Modern Client Management and BigFix Mobile
Welcome to the Modern Client Management and BigFix Mobile documentation, where you can find information about how to install, maintain, and use Modern Client Management and BigFix Mobile.
BigFix Mobile and MCM Overview
Discover how BigFix Mobile and Modern Client Management (MCM) extend unified endpoint management to mobile devices and modern OS platforms like iOS, Android, and Windows 10+, all from a single console.
BigFix Mobile and MCM On-premises Deployment
BigFix Mobile and MCM is available as an On-premises solution. Learn how to deploy BigFix Mobile and MCM in an on-premises environment for secure, centralized mobile device management within your organization's infrastructure.
BigFix Mobile and MCM Key Concepts
Read this section to understand the key concepts of MCM.
User roles
Read this section to understand various users involved in MCM and BigFix Mobile management and their tasks.
Guides in PDF format
This section contains links to PDF versions of all the MCM and BigFix Mobile manuals.
Installing and Configuring BigFix Mobile and MCM
Read this guide to learn about the requirements and available installation scenarios to ensure that the deployment of BigFix MCM and BigFix Mobile goes smoothly in your environment.
MCM and BigFix Mobile server and components installation
This guide provides instructions for installing the MCM and BigFix Mobile server along with its components, ensuring proper setup and configuration.
Identity Service Configuration
Configure identity services for BigFix Mobile and MCM to enable secure authentication and seamless user access. Learn how to integrate with identity providers and streamline user management across Apple, Android, and Windows devices.
Simple Certificate Enrollment Protocol (SCEP) configuration
BigFix MCM supports certificate management and certificate-based authentication through Simple Certificate Enrollment Protocol (SCEP). SCEP is the fastest and most secure way to provision certificates to all your MCM-managed devices. With SCEP, IT Admins can automate issuing certificates to the endpoints to provide access to corporate Wi-Fi, VPN, and secure e-mail through encryption.
Domain join installation and configuration
Read this section to learn the prerequisites and the tasks to install ODJ service to set up your environment to enroll Windows devices and join Active Directory domain or both Active Directory and Azure AD domain.
SAML-authentication configuration
MCM and BigFix Mobile supports Security Assertion Markup Language (SAML) authentication to enroll devices to protect sensitive data and ensure secure access to corporate resources.
Remote Access
The Remote Access feature in BigFix Modern Client Management (MCM) allows administrators to view the screen of managed mobile devices through the BigFix WebUI for troubleshooting and support purposes.
Deployment Guide
This document provides guidance for deploying the certificate enrollment infrastructure required for BigFix Mobile Configuration Management (MCM). It describes how to integrate BigFix MCM with Microsoft certificate services to enable device certificate enrollment using the Simple Certificate Enrollment Protocol (SCEP).
Deployment architecture
The following diagram illustrates the deployment architecture for integrating BigFix MCM with the certificate enrollment infrastructure. It shows the key components involved in the certificate enrollment workflow, including Active Directory, Microsoft Certificate Authority (CA), Network Device Enrollment Service (NDES), NDES Proxy, LDAP Proxy, and BigFix components.
Infrastructure prerequisites
Before configuring certificate enrollment for BigFix MCM, ensure that the required infrastructure components and access permissions are available. The certificate enrollment workflow relies on integration between Active Directory, Microsoft Certificate Services, NDES, and BigFix components.The following prerequisites should be verified before proceeding with the configuration steps described in this guide.
Active Directory setup
Active Directory provides the directory services required for integrating Microsoft Certificate Authority (CA) and Network Device Enrollment Service (NDES). The following steps ensure that the Active Directory environment is properly prepared before configuring the certificate enrollment infrastructure.
Certificate Authority (CA) Configuration
The Microsoft Certificate Authority (CA) is responsible for issuing certificates requested through Network Device Enrollment Service (NDES) using the Simple Certificate Enrollment Protocol (SCEP).This section describes the required configuration on an existing Enterprise Certificate Authority to support certificate enrollment.
SCEP Certificate Template Configuration
A custom certificate template must be created to support SCEP-based certificate enrollment with required security and key configurations.
