Mobile Device Management overview (2024)

  • Article
  • Applies to:
    Windows 11, ✅ Windows 10

Windows provides an enterprise management solution to help IT pros manage company security policies and business applications, while avoiding compromise of the users' privacy on their personal devices. A built-in management component can communicate with the management server.

There are two parts to the Windows management component:

  • The enrollment client, which enrolls and configures the device to communicate with the enterprise management server. For more information, see Enrollment overview.
  • The management client, which periodically synchronizes with the management server to check for updates and apply the latest policies set by IT.

Third-party MDM servers can manage Windows devices using the MDM protocol. The built-in management client is able to communicate with a third-party server proxy that supports the protocols outlined in this document to perform enterprise management tasks. The third-party server has the same consistent first-party user experience for enrollment, which also provides simplicity for Windows users. MDM servers don't need to create or download a client to manage Windows.

For details about the MDM protocols, see

  • [MS-MDE2]: Mobile Device Enrollment Protocol Version 2
  • [MS-MDM]: Mobile Device Management Protocol

MDM security baseline

Microsoft provides MDM security baselines that function like the Microsoft group policy security baseline. You can easily integrate this baseline into any MDM solution to support IT pros' operational needs, addressing security concerns for modern cloud-managed devices.

The MDM security baseline includes policies that cover the following areas:

  • Microsoft inbox security technologies (not deprecated) such as BitLocker, Windows Defender SmartScreen, Exploit Guard, Microsoft Defender Antivirus, and Firewall
  • Restricting remote access to devices
  • Setting credential requirements for passwords and PINs
  • Restricting use of legacy technology
  • Legacy technology policies that offer alternative solutions with modern technology
  • And much more

For more information about the MDM policies defined in the MDM security baseline and what Microsoft's recommended baseline policy values are, see:

  • MDM Security baseline for Windows 11
  • MDM Security baseline for Windows 10, version 2004
  • MDM Security baseline for Windows 10, version 1909
  • MDM Security baseline for Windows 10, version 1903
  • MDM Security baseline for Windows 10, version 1809

For information about the MDM policies defined in the Intune security baseline, see Windows security baseline settings for Intune.

Windows edition and licensing requirements

The following table lists the Windows editions that support Modern device management through (MDM):

Windows ProWindows EnterpriseWindows Pro Education/SEWindows Education
YesYesYesYes

Modern device management through (MDM) license entitlements are granted by the following licenses:

Windows Pro/Pro Education/SEWindows Enterprise E3Windows Enterprise E5Windows Education A3Windows Education A5
YesYesYesYesYes

For more information about Windows licensing, see Windows licensing overview.

Frequently Asked Questions

Can there be more than one MDM server to enroll and manage devices in Windows?

No. Only one MDM is allowed.

How do I set the maximum number of Microsoft Entra joined devices per user?

  1. Sign in to the portal as tenant admin: https://portal.azure.com.
  2. Navigate to Microsoft Entra ID, then Devices, and then select Device Settings.
  3. Change the number under Maximum number of devices per user.

What is dmwappushsvc?

EntryDescription
What is dmwappushsvc?It's a Windows service that ships in the Windows operating system as a part of the Windows management platform. It's used internally by the operating system as a queue for categorizing and processing all Wireless Application Protocol (WAP) messages, which include Windows management messages, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server.
What data is handled by dmwappushsvc?It's a component handling the internal workings of the management platform and is involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further. This service doesn't send telemetry.
How do I turn if off?The service can be stopped from the "Services" console on the device (Start > Run > services.msc) and locating Device Management Wireless Application Protocol (WAP) Push message Routing Service. However, since this service is a component part of the OS and is required for the proper functioning of the device, we strongly recommend not to disable the service. Disabling this service causes your management to fail.
Mobile Device Management overview (2024)
Top Articles
WHAT'S AT THE BOTTOM OF THE DEEPEST HOLE ON EARTH?
8 perfect ways of how to tell someone they didn't get the job
Boomerang Media Group: Quality Media Solutions
Decaying Brackenhide Blanket
Skip The Games Norfolk Virginia
Top Golf 3000 Clubs
Which aspects are important in sales |#1 Prospection
Imbigswoo
B67 Bus Time
Oppenheimer Showtimes Near Cinemark Denton
Socket Exception Dunkin
Jack Daniels Pop Tarts
Bjork & Zhulkie Funeral Home Obituaries
The fabulous trio of the Miller sisters
The Banshees Of Inisherin Showtimes Near Regal Thornton Place
Buff Cookie Only Fans
Suffix With Pent Crossword Clue
Hilo Hi Craigslist
Leader Times Obituaries Liberal Ks
Straight Talk Phones With 7 Inch Screen
Dumb Money, la recensione: Paul Dano e quel film biografico sul caso GameStop
Jbf Wichita Falls
Where Is The Nearest Popeyes
Recap: Noah Syndergaard earns his first L.A. win as Dodgers sweep Cardinals
Aps Day Spa Evesham
8005607994
Kingdom Tattoo Ithaca Mi
Redfin Skagit County
Walgreens 8 Mile Dequindre
Things to do in Pearl City: Honolulu, HI Travel Guide by 10Best
Best Restaurants Ventnor
Word Trip Level 359
Chapaeva Age
Soiza Grass
Bozjan Platinum Coins
Free Robux Without Downloading Apps
Craigslist Car For Sale By Owner
SOC 100 ONL Syllabus
Alpha Asher Chapter 130
Mars Petcare 2037 American Italian Way Columbia Sc
The TBM 930 Is Another Daher Masterpiece
Adam Bartley Net Worth
Verizon Outage Cuyahoga Falls Ohio
What to Do at The 2024 Charlotte International Arts Festival | Queen City Nerve
Garland County Mugshots Today
Holzer Athena Portal
Doe mee met ons loyaliteitsprogramma | Victoria Club
York Racecourse | Racecourses.net
Rétrospective 2023 : une année culturelle de renaissances et de mutations
Zalog Forum
Latest Posts
Article information

Author: Ms. Lucile Johns

Last Updated:

Views: 5697

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Ms. Lucile Johns

Birthday: 1999-11-16

Address: Suite 237 56046 Walsh Coves, West Enid, VT 46557

Phone: +59115435987187

Job: Education Supervisor

Hobby: Genealogy, Stone skipping, Skydiving, Nordic skating, Couponing, Coloring, Gardening

Introduction: My name is Ms. Lucile Johns, I am a successful, friendly, friendly, homely, adventurous, handsome, delightful person who loves writing and wants to share my knowledge and understanding with you.