Device Control
Enroll, lock, find, and manage every laptop
Everything under the Device Control tab: enrolling a laptop for the first time, the day-to-day remote actions, and the one-time admin setup that unlocks the strongest enrollment path.
Enroll a Mac
Two paths — pick per device, based on whether it's already in use.
| Factor | Supervised (Zero-Touch ABM) | No Erase (Profile + Agent) |
|---|---|---|
| Best for | New stock, warehouse inventory, wiped laptops | Laptops already with a customer |
| Data impact | Requires factory erase | Keeps all data |
| Removal resistance | Non-removable by user | Removable in macOS settings |
| Survives a factory reset | Yes — re-enrolls at Setup Assistant | No — needs a manual reinstall |
Supervised — zero-touch via Apple Business Manager
Requires Apple Business Manager connected first, and a factory erase.
Assign the device in Apple Business Manager
In ABM → Devices, search the Mac's serial number, then assign it to the LaptopFirst MDM server.
Erase the Mac
Erase all content and settings (or unbox a fresh unit).
Enroll at Setup Assistant
Connect to Wi-Fi. The Remote Management screen appears automatically — click Continue.
What you'll seeThe Mac enrolls with no manual profile install, and shows as Supervised: Yes on the dashboard.
No Erase — install a profile + agent
Best for a Mac already in use — managed in minutes without wiping it.
Install the profile via Safari
Copy the enrollment URL from Device Control → MDM Settings (unique to your account):
https://mdm.laptopfirst.in/mdm/enroll?tenant_id=<your-account-id>
Open it in Safari on the Mac — it downloads a .mobileconfig profile. Go to System Settings → General → Device Management, double-click the profile, and Install (you'll need the Mac's admin password).
What you'll seeA "LaptopFirst Mite" profile appears under Device Management marked Verified — no red warning, since it's signed with LaptopFirst's Apple Developer ID.
Install the agent via Terminal
Run the agent-install command shown as step 2 of the same card, in Terminal.
If you see"No provisioning key found — contact your admin": get a key from your LaptopFirst account rep and paste it in place of the placeholder, then re-run the command.
Enroll a Windows laptop
Choose the 1-click installer for one-off setup, or PowerShell for scripted mass deployment.
| Factor | 1-Click Installer (.exe) | Administrator PowerShell |
|---|---|---|
| Best for | Field staff, quick onboarding | IT staging benches, mass deployment |
| Method | Double-click the .exe (zero typing) | Paste a single-line command |
| Watch out for | Do not rename the .exe file | Must run PowerShell as Administrator |
1-Click GUI installer
Download the installer
In Device Control → MDM Settings → Windows Enrollment, click Download Windows installer.
ImportantDo not rename the .exe file — it contains your unique account key. Run it as-is.
Run it on the laptop
Transfer the .exe to the laptop and double-click to launch. If Windows SmartScreen warns you, click More info → Run anyway.
What you'll seeThe agent installs silently and the laptop appears on your Devices dashboard.
Administrator PowerShell (mass deployment)
Open PowerShell as Administrator
Search for PowerShell in the Start menu, right-click, and select Run as Administrator.
Run the install command
Copy and paste the command shown in MDM Settings → Windows Enrollment.
What you'll seeThe machine checks in immediately on your Devices list.
Remote actions
Open a device from the Devices list — it expands into a console with these action buttons.
| Status | Meaning |
|---|---|
| Pending | Queued in the dashboard. Not sent anywhere yet. |
| Delivered | Handed off to the device — doesn't mean it's run yet. If the laptop is asleep, a command can sit here until it wakes. |
| Completed | The device fetched the command, ran it, and confirmed success. |
| Failed | The device reported an error, or the command timed out after retries. |
Pull fresh status
Fires two commands together (device info + security info). Doesn't show a live progress bar — it quietly checks for about 26 seconds. Open the device's Activity log to watch the real status.
A fullscreen message, no lock
Type a message (e.g. "Your rental payment is overdue") and send. The device shows a fullscreen warning the user must wait 10 seconds to dismiss, then can keep working. Runs over the agent's live connection, so it's fast.
