Mobile device management: a service such as Microsoft Intune controlling the settings, security and apps of enrolled devices. Intune can push Defender configuration this way using Policy CSP and OMA-URI.
Also called mobile device management.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-200SC-300AZ-802SC-401MD-102
Each book explains MDM in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Intune
Microsoft's endpoint management service, run from the cloud, covering both MDM and MAM. Conditional Access grant controls can depend on its compliance policies for devices and protection policies for apps.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Real-time streaming semantic model
Covers live-fed push, streaming and PubNub models, plus streaming dashboard tiles. Microsoft now steers people towards Real-Time Intelligence in Fabric, as these are being retired and new ones can only be made until 31 October 2027.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Cloud Solution Provider
A programme in which a Microsoft partner, not Microsoft, holds the customer relationship: it decides pricing, invoices the customer and handles first-line support. Azure reaches customers through it as an Azure plan.
- OMA-URI
When Intune has no built-in option for a setting, a custom profile can reach it by this path to the relevant Windows configuration service provider setting.
Related terms
- APNs
The Apple service Intune relies on to reach enrolled Apple devices. It requires an Apple MDM push certificate that lasts 365 days, has a 30-day grace period and has to be renewed, rather than replaced, using the Apple ID that created it.
- Config Refresh
Drift correction in Windows 11: MDM policy settings get reapplied periodically. An admin can suspend this for up to 1,440 minutes with the Pause Config Refresh remote action.
- CSP
The interface through which Windows device settings are read, changed, set or removed. Intune and other MDM services send these settings in SyncML, and a custom profile reaches them by OMA-URI.
- DDM
Apple's newer approach in which a device enforces declarations by itself and reports back on its own status. Apple is phasing out the older MDM update policies, so Intune now relies on this for software updates on macOS 14 and iOS/iPadOS 17 onwards.
- EMM
A generic, non-Microsoft label for mobile device management products. In the Knox Admin Portal, a Samsung Knox Mobile Enrollment profile names Intune as its EMM and carries the enrolment token in its Custom JSON data field.
- FileVault
Apple's whole-disk encryption for Macs. Intune manages it through the settings catalog or an endpoint security disk encryption profile, provided the Mac's MDM enrolment was user-approved.
- Group Policy analytics
Takes backups of GPOs, works out which of their settings MDM supports through a CSP, and moves the supported ones into a settings catalog policy in Intune.
- Intune Management Extension
A Windows agent that Intune deploys on its own once features such as Win32 apps, PowerShell scripts or Remediations are assigned to a device. It keeps its own check-in schedule, separate from MDM.