5 Questions to Ask Before Your First MDM Deployment

Deploying mobile device management for the first time is one of those projects where the decisions you make before you start have more impact than almost anything you do during implementation. Get the fundamentals right upfront, and rollout is smooth. Skip them, and you’ll spend weeks untangling problems that were entirely preventable.

These are the five questions every organization should answer before enrolling the first device in an MDM platform.

1. What Do You Actually Need These Devices to Do?

This sounds obvious, but it’s the question most organizations answer too loosely. “Manage our tablets” is not a use case. “Lock down 200 Android tablets to a single inventory app, push updates without manual intervention, and get alerted when any device goes offline” is a use case, and it’s the kind of specificity that determines which MDM features you need, which platform is the right fit, and how you should configure devices at enrollment.

Start by mapping out the device journey. What is the device doing? Who interacts with it, and how? What apps does it run? Does it need to display content that changes regularly? Does it process payments? Does it handle sensitive data? Is it customer-facing or employee-facing?

For organizations deploying kiosks, POS systems, or digital signage, the answers will drive very different configurations than organizations deploying field service tablets or warehouse handhelds. Moki is purpose-built for dedicated device use cases, single-purpose devices that need to do one job reliably, consistently, and securely. That’s a different design philosophy than an MDM platform built for employee smartphones, and it matters when you’re configuring devices at scale.

The more precisely you define what your devices need to do, the better your MDM configuration will map to your actual operational needs rather than a generic template.

2. Which Devices and Platforms Are You Managing?

MDM capabilities are not uniform across device platforms. What you can do with a supervised iOS device differs from what you can do with an Android Enterprise device, which differs again from a BrightSign player or a Zebra scanner. Before selecting and configuring your MDM platform, inventory your hardware.

You need to know the operating systems and versions your devices run. MDM features often depend on specific OS versions, and older OS versions may not support the management APIs you need. This is especially relevant if you’re inheriting an existing device fleet rather than purchasing new hardware.

You also need to define the device ownership model. Are these company-owned, company-provisioned devices, or do you have any BYOD in the mix? MDM configuration, particularly what you can restrict and how much visibility you have, differs significantly between corporate-owned and personally-owned devices. For dedicated device deployments, corporate ownership is almost always the right model because it enables full management capability.

If you’re managing a mix of iOS, Android, and BrightSign devices, make sure the MDM platform you select handles all three natively rather than requiring separate tools for different platform types. Moki supports iOS, Android Agent, Android Enterprise, and BrightSign from a single dashboard, which is a significant operational advantage over managing multiple point solutions.

Some Android device manufacturers, including Zebra and others, offer MDM extensions that unlock additional management capabilities specific to their hardware. If your fleet includes specialty hardware, confirm that your MDM platform supports those extensions before committing to a platform.

3. How Will You Handle Enrollment at Scale?

Device enrollment is the process of getting a device into MDM management. For small fleets, manual enrollment is manageable. For deployments of 100 devices or more, manual enrollment is a time sink that introduces configuration inconsistencies. Before your first deployment, plan your enrollment process.

Zero-touch enrollment is the gold standard for Android. Through Google’s Zero-Touch Enrollment program, devices ship pre-configured to automatically enroll in your MDM platform when they’re first powered on. No manual setup. No QR code scanning. No IT staff on-site at every location. The device boots, connects to Wi-Fi, and enrolls itself.

Apple’s Device Enrollment Program, now part of Apple Business Manager, offers the equivalent for iOS devices. Devices purchased through Apple or an authorized reseller can be pre-assigned to your MDM platform and auto-enroll on first activation.

For BrightSign deployments, Moki’s BrightSign MDM supports streamlined enrollment and remote provisioning so you’re not configuring players one at a time.

The enrollment method you choose affects how quickly you can deploy new devices, how consistently devices are configured, and how much labor your rollout requires. Planning this before your first deployment, rather than after you’ve already ordered 500 devices, is the difference between a smooth launch and a scramble.

4. What Policies and Restrictions Do You Need?

MDM is most valuable when it enforces a consistent set of device policies at scale. But policies that aren’t thought through before deployment either leave gaps in your security posture or create operational friction that people work around.

Walk through the following policy categories before enrollment begins.

App management

What apps are permitted on these devices? For dedicated-purpose devices, this is typically a short list: the core application the device is deployed to run, plus any supporting tools. App allowlisting ensures devices only run approved apps, preventing employees or customers from installing unauthorized software.

Network access

What Wi-Fi networks should these devices connect to? Should they be restricted to a specific corporate network, or do they need to function on any available connection? How do you handle devices that go offline?

Security policies

Should devices lock after a period of inactivity? What happens after a defined number of failed unlock attempts? Is remote wipe enabled for all devices? These policies are critical for device security and should be set before devices enter the field, not after an incident prompts a review.

Content and update policies

How and when will app updates be pushed? Who has permission to push updates? Is there a staging or approval process before updates reach production devices? Defining this upfront prevents the scenario where an untested update breaks a kiosk at 300 locations simultaneously.

Compliance requirements

If your devices handle payment card data, health information, or other regulated data, your MDM policies need to align with relevant compliance frameworks. For PCI DSS, this includes requirements around device encryption, access control, and logging. For HIPAA, it includes controls around protected health information access and breach response. Map your compliance requirements to specific MDM policy configurations before you deploy.

5. Who Owns This After Deployment?

MDM is not a set-it-and-forget-it investment. Devices need ongoing management: updates pushed, alerts reviewed, new devices enrolled, departing devices decommissioned, policies updated as your business evolves. Before your first deployment, define who owns each of these ongoing responsibilities.

The most common failure mode for MDM deployments isn’t the technology, it’s the lack of a clear owner. The platform is configured, devices are enrolled, and then nobody is explicitly responsible for monitoring alerts, acting on policy changes, or keeping the platform configured correctly as the fleet evolves. Ownership drifts, discipline erodes, and the consistency the MDM was deployed to deliver starts to slip.

Define in writing before deployment: Who monitors device alerts, and in what timeframe do they respond? Who has authority to push updates? Who manages new device enrollment and end-of-life decommissioning? Who reviews and updates policies on a defined cadence?

For organizations that don’t have internal IT staff with MDM expertise, Moki’s Managed Services offering handles ongoing management on your behalf, monitoring, alerting, update management, and policy administration managed by Moki’s team so you don’t have to build internal expertise from scratch.

The organizations that get the most long-term value from MDM are the ones that treat it as an ongoing operational discipline rather than a one-time deployment project. Answering this ownership question before the first device enrolls is the single most impactful thing you can do to protect that long-term value.

Ready to put these answers to work? Start with a free trial of Moki or request a personalized demo to see how the platform maps to your specific deployment.

See Moki in Action

Request a Demo today with by phone, email, or just fill out the form






Skip to content