Fleet Management
Fleet management is the coordinated inventory, configuration, updating, security, support, and retirement of an organization's computers and mobile devices. A central service keeps many endpoints in a known state while each device reports what actually happened.
itInfrastructure and operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Fleet Management
A fleet is a collection of endpoints that has stopped being small enough to manage by memory, spreadsheets, or a hopeful look at the office. Computers, phones, tablets, kiosks, and other devices each have their own habits. Fleet management turns that unruly collection into a control loop: identify, enroll, declare, observe, reconcile.
First comes inventory, which is less a list than a polite argument between several lists. Procurement knows hardware was acquired. The asset register knows custody. A directory knows identities. Network discovery knows what answered. The management service knows what reported recently. None gets the whole story, so the useful work is finding where they disagree.
Then comes enrollment, the trusted relationship between an endpoint and the management service. Organization-owned hardware can take broad device controls. Personal hardware needs a narrower work boundary. This is where the word policy becomes slightly mischievous: the same label on two platforms does not promise the same enforcement. The platform decides what control exists.
A policy declares the state a device should maintain: encryption, credentials, an application, a certificate, or an update target. Assignment is only intent. Delivery is not execution, and execution is not verification. A console can be very pleased with itself while an offline device, a conflict, low storage, or a pending restart has other plans. Fresh observed state is the evidence that settles the argument.
Changes travel through rings because a fleet is not one giant test device wearing several hats. A lab checks installation and rollback. An IT ring finds operational impact. A representative pilot includes the old hardware, remote networks, applications, and operating-system combinations that are waiting to be awkward in production. Then measured waves expand the change, with stop conditions and exceptions kept visible.
The lifecycle continues after a device stops being useful. Offboarding reaches accounts, tokens, managed data, hardware custody, automated enrollment, credentials, and disposal evidence. Removing one console record is a neat administrative gesture, not proof that those handoffs happened.
Read the Intro for the whole control loop and its boundaries. Use Slides when the relationships need a map. Keep the Cheatsheet nearby when tracing a rollout, a stale record, or an offboarding handoff. Field Notes carries the operational traps that make a correct-looking fleet less correct than it appears.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/124/r2/final
Supports
- Centralized device management and endpoint-protection scope
- Organization-owned and personally owned deployment scenarios
- Security across deployment, use, and disposal lifecycle stages
- Asset management, configuration management, monitoring, maintenance, and risk concerns
- https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets
Supports
- Accurate and current inventory of enterprise assets
- Identification and handling of unauthorized assets
- https://support.apple.com/guide/deployment/intro-to-device-management-profiles-depc0aadd3fe/web
Supports
- Device management service, enrollment, profiles, payloads, commands, and queries
- Automated Device Enrollment for organization-owned devices
- Certificate identities and enrollment trust
- Device and user profile scope, profile removal, locking, wiping, software updates, and compliance monitoring
- https://developer.apple.com/documentation/devicemanagement/integrating-declarative-management
Supports
- Declarative management alongside MDM commands and profiles
- Declarations and device status updates
- Gradual adoption of desired-state device management
- https://developer.apple.com/documentation/devicemanagement/leveraging-the-declarative-management-data-model-to-scale-devices
Supports
- Declarative device management introduced in iOS 15
- Declarations, status, and extensibility model
- Device autonomy and reduced polling
- https://developer.android.com/work/guide
Supports
- Work profile separation of organizational and personal data
- Fully managed and dedicated device models
- Device policy controller and managed application configurations
- Android enterprise features from Android 5.0
- https://developers.google.com/android/management/introduction
Supports
- Android enterprise binding, enrollment tokens, policies, and managed-device resources
- Policy-driven Android device management architecture
- https://learn.microsoft.com/en-us/windows/client-management/mdm-overview
Supports
- Enrollment client and periodically synchronizing management client
- Third-party MDM server support through Windows management protocols
- Security policy management and one-MDM enrollment boundary
- Device-initiated management synchronization behavior
- https://learn.microsoft.com/en-us/windows/client-management/device-update-management
Supports
