Transcript
Super Ops is a full-stack unified endpoint management platform with a built-in service desk, giving IT teams complete visibility and control over every device in their environment. Mac, iPhone, iPad, Android, all in one place with no tool hopping and no blind spots. We'll cover zero-touch enrollment, policy management, and how device context flows directly into tickets so your team resolves issues faster. This is what it looks like when devices stay compliant and employees stay productive. In this demo, we will explore how you can manage your Android, iOS, iPadOS, and macOS devices within Super Ops. Modern device fleets are increasingly diverse, and having a single pane of glass to manage all of them is a game-changer for IT teams. We will walk you through several key workflows, starting with how you can enroll these devices at scale, whether through manual enrollment or a zero-touch approach that eliminates hands-on IT involvement entirely. We will also look at how you can dive deeper into policy management to enforce security baselines and maintain compliance across your entire device fleet. We will also look at incident management, in which technicians get the full context they need to troubleshoot and manage mobile devices without ever switching tools. Let's get started with the enrollment process. Once you access the settings and navigate to MDM configurations, you will see options to set up both your Android and Apple devices. For Android, we begin by establishing a connection with Android Enterprise. This is Google's recommended framework for enterprise device management. You simply log in with your Android Enterprise account, connect Super Ops, and you are ready to go. Once this is set up, you will see the connection is active. This unlocks the full range of management capabilities, including manual enrollment and more. Now, it is worth understanding the enrollment modes we support. For manual enrollment, we support fully managed devices, bring your own devices, giving you a secure, containerized separation between personal and work data, and kiosk devices. Zero-touch enrollment is also available for fully managed, corporate-owned devices and kiosk devices. And for organizations already invested in the Samsung ecosystem, we integrate directly with Samsung Knox Mobile enrollment to automatically onboard fully managed and kiosk devices. Let's explore each of these options in more detail. For manual enrollment, you can specify parameters such as the site, department, or requester you are enrolling the device for. This is particularly useful for smaller deployments or one-off device additions. Based on your selections, you can generate a QR code. That QR code can be sent directly to your end user, who simply scans it to kick off the Android Setup Wizard and bring the device under management. For larger rollouts, Zero-touch really shines. Zero-touch enrollment, powered by the Android Zero-touch portal, is Google's answer to Apple's DEP. It lets you pre-configure devices before they ever reach the end user. Here, you specify the location for which you are onboarding devices and select the device types if you have multiple form factors to manage. Super Ops will then generate a JSON configuration, which you paste directly into your Android Zero-touch portal to map devices and automatically enroll them the moment they power on. This is a critical capability because it means devices come pre-enrolled straight out of the box. No manual setup, no imaging, no shipping devices back to IT. It also directly addresses shadow IT risk by ensuring every corporate device is captured under management from day one. For organizations running a Samsung Knox portal, the integration is equally seamless. You can enroll your fully managed and kiosk devices through Knox Mobile Enrollment, which is widely used in industries like retail, logistics, and healthcare, where dedicated use devices are common. You simply generate the required inputs, your APK URL, and the JSON for your DPC extras, and paste them directly into your Samsung portal. From that point forward, any device added to your Samsung portal will be automatically synced into Super Ops, with no additional manual steps on the IT side. Let's take a deeper look at Apple configuration. The first critical step is integrating with Apple Push Notification Service, or APNs. This is the foundation of any Apple MDM deployment. It establishes the secure, encrypted channel that Apple mandates before an MDM solution can communicate with its devices. Without a valid APNs certificate, enrollment simply isn't possible. And it's worth noting that this certificate must be renewed annually, or device communication will break entirely. Once APNs is configured, we can then integrate with Apple Business Manager, or ABM. This is where things get really powerful for IT teams managing Apple at scale. It unlocks automated device enrollment and connects to apps and books, allowing you to centrally manage volume-purchased app licenses and push them silently to managed devices. Let's explore automated device enrollment in more detail. This is Apple's preferred zero-touch provisioning method, and it's a genuine game-changer for enterprise deployments. The key advantage here is that devices are supervised, meaning IT has a deeper level of control than standard MDM enrollment, including the ability to prevent users from removing