Transcript
built for MSP's managing device fleets across multiple clients. SuperOps is a full-stack unified endpoint management platform with a built-in PSA and Service Desk, giving MSPs complete visibility and control across every client device and every OS from one console. We'll cover zero-touch enrollment, cross-OS policy management, and how every managed device ties directly back to client contracts. When your device data and billing live in the same platform, unbilled devices and revenue leakage stop being a problem. Let's dive in. This session will cover four key areas. How to onboard your mobile devices, how to apply policies to your mobile devices, how to manage device visibility and take actions across your mobile fleet, and finally, what happens when a ticket comes in and how that entire experience works seamlessly within your PSA. Let's get started. When you navigate to Settings in the Mobile Device Configurations page, you'll find your enrolled mobile devices listed under the MDM Configuration section. You'll notice there are multiple clients here, and this is by design. SuperOps is a truly multi-tenant platform, meaning you can set up separate APNs, Android Enterprise, and Apple Business Manager tokens, one for each client. One of the operational headaches MSPs face with MDM is token expiry. APN certificates, for instance, expire annually, and if they lapse, you lose management of every Apple device under that client. To address this, we show you tokens that require renewal or have already expired, so you can seamlessly renew them and maintain uninterrupted device management. Let's take a closer look at one client. We support enrollment for both Android and Apple devices. For Android, we leverage the Android Enterprise framework, Google's modern standard for separating work and personal data on managed devices, giving you a secure, scalable way to establish the handshake and onboard your fully managed devices through either zero-touch enrollment or manual enrollment. You also have the flexibility to manage BYOD scenarios and dedicated kiosk devices, which is critical for organizations running mixed device fleets. Let's start by walking through zero-touch enrollment. Zero-touch is Google's out-of-box provisioning method, meaning devices ship pre-configured directly from the reseller and are ready to enroll the moment they power on. No IT technician required. Choose the type of device you would like to enroll and select the site and the requester, then follow a few straightforward steps by opening the Android Zero Touch portal, where you configure the DPC extras and bind the enrollment configuration to your device policy. Once that configuration is in place, you can map the devices you've created in the portal, and those devices are ready to provision at scale with zero manual setup. If you are enrolling a dedicated kiosk device, think point-of-sale terminals, shared tablets, or field equipment running a single-purpose app, you can set up the policy, select the site and requester, and it's also worth noting that any pre-installed apps on the device can be retained during enrollment, which saves time and avoids disruption to existing workflows. The setup flow in the Android Zero Touch portal follows the same consistent pattern across device types. If you prefer to manually enroll devices, useful when zero-touch isn't available, the reseller isn't zero-touch certified, or you're simply handling a smaller batch. You have the choice between enrolling a fully managed corporate-owned device, where you select the site and requester, or you can also support BYOD enrollment. With BYOD on Android, the process is similar. You can generate a QR code and use it to enroll the device. And just like with zero-touch enrollment, you can also provision these manually enrolled devices as dedicated kiosk devices, locking them down to a single app. On the Apple side, we integrate with Apple Business Manager to enable automated device enrollment, Apple's equivalent of zero-touch. This syncs all Apple devices, including iPhone, iPad, and Mac, directly into SuperOps. Syncing can be triggered on demand or scheduled as a daily sync. We also integrate with apps and books, formerly known as Apple's Volume Purchase Program, or VPP, which allows you to centrally manage app licenses and deploy them at scale to your Apple devices. Manual enrollment is supported here as well. Devices enrolled through Apple Business Manager are supervised, giving you the deepest level of management control Apple offers, while manually enrolled devices are unsupervised across Mac, iPhone, and iPad. For manual enrollment, you generate a profile file and share it with the user to install. The process is designed to be straightforward, regardless of the enrollment path. In summary, both Apple and Android support zero-touch enrollment for a fully automated onboarding experience. But for edge cases or personally owned devices that need manual enrollment, that's easily handled through QR code or profile-based enrollment as well. Now, once devices are onboarded, the next critical step is ensuring that the right policies are applied immediately. A device without a policy is essentially unmanaged, and that's a risk. Let's look deeper at the policy framework. Depending on your client base, you can choose between a hierarchical policy model or an advanced policy framework. The hierarchical model works well when your security baseline is largely consistent across clients. In this model, there is one global policy at the root, with the flexibility to apply client-level or site-level overrides where needed. This is ideal for MSPs who want to standardize their security posture