Oneleet MDM
Oneleet MDM lets your team manage company-owned devices from the same dashboard as the rest of your security and compliance program. Admins can confirm that devices are managed, see each device’s security posture, enforce security settings, and take remote action when a device is lost, stolen, or being offboarded.
How a device is managed depends on its platform:
- Apple devices — Macs enroll through Apple’s Mobile Device Management framework, either manually or zero-touch through Automated Device Enrollment, and the Oneleet Agent is installed automatically after enrollment.
- Windows devices — Windows devices are managed through the Oneleet Agent, which installs in minutes and delivers security checks, configuration policies, and remote actions with no enrollment infrastructure to set up first.
- Linux devices — Linux workstations are managed through the Oneleet Agent as well, with security checks and remote actions across major distributions.
Whichever path a device takes, it appears in the same Devices view in the Oneleet Dashboard, and the capabilities below apply across platforms.
The Managed badge and MDM enrollment filter use the same status across macOS, Windows, and Linux. Managed includes Macs enrolled in your organization’s Oneleet MDM and Windows or Linux devices included by enrollment rules or device exceptions. Not managed includes devices excluded from those rules and Macs that aren’t currently enrolled in your organization’s Oneleet MDM. The filter’s Unenrolled (Mac) option finds Macs that unenrolled from your organization’s Oneleet MDM.
Choose which Windows and Linux devices are managed
Section titled “Choose which Windows and Linux devices are managed”Open Device Monitoring → Configuration Profiles, choose Windows or Linux, and select MDM enrollment. Each platform has its own enrollment rule:
- All devices includes the platform’s devices in MDM. This is the default, preserving existing management until you change the rule.
- Specific people groups includes devices whose assigned Device owner belongs to any selected people group. Changes to group membership or device assignment affect enrollment automatically. Unassigned devices don’t match a group.
- Devices selected individually includes devices with an explicit device exception.
Review the affected devices before saving. Group rules apply to current and future devices.
You can’t delete a people group while a Windows or Linux enrollment rule uses it. Remove the group from the rule first. If it’s the rule’s last selected group, choose another group or a different enrollment rule.
To make a device exception, open the device and choose Manage device → MDM enrollment. Choose Include in MDM or Exclude from MDM, optionally record a reason, and save. Device exceptions take precedence over group rules. Choose Follow enrollment rules to return the device to the platform’s enrollment rule.
For an employee’s personal device, choose Exclude from MDM. The Oneleet Agent stays installed and security monitoring continues, including compliance results. Exclusion is separate from archiving a device or changing its compliance scope.
Archived Windows and Linux devices aren’t managed. To change an archived device’s enrollment or use management actions, first choose Manage device → Unarchive.
Excluded devices can’t receive new remote management commands or automatic fixes. Queued commands are checked again before delivery. A command already delivered to the agent may still finish. On Windows, the agent stops enforcing your organization’s configuration policies after its next successful policy download from Oneleet, which happens within about 15 minutes while the device is online. Until then, the agent keeps re-applying the policies it already has, so a device that stays offline or can’t reach Oneleet may keep enforcing them indefinitely. If another organization that uses Oneleet also manages the device, that organization’s policies still apply. Excluding a device doesn’t undo settings that were already applied, decrypt its disk, or uninstall the agent. The enrollment label describes the current rule, not confirmation that an offline device has received it.
Linux supports the same enrollment controls for remote actions. Linux configuration policies remain in progress.
Secure defaults
Section titled “Secure defaults”When device configuration management is enabled for your workspace, Oneleet offers a recommended secure baseline for macOS and Windows that can be applied in one click. Applying the secure defaults pre-fills settings as your organization-wide device policy - nothing is locked in. Every value stays editable, admins can override individual settings per device, and teams that prefer to build their own policy from scratch can skip the baseline entirely.
Activity log
Section titled “Activity log”Oneleet records device management actions in the device activity log. This gives admins a history of who requested an action, what action was sent, and how it completed.
The log also records MDM profile installed and MDM profile removed when a Mac reports enrollment in or removal from Oneleet MDM. These informational events appear as completed activities. Open an event to view its device and enrollment details in the Result section, or use the activity type filters to find installation and removal events.
Re-enrolled in MDM records a new enrollment for a Mac with a previous enrollment history, including when no removal event was received. Its details include the previous enrollment or removal time when available. This event confirms another enrollment; it does not establish why the device re-enrolled or whether it was erased.
This is useful for:
- confirming that an action such as a wipe or restart was requested and completed;
- reviewing device offboarding activity;
- keeping an audit trail for security and compliance reviews.
Remote actions delivered through the Oneleet Agent are also cryptographically signed and expire if not picked up promptly, so devices only execute instructions that verifiably came from Oneleet.
Automatic agent updates
Section titled “Automatic agent updates”The Oneleet Agent keeps itself up to date with cryptographically signed update packages — there is nothing for admins or employees to maintain after installation.