the MDM profile. Once the ABM integration is in place, as shown here, we can sync iPad, iPhone, and Mac devices directly from ABM. We can verify that these devices are assigned to the correct department and requesters, and we can quickly mark them for enrollment. This triggers the enrollment process automatically, and the relevant policies for these devices apply without any manual configuration on the end-user's side. Devices come out of the box pre-configured, supervised, secured, and policy-compliant from the moment they're powered on. This eliminates the risk of unmanaged Apple devices entering your environment entirely. Once devices are synced, we can also connect to apps and books, as mentioned earlier. This allows us to connect to each location within apps and books and sync all relevant apps for that specific location. This is especially valuable for organizations with multiple offices or regions that have different app requirements. Alternatively, the sync can also be organization-wide, and these apps can then be referenced in policies to silently deploy exactly the right apps onto the right devices. In cases where you have a handful of ad-hoc devices that need to be enrolled outside of ABM, whether it's a Mac, iPhone, or iPad, we can follow a similar flow to the Android experience. Assign the correct department and requester, and then generate the enrollment profile. This profile can be downloaded and delivered via email directly to the end-user. These devices will appear in the Unsupervised section, These devices will appear in the Unsupervised section, which is expected behavior for manually enrolled devices. They won't have the same depth of control as ABM-enrolled supervised devices, but they're still managed, visible, and policy-governed. Whether through zero-touch automated device enrollment or manual profile-based enrollment, the process is streamlined and significantly reduces the operational burden on IT teams. Once enrollment is complete, we can move on to configuring the policies that define exactly how these devices behave in the field. Let's go deeper into how you can manage these devices through policy management. You can set up policies specific to Android, iOS, iPad, and Mac. Let's start with Android policy. We support both BYOD and fully-managed device modes, and the policy sets for each mode can be entirely different. BYOD setup ensures that work and personal data remain completely separated with all controls managed through the policy engine. The policy itself is divided into two main sections, Restrictions and Configurations. Restrictions determine what users can and cannot do, while Configurations establish the baseline security posture for those devices. Focusing on Restrictions in the General section, you can manage access to hardware features such as the camera and microphone. You can also define cross-profile data sharing roles. For example, you can choose whether users are allowed to copy, paste, or transfer data between work and personal profiles, or if work contacts can sync into the personal address book. These controls are vital for organizations with strict data loss prevention requirements. Factory Reset Protection is another essential control in our system. If a device is lost, wiped, and someone tries to reactivate it, the device will require the designated email address to sign in before it can be used. This serves as a strong anti-theft measure, preventing unauthorized reuse of corporate devices. Lockscreen controls allow us to define exactly what is visible when the device is locked. For example, we can choose whether the camera is accessible from the lock screen, whether notifications are shown, or if sensitive notification content is hidden. It's also possible to require specific biometric authentication methods on the lock screen, adding an additional layer of security. Network controls help us manage how devices connect to the Internet and nearby devices through Bluetooth and Wi-Fi. One particularly valuable feature is the Network Escape Hatch. During zero-touch enrollment, if a device encounters a network issue, the Escape Hatch enables the user to connect temporarily to an alternative network in order to complete enrollment and download policies. After enrollment, that temporary network connection is automatically forgotten, which maintains the device's security. App restrictions give us control over what users can install or uninstall and how they interact with the Play Store. We can limit users to managed apps only. There is also the option to restrict access to the full Play Store or allow access only to managed apps approved by the organization. Enabling Google Play Protect adds another layer of malware detection. Additionally, developer options can be locked down to prevent tampering. On the configuration side, we can manage password complexity requirements, push Wi-Fi profiles so devices connect automatically to the correct networks upon enrollment, and control both app and OS update behaviors. With App Management, we have powerful flexibility to deploy apps directly from the Google Play Store. This is done through Android's Manage Google Play framework, which gives IT teams granular control over exactly which apps are available to end users. We simply select any approved apps and add them to our bundle. If there are private or internally developed apps specific to our organization, we can