, and a complete wipe. A personally owned phone should normally use Android’s work profile, where the organization controls only the work container and can remove business data without locking or wiping the personal side. If lost mode is locking the whole BYOD phone, check that the device was enrolled as a work-profile device rather than as fully managed or dedicated. Also verify that the product supports remote removal of the work profile and corporate data; downloading or backing up data to company servers is usually handled by the applications and compliance policies, not by MDM alone.

Answered By QuietHarbor8 On

Test the enrollment experience before comparing long feature lists. Enroll several devices, try both company-owned and BYOD scenarios, and verify that apps, policies, the managed app store, and account setup all work consistently. If enrollment is unreliable, the product will be frustrating every day even if its policy engine is powerful.

MellowPine47 -

That makes sense. I am currently comparing a couple of products, so I will focus on testing the complete enrollment flow rather than just checking individual features.

Answered By CopperLark29 On

For Samsung hardware, start by setting up Samsung Knox Mobile Enrollment and have your suppliers associate new purchases with it. That lets new company-owned phones automatically point to the chosen management system during initial setup instead of being treated like personal devices. For identity and app management, Google Workspace may be worth evaluating if Microsoft licensing is not available. There are other Samsung-focused options too, but check whether they support your future Windows requirements. No full MDM deployment is likely to be entirely free, so compare the total per-device cost carefully.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.