Enroll with intent
Prepare platform certificates, distribute your Apple enrollment profile or signed desktop installer, and verify the first check-in.
Beam MDM · Apple + Windows
The devices your team works on deserve the same attention as the agents they run.
Enroll Apple and Windows devices, deploy their settings, and follow remote operations from your Beam workspace.
Self-hosted service · Fleet-powered MDM · Intune integration available
24
Managed devices
2
Platforms
1
Workspace
Design MacBook
macOS
Engineering PC
Windows
Team iPad
iPadOS
From setup to daily operations
Prepare platform certificates, distribute your Apple enrollment profile or signed desktop installer, and verify the first check-in.
Deploy Apple configuration profiles and Windows configuration files. Inspect each device’s reported delivery state as settings reach the fleet.
Refresh inventory and track submitted operations. Enabled remote actions require administrator access, device confirmation, and password verification.
Apple
Apple enrollment profiles and device settings, backed by the platform’s management protocols. Use manual enrollment or configure Apple Business Manager in the engine for automated enrollment.
Requires Apple MDM push and identity certificates. Available controls depend on OS version, supervision, enrollment type, and engine configuration.
Windows
Workspace installers, enrollment state, and Windows configuration profiles in the same operational view. See when a device last checked in and whether its settings have reached it.
Requires Windows enrollment identity setup and a signed installer. Enrollment needs a signed-in user; supported actions vary by edition and engine configuration.
Choose your connection
Deploy Beam’s management service with a dedicated Fleet engine per workspace. Beam provides the workspace controls and operation history; Fleet runs enrollment and device protocol delivery. Fleet-based lock and wipe require Fleet Premium. Certificates and signed packages are provisioned by your deployment administrator.
Use native Apple lock and erase commands through a separately provisioned NanoMDM enrollment, or Beam’s signed Windows worker for session disconnect and OS reset. This path does not require Fleet Premium. It adds per-device wipe enablement, password verification, explicit confirmation and a command journal. Windows session disconnect is not persistent device lockout. Certificates, signing and real-device validation are required before activation.
Connect an existing licensed tenant to review Apple and Windows inventory, provider-reported compliance and encryption, and request device sync. Enrollment and policy management stay in Intune for this connection.
Start with a test fleet. Verify enrollment, then plan your rollout.