easily distribute those as well without ever publishing them publicly. We start by uploading the app file, either in APK or in AAB format, which is Google's newer, more efficient packaging standard. The upload process typically takes around 10 minutes, after which the app becomes available to assign for deployment. For web-based tools or internal portals that need to feel like native apps on the device, we have the option to configure a web application. We can control how it's displayed, for instance, whether it opens in a standalone window or a browser tab. Here we have a Claude web app that we want to push to devices, and we can bring it right into the mix alongside our other managed apps. We simply click Add in the relevant section, and click Save and these apps will be pushed out to enrolled devices. For OS updates, everything is handled automatically, reducing operational overhead. Updates can be scheduled for off hours to minimize disruption, or pushed immediately as soon as they are available from Google. Just as with standard Android policies, kiosk device policies offer the same depth of control over restrictions and network security, all specifically fine-tuned for your kiosk fleet. This is important because kiosk devices are often customer-facing or mission-critical, so ensuring they are properly locked down is essential. Here you have the option to add a public app, a single app pulled directly from the Play Store, In this example, we have added Shopify. You can swap out this app at any time without needing to rebuild your entire policy, and you can designate it as the single app to which the device is locked. This is the core of kiosk mode. By defining one app, you set the device's entire purpose. It runs exclusively in the foreground. Even though the device is locked to Shopify, there are still background processes that must run to keep everything operating smoothly. These might include silent update processes or analytics tools, such as Google Ads. You can also control whether to automatically update and install these apps. Additionally, you can block any apps that should not be running on a locked-down device, which helps reduce your attack surface and maintain a clean user experience. This approach truly defines a kiosk deployment. The primary app is locked in kiosk mode, necessary background processes run silently to support it, and all other apps are either controlled or blocked. All the additional policy settings we discussed for Android apply here as well. You maintain full control to manage the kiosk policy over time, pushing restriction updates, adjusting MDM configurations or swapping apps, all without physically touching the device. Now, moving to Apple devices, we provide equally comprehensive policy controls for iOS, iPad, and Mac. Let's take a closer look at the iOS policy. The goal here is to maintain strong security and compliance while also preserving the seamless, intuitive experience that Apple users expect from a configuration standpoint. During automated device enrollment, you can allow users to skip non-essential setup steps, streamlining the out-of-box experience. At the same time, you can make the MDM profile mandatory, non-removable, and supervised, ensuring the device remains under management regardless of user actions. You can enforce password policies across all devices directly from here, and you can push network configurations such as Wi-Fi and VPN profiles. Just as with Android, we offer fine-grained control over OS updates. You can enforce minor updates after a defined grace period, enforce major version upgrades, or require specific app versions to be installed by a set deadline. When setting update requirements, it is possible to define a default deferral period, giving time to validate updates in your environment before rolling them out to end users. This is a best practice in mobile device management. Test first, then enforce, to balance control with user autonomy. IT admins can also define whether users are allowed to manage their own rapid security responses. This is Apple's mechanism for fast, targeted security patches, allowing users to install or roll back as needed. Additionally, users can trigger OS update downloads directly from their device. Managing Apple and iOS apps is a critical part of any MDM strategy, and Super Ops makes this straightforward. Apps can be pulled directly from Apple Business Manager's Apps & Books program using the VPP licensing configuration set up earlier. This is key for deploying paid apps at scale without requiring individual Apple IDs on each device. You can also add free apps straight from the public App Store. Once the apps are added, there is full control over deployment behavior, choosing exactly when apps are pushed out, how frequently they're updated, and whether installations happen automatically or on-demand. This is especially useful for keeping line-of-business apps current without any end-user intervention. If there are apps that pose a security risk or simply don't belong on managed devices, they can be blocked entirely. This provides an extra layer of control that compliance-conscious organizations really depend on. We also support custom payloads, which means any MDM configuration profile can be pushed directly to managed iPhone and iPad devices. Going beyond the built-in settings provided out-of-the-box, think of this as a safety net for edge