Install and manage MCM and BigFix Mobile components - On-premises only

MDM on-premises requires you to perform one-time MDM Server setup. You must have the required hardware and software set up in prior to deploy MDM on-premises. Set up your environment through BigFix WebUI.

For details on prerequisites, setup instructions, and other information seeOn-premises deployment setup section of the Installation and Configuration Guide.

To set up and manage MDM components through BigFix WebUI:
  • Ensure that you are a Master Operator (MO)
  • From WebUI main page, click Apps > MCM and from the Modern Client Management page, click Admin

Install MDM server: You can either install standalone versions of Windows, Apple®, or Android MDM server. You can also add capabilities to the MDM server to manage a combination of these operating systems. Before installing MDM server, do the following:
  • Install Docker Engine, Docker Compose, and OpenSSL.
  • Install BES client on the target computer in which you want to install MDM server. This is because you need to install MDM server through WebUI or Fixlets.

Add capability: For MDM servers with only one component installed (Windows, Apple, or Android), you can add the missing component.

Install MDM Plugin: Installing MDM Plugins is required to set up a connection between the MDM Servers and the BigFix Plugin Portal. MDM Plugins communicate with the MDM Server through REST APIs and the AMQP protocol using client certificates. MDM Plugins are available to manage Apple, Windows, and Android devices.

Before installing MDM Plugin:
  • Ensure that the server host is running the Plugin Portal version 10.0.2 or later
  • Ensure BigFix agent version 10.0.2 or later is running locally. For details about installing the BigFix Client, see Installing the BigFix components.
  • Ensure you have required credentials, specifically from cacert, the client cert, and the client key that is generated from BESAdmin.sh. For details, see MDM SSL certificates.
  • Ensure you have TLS certificate and MDM Push credentials of various forms for Apple, Windows and Android servers.

Update: Update MDM servers and Plug ins as necessary. See update MDM components.

Uninstall: At any point in time, you can uninstall MDM components from WebUI. Note that uninstalling MDM components removes the capability to manage some or all of the enrolled devices.