Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Look for a coverage matrix across enrollment modes, since BYOD vs. corporate-owned devices need genuinely different policy models, not the same profile applied everywhere.
BYOD adoption depends on credible privacy separation — look for a container/work-profile model with explicit, user-verifiable limits on admin visibility, not vague 'we respect privacy' assurances.
Look for graduated, automated remediation tied to compliance state, not just a dashboard flag requiring manual admin follow-up on every non-compliant device.
Per-app VPN and app-level DLP are what separate real enterprise mobility management from basic device-list MDM — look for these specifically, not just app push capability.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for a real IdP integration (Entra ID Conditional Access, Okta) with a stated revocation latency — compliance policy without access enforcement is just a report nobody acts on.
Look for an honest answer on offline-device wipe behavior (queued command executed on next check-in, with a stated typical delay) — a platform that implies instant wipe regardless of connectivity is overpromising.
Shared/dedicated-device fleets are a distinct use case from BYOD/corporate-issued — look for specific kiosk-mode capability and remote diagnostics, not just standard MDM applied to a shared device.
Look for real-time (not daily-batch) inventory and framework-mapped exportable reports — stale inventory data undermines every other compliance claim built on top of it.
Look for transparent, tier-differentiated pricing; a vendor who can't distinguish full-MDM cost from lighter app-level-management cost may be overselling one for a use case that needs the other.
Remote wipe alone doesn't answer 'what was actually exposed before we wiped it' — ask for a real forensic-reconstruction capability and a concrete customer incident example.
Compliance-policy enforcement (encryption required, jailbreak detection) is distinct from active threat detection — a vendor should clarify whether real MTD-style detection exists natively or requires a separate product.
Full MDM enrollment is often a nonstarter for personal-device users (privacy concerns) — ask for a real lighter-weight containerization alternative and how its security posture compares.
A vendor with only single-region processing regardless of the managed device's actual location is a real compliance gap for a global, regulated workforce.
Ask for a real completion-rate figure from a customer reference, not just a provisioning capability — incomplete rollout leaves real coverage gaps.
Trend-over-time compliance reporting is a distinct capability from a real-time snapshot — confirm this exists as a maintained, exportable report.
A real, documented API is materially more useful for a mature IT/security team than console-only access requiring manual export for every downstream use case.