cases, such as custom Wi-Fi or VPN configurations that require vendor-specific parameters or certificate deployments. This is especially powerful in enterprise environments. For example, if you want to configure Zoom notifications or preset meeting preferences, simply upload your XML file here and save it. Alternatively, this can be uploaded as a file to a mobile config, plist, XML, or .txt format, which is especially useful when deploying different configurations across multiple IT environments. There is also the option to set up default placeholders, which dynamically pull from asset information. Instead of hard-coding values, the platform automatically populates the right details for each device. This means that you can maintain multiple custom payloads, keeping each configuration clean, isolated, and easy to update at scale. Along with custom profiles, it is now possible to manage user identity directly within Super Ops. This is especially valuable for organizations running Microsoft Entra ID. When users open a work app on their iPhone or iPad, they are automatically signed in with their Entra ID credentials. No manual login required. This kind of SSO extensibility is essential for modern zero-trust architectures. When setting this up, the Authentication Flow SSO Extensible Bundle and Redirection URLs are already prefilled. You can also add additional redirection URIs as needed and control exactly how authentication behaves when the screen is locked. It is possible to decide whether browser-based SSO is permitted and whether to skip duplicate account registrations, giving you fine-grained control over the end-user experience. You can also define exactly which apps are included in the SSO policy. For example, if you want to cover the entire suite of Zoom apps, you can add the Zoom Bundle ID here. That single entry will cover all Zoom-related apps under one SSO policy, keeping things organized and reducing the risk of accidentally leaving any apps outside your identity perimeter. With Mac, we take a hybrid approach to management. This means you get MDM-based controls for security compliance and configuration enforcement, alongside agent-based controls for real-time monitoring, alerting, and automated remediation. Under restrictions, just like with iOS and iPad, you will find general security and app restrictions. Configuration settings can be managed, and agent-based alerting can be set up, enabling real-time visibility into Mac health and performance. For more details on how the RMM agent works, please visit support.superops.com. When it comes to patch management on Mac, we take a dual approach. The MDM-based method enforces OS updates by a defined deadline, while also giving users visibility into available downloads and installations. As discussed earlier, the agent-based method provides patch-level granularity, so patch categories can be reviewed and approved before deployment. Patches can be marked as approved and pushed on a scheduled basis, or managed manually through the patch dashboard. The key design principle here is that both methods work in sync and never conflict. If a patch has already been enforced via MDM, the agent recognizes this and skips it automatically, and vice versa. This eliminates duplicate patching and keeps your patch compliance data clean. We also manage software on Mac devices, allowing you to deploy apps from apps and books, similar to the iOS experience discussed earlier. But in addition to that, we also integrate with Homebrew, the widely used Mac package manager. This allows you to deploy open-source and developer tools that specific organizations rely on. You can also add custom software packages and schedule their deployment for a specific date and time. This approach ensures consistent software enforcement across your entire Mac fleet, regardless of user behavior. That covers the policy. Now that we've seen how policies can be configured, let's dive deeper into how we manage and monitor mobile devices across the organization. When we navigate to the Asset Management section, we get a unified view of our entire device fleet, including our Android and Apple iOS devices. This gives IT teams the end-to-end visibility they need to stay on top of compliance, security, and support, all from one place. Let's drill into one of these Android devices to see what's possible. The device details screen is really the command center for that endpoint. Everything an IT admin needs, whether for compliance enforcement, security auditing, or help desk troubleshooting, lives here. For instance, we can immediately see battery health, internal storage utilization, and RAM usage, which are all common culprits when users report performance issues. But perhaps most powerful is the geolocation data. In MDM, location tracking is essential for both asset management and security. We can see, over the last 30 days or so, a full location history showing exactly where the device has traveled. This is invaluable in real-world scenarios. Whether an employee has lost a device, or you simply need to verify that a corporate device hasn't left an approved geographic zone. Beyond location, we surface detailed software inventory data that is critical when troubleshooting app conflicts or OS-level issues, along with full hardware specifications and network connectivity details like IP address, carrier, and Wi-Fi status. Here, we can see the devices that are