Microsoft Device Ecosystem Platform Overview

Microsoft Device Ecosystem Platform (MDEP) transforms the Android Open-Source Project (AOSP) into a Microsoft-powered enterprise platform for connected and specialty devices. It provides a shared, extensible foundation for collaboration, digital signage, kiosks, IoT, embedded, and emerging intelligent devices, with Microsoft security, management, reliability, and accessibility capabilities built into the platform.

Why MDEP

Connected devices are expanding beyond traditional PCs and phones into meeting rooms, digital signage, kiosks, IoT environments, embedded systems, and emerging agent-driven experiences. Android is often selected for these devices because it is flexible and adaptable. However, independently maintained Android implementations can create inconsistent security, servicing, deployment, and management experiences across an enterprise fleet.

For enterprise customers, MDEP brings familiar Microsoft identity, security, management, and lifecycle practices to specialty devices. For manufacturers and developers, it provides an extensible platform that preserves Android application compatibility and allows engineering teams to focus more investment on customer experiences instead of rebuilding core platform capabilities.

Platform value

Trusted

MDEP moves device trust from assumed, to verifiable. Hardware-backed identity, secure and verified boot, rollback protection, and Microsoft PKI-backed device attestation can provide cryptographic evidence that a device is genuine, running authorized software, and operating within an expected integrity boundary. Encrypted device-to-cloud communications extend that trust into connected services.

Enterprise grade

MDEP is built for enterprise deployment, management, and lifecycle operations. Consistent provisioning, policy, updates, diagnostics, telemetry, governance, and remote support help reduce fragmentation and operational risk across diverse device fleets.

Ready for what is next

MDEP provides a foundation for cloud-connected and AI-enabled experiences. Where supported, partners can combine on-device processing and Azure AI services with enterprise identity, authorization, device-integrity, and management controls. Capabilities and availability vary by device and scenario.

Key capabilities

MDEP integrates core platform capabilities so partners can accelerate product development, and organizations can operate devices through a more consistent enterprise model.

Capability What it enables
Device trust and security Hardware-backed identity, verified boot, device attestation, encrypted communications, and integrity verification help establish trust from silicon to cloud.
Deployment and provisioning Consistent enrollment and provisioning experiences help organizations deploy specialty devices at scale.
Unified management Integration with Microsoft Entra ID and other Microsoft services, supports familiar identity, policy, security, and management workflows.
Lifecycle operations Predictable servicing, updates, diagnostics, telemetry, and remote support help organizations operate devices throughout their lifecycle.
Accessibility Built-in support for multiple input methods, Narrator with offline text-to-speech, live captions, and translation helps partners create more inclusive experiences.
AI-ready foundation On-device processing and Azure AI services can be combined with enterprise identity, authorization, integrity, and management controls for intelligent device experiences.
Developer platform A common SDK, APIs, and integration-ready components reduce the need to rebuild core platform services and allow partners to focus on differentiated products.

Built for enterprise scenarios

MDEP is purpose-built for specialty devices that may operate continuously, serve multiple users, or run in shared and unattended spaces. These devices can connect enterprise identities, networks, cloud services, cameras, microphones, sensors, and peripherals, making platform trust and lifecycle management essential.

The platform supports a growing range of scenarios, including:

  • Collaboration and meeting-room devices
  • Digital signage and interactive displays
  • IoT and embedded devices
  • Emerging intelligent and agent-driven devices

A common platform foundation helps organizations broaden device choice without adopting a separate security, management, and servicing model for every manufacturer or device category.

Security and management

Security is designed into MDEP across development, manufacturing, deployment, operation, servicing, and retirement. The platform aligns with Microsoft's Secure Future Initiative principles of secure by design, secure by default, and secure operations, and incorporates threat modeling, security reviews, automated screening, independent testing, and red-team exercises.

MDEP uses a multilayered, continuously verified model spanning engineering systems, silicon and firmware, the operating system, identities, applications, networks, and cloud services. Hardware-backed trusted environments protect security-critical functions, while secure boot, verified boot, rollback protection, secure device identity, and attestation establish integrity signals that can inform cloud policy and access decisions where supported.

Integration with key Microsoft services helps IT administrators bring MDEP devices into familiar identity, policy, security, and management workflows. Available integrations and enforcement capabilities vary by device, service, and deployment scenario.

Predictable lifecycle support

MDEP is designed to keep devices secure and current throughout their supported lifecycle. Microsoft provides monthly sustaining and security updates, complemented by platform enhancements released multiple times each year and multi-year support for MDEP device partners. OEMs integrate and validate updates for their device-specific hardware and software and deliver approved releases to customers through over-the-air update mechanisms.

Consistent updates, diagnostics, telemetry, and remote-support capabilities help IT teams monitor device health, resolve issues, and reduce operational risk. Customers remain responsible for identity, access, network, application, compliance, and lifecycle policies in their environments.

An ecosystem for innovation

MDEP supports a growing ecosystem of original equipment manufacturers (OEMs), original design manufacturers (ODMs), software developers, and system integrators. Partners build on a shared platform contract while retaining the ability to differentiate hardware, software, and user experiences.

A common SDK, APIs, and integration-ready components for security, networking, provisioning, updates, diagnostics, and device health reduce integration complexity and accelerate time to market. MDEP is proven in production through collaboration devices and has recently expanded to additional specialty-device scenarios. Microsoft develops and secures the core platform and defines platform requirements; OEMs integrate, validate, and maintain device-specific components. This shared platform contract preserves differentiation while improving consistency across device categories and supported silicon families.

Learn more

Explore the following MDEP documentation for current platform design, security, services, operations, release information, and supported capabilities: