Every device your company owns, under one set of rules
Apple, Windows, Android, and Linux in a single console. Enroll and configure them, order their vulnerabilities by real-world risk, gate access on live posture, and keep the whole configuration in Git.
One console, four platforms
Real fleets are not one platform, and most tools quietly assume they are. Yours has Macs in design, Windows in finance, phones everywhere, and Linux under the build system. All four live in the same inventory, under the same groups and policies.
Profiles, FileVault, Setup Assistant
Policy, encryption, patch state
Managed apps and restrictions
Agent-based inventory and hardening
Four things it does that most MDMs don't
CVEs ordered by real-world risk, not just CVSS
A severity score alone tells you a CVE is bad, not whether it is being used against people today. The register orders by CISA Known Exploited first, then severity, then CVSS and EPSS exploit probability, so the top of the list is the work that actually reduces risk this week.
Posture decides access, at the moment of the request
Gate app and resource access on each device's live posture. A machine that falls out of compliance, goes unmanaged, or stops checking in loses access without anyone filing a ticket. Unknown devices are denied by default rather than allowed until noticed.
Your fleet configuration, in Git
Export groups, automation policies, compliance policies, and content-filter rules as a versioned YAML or JSON bundle. Commit it, review it, and re-import it with a diff preview so you see exactly what a change does before it lands.
Per-device and per-group, not per-network
Granular URL, keyword, and category rules scoped to a single device or a whole group, with time-based restrictions, custom block pages, and blocked-content reporting. Block a site on one device and allow it on another. Most rivals stop at DNS-level filtering, which fails the moment someone changes resolver.
Inside the console

Every CVE affecting the fleet, ordered by exploited-in-the-wild status before severity.

One list for every platform, with enrollment status and last check-in per device.

Policies evaluated against live posture, with an inline tester for any device and resource.

Snapshot the tenant into a versioned bundle, commit it, and re-import with a diff.
And the rest of the day job
Enrollment that scales
Automated Device Enrollment through Apple Business and School Manager, PreStage flows, token and QR invitations, and Setup Assistant customization. Hardware ships to the person, not to IT.
Configuration profiles
Wi-Fi, VPN, certificates, restrictions, and preference payloads deployed to smart groups whose membership updates as devices change.
Patch management
OS update enforcement, patch policies with triggers, schedules and target groups, plus a software titles catalog with auto-update.
Threat detection
Endpoint detection and response, continuously evaluating the fleet against detection rules and threat intelligence, with severity triage.
Command queue
Lock, erase, restart, shut down, clear passcode, and Lost Mode, queued and tracked per device so you can see what ran and what is pending.
Remote screen capture
Capture the live screen of an agent-managed device from the console, so you can see what someone is looking at instead of asking them to describe it.
AI assistant
Ask questions about the fleet in plain language, and draft profiles, policies, filter rules, and scripts grounded in your live, tenant-scoped data.
Reporting and self-service
Fleet reporting alongside a self-service portal, so routine requests resolve without a ticket reaching a human.
Where OhKube MDM pulls ahead
True multi-tenant isolation
Every tenant gets its own isolated database, not a shared table with a tenant column. That is MSP-grade separation, and most of the field cannot match it.
Four platforms, one console
Apple, Windows, Android, and Linux in the same inventory, under the same groups and policies. Most MDMs are strong on one platform and apologetic about the rest.
One directory, four products
MDM reads the same person record as Desk, Swift, and People. A device assignment during onboarding is not an integration between two systems. It is a join inside one.
Migrating a fleet sounds like a weekend you'll never get back. It isn't.
Moving hundreds of machines off an old MDM can be done with zero walk-ups and zero downtime. We wrote the guide because we get asked every week.