1. Security
An MDM concentrates administrative power over the whole fleet: whoever controls the console can wipe, lock and locate devices. That makes the security of the product itself matter as much as the features it ships. Look at encryption in transit and at rest, tenant isolation, two-factor authentication for administrators, and an audit trail for every command issued.
Ask the vendor
- — Is there an audit trail of administrative commands, with actor, timestamp and outcome?
- — Does the platform support MFA and granular role-based permissions for the IT team?
- — How is data from different customers isolated on shared infrastructure?
2. Android Enterprise
Android Enterprise is Google’s official API set for corporate management. Solutions built on it — particularly on the Android Management API (AMAPI) — need neither root access nor invasive agents, and they track the security changes in each Android release. Check which modes the vendor actually supports: fully managed, work profile, COPE (corporate-owned, personally enabled) and dedicated/kiosk devices.
Ask the vendor
- — Is management delivered through the Android Management API or a legacy proprietary agent?
- — Which ownership modes are supported: fully managed, work profile, COPE and dedicated?
- — Is the platform recognised in Google’s Android Enterprise program?
3. Enrollment
Enrollment is the step where a device comes under management, and it is usually the biggest operational bottleneck in large fleets. Methods such as QR Code, Zero-Touch and manufacturer programs (Samsung Knox, for instance) let a device arrive configured straight out of the box. The practical question is how much time and manual work each device costs.
Ask the vendor
- — Which methods are supported: QR Code, Zero-Touch, NFC, EMM token, manufacturer programs?
- — Can a device be re-provisioned remotely, without passing through the IT team’s hands?
- — How long does provisioning a batch of 100 devices actually take?
4. Kiosk mode
Kiosk mode locks a device to one app or a restricted set of apps — essential for kiosks, point-of-sale terminals, logistics scanners, self-service tablets and shared equipment. The difference between platforms lies in how far the lockdown customises: hiding the status bar, defining allowed apps, controlling volume and brightness, showing your own branding, and preventing the user from exiting.
Ask the vendor
- — Does kiosk mode allow multiple apps and a custom home screen with our branding?
- — Can we lock the status bar, hardware buttons and system settings?
- — How does the device recover if the kiosk app crashes or is removed?
5. App management
App distribution is what keeps the fleet usable day to day. Check whether the vendor integrates Managed Google Play (the corporate catalogue), whether it can publish internal private apps, whether it controls versions and automatic updates, and whether it can block installs from outside the approved catalogue.
Ask the vendor
- — Is there Managed Google Play integration and support for private in-house apps?
- — Can we pin a specific app version and control when it updates?
- — Can installs from outside the approved catalogue be blocked?
6. Remote management
When a device is lost, broken or misused, the team has to act without holding it. The most-used commands are lock, wipe (full or work-profile only), reboot, lost mode, password reset and location. Beyond commands, assess whether remote screen access exists for support — and how user consent is handled.
Ask the vendor
- — Which remote commands exist, and are all of them recorded in the audit trail?
- — Is there remote screen view or control for support? On which devices?
- — Can a wipe remove only corporate data, preserving personal data on BYOD?
7. APIs and automation
Without an API, every process becomes manual console work. A well-documented API lets you automate employee onboarding and offboarding, sync inventory with your ERP or ITSM, and generate reports on demand. Check too whether webhooks exist for events such as a device falling out of compliance, critical battery or a geofence exit.
Ask the vendor
- — Is the API public and documented? Does it cover the same capabilities as the console?
- — Are there webhooks for events, or only polling?
- — Are there rate limits that could break a daily synchronisation?
8. Scalability
A platform that performs well with 50 devices can crawl at 5,000. Ask about the largest customer in production, how the platform organises groups and policies at scale, and whether bulk actions (pushing a policy to 3,000 devices) run as a batch or one at a time. For anyone managing several companies, multi-tenant architecture makes a real difference.
Ask the vendor
- — What is the largest fleet running on the platform today?
- — How do groups, policy inheritance and bulk actions work?
- — Is the architecture multi-tenant, letting us manage clients or branches separately?
9. Pricing and billing model
Much of the MDM market does not publish pricing and sells consultatively, which makes comparison harder. List price is only part of it: check whether billing is per device or per user, whether there is a contracted minimum, an onboarding fee, extra cost for modules, and what happens to inactive devices. Compare total monthly cost for your fleet size, not the per-device figure in isolation.
Ask the vendor
- — Is billing per device or per user? Is there a monthly minimum?
- — Are there implementation, training or module fees charged separately?
- — Are deactivated devices still billed until the end of the cycle?
10. Support
Support is only noticed when something breaks — and at that point language, time zone and SLA matter more than any product feature. Check available channels, contractual response times by severity, and whether you reach someone who knows the platform or a generic first line.
Ask the vendor
- — What is the SLA for first response and for resolution, by severity level?
- — Does support operate in our language and in our time zone?
- — Is there assisted onboarding or a named technical contact for the account?
11. Compliance and privacy
An MDM processes personal data — location, device identifiers and, in some cases, app usage — which puts it under GDPR in Europe and LGPD in Brazil. Third-party audited certifications such as SOC 2 Type II and ISO 27001 say more than a compliance claim on a website. Check as well where data is hosted and whether the vendor will sign a data processing agreement.
Ask the vendor
- — Do you hold a current SOC 2 Type II or ISO 27001? Can you share the report?
- — In which country is data hosted, and how long is it retained?
- — Do you sign a DPA and support data subject requests (access, deletion)?
12. Reporting and visibility
Without reporting there is no way to prove compliance or justify the investment. Assess whether the platform shows a full inventory (model, Android version, security patch), which devices are out of compliance, data and battery usage, and whether all of that can be exported or scheduled for automatic delivery.
Ask the vendor
- — Which reports ship out of the box, and which have to be built?
- — Can we export to CSV or consume the data through the API?
- — How long is historical data kept available?
13. Integrations
An MDM is rarely the only system involved. Integration with your identity directory (Google Workspace, Microsoft Entra ID) avoids manual user creation; ITSM integration opens tickets automatically; and in environments already running another management platform, being able to coexist avoids migrating everything at once.
Ask the vendor
- — Is there native integration with our identity directory and SSO?
- — Does the platform talk to our ITSM or to our security tooling?
- — Can it coexist with the platform we already run during a transition?