Skip to content
OhKube MDM

Every device your company owns, under one set of rules

Apple, Windows, Android, and Linux in a single console. Enroll and configure them, order their vulnerabilities by real-world risk, gate access on live posture, and keep the whole configuration in Git.

console.ohkube.com / mdmLive
Apple
412
Windows
268
Android
154
Linux
96
mbp-r-chenmacOS 15.4compliant
thinkpad-a-oseiWindows 11compliant
iphone-j-milleriOS 19.2pending
pixel-s-patelAndroid 16compliant
build-runner-04Debian 12compliant

One console, four platforms

Real fleets are not one platform, and most tools quietly assume they are. Yours has Macs in design, Windows in finance, phones everywhere, and Linux under the build system. All four live in the same inventory, under the same groups and policies.

Apple
macOS, iOS and iPadOS

Profiles, FileVault, Setup Assistant

Windows
Windows 10 and 11

Policy, encryption, patch state

Android
Work profiles

Managed apps and restrictions

Linux
Debian and derivatives

Agent-based inventory and hardening

Four things it does that most MDMs don't

Vulnerabilities

CVEs ordered by real-world risk, not just CVSS

A severity score alone tells you a CVE is bad, not whether it is being used against people today. The register orders by CISA Known Exploited first, then severity, then CVSS and EPSS exploit probability, so the top of the list is the work that actually reduces risk this week.

CISA KEV catalogEPSS exploit probabilityPer-title remediation
Conditional access

Posture decides access, at the moment of the request

Gate app and resource access on each device's live posture. A machine that falls out of compliance, goes unmanaged, or stops checking in loses access without anyone filing a ticket. Unknown devices are denied by default rather than allowed until noticed.

Deny-by-defaultLive posture evaluationPriority-ordered policies
Config as code

Your fleet configuration, in Git

Export groups, automation policies, compliance policies, and content-filter rules as a versioned YAML or JSON bundle. Commit it, review it, and re-import it with a diff preview so you see exactly what a change does before it lands.

Versioned bundlesDiff preview on importGitOps-ready
Content filtering

Per-device and per-group, not per-network

Granular URL, keyword, and category rules scoped to a single device or a whole group, with time-based restrictions, custom block pages, and blocked-content reporting. Block a site on one device and allow it on another. Most rivals stop at DNS-level filtering, which fails the moment someone changes resolver.

Per-device rulesTime-based windowsBlocked-content reporting

Inside the console

OhKube MDM vulnerability register, showing CVEs ordered by risk with CVSS, EPSS and CISA KEV columns
Vulnerability register

Every CVE affecting the fleet, ordered by exploited-in-the-wild status before severity.

OhKube MDM device list showing enrolled devices across Apple, Windows, Android and Linux
Fleet inventory

One list for every platform, with enrollment status and last check-in per device.

OhKube MDM conditional access policies gating resource access on device posture
Conditional access

Policies evaluated against live posture, with an inline tester for any device and resource.

OhKube MDM config as code screen for exporting tenant configuration as a versioned bundle
Config as code

Snapshot the tenant into a versioned bundle, commit it, and re-import with a diff.

And the rest of the day job

Enrollment that scales

Automated Device Enrollment through Apple Business and School Manager, PreStage flows, token and QR invitations, and Setup Assistant customization. Hardware ships to the person, not to IT.

Configuration profiles

Wi-Fi, VPN, certificates, restrictions, and preference payloads deployed to smart groups whose membership updates as devices change.

Patch management

OS update enforcement, patch policies with triggers, schedules and target groups, plus a software titles catalog with auto-update.

Threat detection

Endpoint detection and response, continuously evaluating the fleet against detection rules and threat intelligence, with severity triage.

Command queue

Lock, erase, restart, shut down, clear passcode, and Lost Mode, queued and tracked per device so you can see what ran and what is pending.

Remote screen capture

Capture the live screen of an agent-managed device from the console, so you can see what someone is looking at instead of asking them to describe it.

AI assistant

Ask questions about the fleet in plain language, and draft profiles, policies, filter rules, and scripts grounded in your live, tenant-scoped data.

Reporting and self-service

Fleet reporting alongside a self-service portal, so routine requests resolve without a ticket reaching a human.

Where OhKube MDM pulls ahead

True multi-tenant isolation

Every tenant gets its own isolated database, not a shared table with a tenant column. That is MSP-grade separation, and most of the field cannot match it.

Four platforms, one console

Apple, Windows, Android, and Linux in the same inventory, under the same groups and policies. Most MDMs are strong on one platform and apologetic about the rest.

One directory, four products

MDM reads the same person record as Desk, Swift, and People. A device assignment during onboarding is not an integration between two systems. It is a join inside one.

Migrating a fleet sounds like a weekend you'll never get back. It isn't.

Moving hundreds of machines off an old MDM can be done with zero walk-ups and zero downtime. We wrote the guide because we get asked every week.