Fleet Management
Fleet management is the coordinated inventory, configuration, updating, security, support, and retirement of an organization's computers and mobile devices. A central service keeps many endpoints in a known state while each device reports what actually happened.
itInfrastructure and operations | OpenSkills.info
Intro
Fleet management
Fleet management is the coordinated control of an organization's computers, phones, tablets, kiosks, and other endpoints. It gives an operations team one system for discovering devices, enrolling them, assigning policy, distributing software, checking state, responding to loss, and retiring them.
The word fleet emphasizes that an endpoint is not managed in isolation. A configuration that works on one laptop still has to reach thousands of devices with different owners, operating systems, locations, and network conditions. Fleet management turns those differences into explicit groups, ownership models, policies, deployment waves, and exceptions.
Mobile device management, or MDM, is one part of this field. MDM uses management frameworks built into operating systems to enroll devices and deliver settings or commands. Unified endpoint management, or UEM, brings several platforms and device classes into one administrative system. Client management and remote monitoring and management products often use installed agents for inventory, software delivery, scripting, and support. A fleet can use more than one mechanism, but it still needs one accountable inventory and a clear source of truth for each control.
The control loop
A managed fleet is a feedback system with five recurring stages:
- Identify. Record the device, its hardware identity, owner, purpose, operating system, and management status.
- Enroll. Establish trust between the device and a management service. Enrollment may use an operating-system framework, an installed agent, a certificate, or a combination of these.
- Declare. Assign desired state through profiles, policies, applications, scripts, update rings, or compliance rules.
- Observe. Collect inventory, check-in time, configuration state, update state, security posture, and command results.
- Reconcile. Compare observed state with desired state, then remediate, quarantine, investigate, or record an approved exception.
The management plane holds inventory, assignments, desired state, administrative roles, and audit history. The endpoint-side client applies supported settings and reports status. Some platforms build this client into the operating system. Others require an agent. A notification service may prompt a device to check in, but the device usually initiates the authenticated management session.
This distinction matters during troubleshooting. A console can show that a policy was assigned without proving that the endpoint received or applied it. Useful states separate assignment, delivery, execution, and verification. A timeout means the control loop lacks fresh evidence; it does not automatically mean that the requested setting failed.
Inventory is the operating foundation
Fleet work starts with an inventory that answers four questions: What exists? Who or what uses it? Is it managed? What state is it in?
A useful device record joins several kinds of data:
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/124/r2/final
Supports
- Centralized device management and endpoint-protection scope
- Organization-owned and personally owned deployment scenarios
- Security across deployment, use, and disposal lifecycle stages
- Asset management, configuration management, monitoring, maintenance, and risk concerns
- https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets
Supports
- Accurate and current inventory of enterprise assets
- Identification and handling of unauthorized assets
- https://support.apple.com/guide/deployment/intro-to-device-management-profiles-depc0aadd3fe/web
Supports
- Device management service, enrollment, profiles, payloads, commands, and queries
- Automated Device Enrollment for organization-owned devices
- Certificate identities and enrollment trust
- Device and user profile scope, profile removal, locking, wiping, software updates, and compliance monitoring
- https://developer.apple.com/documentation/devicemanagement/integrating-declarative-management
Supports
- Declarative management alongside MDM commands and profiles
- Declarations and device status updates
- Gradual adoption of desired-state device management
- https://developer.apple.com/documentation/devicemanagement/leveraging-the-declarative-management-data-model-to-scale-devices
Supports
- Declarative device management introduced in iOS 15
- Declarations, status, and extensibility model
- Device autonomy and reduced polling
- https://developer.android.com/work/guide
Supports
- Work profile separation of organizational and personal data
- Fully managed and dedicated device models
- Device policy controller and managed application configurations
- Android enterprise features from Android 5.0
- https://developers.google.com/android/management/introduction
Supports
- Android enterprise binding, enrollment tokens, policies, and managed-device resources
- Policy-driven Android device management architecture
- https://learn.microsoft.com/en-us/windows/client-management/mdm-overview
Supports
- Enrollment client and periodically synchronizing management client