across their entire book of business while still accommodating minor client-specific requirements. The advanced policy framework is better suited for MSPs who offer tiered service plans, for example, gold, silver, or black-tier contracts, where the scope of management and the policies applied can vary significantly between clients. Policies in this model can still inherit settings from a root policy, giving you consistency at the top level while allowing full flexibility at the child level. There is active inheritance in place, so changes at the root propagate down, while still allowing you to configure the child policy independently where needed. Now let's look at the four policy types available. We have Android, Apple iOS, iPad, and Mac policies. Let's start with Android device policies. Android is often the more complex environment to manage, particularly in mixed fleets where you have both corporate-owned and personally-owned devices. That's why we've prioritized granular security controls here. As an MSP admin, you have full control over Android device behavior. This is especially important because we support both BYOD and fully-managed device modes, and the policy sets for each can be entirely different. This ensures that work and personal data remain completely separated, with everything governed through the policy engine. A policy is divided into two main sections, restrictions and configurations. Restrictions define what users can and cannot do, while configurations establish the security posture baseline for those devices. Starting with restrictions. In the general section, you can control access to hardware features like the camera and microphone. You can also define cross-profile data sharing rules. For example, whether users are permitted to copy, paste, or transfer data between the work and personal profiles, or whether work contacts can sync into the personal address book. These controls are essential for organizations with strict data loss prevention requirements. Factory reset protection is another important control here. If a device is lost, wiped, and someone attempts to reactivate it, the device will require the designated email address to sign in before it can be used. This is a powerful anti-theft measure that prevents unauthorized reuse of corporate devices. Lock screen controls let you define exactly what's visible when the device is locked, whether the camera is accessible from the lock screen, whether notifications are shown, or whether sensitive notification content is redacted. You can also require specific biometric authentication methods on the lock screen, adding another layer of security. Network controls determine how devices connect to the internet and nearby devices via Bluetooth and Wi-Fi. One particularly useful feature here is the network escape hatch. During zero-touch enrollment, if a device encounters a network issue, the escape hatch allows the user to temporarily connect to an alternative network to complete the enrollment and policy download process. Once enrollment is complete, that temporary network connection is automatically forgotten, keeping the device secure. App restrictions give you control over what users can install or uninstall, and how they interact with the Play Store. You can restrict users to managed apps only, preventing them from sideloading untrusted applications, a common attack vector in Android environments. You can also control whether users have access to the full Play Store or only to managed apps approved by your organization, and you can enable Google Play Protect for an additional layer of malware detection. Developer options can also be locked down to prevent tampering. On the configuration side, you can manage password complexity requirements, push Wi-Fi profiles the devices connect to the right networks automatically upon enrollment, and control app and OS update behavior. For app management, you can browse the Play Store directly within SuperOps, select apps to deploy, and organize them into the system. You can also create app bundles tailored to specific departments, marketing, HR, or security, ensuring each team gets exactly the apps they need, nothing more and nothing less. This way, you can manage both deployment and updates centrally. If an app is already installed on a device, SuperOps will simply manage updates going forward. You can also silently block specific apps, making them completely invisible to the end user. For OS updates, everything is handled automatically to reduce your operational overhead. Updates can be scheduled for off-hours windows to minimize disruption, or pushed immediately as soon as they become available from Google. Just like with your standard Android policy, your kiosk device policies offer the same depth of control when it comes to restrictions and network security, all fine-tuned specifically for your kiosk fleet. This matters because kiosk devices are often customer-facing or mission-critical, so locking them down properly is essential. Here you have the option to add a public app, a single app pulled directly from the Play Store. In this example, we've added Shopify, so you can swap out this app at any time without having to rebuild your entire policy. And you can designate this as the single app that the device is locked to. This is the heart of kiosk mode. You're essentially defining the device's entire purpose. You select one app and it runs exclusively in the foreground. Even though the device is locked to Shopify, there are still background processes that need to run to keep things operating smoothly. These might include silent update processes or analytics tools, for example Google Ads, where you can