What’s new - Latest Features & Enhancements

Overview of the enhancements made in the current release of BigFix Modern Client Management (MCM) and BigFix Mobile.

The BigFix Modern Client Management (MCM) and BigFix Mobile version 3.7 release introduces several enhancements to improve management flexibility and extend platform support.

ChromeOS Zero-Touch Enrollment (ZTE)

BigFix MCM 3.7 introduces support for ChromeOS zero-touch enrollment (ZTE), enabling IT administrators to ship devices directly to end users for automatic domain registration and corporate policy application upon initial internet connection. This feature streamlines deployment by eliminating manual setup and centralizing lifecycle management, including remote device actions, directly within the BigFix WebUI.

iPadOS Support for Geofencing

Geofencing capabilities are now available for iPadOS devices. The workflow for configuration—creating zones, defining settings, and deployment—mirrors the existing Android and iOS processes.
Note: Ensure the BigFix UEM app is installed on iPadOS devices with location permissions granted to enable these features.

Jailbreak and Root Detection Enhancements

  • Pre-Enrollment Detection for Android: You can now identify and handle rooted or compromised Android devices during enrollment. Administrators can configure to block the enrollment, preventing the device from being added to the MDM server.

For complete information, refer to Jailbreak Detection.

Lost Mode for Mobile Devices

BigFix Modern Client Management (MCM) and BigFix Mobile version 3.7 introduces Lost Mode, a powerful security capability that enables IT administrators to remotely secure, locate, and recover missing or stolen company-owned mobile devices directly from the BigFix WebUI. This feature is accessible under Apps → MCM → Actions → Lost Mode.

Key features and platform capabilities include:

  • Remote Security & Access Control: Activating Lost Mode immediately locks the device and blocks access to all applications, safeguarding sensitive corporate networks and emails from unauthorized access.
  • Custom Recovery Screen Layouts: Administrators can customize recovery information displayed on the lock screen, enforcing mandatory input fields such as custom return instructions and a callback phone number, with optional organization names and footnotes tailored to platform specifications.
  • Platform-Specific Sound Playback:

    • Android: Automatically triggers a continuous sound alert immediately upon mode activation.
    • iOS/iPadOS: Allows administrators to manually trigger or re-trigger a background alert sound as a standalone action to locate a nearby device.
  • Interactive Location Hyperlinks: Location reporting initiates automatically when Lost Mode is deployed. For enhanced usability, the WebUI displays latitude and longitude coordinates as clickable hyperlinks that redirect administrators directly to Google Maps to pinpoint the physical location of the device.
  • Advanced Lifecycle Management: From the Manage Lost Mode interface, administrators can seamlessly execute secondary recovery operations, such as unlocking the device via Disable Lost Mode once found or pushing an irreversible remote Wipe Data factory reset if the device is compromised beyond physical recovery.
Note: Lost Mode is not supported on personally-owned Android BYOD devices, ChromeOS, non-supervised Apple, and Windows endpoints. Input text limitations (For example, a maximum of 150 characters for Lost Mode Messages and 65 characters for iOS footnotes) are automatically enforced directly within the WebUI.

For detailed information, refer to Lost mode.

Remote Access enhancements

The following enhancements and fixes have been implemented for the Remote Access feature to ensure a more reliable and informative user experience:
  • Improved Error Messaging and Session Handling:
    • Device Status Updates: Devices now receive accurate response messages if a remote session is terminated, ensuring the status is clearly communicated in the device logs.
    • Server Restart Recovery: If the management server (MDM broker) restarts during an active session, appropriate error messages are now displayed on both the device and the browser instead of failing silently.
    • Accurate Connection Status: Sessions interrupted by network disruptions are now correctly marked as "failed" in the application rather than "completed," providing a true reflection of the session's outcome.
  • Configuration and Security Refinements:
    • Service Readiness Scans: A new scan feature ensures that all system requirements and port availabilities are verified before allowing a service installation, preventing setup errors.
  • Enhanced Health Monitoring:
    • Visibility Control: Health check details are now intelligently hidden if the service is not installed or if the analysis feature is disabled, reducing clutter on the Health check dashboard.
    • Real-time Dashboard Details: For active installations, the health check page now provides comprehensive details, including the server name, version, secure port information, and the exact time it was last updated.
    • Proactive Failure Alerts: The system now monitors for and reports specific failure scenarios, such as:
      • Stopped or uninstalled services.
      • Inactive or blocked connection ports.
      • Corrupted security certificates or configuration files.

Shared Device Management

BigFix UEM v3.7 introduces Shared Device Management, a secure solution for deploying pooled Android devices to frontline and shift workers. This feature transforms devices into shared tools that maintain strict corporate security while delivering a personalized experience for every user.

Key Highlights:
  • Role-Based Access: When users sign in, they see only the apps and configurations relevant to their specific role or team.
  • Privacy & Automatic Cleanup: All local data—including app history, cache, messages, and files—is automatically wiped upon logout, ensuring a clean slate for the next user.
  • Work Shift Management: Includes built-in tools to track shift schedules, show countdown timers, and automatically sign users out at the end of their shift.
  • Guest Mode: Provides temporary, limited access for visitors (e.g., industrial guests) without requiring personal account credentials.

  • Enterprise Branding: Fully customize the login interface to match your corporate identity with custom logos, colors, and welcome messages.
  • Persistent Enrollment: Devices are enrolled once as "Dedicated Devices" and remain stable across all user login/logout cycles, with no need for re-enrollment.

Read the full documentation here for implementation steps, system requirements, and troubleshooting guides.

Specialized feature enablement

Granular feature enablement: Starting with v3.7, advanced management features—Geofencing, Battery Health, Jailbreak Detection, Remote Access—are now optional and must be explicitly enabled via the updated Feature Configuration screen. This selection is handled on an OS-specific basis rather than globally.

Streamlined Server Configuration: Initial server setup for advanced feature configuration now requires users to input specific environment details, including database (DB) name, region, and credentials, along with a validated GCP service account JSON file. Once deployed, these fields are locked to prevent redundant data entry. For details on the initial server setup and configuration, refer to Feature configuration.

Cloud automation is enhanced quicker set up.

Upgrade: For customers migrating from v3.6 — where advanced features were enabled by default — the upgrade process automatically maps and enables existing features for Android and iOS to ensure continuity.

Web Content Filtering (Allow List / Block List)

BigFix MCM v3.7 introduces comprehensive Web Content Filtering, providing administrators with the ability to manage and secure the web browsing experience on managed devices. By implementing URL-based policies, organizations can ensure that users access only approved content, reducing the risk of data exposure and increasing productivity.

For detailed configuration procedures refer to Web content filter.