Set up your workspace

Request MDM access, check platform readiness, and get your first managed device into inventory.

On this page

Start with one test device and an owner or administrator account. You will need a Beam workspace, an enabled MDM feature, and a configured management connection. Readiness indicators report service configuration; they do not establish that a physical device has enrolled successfully.

Request MDM access

  1. Sign in to the Beam dashboard.
  2. Open Setup and request enterprise MDM access if it has not been activated.
  3. Have your deployment operator configure an isolated Fleet engine, enrollment identities, and installers for your workspace.
  4. After the MDM feature is granted, open Device management. An access request does not itself grant the feature.

For hosted setup, Beam staff configure the provider connection. The provisioning worker checks that connection; it does not automatically build Fleet infrastructure, obtain Apple certificates, or sign installers.

Check the connection

Open Device management → Enrollment & installers at /dashboard/mdm/setup. Check the workspace identity before distributing anything. Review Apple enrollment readiness, Windows enrollment readiness, and available desktop installers.

A Service connected indicator means the service can reach the engine. Apple readiness depends on APNs and SCEP configuration. Windows readiness depends on its WSTEP identity. A missing installer requires your operator to publish a signed artifact even when the platform connection is ready.

Enroll one device

Choose the matching guide:

Distribute workspace enrollment files privately. They carry enrollment authority and are not expiring, single-use invitations. Installing the Agent CLI and enrolling a device in MDM are separate tasks.

Verify the result

Return to Device management and open the device. Compare the identity, OS, enrollment status, encryption state, and last check-in with the actual machine and provider console. Missing or unknown values should remain unknown until the device reports them.

Deploy a low-impact test profile only after checking its target group. Verify delivery on the device, then verify removal. Keep high-impact actions disabled until their response channel and recovery procedures have been tested on disposable hardware.

If setup stalls

Ask the operator to check the exact workspace-to-provider mapping and feature grant. A running service is not proof that its storage or platform identities are healthy. Use the troubleshooting guide to distinguish access, connection, enrollment, and command delivery failures.

Explore the docs