control whether to automatically update and install it. You can also block any apps that have no business running on a locked-down device, reducing your attack surface and keeping the experience clean. This is what truly defines a kiosk deployment. The primary app is locked in kiosk mode. The necessary background processes are running silently to support it, and everything else is either controlled or blocked. All the additional policy settings we covered for Android apply here as well. You retain full control to manage the kiosk policy over time, pushing restriction updates, adjusting MDM configurations, or swapping apps, all without touching the device physically. Moving to Apple, we provide equally comprehensive policy controls for iOS, iPad, and Mac devices. Let's look more closely at the iOS policy. The philosophy here is to maintain strong security and compliance while preserving the seamless, intuitive experience Apple users expect. From a configuration standpoint, during automated device enrollment, you can allow users to skip non-essential setup steps, streamlining the out-of-box experience. At the same time, you can make the MDM profile mandatory, non-removable, and supervised, ensuring the device remains under management regardless of what the user does. You can enforce password policies across all devices right here, and you can push network configurations like Wi-Fi and VPN profiles. Just as with Android, we give you fine-grained control over OS updates. You can enforce minor updates after a defined grace period, enforce major version upgrades, or require specific app versions to be installed by a set deadline. When setting update requirements, you can define a default deferral period, giving you time to validate updates in your environment before rolling them out to end users. This is a best practice in MDM. Test first, then enforce. To balance control with user autonomy, MSP admins can also define whether users can manage their own rapid security responses, Apple's mechanism for fast, targeted security patches, allowing them to install or roll back as needed. Users can also trigger OS update downloads directly from their device. Managing Apple and iOS apps is a critical part of any MDM strategy, and Super Ops makes this straightforward. You can pull apps directly from Apple Business Manager's Apps and Books program using the VPP licensing configuration we set up earlier. This is key for deploying paid apps at scale without requiring individual Apple IDs on each device. You can also add free apps straight from the public app store. Once your apps are added, you have full control over deployment behavior, choosing exactly when apps are pushed out, how frequently they're updated, and whether installations happen automatically or on demand. This is especially useful for keeping line-of-business apps current without any end-user intervention. And if there are apps that pose a security risk or simply don't belong on managed devices, you can block them entirely, giving you that extra layer of control that compliance-conscious organizations really depend on. We also support custom payloads, which means you can push any MDM configuration profile directly to your managed iPhone and iPad devices, going beyond the built-in settings we provide out of the box. Think of this as a safety net for edge cases. Things like custom Wi-Fi, VPN configurations that require vendor-specific parameters, or certificate deployments. This is especially powerful in enterprise environments. For example, if you want to configure Zoom notifications or preset meeting preferences, just upload your XML file here and save it. Alternatively, you can upload this as a file in .mobileconfig, .plist, .xml, or .txt format, which is especially useful when you're deploying different configurations across multiple IT environments. You also have the option to set up default placeholders, which dynamically pull from asset information. So instead of hard-coding values, you're letting the platform populate the right details per device automatically. This means you can maintain multiple custom payloads and keep each configuration clean, isolated, and easy to update at scale. Along with custom profiles, you can now also manage user identity directly within Super Ops, which is a big deal for organizations running Microsoft Entra ID. When users open a work app on their iPhone or iPad, they're automatically signed in using their Entra ID credentials, with no manual login required. This kind of SSO extensibility is what modern Zero Trust architectures depend on. When you set this up, the authentication flow, SSO extensible bundle, and redirection URLs are already prefilled. You can also add additional redirection URLAs as needed, and control exactly how authentication behaves when the screen is locked, whether browser-based SSO is permitted, and whether to skip duplicate account registrations, giving you fine-grained control over the end-user experience. Finally, you can define exactly which apps are in scope for SSO. For example, if you want to cover the full suite of Zoom apps, you can add the Zoom Bundle ID here, and that single entry covers all Zoom-related apps under one SSO policy, keeping things tidy and reducing the risk of apps being accidentally left out of your identity perimeter. With Mac, we take a hybrid approach to management. This means you get MDM-based controls for security, compliance, and configuration enforcement, alongside agent-based controls for real-time monitoring, alerting, and automated remediation. Under restrictions, just like iOS and iPad, you'll find general security and app restrictions. You can manage configuration settings and