Mobile Device Management overview
Windows 10 and Windows 11 provide an enterprise management solution to help IT pros manage company security policies and business applications, while avoiding compromise of the users' privacy on their personal devices. A built-in management component can communicate with the management server.
There are two parts to the Windows management component:
- The enrollment client, which enrolls and configures the device to communicate with the enterprise management server.
- The management client, which periodically synchronizes with the management server to check for updates and apply the latest policies set by IT.
Third-party MDM servers can manage Windows 10 by using the MDM protocol. The built-in management client is able to communicate with a third-party server proxy that supports the protocols outlined in this document to perform enterprise management tasks. The third-party server will have the same consistent first-party user experience for enrollment, which also provides simplicity for Windows 10 users. MDM servers don't need to create or download a client to manage Windows 10. For details about the MDM protocols, see [MS-MDM]: Mobile Device Management Protocol and [MS-MDE2]: Mobile Device Enrollment Protocol Version 2.
MDM security baseline
With Windows 10, version 1809, Microsoft is also releasing a Microsoft MDM security baseline that functions like the Microsoft GP-based security baseline. You can easily integrate this baseline into any MDM to support IT pros' operational needs, addressing security concerns for modern cloud-managed devices.
The MDM security baseline includes policies that cover the following areas:
- Microsoft inbox security technology (not deprecated) such as BitLocker, Windows Defender SmartScreen, and Device Guard (virtual-based security), Exploit Guard, Microsoft Defender Antivirus, and Firewall
- Restricting remote access to devices
- Setting credential requirements for passwords and PINs
- Restricting use of legacy technology
- Legacy technology policies that offer alternative solutions with modern technology
- And much more
For more information about the MDM policies defined in the MDM security baseline and what Microsoft's recommended baseline policy values are, see:
- MDM Security baseline for Windows 11
- MDM Security baseline for Windows 10, version 2004
- MDM Security baseline for Windows 10, version 1909
- MDM Security baseline for Windows 10, version 1903
- MDM Security baseline for Windows 10, version 1809
For information about the MDM policies defined in the Intune security baseline, see Windows security baseline settings for Intune.
Learn about device enrollment
- Mobile device enrollment
- Federated authentication device enrollment
- Certificate authentication device enrollment
- On-premise authentication device enrollment
Learn about device management
- Azure Active Directory integration with MDM
- Enterprise app management
- Mobile device management (MDM) for device updates
- OMA DM protocol support
- Structure of OMA DM provisioning files
- Server requirements for OMA DM
- Enterprise settings, policies, and app management