Deploy MCM actions

With MCM and BigFix Mobile, you can perform the following MDM-specific actions:

  • Lock
  • Wipe
  • Restart
  • Shutdown
  • Remove Policy
  • Deploy BigFix Agent
  • Deploy MDM Application
  • Windows 10 Enrollment
  • Regenerate Encryption Recovery Key
  • Unenroll


Note:
  • You can deploy MDM actions only to the MCM and BigFix Mobile managed devices.
  • You can also deploy MDM actions to correlated devices that have MCM and BigFix Mobile representation.
  • Certain actions are operating system specific, and each action has an operating system logo on it to indicate which operating system it applies to. If you find more than one logo for an action, it represents that action can be applied to each operating system depicted.
  • Deploying the Deploy BigFix Agent action requires installer packages to be pre-staged to work properly. For macOS, see Prestage macOS BigFix installer. For Windows, see Prestage Windows BigFix Installer.
To perform different MDM actions, follow these steps:
  1. Login to the WebUI.
  2. Click Apps and select MCM.
  3. From the Modern Client Management page, click Actions.
  4. The MDM Actions page displays all the possible actions along with the supported operating system for every action. You can also filter applicable actions by using the Supported Operating Systems filter. Click on the specific MDM action you want to deploy on MDM endpoints.

Lock Device

Use this action to remotely lock devices that are lost or stolen. Lock helps protect the data stored on devices when they are lost or stolen. If after initiating a lock action the device is recovered, the device can be unlocked using the recovery pin set initially by the action launched from the WebUI.

Note:
  • Lock action is applicable for macOS, iOS, iPadOS, and Android devices.
  • Lock action is not applicable to Windows devices. The lock action deployed on Windows MDM devices does not lock those Windows devices, and this action reports as failed.
  1. From the list of available actions, select Lock .
  2. On the following screen, click Edit Devices to add or remove the devices.

  3. Click Send Command to deploy the action to the targeted devices.
    Result: The targeted devices are locked.
    Note: Different operating systems prompt users for different options during the lock operation. For Android devices, users can enter the Android Command duration (in seconds). The command expires if not executed within the time specified.

Wipe

Use this action to erase the data on the remote device, even if the device is locked. The Wipe action helps you to completely erase the data from the targeted devices from the BigFix management without warning the end-user.

Note:
  • The recovery code applies only to macOS devices. Windows devices will execute the Wipe action while ignoring the recovery pin.
  • Users can wipe only one device at a time and cannot execute wipe on device groups.
  • When targeting Android devices, the following options are available to specify the level of wipe on the Android device:
    • WIPE DATA UNSPECIFIED: This value is ignored.
    • PRESERVE RESET PROTECTION DATA: Preserve the factory reset protection data on the device.
    • WIPE EXTERNAL STORAGE: Additionally wipe the external storage of the device.

  1. From the list of available actions, select Wipe.
  2. On the following screen, click Edit Devices to add or remove devices.
    MDM Wipe
  3. If you select macOS devices to wipe, set a six-digit recovery PIN. This PIN is required to reinstall the operating system on the device. Ensure to record it and share it with the device owner.
  4. Click Send Command to deploy the action to the targeted devices.

    Result: Once the deployment is complete, the targeted devices are wiped from MDM.

Restart

Use this action to restart the targeted devices.

  1. From the list of available actions, select Restart.
  2. On the following screen, click Edit Devices to add or remove devices.
  3. Click Send Command to deploy the action to the targeted device.
Note: The restart action is only available for Apple DEP devices. Non-supervised Apple devices targeted with the restart action will ignore the restart command.

Shutdown

Use this action to shutdown the targeted devices.

  1. From the list of available actions, select Shutdown.
  2. From the following screen, click Edit Devices to add or remove devices.

  3. Click Send Command to deploy the action to the targeted devices.
    Note:
    • The restart action is only available for Apple DEP devices. Non supervised Apple devices targeted with the restart action will ignore the restart command.
    • Shutdown action is available only for macOS/iOS/iPadOS and not for Windows.

Remove Policy

You can remove policies from selected devices using this action. You can only remove policies on devices that are enrolled in MCM and BigFix Mobile.

Note:
  • If remove policy action is sent to macOS devices that do not have the selected policy, the action fails.
  • You cannot remove Android policy. You can only overwrite Android policy by deploying another policy through Policy Groups.
  1. From the list of available actions, select Remove Policy.
  2. From the following screen, click Edit Devices to add or remove devices.

  3. Click Edit Policies to select the policy that needs to be removed from the targeted devices.
  4. Click Send Command to deploy the action to the targeted devices.

Deploy BigFix Agent

See Deploy BigFix Agent.

Deploy MDM Application

See Deploy BigFix Agent.

Windows 10 Enrollment

If ppkg file is present in your MDM server, then you can also initiate Windows 10 bulk enrollment via this page. To do that:
  1. From the list of available actions, select Windows 10 Enrollment.
  2. From the following screen, click Edit Devices to select Windows 10 devices in your environment that have BigFix agent installed.
    Windows 10 enrollment
  3. Action Staggering Settings: Select Enable Action Staggering and enter Stagger Action Over Duration in minutes. Use this setting to spread out the load on the MDM server and network to prevent all the targeted endpoints attempting to enroll at the same time. Staggering enrolling endpoints normalizes the amount of traffic generated by newly enrolled devices over a broader more manageable period of time. When this is set, each endpoint selects a random time within the specified time interval to enroll.
  4. For Select Your Provisioning Package, select the MDM server to which you want to enroll the selected devices.
  5. Click Send Command. A BigFix deployment is generated that initiates MDM enrollment on the selected devices, and users are taken to a deployment document with information on devices targeted and device results. At any point, to stop the deployment, click Stop Deployment.
    Bulk enroll - Status overview

Regenerate Encryption Recovery Key

See Regenerate Encryption Recovery Key.

Unenroll

See Unenroll devices

Send Client Refresh

Use this action to send client refresh to devices.

This action is available for all BigFix managed devices, regardless of whether the device is managed by MDM, by BigFix Native agent, or through cloud plugins.

Send Client Refresh action becomes available under Administration menu, when you select one or more devices from the Device List.
Client refresh
By deploying the Send Client Refresh action, you can send a full client refresh request to devices. It is equivalent to performing Send Refresh on the BigFix Console.
In BigFix 9.5, send client refresh creates an action against targeted devices with the ActionScript notify client ForceRefresh.

In MCM and BigFix Mobile, WebUI sends a direct API call to force clients to perform full refresh.