Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can one do this as an individual as well?


If you have an Apple device enrolled in Find My you can remote wipe it.


Cisco had their Meraki MDM free for small numbers of devices - but that was a while ago and I'm not sure if they still offer it. Was only compatible with I believe Samsung phones as they had the best hardware security built in (KNOX?). Apple phones required (still do?) a Mac in order to deploy specific certificates to devices to enroll in MDM as well.


These days Android MDM has changed a lot.

In the 'old' days, there was an app called device admin which would control the phone. This app would be supplied by the MDM vendor. This could leverage APIs from various vendors. Samsung had Knox but almost every phone vendor had their own plugin.

This was a huge PITA because each MDM feature only worked on manufacturers A and B and very often was limited to OS versions Y and Z. It meant we had to validate each phone and OS version and have a long list of what phones people could and couldn't use. It was a nightmare as an admin. Users hated it because they often only found out after they'd bought the phone. Samsung was indeed one of the best here, I have to agree.

Since then Google has thrown this overboard and started afresh with Android Enterprise. Controlled only by Google, and offering new ways of management like the work profile which is basically a kind of "phone inside a phone". Have your work profile managed by work and the rest of your phone to yourself.

For company-owned phones they also still have more comprehensive management options like COBO and COPE. But as long as the phone supports Android Enterprise, it supports everything.

Sadly some vendors in particular Samsung are fighting this approach because they feel they have invested too much in the old method. For example Samsung won't support Google Zero Touch auto-enrolment, having instead their own alternative Knox Mobile Enrolment. This is again making things more difficult for admins. But because Samsung is such a big party, and KME is free, we have gone for it anyway (Also Google Zero Touch is not available very widely yet, each reseller has to support it)

As an Admin I'm glad to see the end of the old management model. It's deprecated as of Android 11 (and already severely limited in 10) but we've already dropped it altogether.

And no, for managing Apple phones you don't need a Mac. You just need this for manual installation of management profiles, if you use an MDM you don't need it.

However if you want to manually supervise phones (instead of using Apple DEP / or Automated Device Enrolment as they call it now), you do need one. But this is really rare now.


For iOS you can use Apple Configurator for profile-based M2M. For remote management you need a server-based solution and I believe there's an open-source implementation of that out there.


Yep it's called MicroMDM.

https://micromdm.io/

Only supports Apple though! Not Android.


There’s a handful of others, including some that support both platforms


Oh which? I haven't heard of others, MicroMDM is fairly common, even used by some smaller companies.

I'm always interested as it's my work so I'll probably give them a spin.


Here’s a couple, but there’s more...

Android only:

https://github.com/h-mdm

Apple only:

https://github.com/cmdmnt/commandment

Both:

https://github.com/flyve-mdm


Thanks, I definitely will look into those!

I've been using Intune at home because I use it at work too and I already had a personal O365 setup. It was nice to have a fully owned instance when I was learning it, but I'm trying to scale back my costs now so something like this might just suffice.


Is this any different from the Find My Apple Stuff feature on modern iDevices? One of the options is remote wiping. I assume android as a similar feature.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: