See the whole estate, then govern the right control plane.
40 min3 lessons3 retrieval drills
The promise
What you will be able to do by the end of this module
Scope an MDM conversation accurately, including the OS version floors that decide whether a customer gets modern management or fallback behaviour.
State the MDM enrollment floors: iOS 10.0+, iPadOS all versions, Android 8.0 Oreo+.
Explain Declarative Device Management's much higher floor — iOS/iPadOS 17.0, macOS 14.0 — and the silent fallback below it.
Tell a customer that zero-touch needs Apple Business Manager, Apple School Manager, or Android Enterprise regardless of which MDM they buy.
Scope a BYOD conversation around ownership, privacy, and what you are actually permitted to wipe.
Position against a bundled MDM on unified estate rather than fighting it on feature parity.
Start from what you already know
Mobile is where deals stall on details nobody checked. Enrollment model and OS floor are the two questions that decide whether the POC works, and both are answerable before you promise anything.
01
Control planes
MDM governs mobile-native behavior
MDM handles enrollment, configuration, applications, security policy, and supported remote actions for Apple and Android estates. Ownership and enrollment model determine what controls are appropriate.
Corporate-owned, BYOD, and shared/kiosk scenarios differ.
Apple and Android enrollment programs affect automation.
App, configuration, and security policy need exception paths.
Retirement includes access removal and supported wipe actions.
NinjaOne ITAM brings agent-managed, network-discovered, offline, and unmanaged records into one inventory, then adds relationships, license, warranty, and lifecycle context.
Discover and normalize the estate.
Identify ownership and business criticality.
Track licenses, warranties, renewals, and lifecycle events.
Route unmanaged risk toward enrollment, remediation, or retirement.
A useful asset record answers 'what should happen next?' Tie discovery to onboarding, vulnerability remediation, license optimization, service workflows, financial planning, or decommissioning.
Field move
Use one asset example from purchase through enrollment, support, renewal, replacement, and disposal.
Each item is tagged with how far it can be trusted. Verified means checked against official documentation; field means it is our recommendation, not a vendor claim; unpublished means NinjaOne does not state it at all.
Platform support and minimum versions
verified
MDM enrollment supports Apple iOS 10.0 and later, Apple iPadOS all versions, and Android 8.0 (Oreo) and later. macOS is managed as well.
Declarative Device Management has a much higher floor
verified
DDM requires iOS 17.0, iPadOS 17.0, or macOS 14.0. Devices below those versions fall back to standard MDM behaviour — they still work, but without DDM's autonomous configuration.
Zero-touch requires the vendor programme, not just the MDM
verified
Automated enrollment depends on Apple Business Manager, Apple School Manager, or Android Enterprise. Android Enterprise binding uses a managed Google account. Without the programme there is no zero-touch, regardless of MDM.
Mobile is not an agent policy with extra settings. It is a distinct policy type alongside Agent, NMS and VM — which matters when a customer asks how mobile fits the governance model you drew.
“Are your mobile devices corporate-owned or BYOD, and what is the split?”
Listen for: Ownership decides enrollment model, privacy posture, and what you are allowed to wipe.
“Are you enrolled in Apple Business Manager or Android Enterprise today?”
Listen for: If not, zero-touch is a prerequisite project, not a feature. Say so early.
“What is the oldest OS version still in production?”
Listen for: Below iOS 17 or macOS 14 means fallback rather than DDM. Below iOS 10 or Android 8 means unsupported.
Demo path
Three moves, in this order
1
QR enrollment on a real device.
“This is the path for devices already in someone's hand.”
2
An MDM policy alongside an agent policy.
“Same governance model, different policy type.”
3
Mobile appearing in the same asset view as everything else.
“One inventory, not a separate mobile console.”
Objection handling
What they say, what you say, how you prove it
“We already have Intune.”
Then the question is consolidation of view, not replacement of capability. Where does mobile state show up next to your laptops and servers today?
Proof method: Do not fight a platform-bundled MDM head on. Compete on unified estate and workflow.
“Can you do zero-touch?”
Yes, through Apple Business Manager, Apple School Manager, or Android Enterprise. If you are not enrolled in those, that is the first step and it is independent of us.
Proof method: Check their ABM/ASM status in discovery. Assuming it is done is a common way POCs slip.
Where SEs blow it
Do not say these
Do not promise DDM without checking OS versions. iOS 17 and macOS 14 are recent floors.
Do not imply NinjaOne provides zero-touch without the Apple or Google programme.
Do not blur MDM policy with agent policy when describing governance.
From NinjaOne's channel
Watch it explained
Short clips from NinjaOne's own channel that reinforce the mechanics above. Each one says why it is here and what it backs up. These are supporting context, not product demonstrations — the sourced claims stay in the mechanics section.
Why this is here: Ownership model drives enrollment model, privacy posture, and what you are allowed to wipe.Watch on YouTube ↗Why this is here: Naming and identity discipline is what makes an asset inventory queryable later.Watch on YouTube ↗Why this is here: The discovery gap from the whiteboard — you cannot govern what you cannot enumerate.Watch on YouTube ↗Why this is here: How the MDM category is evaluated, useful before the OS-floor conversation.Caveat: Comparison-format video covering multiple vendors, not a NinjaOne MDM walkthrough.Watch on YouTube ↗
Retrieval practice
Rapid fire
Answer aloud before opening each response.
01MDM versus Endpoint Management?+
MDM uses mobile-platform enrollment and policy controls; Endpoint Management is the broader cross-platform operations plane.
02Managed versus unmanaged?+
Managed devices have the endpoint-management agent/control; ITAM also tracks discovered, offline, or otherwise unenrolled assets.
03Why warranty data?+
It turns age and coverage into repair, replacement, renewal, and budget decisions.