NDES Installation and Configuration
The Network Device Enrollment Service (NDES) provides the SCEP interface that allows devices managed by BigFix MCM to request certificates from the Microsoft Certificate Authority. This section describes how to install and configure NDES and verify that it is ready to process certificate enrollment requests.
NDES Proxy Configuration
This document provides step-by-step instructions for installing and configuring HAProxy as a proxy for the Network Device Enrollment Service (NDES), covering both challenge and certificate enrollment requests.
LDAP Proxy Configuration
This section provides step-by-step instructions to install and configure OpenLDAP as an LDAP proxy on RHEL 8.
BigFix Configuration for Certificate Enrollment
This section describes how to configure BigFix MCM to integrate with the certificate enrollment infrastructure using NDES Proxy and LDAP Proxy.
SCEP Profile Configuration in BigFix
This section describes how to create and configure a SCEP profile in BigFix MCM to enable device certificate enrollment using the configured NDES Proxy infrastructure.
Communication Ports and Network Flow
This section describes the network communication paths and required ports between components involved in the certificate enrollment workflow for BigFix MCM.
Certificate Enrollment Flow
This section describes the end-to-end certificate enrollment flow for devices managed by BigFix MCM, using MCM Proxy, NDES Proxy, and Microsoft Certificate Authority.
How-to guide
This section provides step-by-step instructions for setting up a BigFix environment, focusing on integration with third-party prerequisites such as Apple Business Manager and Google Play. It guides users through the necessary configuration steps to ensure seamless interoperability with these external services.
Apple Business Manager Quick Start Guide for DEP
The purpose of this document is to provide a quick start into the Apple Business Manager (ABM) portal steps required to get macOS devices enrolled into MCM and iOS and iPadOS devices enrolled to BigFix Mobile using Apple Device Enrollment Program (DEP).
How to create a Microsoft developer account
You need Microsoft developer account to create WNS credentials. WNS credentials is needed to install or upgrade Windows MDM server and utilize BigFix MCM features.
Windows Autopilot configuration guide
This guide provides step-by-step instructions for configuring Windows Autopilot, tailored for BigFix Admins and IT teams. It covers both manual setup in the Azure portal and automated configuration using the autopilotcli tool, ensuring a streamlined deployment process.
Windows Errors
This topic provides a list of common errors encountered when enrolling Windows endpoints using Windows MDM through BigFix MCM. It includes links to detailed information on Windows MDM errors, WinHTTP errors, XML parsing errors, and Windows BITS client errors.
Sample Android Custom Policies
This topic provides sample Android custom policies in JSON format for use with BigFix WebUI, covering configurations such as kiosk mode, Wi-Fi restrictions, app verification, and VPN setup. Each policy can be modified to meet organizational requirements and includes guidance for uploading and assigning policies. Reference links to official documentation are provided for further customization and policy details.
Configure NDES server for SCEP
Learn how to configure the Network Device Enrollment Service (NDES) on a Windows Server to enable Simple Certificate Enrollment Protocol (SCEP) infrastructure. This topic outlines installation prerequisites, provides a step-by-step guide, and offers troubleshooting resources for common NDES issues.
Okta integration with LDAP
Integrating Okta with an LDAP server allows users to authenticate to Okta using their LDAP credentials. This integration is required to enable SAML authentication for device enrollment.
Azure AD registration and configuration
MCM integrates with Azure Active Directory to enable identity and access management features, including conditional access, role-based access control, and identity governance. These capabilities help you manage and secure access to applications and resources. Refer to the linked documentation for detailed configuration steps.
Okta configuration for enabling Device Trust
BigFix Mobile enables Device Trust integration with Okta, allowing secure access from trusted devices. Configuration involves setting up Okta for domain and management hints, followed by managed app policies for deployment. Refer to the linked documentation for detailed setup instructions.
Windows custom policies
You can find sample Windows policies on this page. You can create custom policy through WebUI using these sample policies.
