LlaptopfirstGuides

Device Control

Enroll, lock, find, and manage every laptop

Everything under the Device Control tab: enrolling a laptop for the first time, the day-to-day remote actions, and the one-time admin setup that unlocks the strongest enrollment path.

Enroll a Mac

Two paths — pick per device, based on whether it's already in use.

FactorSupervised (Zero-Touch ABM)No Erase (Profile + Agent)
Best forNew stock, warehouse inventory, wiped laptopsLaptops already with a customer
Data impactRequires factory eraseKeeps all data
Removal resistanceNon-removable by userRemovable in macOS settings
Survives a factory resetYes — re-enrolls at Setup AssistantNo — needs a manual reinstall

Supervised — zero-touch via Apple Business Manager

Requires Apple Business Manager connected first, and a factory erase.

1

Assign the device in Apple Business Manager

In ABM → Devices, search the Mac's serial number, then assign it to the LaptopFirst MDM server.

2

Erase the Mac

Erase all content and settings (or unbox a fresh unit).

3

Enroll at Setup Assistant

Connect to Wi-Fi. The Remote Management screen appears automatically — click Continue.

What you'll seeThe Mac enrolls with no manual profile install, and shows as Supervised: Yes on the dashboard.

No Erase — install a profile + agent

Best for a Mac already in use — managed in minutes without wiping it.

1

Install the profile via Safari

Copy the enrollment URL from Device Control → MDM Settings (unique to your account):

https://mdm.laptopfirst.in/mdm/enroll?tenant_id=<your-account-id>

Open it in Safari on the Mac — it downloads a .mobileconfig profile. Go to System Settings → General → Device Management, double-click the profile, and Install (you'll need the Mac's admin password).

What you'll seeA "LaptopFirst Mite" profile appears under Device Management marked Verified — no red warning, since it's signed with LaptopFirst's Apple Developer ID.

2

Install the agent via Terminal

Run the agent-install command shown as step 2 of the same card, in Terminal.

If you see"No provisioning key found — contact your admin": get a key from your LaptopFirst account rep and paste it in place of the placeholder, then re-run the command.

Enroll a Windows laptop

Choose the 1-click installer for one-off setup, or PowerShell for scripted mass deployment.

Factor1-Click Installer (.exe)Administrator PowerShell
Best forField staff, quick onboardingIT staging benches, mass deployment
MethodDouble-click the .exe (zero typing)Paste a single-line command
Watch out forDo not rename the .exe fileMust run PowerShell as Administrator

1-Click GUI installer

1

Download the installer

In Device Control → MDM Settings → Windows Enrollment, click Download Windows installer.

ImportantDo not rename the .exe file — it contains your unique account key. Run it as-is.

2

Run it on the laptop

Transfer the .exe to the laptop and double-click to launch. If Windows SmartScreen warns you, click More info → Run anyway.

What you'll seeThe agent installs silently and the laptop appears on your Devices dashboard.

Administrator PowerShell (mass deployment)

1

Open PowerShell as Administrator

Search for PowerShell in the Start menu, right-click, and select Run as Administrator.

2

Run the install command

Copy and paste the command shown in MDM Settings → Windows Enrollment.

What you'll seeThe machine checks in immediately on your Devices list.

Remote actions

Open a device from the Devices list — it expands into a console with these action buttons.

StatusMeaning
PendingQueued in the dashboard. Not sent anywhere yet.
DeliveredHanded off to the device — doesn't mean it's run yet. If the laptop is asleep, a command can sit here until it wakes.
CompletedThe device fetched the command, ran it, and confirmed success.
FailedThe device reported an error, or the command timed out after retries.
Refresh

Pull fresh status

Fires two commands together (device info + security info). Doesn't show a live progress bar — it quietly checks for about 26 seconds. Open the device's Activity log to watch the real status.

Alert

A fullscreen message, no lock

Type a message (e.g. "Your rental payment is overdue") and send. The device shows a fullscreen warning the user must wait 10 seconds to dismiss, then can keep working. Runs over the agent's live connection, so it's fast.

