Every company phone and tablet
under one policy.
Aegis UEM enrolls, locks down and monitors your Android and iOS fleet from a single console. Write the policy once — we translate it to Android Management API and Apple configuration profiles for you.
Ask your fleet in plain language — answers come with the devices and a one-click fix.
Policy, enrollment and device commands
App approval and delivery
Signed configuration profiles
Automated Device Enrollment and app licences
Push wake-ups that trigger device check-in
Device identity certificates issued at enrollment
Ask your fleet a question.
Get the devices, not a dashboard.
Aegis already collects every device's hardware, software, policy state and command history. AI turns that into plain-language answers — and the remediation is one click away, because it's the same bulk action the console already runs.
Grounded in tenant data only. No fleet data leaves your tenant for model training.
Describe the lockdown in words; review the generated policy field by field before it pushes.
Flags the device that suddenly left kiosk, changed SIM, or stopped reporting.
Two platforms. Three enrollment paths.
Windows, macOS and ChromeOS are on the roadmap — we'd rather tell you that now than in month three of a rollout.
Android Management API
Fully managed, work profile and dedicated (kiosk) modes. Apps distributed through Managed Google Play, zero-touch or QR enrollment.
Our own device-owner app
The budget tablets and rugged handhelds that ship without Google services — managed by our DPC agent, with the same policy model. Most MDM vendors simply can't touch these.
Apple MDM protocol
Signed configuration profiles over APNs. Supervised via Apple Business Manager for Single App Mode, Lost Mode, locate and full restriction control.
Write it once. We speak both dialects.
You configure a normalized policy. Aegis translates it into an Android Management API policy and an Apple configuration profile, then reconciles what each device actually reports back.
{
"cameraDisabled": true,
"screenCaptureDisabled": true,
"passwordPolicies": [{
"passwordQuality": "ALPHANUMERIC",
"passwordMinimumLength": 6 }],
"kioskCustomLauncherEnabled": true,
"applications": [ … 7 allowed ]
}com.apple.applicationaccess allowCamera = false allowScreenShot = false com.apple.mobiledevice.passwordpolicy minLength = 6 requireAlphanumeric = true com.apple.app.lock (supervised) com.apple.wifi.managed
Supervision matters: on iOS most block-and-force controls require an ABM-supervised device. The console tells you which of your devices qualify before you push.
Everything below is shipping today.
Kiosk & lockdown
Single-app or multi-app kiosk on Android and supervised iOS. Lock the device to the job, not the whole OS.
App allow / block lists
Push from Managed Play or upload your own APK. Approve, force-install, or silently remove.
Hardware controls
Camera, microphone, screenshots, USB, Bluetooth, tethering, factory reset — on or off per group.
Time-bound access
Grant an app or a policy exception that expires by itself. No sticky “temporary” unlocks.
Dynamic groups & bulk actions
Group by site, model or role, then lock, reboot or repush policy to the whole group at once.
Compliance auto-remediation
Define the rule once — a drifted device gets flagged and corrected without a ticket.
Lock, wipe, locate, Lost Mode
Remote commands with a full command history — who ran what, when, and whether the device acked.
Enrollment that scales
QR and token enrollment, 1:1 or shared-device assignment, ADE for Apple hardware.
Inventory & audit log
Hardware, OS, storage, battery, last-seen and every admin action, retained per tenant.
Know what every device is doing — or when it stopped.
Search 1,200 devices by serial, IMEI or UDID. Filter by platform, enrollment state, compliance and management mode. Select rows and act in bulk.
Where teams put it to work
Logistics & field
Shared rugged handhelds locked to the scanning app.
Retail & POS
Store tablets in kiosk mode, updated after hours.
Schools & EdTech
1:1 tablets, exam lockdown, time-bound app access.
Healthcare
Shift-shared iPads with enforced passcode and wipe.
Built multi-tenant, encrypted, and auditable.
Every tenant is isolated at the data layer. Credentials — Google service accounts, APNs push certificates, VPP tokens — are encrypted at rest with rotatable keys.
One console, many organizations — sell to a group, not one site.
Envelope encryption with documented key rotation.
Owner, admin and member scopes; 2FA and passkeys.
Every push, command and login recorded per tenant.
An honest roadmap
— because month three is a bad time to find out- Android GMS + non-GMS + iOS
- Kiosk & exam lockdown
- App allow / block lists
- Hardware restriction controls
- Time-bound app access
- Temporary policy unlocks
- Dynamic groups, bulk actions
- Lock / wipe / locate / Lost Mode
- Compliance auto-remediation
- Audit log & command history
- Multi-tenant + encryption
- QR, token & ADE enrollment
- Recurring schedules (9am–3pm)
- Per-app usage analytics
- Web / URL content filtering
- Email & push alerting
- CSV & report exports
- VPN and per-app VPN
- Aegis AI fleet queries
- AI policy drafting
- Windows & macOS
- Onboarding wizard
See it against your own fleet.
Bring two devices — one Android, one iPhone or iPad. In 30 minutes we'll enroll them live, push a policy and lock one into kiosk mode while you watch.
We reply within one business day. No newsletter, no drip sequence.