Delegation of Control to enable Offline Domain Join
This document provides step-by-step instructions for delegating control to a domain user, enabling them to perform offline domain joins beyond the default limit of 10 computers without requiring domain admin privileges. The process involves configuring permissions in Active Directory Users and Computers for the relevant Organizational Units. For further details on domain join installation and configuration, refer to the BigFix MCM Help Center.
Quick Start
This quick start guide gets you up and running with your BigFix MCM and BigFix Mobile solution. It helps you secure, configure, and manage your mobile devices quickly and efficiently.
Administrator Guide
Read this guide to learn about enrolling, administering, and troubleshooting endpoints through BigFix MCM and BigFix Mobile.
Modern Client Management and BigFix Mobile
This guide is intended for HCL BigFix Master Operators (MO) and those who administer BigFix deployments. If you are looking for information about using Modern Client Management (MCM) and BigFix Mobile, see the WebUI User's Guide.
BigFix MCM
Read this section to learn enrolling and managing Windows and macOS desktop and laptop devices.
BigFix Mobile
BigFix Mobilesimplifies the management and security of Android, iOS, and iPadOS devices, enabling IT admins to seamlessly enroll, configure, and monitor mobile devices, ensuring compliance and protection of corporate data.
Feature configuration
The Feature Configuration page in BigFix WebUI enables you to target specific MDM servers and deploy advanced feature modules to managed endpoints. After uprading to MCM v3.6 or later, use the Feature Configuration page to activate specialized management capabilities like Geofencing, Battery Health monitoring, Jailbreak detection, and Remote Access for your MDM servers.
SCEP Certificate-based authentication
BigFix MCM supports certificate-based authentication through Simple Certificate Enrollment Protocol (SCEP). SCEP is the fastest and most secure way to provision certificates to all your MCM-managed devices. With SCEP, IT Admins can automate issuing certificates to the endpoints to provide access to corporate Wi-Fi, VPN, and secure e-mail through encryption.
SAML-authenticated enrolment flow
When you configure SAML as the authentication method, when a user hits the enrollment URL and click Enroll, the user is first authenticated via the identity provider before proceeding with the enrollment process.
Application management
App Management in BigFix Mobile and MCM provides a centralized way to distribute, update, and control applications across multiple device platforms. Administrators can deploy both public store apps and internal corporate apps, enforce policies, and secure company data while simplifying the app lifecycle for end users.
Battery health and level monitoring
The Battery Health feature provides visibility and proactive monitoring of mobile device battery performance to improve device reliability and minimize user productivity disruption. Monitoring is event-driven and avoids continuous polling mechanisms.
Email configuration management
With BigFix MCM and BigFix Mobile, you have the ability to install and set up email application that can connect to your email system. This allows users to easily connect, verify their identity, and synchronize their work email accounts on their devices.
VPN management
BigFix MCM and BigFix Mobile enable organizations to manage and configure Virtual Private Network (VPN) settings on enrolled Android, Apple, and Windows devices, ensuring secure remote access to corporate networks.
Wi-Fi configuration management
BigFix MCM and BigFix Mobile offer WiFi configuration management, where administrators can control and configure the wireless network settings on MCM-enrolled devices. This helps organizations to maintain a secure and reliable wireless network infrastructure while providing flexibility for users to connect to authorized networks.
Jailbreak Detection
Jailbreak Detection enables administrators to identify compromised mobile devices enrolled in the MDM platform.
Geofencing
Geofencing is a location-based technology that creates a virtual boundary (or “zone”) around a real-world area using GPS, Wi-Fi, cellular data, or RFID signals.
Remote Access
This procedure outlines the steps required to start a Remote Access session using Modern Client Management.
BigFix MCM and Mobile Known Limitations
This topic lists known limitations and restrictions in BigFix Modern Client Management (MCM) and BigFix Mobile for each version. Use this to understand feature gaps, known issues, or unsupported configurations relevant to your environment.
Troubleshooting
This section is intended to help you solve problems that might occur when installing BigFix MCM and BigFix Mobile.
Frequently Asked Questions
Read this section for commonly asked questions and their answers to manage the MCM deployments better.
Glossary
This glossary provides terms and definitions for the BigFix software and products.