Lock

The core control — fully reversible

On a Mac: click Lock, enter a 6-digit PIN, confirm. On Windows: set a Lock Password and an optional on-screen message; every account is switched to that password and the user is signed out. Unlock reverses it remotely.

Reboot

Remote restart

Gracefully restarts the laptop to resolve freezes or apply updates. Gives the user a 5-minute on-screen warning to save their work before it force-restarts.

The overflow (⋯) menu

macOS
  • Install / Reinstall Agent — pushes the agent via MDM (adds location, alerts, inventory).
  • Wipe device — erases all data and resets it. Irreversible; confirms first.
  • Retire device — removes it from your active fleet locally. Doesn't touch the Mac itself.
Windows
  • BitLocker — escrow or view the 48-digit recovery key, or force a BitLocker lock (drive won't boot without the key).
  • Apply Windows lockdown — blocks unenrollment and hides Reset, via native MDM.
  • Uninstall protection — require a rotating code (changes every 30s) to remove the agent.

CarefulWipe and Force BitLocker lock are destructive and hard to reverse. Use Lock for day-to-day non-payment control instead — it's fully recoverable.

Hardware specs & GPS location

Hardware panel

Confirm returned hardware matches what was originally dispatched:

  • CPU / Chip — exact processor model
  • RAM — installed memory, to catch swapped sticks
  • Storage — primary drive capacity, to confirm drive integrity
  • Serial number — one-click copy for billing/warranty lookup

Location panel

Track the physical whereabouts of your fleet:

  • An interactive map pinned to the device's latest position
  • The last 5 hourly pings, with timestamps, to confirm the device is still checking in

Add to inventory & retire a device

Add to inventory

Click + Add to Inventory in the device console. All verified specs (CPU, RAM, storage, serial number) copy automatically into your Device Inventory catalog — no manual data entry.

Moving between customers

Do not remove the agent. When a laptop comes back from one customer and goes to another, keep the agent installed and just reassign the device to the new order.

Permanent disposal or sale

Open the device's ⋯ menu and select Retire. This unenrolls it from MDM and automatically uninstalls the agent from the machine.

Admin setup: Apple Business Manager & Push Certificate

One-time setup, done once per organization, that unlocks Supervised (zero-touch) enrollment and your own independent Apple push identity.

Connect Apple Business Manager

PrerequisiteWhat you need
D-U-N-S NumberA free 9-digit business identifier from dnb.com
Work emailA corporate domain email (no Gmail/Yahoo)
Signing authorityA Director or CEO's contact info, for Apple's phone verification
1

Get a D-U-N-S number

Free at dnb.com, if you don't already have one.

2

Enroll at business.apple.com

Click Enroll now, enter your business and contact details.

3

Apple verifies your company

Apple calls or emails your signing authority to confirm the business is legitimate.

4

Activate your admin account

Click the approval link in your email to create your Managed Apple ID and accept the terms.

5

Connect it to LaptopFirst

In MDM Settings, download the public key, add LaptopFirst as an MDM server in ABM under Settings → MDM Servers, upload the key, then download and upload the resulting .p7m token back into LaptopFirst.

Set up your own Apple Push Certificate

Optional — devices work fine on LaptopFirst's shared certificate. This gives your organization its own independent push identity.

1

Use a dedicated company Apple ID

Not a personal one — create one just for this, e.g. apns@yourcompany.com.

2

Generate a request in LaptopFirst

In MDM Settings → Apple Push Certificate, click Generate & download request.

3

Upload it to Apple

Sign in at identity.apple.com/pushcert, and upload the request file.

4

Upload the certificate back

Apple issues a .pem certificate — upload it into LaptopFirst's MDM Settings.

One year laterAPNs certificates expire after 365 days. Renew using the exact same Apple ID — never create a new one, or every enrolled Mac disconnects.

Uninstall the agent

Remove the agent from a device when a rental ends and it won't be re-leased through LaptopFirst.

macOS — Terminal

sudo /Library/LaptopFirst/agent uninstall

Windows — PowerShell (Administrator)

& "C:\Program Files\LaptopFirst\mite.exe" uninstall

If uninstall protection is on, you'll need the current code from Show uninstall code in the device's ⋯ menu.