available instantly and remotely. There are also powerful remote actions available directly from this screen, such as pushing an emergency message to the user, pinging the device to confirm it's online and responsive, remotely resetting the password to enforce security policy, or performing a full factory wipe if the device is compromised. You have access to corporate resources without needing the device in hand. One of the standout capabilities here is the ability to remote into Android devices directly. When you initiate a remote session, a remote viewer launches and allows you to request screen control and navigate the Samsung device in real-time. This is a game-changer for help desk teams. You can then call, resolve the issue, and get them back to work in minutes. And because this is a true end-to-end platform, you can always review the compliance policies actively applied to this device, push configuration changes specific to this Android device, or investigate any open support tickets tied to it, all without leaving the device view. That unified context dramatically reduces We've walked through the Android experience, but the same depth of management applies to iOS and Mac devices. On the iOS side, key MDM actions include activating Lost Mode, which locks the device and displays a custom message, or performing a remote wipe if the device is stolen or decommissioned. For Mac devices, you get the added advantage of agent-based monitoring layered on top of MDM enrollment, the deep policy enforcement of MDM combined with the real-time telemetry and compliance checks that only an agent can provide. Let's now have a deeper look at how your team can manage issues related to your MDM devices. Because Super Ops includes a built-in ticketing module, all your tickets are organized under the Work Management section, keeping your help desk and device management workflows Within Work Management, let's walk through a real-world scenario. A user reaches out to report that their iPad isn't working. For the most common help desk tickets, having a structured response process matters. The first step is to leverage runbooks, which automatically detect that this is an Apple device issue and surface the relevant Apple Device Manager connection. If the user can't access the camera, a guided checklist appears with clear, actionable steps for the technician to follow. If you need to reference an IT document, such as your Camera Permission Policy or MDM Enrollment Guide, you can pull it up directly from this interface without switching tools. If you need to trigger an approval workflow or verify specific configuration details on the Device Details page, everything is accessible right here. To access the Device Details page, we simply link the device directly within this section on the Assets page, giving you full visibility into enrollment status, installed profiles, and compliance state. This allows the technician or IT team member to examine the asset in depth and accurately diagnose what's happening. If the issue requires deeper investigation, AI-powered features kick in, allowing you to summarize the ticket instantly, make troubleshooting recommendations based on previous tickets, and review similar past conversations and resolutions. This is particularly valuable in environments where you're often dealing with recurring issues across a fleet of devices, things like MDM enrollment failures, certificate expirations, or policy conflicts. The technician can now respond to the user more effectively with full device context. In this scenario, the technician has finished diagnosis and can use canned responses to respond faster and resolve the issue. See, since the entire context is available in one tab, managing tickets is significantly more efficient. Think about how much time is typically lost toggling between your MDM console, your ticketing system, and your asset database. This consolidation eliminates that friction entirely. Additionally, you can generate powerful reports directly on your MDM data. For example, if you want to create a report to review your MDM-related assets, something that's critical for audits, compliance checks, or just staying on top of your device inventory, you can name it MDM Assets and then select Asset as the category, where you can label it as Mobile Device Assets. You can choose to display key details, such as device name, serial number, host and enrollment status, giving you a real-time snapshot of exactly which devices are enrolled, active, and compliant, allowing you to review the full list of details and save the report. For inventory management and compliance reporting, you can export or share this report, or schedule it to be delivered to your inbox on a recurring basis, daily, weekly, or monthly. This brings us to the end of the demo, and what we've walked through today is a truly comprehensive, end-to-end overview of how modern IT operations can look when MDM is natively built into your platform. We've seen how the platform handles the full device lifecycle, from MDM enrollment to patch management to asset tracking and all the way through to ticket resolution. No more siloed tools, no more context switching, and no more chasing down device details across multiple consoles. With everything centralized, your IT team can move faster and with greater confidence. That's the power of a unified IT platform with MDM built in. Thank you.