set up alerting, which is agent-based, enabling real-time visibility into Mac health and performance. For more details on how the RMM agent works, visit support.superops.com. When it comes to patch management on Mac specifically, we take a dual approach. The MDM-based method enforces OS updates by a defined deadline, while also giving users visibility into available downloads and installations, as we saw earlier. The agent-based method gives you patch-level granularity, or patch categories can be reviewed and approved before deployment. You can mark patches as approved and push them on a scheduled basis, or manage them manually through the patch dashboard. The key design principle here is that both methods work in sync and never conflict. If a patch has already been enforced via MDM, the agent recognizes this and skips it automatically, and vice versa. This eliminates duplicate patching and keeps your patch compliance data clean. We also manage software on Mac devices, letting you deploy apps from apps and books, just like the iOS experience we covered earlier. But on top of that, we also integrate with Homebrew, the widely used Mac Package Manager, so you can deploy open source and developer tools that specific organizations rely on. You can also add custom software packages and deploy them at a specific scheduled date and time. This ensures consistent software enforcement across your entire Mac fleet, regardless of user behavior. That covers the policy layer. Now let's move into device management, where you'll see your Android, iOS, and iPad devices listed. Drilling into an individual Android device, the goal of this page is to give the technician complete situational awareness, everything they need to troubleshoot and act, without ever needing to remote into the device. We surface all the critical baseline information about the device, battery level, internal storage, network details that can assist with connectivity troubleshooting, hardware specifications, and managed software information, including installed apps. We also provide a full list of apps in their current installation statuses. For urgent situations, mission-critical actions like remote wipe or password reset are just one click away. You can also remotely lock the screen. If you need to communicate with the user before taking action, for example to warn them before a wipe, you can send a message directly to the user from within the platform. If you suspect a device may be offline or outside its expected location, you can run a quick ping to verify connectivity in real time. The same depth of device visibility and remote actions is available for iOS, iPad, and Mac, giving your technicians everything they need to troubleshoot and resolve issues. Now let's look at the PSA side of the equation. What happens when an incident comes in? Because Super Ops combines PSA and RMM in a single platform, you never need to switch context to manage a mobile device incident. In this example, a user named John is experiencing issues with his camera being disabled on his iPad, a common scenario in MDM environments where camera restrictions are enforced through a configuration profile or supervised device policy. He has reached out to the MSP support team for assistance. The technician is able to access all the necessary context within a single platform to support the user. Rather than jumping between an RMM, a PSA, and a separate MDM console, everything lives here. This begins with actionable checklists tailored specifically for Apple device management, which can be created by the MSP admin. These checklists provide clear, step-by-step instructions on what actions need to be taken, including references to IT documentation that details Apple's MDM capabilities. If a deeper investigation into the asset is required, the technician can access the user's device directly within the same platform. This can be done with a single click, allowing the technician to explore device details such as enrollment status, installed profiles, and applied restrictions. This streamlined workflow eliminates context switching and gives the technician everything they need in one place within a single platform. Even if John decides to log in to Super Ops as a requester, he will have access to a comprehensive knowledge base covering Apple device management, empowering him to self-serve and resolve common issues without needing to raise a ticket. From a billing perspective, which is the fourth critical pillar we discussed, Super Ops helps ensure that MSPs are accurately billing for every Apple device they manage and support. For example, if a contract is in place, that contract can encompass all services delivered under Apple device management, from enrollment and profile management to ongoing compliance monitoring. Additionally, there is a clear overview of the services being delivered through our unique feature called the delivery map. This gives you full visibility into all Apple managed devices and their associated charges. By consolidating everything into one platform, Super Ops ensures that no managed device falls through the cracks. Every Apple device is accounted for and billed appropriately, protecting your revenue. This brings us to the end of the demo. As you've seen, Super Ops enables MSPs to manage mobile devices alongside traditional endpoints in a way that is efficient, secure and compliance focused, all within a single pane of glass. It also gives you the billing controls needed to ensure there are no unbilled devices, eliminating revenue leakage and protecting your profitability. Thank you for your time. We look forward to partnering with you on your mobile device management journey.