Managed MDM handles the setup, configuration, and ongoing management of your organization's device management platform (JumpCloud), so your devices stay secure and compliant without requiring your own IT team. It's a collaborative service: Deel IT manages the environment on your behalf, but your input guides the policies and priorities.
- Service: Managed Mobile Device Management (MDM)
- Availability: Global
- Platform: JumpCloud
- Type: Ongoing managed service
What's Included
- Setup and environment configuration
- Device enrollment support
- Device policy management and enforcement
- Patch and software update management
- On-device application management
- Day-to-day changes and updates on request
- Ad-hoc device actions (lock, wipe, retirement)
- Fleet reporting on request
In this article
Scope of Service
Setup and Onboarding
Deel IT configures the user's MDM environment, tenant, device groups, policies and assignment, and integration with the Deel platform, informed by requirements gathered at kickoff. Policy migration from an existing MDM is excluded here; it is delivered under the separate MDM Migration service.
Device Enrollment
Enrollment is the user's responsibility unless the device pre-configuration service is purchased as an add-on. Once purchased, the method depends on region:
- New devices - automated in Deel IT hub regions (with Apple Business Manager set up beforehand), where devices are configured before delivery and enroll on first boot with no user action; user-driven elsewhere, handled by Deel IT via a short video call
- Existing devices - Deel IT provides a self-enrollment page. The user distributes it internally; Deel IT is not responsible for chasing end users to enroll
Policy Management
Deel IT configures device policies to the user's goals and requirements, which the MDM enforces on devices. The service deploys and manages the policies the MDM provider natively supports; custom policy implementations beyond the provider's native set are not supported. Deel IT does not monitor in real time when a device deviates from its desired state; configuration drift is surfaced and resolved in accordance with fleet reporting.
Patch and Software Update Management
Deel IT implements the user's preferred patch-management and operating-system (OS) upgrade rules through the MDM. Deel IT does not monitor patch status in real time; failed or missed patches are surfaced and resolved through periodic reporting.
On-Device Application Management
Deel IT deploys and maintains user-approved applications across the fleet through the MDM. The user decides which applications belong on which devices; Deel IT deploys and enforces that decision. Deel IT does not vet or assess the security or suitability of third-party applications.
Day-to-Day Operations
Deel IT implements requested changes to the MDM environment, policy modifications, tenant adjustments, and reports. Requests must be submitted through the official Deel IT support channel (techsupport@deel.com) and are validated and implemented by Deel IT. Routine changes are included; wholesale redesign of the policy environment is handled separately.
Ad-Hoc Actions
On request via an official Deel IT support channel, Deel IT can perform ad-hoc device actions such as remote lock, wipe, selective data removal, device retirement, and recovery-key retrieval on the user's behalf. These actions are also available to the user directly in the Deel IT and MDM platforms.
Fleet Reporting
On request, Deel IT can provide periodic reporting (for example, bi-weekly) using data from the Deel IT and MDM platforms. This is not real-time monitoring: Deel IT does not track individual non-compliant devices continuously or chase end users. Reports surface where devices have drifted from policy or missed patches; the user reviews them and flags what needs action. Where the fix is within MDM (e.g., re-applying a policy, reinstalling the agent, re-issuing a patch), Deel IT executes it on request. Where resolution depends on end-user behavior, it is the user's responsibility.
What's Not Included
- Device procurement or hardware repair
- Enrollment chasing (user distributes enrollment link)
- Real-time device monitoring
- Custom policy implementations beyond platform capabilities
- Direct end-user support (available through 24/7 Tech Support)
- Policy migration from existing systems