UEM, or unified endpoint management, is software that enables IT and security teams to monitor, manage and secure all of an organization’s end-user devices, such as desktops and laptops, smartphones, tablets, wearables and more, in a consistent manner with a single tool, regardless of operating system or location.
UEM strengthens endpoint security by simplifying it, enabling security and IT teams to protect all endpoint devices by using one tool in one consistent way.
A relatively new technology, UEM combines the capabilities of legacy mobile management solutions, including mobile device management (MDM) and mobile application management (MAM), with those of tools used to manage on-premises and remote PCs.
Already popular for managing bring your own device (BYOD) programs and hybrid (mixed on-premises and remote) workforces, UEM's use has exploded as security and IT departments adapt to support expanded work-from-home (WFH) initiatives in the advent of the COVID-19 pandemic.
UEM is the latest in a series of mobile security management tools, which are tools that emerged and evolved in response to the changing relationship between organizations, employees, mobile devices and working styles over the last two decades.
From MDM...
The first mobile devices introduced in the workplace were company-owned, and mobile device management (MDM) tools were developed to enable IT administrators to manage and secure these devices. MDM tools gave administrators total control over all features of a device. They might provision, enroll and encrypt devices, configure and control wireless access, install and manage enterprise apps, track the location of the devices, and lock and wipe a device if it was lost of stolen.
...to MAM...
MDM was an acceptable mobile management solution until smartphones became so popular that employees wanted to use their personal smartphones for work (instead of carrying both a work and a personal device). BYOD was born. And soon, employees bristled at surrendering total control of their personal phones and personal data to MDM.
A new solution, mobile application management (MAM), emerged. Instead of focusing on management control of the entire mobile device, MAM focused on app management. With MAM, administrators might take total control over corporate apps and the corporate data associated with them; they might also exercise enough control over employees’ personal apps to protect corporate data, without touching or even seeing employees’ personal data.
...to EMM...
But MAM solutions also found their limits, most of which resulted from their sheer inability to keep pace with the explosion of new apps employees might add to their iOS or Android devices. In response, vendors combined MDM, MAM and some related tools to create enterprise mobility management (EMM) suites. EMM provided the corporate data security of MDM, the superior employee experience of MAM, and management and security control over all devices used outside of the office—not only smartphones, but off-site laptops and PCs too.
...to UEM
EMM left one final endpoint management gap (and potential security vulnerability). Because it didn’t offer capabilities for managing onsite end-user devices, it required administrators to use separate tools and policies for onsite and off-site device management and security. This created more work, confusion and opportunity for error, right about the same time that more employers were trying to let more employees work from home.
UEM emerged as the solution to this problem. It combines the functions of EMM with the capabilities of client management tools (CMTs) used traditionally to manage on-premises PCs and laptops. Most UEM tools also include, integrate or interact with endpoint security tools such as antivirus and anti-malware software, web control software, user and entity behavior analytics (UEBA) solutions, integrated firewalls and more.
Using multiple endpoint management tools to manage and secure different endpoint devices in different locations results in lots of manuals and repeated work for security and IT teams, and increases the opportunity for inconsistencies, misconfigurations and errors that can leave the endpoints and the network vulnerable to attack.
UEM greatly reduces the work and the risk by creating a single, central dashboard where IT administrators and security teams can view, manage and secure every endpoint device connected to the enterprise network.
UEM tools work across all PC and mobile operating systems including Apple iOS and MacOS, Google ChromeOS and Android, Linux® and Microsoft Windows. (Some solutions might also support the BlackBerry OS and Windows phone mobile operating systems.) Many UEM solutions also support printers and other end-user IoT devices, smartwatches and other wearables, virtual reality headsets and virtual assistants to anything that an employee or business partner might use to connect to the network and get work done.
UEM is aware of all devices on the network no matter the type of connection, how often they connect, and where they connect from. It can even discover connected devices that administrators or security teams aren’t aware of, in real-time.
From this, central dashboard administrators can perform or automate critical management and security tasks for any or all devices, including:
The bottom line is that for these and other tasks, UEM’s all-encompassing approach enables security and IT departments to ignore the distinctions between on- and off-site devices, mobile and desktop devices, Windows or Mac or Chrome or Linux operating systems—and focus simply on device and security management.
As mentioned above, UEM evolved from the collision of changing technologies for managing and securing organizations BYOD policies, increasingly hybrid workforces, and expanding work-from-home programs. But organizations adopt UEM to support other strategic management and security initiatives, including:
Simplified regulatory compliance: Hybrid workforces can add to the complexity of demonstrating and enforcing compliance with industry and data privacy regulations. UEM solutions can help cut through that complexity.
For example, UEM enables an organization to set a single policy that ensures every device complies with the encryption requirements specified by GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability Act) and other data privacy regulations. UEM data isolation and application control capabilities help administrators ensure that only authorized applications or mobile apps can access highly regulated data.
Zero trust security: In a zero trust security approach, all endpoints are considered hostile by default. All entities—users, devices, accounts—are granted the least privileged access required to support their jobs or functions, and all entities must be continuously monitored and regularly reauthorized as access continues. UEM can support zero trust implementation in several ways, from simplifying the provisioning of all devices for least privileged access, to providing real-time visibility into every device connected to the network.
Discover how you can maximize your ROI by decreasing device configuration and end-user setup times with MaaS360.
Access the report and discover new insights for selecting the unified endpoint management (UEM) software vendor that best aligns to your organization’s goals.
Gain insights to prepare and respond to cyberattacks with greater speed and effectiveness with the IBM X-Force Threat Intelligence Index.
Start a 30-day free trial of IBM MaaS360 and experience universal device management with built-in endpoint security and AI-powered analytics.
Data breach costs have hit a new high. Get essential insights to help your security and IT teams better manage risk and limit potential losses.