Skip to content

Oneleet MDM

Oneleet MDM lets your team manage company-owned devices from the same dashboard as the rest of your security and compliance program. Admins can confirm that devices are managed, see each device’s security posture, enforce security settings, and take remote action when a device is lost, stolen, or being offboarded.

How a device is managed depends on its platform:

  • Apple devices — Macs enroll through Apple’s Mobile Device Management framework, either manually or zero-touch through Automated Device Enrollment, and the Oneleet Agent is installed automatically after enrollment.
  • Windows devices — Windows devices are managed through the Oneleet Agent, which installs in minutes and delivers security checks, configuration policies, and remote actions with no enrollment infrastructure to set up first.
  • Linux devices — Linux workstations are managed through the Oneleet Agent as well, with security checks and remote actions across major distributions.

Whichever path a device takes, it appears in the same Devices view in the Oneleet Dashboard, and the capabilities below apply across platforms.

When device configuration management is enabled for your workspace, Oneleet offers a recommended secure baseline for macOS and Windows that can be applied in one click. Applying the secure defaults pre-fills settings as your organization-wide device policy - nothing is locked in. Every value stays editable, admins can override individual settings per device, and teams that prefer to build their own policy from scratch can skip the baseline entirely.

Oneleet records device management actions in the device activity log. This gives admins a history of who requested an action, what action was sent, and how it completed.

This is useful for:

  • confirming that an action such as a wipe or restart was requested and completed;
  • reviewing device offboarding activity;
  • keeping an audit trail for security and compliance reviews.

Remote actions delivered through the Oneleet Agent are also cryptographically signed and expire if not picked up promptly, so devices only execute instructions that verifiably came from Oneleet.

The Oneleet Agent keeps itself up to date with cryptographically signed update packages — there is nothing for admins or employees to maintain after installation.