Mobile Device Management overview (2024)

  • Article
  • Applies to:
    Windows 11, ✅ Windows 10

Windows provides an enterprise management solution to help IT pros manage company security policies and business applications, while avoiding compromise of the users' privacy on their personal devices. A built-in management component can communicate with the management server.

There are two parts to the Windows management component:

  • The enrollment client, which enrolls and configures the device to communicate with the enterprise management server. For more information, see Enrollment overview.
  • The management client, which periodically synchronizes with the management server to check for updates and apply the latest policies set by IT.

Third-party MDM servers can manage Windows devices using the MDM protocol. The built-in management client is able to communicate with a third-party server proxy that supports the protocols outlined in this document to perform enterprise management tasks. The third-party server has the same consistent first-party user experience for enrollment, which also provides simplicity for Windows users. MDM servers don't need to create or download a client to manage Windows.

For details about the MDM protocols, see

  • [MS-MDE2]: Mobile Device Enrollment Protocol Version 2
  • [MS-MDM]: Mobile Device Management Protocol

MDM security baseline

Microsoft provides MDM security baselines that function like the Microsoft group policy security baseline. You can easily integrate this baseline into any MDM solution to support IT pros' operational needs, addressing security concerns for modern cloud-managed devices.

The MDM security baseline includes policies that cover the following areas:

  • Microsoft inbox security technologies (not deprecated) such as BitLocker, Windows Defender SmartScreen, Exploit Guard, Microsoft Defender Antivirus, and Firewall
  • Restricting remote access to devices
  • Setting credential requirements for passwords and PINs
  • Restricting use of legacy technology
  • Legacy technology policies that offer alternative solutions with modern technology
  • And much more

For more information about the MDM policies defined in the MDM security baseline and what Microsoft's recommended baseline policy values are, see:

  • MDM Security baseline for Windows 11
  • MDM Security baseline for Windows 10, version 2004
  • MDM Security baseline for Windows 10, version 1909
  • MDM Security baseline for Windows 10, version 1903
  • MDM Security baseline for Windows 10, version 1809

For information about the MDM policies defined in the Intune security baseline, see Windows security baseline settings for Intune.

Windows edition and licensing requirements

The following table lists the Windows editions that support Modern device management through (MDM):

Windows ProWindows EnterpriseWindows Pro Education/SEWindows Education
YesYesYesYes

Modern device management through (MDM) license entitlements are granted by the following licenses:

Windows Pro/Pro Education/SEWindows Enterprise E3Windows Enterprise E5Windows Education A3Windows Education A5
YesYesYesYesYes

For more information about Windows licensing, see Windows licensing overview.

Frequently Asked Questions

Can there be more than one MDM server to enroll and manage devices in Windows?

No. Only one MDM is allowed.

How do I set the maximum number of Microsoft Entra joined devices per user?

  1. Sign in to the portal as tenant admin: https://portal.azure.com.
  2. Navigate to Microsoft Entra ID, then Devices, and then select Device Settings.
  3. Change the number under Maximum number of devices per user.

What is dmwappushsvc?

EntryDescription
What is dmwappushsvc?It's a Windows service that ships in the Windows operating system as a part of the Windows management platform. It's used internally by the operating system as a queue for categorizing and processing all Wireless Application Protocol (WAP) messages, which include Windows management messages, and Service Indication/Service Loading (SI/SL). The service also initiates and orchestrates management sync sessions with the MDM server.
What data is handled by dmwappushsvc?It's a component handling the internal workings of the management platform and is involved in processing messages that have been received by the device remotely for management. The messages in the queue are serviced by another component that is also part of the Windows management stack to process messages. The service also routes and authenticates WAP messages received by the device to internal OS components that process them further. This service doesn't send telemetry.
How do I turn if off?The service can be stopped from the "Services" console on the device (Start > Run > services.msc) and locating Device Management Wireless Application Protocol (WAP) Push message Routing Service. However, since this service is a component part of the OS and is required for the proper functioning of the device, we strongly recommend not to disable the service. Disabling this service causes your management to fail.
Mobile Device Management overview (2024)
Top Articles
Property Tax System Basics
'The art of Zen' education resource: History of Zen Buddhism
Funny Roblox Id Codes 2023
Mybranch Becu
Where are the Best Boxing Gyms in the UK? - JD Sports
Combat level
How Much Does Dr Pol Charge To Deliver A Calf
Celebrity Extra
DEA closing 2 offices in China even as the agency struggles to stem flow of fentanyl chemicals
Mylife Cvs Login
123 Movies Black Adam
Mikayla Campinos Videos: A Deep Dive Into The Rising Star
2013 Chevy Cruze Coolant Hose Diagram
Robot or human?
2135 Royalton Road Columbia Station Oh 44028
Mid90S Common Sense Media
Stihl Km 131 R Parts Diagram
Michael Shaara Books In Order - Books In Order
Rams vs. Lions highlights: Detroit defeats Los Angeles 26-20 in overtime thriller
How to Create Your Very Own Crossword Puzzle
Wausau Obits Legacy
Aps Day Spa Evesham
Understanding Genetics
Tu Pulga Online Utah
[PDF] NAVY RESERVE PERSONNEL MANUAL - Free Download PDF
Marion City Wide Garage Sale 2023
Sorrento Gourmet Pizza Goshen Photos
Rgb Bird Flop
Kaliii - Area Codes Lyrics
Craigslist Boerne Tx
Ugly Daughter From Grown Ups
Halsted Bus Tracker
Warn Notice Va
Math Minor Umn
Why Are The French So Google Feud Answers
L'alternativa - co*cktail Bar On The Pier
Mumu Player Pokemon Go
Colin Donnell Lpsg
Flixtor Nu Not Working
SOC 100 ONL Syllabus
Maxpreps Field Hockey
Gpa Calculator Georgia Tech
Philadelphia Inquirer Obituaries This Week
Stanley Steemer Johnson City Tn
2023 Nickstory
Smite Builds Season 9
Powerspec G512
The Complete Uber Eats Delivery Driver Guide:
Jimmy John's Near Me Open
Helpers Needed At Once Bug Fables
What Are Routing Numbers And How Do You Find Them? | MoneyTransfers.com
Latest Posts
Article information

Author: Ms. Lucile Johns

Last Updated:

Views: 5697

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Ms. Lucile Johns

Birthday: 1999-11-16

Address: Suite 237 56046 Walsh Coves, West Enid, VT 46557

Phone: +59115435987187

Job: Education Supervisor

Hobby: Genealogy, Stone skipping, Skydiving, Nordic skating, Couponing, Coloring, Gardening

Introduction: My name is Ms. Lucile Johns, I am a successful, friendly, friendly, homely, adventurous, handsome, delightful person who loves writing and wants to share my knowledge and understanding with you.