The core control — fully reversible
On a Mac: click Lock, enter a 6-digit PIN, confirm. On Windows: set a Lock Password and an optional on-screen message; every account is switched to that password and the user is signed out. Unlock reverses it remotely.
Remote restart
Gracefully restarts the laptop to resolve freezes or apply updates. Gives the user a 5-minute on-screen warning to save their work before it force-restarts.
The overflow (⋯) menu
- Install / Reinstall Agent — pushes the agent via MDM (adds location, alerts, inventory).
- Wipe device — erases all data and resets it. Irreversible; confirms first.
- Retire device — removes it from your active fleet locally. Doesn't touch the Mac itself.
- BitLocker — escrow or view the 48-digit recovery key, or force a BitLocker lock (drive won't boot without the key).
- Apply Windows lockdown — blocks unenrollment and hides Reset, via native MDM.
- Uninstall protection — require a rotating code (changes every 30s) to remove the agent.
CarefulWipe and Force BitLocker lock are destructive and hard to reverse. Use Lock for day-to-day non-payment control instead — it's fully recoverable.
Hardware specs & GPS location
Hardware panel
Confirm returned hardware matches what was originally dispatched:
- CPU / Chip — exact processor model
- RAM — installed memory, to catch swapped sticks
- Storage — primary drive capacity, to confirm drive integrity
- Serial number — one-click copy for billing/warranty lookup
Location panel
Track the physical whereabouts of your fleet:
- An interactive map pinned to the device's latest position
- The last 5 hourly pings, with timestamps, to confirm the device is still checking in
Add to inventory & retire a device
Add to inventory
Click + Add to Inventory in the device console. All verified specs (CPU, RAM, storage, serial number) copy automatically into your Device Inventory catalog — no manual data entry.
Moving between customers
Do not remove the agent. When a laptop comes back from one customer and goes to another, keep the agent installed and just reassign the device to the new order.
Permanent disposal or sale
Open the device's ⋯ menu and select Retire. This unenrolls it from MDM and automatically uninstalls the agent from the machine.
Admin setup: Apple Business Manager & Push Certificate
One-time setup, done once per organization, that unlocks Supervised (zero-touch) enrollment and your own independent Apple push identity.
Connect Apple Business Manager
| Prerequisite | What you need |
|---|---|
| D-U-N-S Number | A free 9-digit business identifier from dnb.com |
| Work email | A corporate domain email (no Gmail/Yahoo) |
| Signing authority | A Director or CEO's contact info, for Apple's phone verification |
Get a D-U-N-S number
Free at dnb.com, if you don't already have one.
Enroll at business.apple.com
Click Enroll now, enter your business and contact details.
Apple verifies your company
Apple calls or emails your signing authority to confirm the business is legitimate.
Activate your admin account
Click the approval link in your email to create your Managed Apple ID and accept the terms.
Connect it to LaptopFirst
In MDM Settings, download the public key, add LaptopFirst as an MDM server in ABM under Settings → MDM Servers, upload the key, then download and upload the resulting .p7m token back into LaptopFirst.
Set up your own Apple Push Certificate
Optional — devices work fine on LaptopFirst's shared certificate. This gives your organization its own independent push identity.
Use a dedicated company Apple ID
Not a personal one — create one just for this, e.g. apns@yourcompany.com.
Generate a request in LaptopFirst
In MDM Settings → Apple Push Certificate, click Generate & download request.
Upload it to Apple
Sign in at identity.apple.com/pushcert, and upload the request file.
Upload the certificate back
Apple issues a .pem certificate — upload it into LaptopFirst's MDM Settings.
One year laterAPNs certificates expire after 365 days. Renew using the exact same Apple ID — never create a new one, or every enrolled Mac disconnects.
Uninstall the agent
Remove the agent from a device when a rental ends and it won't be re-leased through LaptopFirst.
sudo /Library/LaptopFirst/agent uninstall
& "C:\Program Files\LaptopFirst\mite.exe" uninstall
If uninstall protection is on, you'll need the current code from Show uninstall code in the device's ⋯ menu.