- Third-party MDM server support through Windows management protocols
- Security policy management and one-MDM enrollment boundary
- Device-initiated management synchronization behavior
- https://learn.microsoft.com/en-us/windows/client-management/device-update-management
Supports
- Update policy, approval, applicability, staged testing, installation, and compliance status
- Separation of update service metadata, management service action, and endpoint installation
- https://github.com/sindresorhus/awesome
Supports
- Starting point for curated awesome-list discovery
- https://github.com/awesome-foss/awesome-sysadmin
Supports
- Discovery of GLPI, OCS Inventory NG, opsi, Snipe-IT, and Rudder in IT asset or configuration management categories
- https://www.glpi-project.org/en/features/
Supports
- Computer, software, device, user, location, contract, ticket, and lifecycle inventory
- Asset administration and integration with service management
- https://wiki.ocsinventory-ng.org/
Supports
- Platform agents, inventory queries, groups, network discovery, package deployment, and API
- https://documentation.ocsinventory-ng.org/
Supports
- Current learner documentation destination
- https://docs.opsi.org/opsi-docs-en/4.3/index.html
Supports
- Windows, Linux, and macOS client management
- Central configuration, depot servers, software distribution, inventory, operating-system installation, and patching
- https://snipeitapp.com/product
Supports
- Asset assignment, location, checkout, check-in, maintenance, auditing, lifecycle history, and API integrations
- https://docs.rudder.io/reference/current/usage/advanced_configuration_management.html
Supports
- Desired-state policy generation using node inventory
- Expected reports, node-specific policy, policy validation, replacement, and regeneration
- https://www.openmobilealliance.org/tech/affiliates/syncml/syncml_dm_std_obj_v11_20020215.pdf
Supports
- 2002 date and standardized device-management objects
- Shared management tree structures and semantics
- https://www.openmobilealliance.org/release/DM/V1_1_2-20031209-A/OMA-SyncML-DMProtocol-V1_1_2-20031203-A.pdf
Supports
- December 2003 Device Management Protocol version 1.1.2
- https://csrc.nist.gov/pubs/sp/800/124/r1/final
Supports
- Original SP 800-124 publication date in November 2008
- Revision 1 publication in June 2013
- Organization-provided and personally owned device scope in Revision 1
- https://www.apple.com/newsroom/2010/04/08Apple-Previews-iPhone-OS-4/
Supports
- April 2010 preview of iPhone OS 4 mobile device management
- Third-party server integration for wireless configuration, query, lock, and wipe
- https://developer.android.com/about/versions/lollipop
Supports
- Android 5.0 work profiles for personally owned devices
- Device-owner control for organization-owned devices
- October 2014 Android 5.0 milestone
- https://learn.microsoft.com/en-us/windows/whats-new/ltsc/whats-new-windows-10-2015
Supports
- Windows 10 first availability on 2015-07-29
- OMA-based MDM across PCs, laptops, tablets, and phones
- Corporate and personal device-management scenarios
- https://developer.apple.com/news/?id=y3h32xgt
Supports
- June 2021 introduction of declarative device management
- Device-side policy and status-channel model
- https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune
Supports
- Intune endpoint management and integration with Microsoft security and identity services
- Paid proprietary subscription packaging
- https://www.jamf.com/products/jamf-pro/
Supports
- Apple automated enrollment, inventory, policy, applications, updates, restrictions, and remote commands
- Paid proprietary product packaging
- https://www.iru.com/
Supports
- Endpoint management, patching, security, identity, compliance, visual assignments, and configuration as code
- Apple, Windows, and Android coverage and proprietary paid offering
- https://www.omnissa.com/products/workspace-one-unified-endpoint-management/
Supports
- Cross-platform enrollment, policy, application lifecycle, compliance, roles, groups, and orchestration
- Mobile, desktop, rugged, shared, and server endpoint coverage
- Paid proprietary subscription editions
- https://www.ibm.com/products/maas360
Supports
- Multi-platform UEM, enrollment, policy, compliance, applications, patching, and support
- Paid proprietary offering
- https://www.manageengine.com/products/desktop-central/
Supports
- Inventory, software delivery, patching, operating-system deployment, remote support, and MDM
- Computer, server, phone, and tablet management
- Proprietary product with a free edition
- https://jumpcloud.com/platform/mdm
Supports
- Identity-linked cross-platform management
- Agent management for computers and native Apple and Android management paths
- Paid proprietary offering
- https://www.hcl-software.com/bigfix/home
Supports
- Agent-centric inventory, lifecycle, compliance, patching, remediation, and infrastructure coverage
- Paid proprietary offering
- https://fleetdm.com/
Supports
- osquery-based inventory, cross-platform agent, patching, configuration as code, review, history, and rollback
- Public source code, free edition, and paid offering
- https://www.automox.com/platform
Supports
- Cloud-agent patching, configuration, software, and scripted remediation for Windows, macOS, and Linux
- Paid proprietary offering
