MDM Agent Overview

Last updated: April 21, 2026

The Mycroft MDM (Mobile Device Management) solution, included with the Mycroft Platform, is designed to help organizations safeguard sensitive information through automated policy enforcement and strong encryption. While we recognize that MDM is often not installed on personal devices, enrolling your device is the most efficient way to ensure you meet corporate security standards.

What is it?

Mycroft’s Mobile Device Manager (MDM) is an agent that runs in the background on each managed device.

What it tracks:

  • Whether encryption is enabled

  • If the computer has an antivirus

  • Hardware specs (CPU, OS, memory, disk size)

  • Installed software

What can admins see on my device?

Admins see a high-level overview of the device’s health to ensure it isn't a risk to the network. This includes:

  • Hardware Specs: CPU, RAM, and disk size.

  • Security Status: Encryption status (FileVault/BitLocker) and Antivirus activity.

  • Software Inventory: A list of installed applications to check for known security vulnerabilities.

  • Metadata: OS version and last sync status.

What it can do:

It can remotely lock (link to locking and unlocking article) your device in case it is stolen, lost or has a security related incident to prevent access to the computer’s data. For MacOS and Windows, the MDM must be enabled to detect password protection.

Performance impact:

Very low. The agent is designed to be non-disruptive and uses minimal system resources.

Supported Operating Systems

Mycroft MDM supports a wide range of platforms to ensure all team members can remain compliant:

  • Windows

  • macOS

  • Linux (Fedora & Ubuntu)

    • Note: On Linux systems, password detection is not currently supported via MDM and must be verified manually with a screenshot

FAQs

What stays private using Mycroft's MDM?

Mycroft's MDM is not a surveillance tool. It does not inspect or log:

  • Personal files, photos, or documents.

  • Internet browsing history, search queries, or clicks.

  • Private messaging or email content.

Is installing the MDM agent a requirement for SOC2?

Technically, no. SOC2 compliance requires proof that devices accessing company data are secure, encrypted, and password-protected. The MDM agent is simply the tool we use to automate that "proof."

What if I choose not to install the MDM?

If you prefer not to install the agent on a personal device, you are still required to provide manual evidence of compliance to our auditors. This typically involves:

  1. Manual Screenshots: Periodically providing dated screenshots of your system settings showing disk encryption is "On."

  2. Antivirus Logs: Providing proof of active, up-to-date antivirus software.

  3. OS Verification: Proof that your operating system is receiving the latest security patches.

My employees use personal devices and do not want to install a MDM solution. What are our options?

Visit our article for Mac Devices: Evidence for Secure Mac Devices (no MDM Solution)

Visit our article for Windows Devices: Evidence for Secure Windows Devices (no MDM Solution)

Can the company wipe my personal phone or laptop?

The agent allows admins to remotely lock a device in the event it is lost or stolen to prevent data breaches. It is designed to protect company data during a security incident, not to manage your personal life.