- Update policy, approval, applicability, staged testing, installation, and compliance status
- Separation of update service metadata, management service action, and endpoint installation
- https://github.com/sindresorhus/awesome
Supports
- Starting point for curated awesome-list discovery
- https://github.com/awesome-foss/awesome-sysadmin
Supports
- Discovery of GLPI, OCS Inventory NG, opsi, Snipe-IT, and Rudder in IT asset or configuration management categories
- https://www.glpi-project.org/en/features/
Supports
- Computer, software, device, user, location, contract, ticket, and lifecycle inventory
- Asset administration and integration with service management
- https://wiki.ocsinventory-ng.org/
Supports
- Platform agents, inventory queries, groups, network discovery, package deployment, and API
- https://documentation.ocsinventory-ng.org/
Supports
- Current learner documentation destination
- https://docs.opsi.org/opsi-docs-en/4.3/index.html
Supports
- Windows, Linux, and macOS client management
- Central configuration, depot servers, software distribution, inventory, operating-system installation, and patching
- https://snipeitapp.com/product
Supports
- Asset assignment, location, checkout, check-in, maintenance, auditing, lifecycle history, and API integrations
- https://docs.rudder.io/reference/current/usage/advanced_configuration_management.html
Supports
- Desired-state policy generation using node inventory
- Expected reports, node-specific policy, policy validation, replacement, and regeneration
- https://www.openmobilealliance.org/tech/affiliates/syncml/syncml_dm_std_obj_v11_20020215.pdf
Supports
- 2002 date and standardized device-management objects
- Shared management tree structures and semantics
- https://www.openmobilealliance.org/release/DM/V1_1_2-20031209-A/OMA-SyncML-DMProtocol-V1_1_2-20031203-A.pdf
Supports
- December 2003 Device Management Protocol version 1.1.2
- https://csrc.nist.gov/pubs/sp/800/124/r1/final
Supports
- Original SP 800-124 publication date in November 2008
- Revision 1 publication in June 2013
- Organization-provided and personally owned device scope in Revision 1
- https://www.apple.com/newsroom/2010/04/08Apple-Previews-iPhone-OS-4/
Supports
- April 2010 preview of iPhone OS 4 mobile device management
- Third-party server integration for wireless configuration, query, lock, and wipe
- https://developer.android.com/about/versions/lollipop
Supports
- Android 5.0 work profiles for personally owned devices
- Device-owner control for organization-owned devices
- October 2014 Android 5.0 milestone
- https://learn.microsoft.com/en-us/windows/whats-new/ltsc/whats-new-windows-10-2015
Supports
- Windows 10 first availability on 2015-07-29
- OMA-based MDM across PCs, laptops, tablets, and phones
- Corporate and personal device-management scenarios
- https://developer.apple.com/news/?id=y3h32xgt
Supports
- June 2021 introduction of declarative device management
- Device-side policy and status-channel model
- https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune
Supports
- Intune endpoint management and integration with Microsoft security and identity services
- Paid proprietary subscription packaging
- https://www.jamf.com/products/jamf-pro/
Supports
- Apple automated enrollment, inventory, policy, applications, updates, restrictions, and remote commands
- Paid proprietary product packaging
- https://www.iru.com/
Supports
- Endpoint management, patching, security, identity, compliance, visual assignments, and configuration as code
- Apple, Windows, and Android coverage and proprietary paid offering
- https://www.omnissa.com/products/workspace-one-unified-endpoint-management/
Supports
- Cross-platform enrollment, policy, application lifecycle, compliance, roles, groups, and orchestration
- Mobile, desktop, rugged, shared, and server endpoint coverage
- Paid proprietary subscription editions
- https://www.ibm.com/products/maas360
Supports
- Multi-platform UEM, enrollment, policy, compliance, applications, patching, and support
- Paid proprietary offering
- https://www.manageengine.com/products/desktop-central/
Supports
- Inventory, software delivery, patching, operating-system deployment, remote support, and MDM
- Computer, server, phone, and tablet management
- Proprietary product with a free edition
- https://jumpcloud.com/platform/mdm
Supports
- Identity-linked cross-platform management
- Agent management for computers and native Apple and Android management paths
- Paid proprietary offering
- https://www.hcl-software.com/bigfix/home
Supports
- Agent-centric inventory, lifecycle, compliance, patching, remediation, and infrastructure coverage
- Paid proprietary offering
- https://fleetdm.com/
Supports
- osquery-based inventory, cross-platform agent, patching, configuration as code, review, history, and rollback
- Public source code, free edition, and paid offering
- https://www.automox.com/platform
Supports
- Cloud-agent patching, configuration, software, and scripted remediation for Windows, macOS, and Linux
- Paid proprietary offering
- https://www.jamf.com/blog/stanford-mdm-device-migration-jnuc2022/
Supports
- MDM migration phases covering pilot, user communication, enforcement, and cleanup
- Real-time tracking of which management service owns each device
- Centralized and distributed administration boundaries during large device migrations
