Choosing between AirWatch, Apperian, BES 10, Divide, Fixmo and Good Technology depends on specific use cases
Mobile device management tools make sense when you are trying to control who can access your enterprise network and applications from particular phones and tablets. But to effectively evaluate these products, you should first identify what you’re trying to control: the apps on particular devices, the pairing of a user with his device, the device itself, or the files on each device.
We looked at six products: AirWatch, Apperian EASE, BlackBerry Enterprise Server 10 (BES10), Divide, Fixmo, and Good Technology’s Good for Enterprise. Each has a somewhat different perspective and different strengths in terms of what it can control best. (Watch the slideshow version.)
All support Android and iOS devices, and some also support BlackBerries, Windows Phones, and even (in the case of AirWatch) desktops. Pricing varied between $20 to $75 per user or per device per year, and will depend on the particular features, with quantity discounts typically available. The most transparent pricing schemes came from AirWatch and BlackBerry. We wish others would follow their lead.
Certainly, assembling the various bits and pieces of a typical MDM solution isn’t easy: in between the server and client components there is a lot of other stuff that interacts with a great portion of your network infrastructure, including Active Directory, Web proxies, email servers and firewall rules.
For example, some of the solutions we tested tightly couple with Active Synch so that you can save deployment time and use your existing security policy frameworks in Active Directory. But your own Active Directory implementation may not have any of these fields enumerated, so this may not be as useful as it sounds.
[ALSO: 5 Ways to secure Wi-Fi networks ]
If you have a variety of mobile phones from various vendors running vintage OSs, you will quickly run into installation issues. (We used our Kindle Fire as the oddest of oddball Android versions for that specific reason.)
MDMs are not quite mature protection devices on two other counts: First, for iOS in particular, you can’t have more than one vendor’s profile active at any given time. This means if your phone or tablet has to traverse two or more networks that are using different MDMs, you are going to have problems. Second, while these products can identify once a phone has been rooted, they can’t “unroot” it: you’ll have to go through the process on each phone individually.
But there is some good news. Apple has been listening to enterprise users and iOS 7, which came out just as we began our review, offers better certificate management and APIs to incorporate into MDM tools. The new iOS also includes other corporate features, such as support for single sign-on, automatic app updates, and a mechanism to prevent reactivation of stolen phones.
No winners
No single MDM product won this review; all had flaws. But all had strong points as well.
For example, AirWatch had the widest phone/tablet/desktop support. But it also requires a messy collection of different downloaded apps that could be confusing to actually use.
Fixmo doesn’t support many device OS versions and its cloud server still needs a supplemental VPN to be completely secure. However, if you’re going the secure container route, Fixmo is a strong contender.
BlackBerry now supports Android and iOS devices, but not in a smoothly integrated way. However, BlackBerry should be on your short list if your primary goal is protecting your messaging infrastructure.
Good Technology is a mature product that features solid email security, fast device enrollment, extensive security policies and wide device support. But Good has weak support for sharing files and apps.
Divide had the most appealing management console and overall simplest setup routines, and also supports licensing unlimited devices per user. It features the best overall approach to MDM and is the easiest to operate, but has the most limited device OS version support.
Apperian does a great job with setting up a protected app portal, but falls down on some basic MDM issues. Consider Apperian if you have developed a large collection of your own apps and want a consistent set of security policies when deploying them.
AirWatch
AirWatch supported the largest collection of devices, and was the only product that had both mobile and desktop management support. It supports iOS7 and the MDM API that Apple developed for its latest mobile OS, and it has an app in the BlackBerry World app store as well. That is the good news.
The bad news is that AirWatch sells three different products: one for MDM, one for mobile content management and one for mobile applications management. They use a single integrated management console, but have different client pieces for each mobile device. All of this software is delivered from the cloud, although they will work with companies that want on-premises servers or virtual appliances.
Initially, you bring up a browser to begin the installation process. After you sign in to its Web console, you are presented with a lengthy task list and a series of more than a dozen wizards that will take you through lots of sequential steps. Fortunately, there are video and help files galore, including an online chat line for additional guidance.
The enrollment step first installs the app on your phone, then automatically switches back and forth between the browser on your phone and the app to complete the process. This is necessary because AirWatch needs to make use of your Apple certificates to sign its apps, but it is all very smooth.
AirWatch automatically recognized that we had an older version of iOS and downloaded an older agent version to match it. There is even the ability to customize the terms-of-use text when you enroll each device, not that anyone reads this stuff anyway.
Once enrollment is complete, there are additional steps. Menus are clearly laid out and there is a lot of online support, videos, and help, too. The “dashboard” is somewhat of a misnomer: this is where you will find several reports including how many devices are enrolled and in compliance with the stated policies. In addition to this is a separate “Hub,” which is actually more of a dashboard, that lists devices, compliance, apps, and other details about your installation.
We had some initial confusion over separating our administrative and user accounts, but once that was resolved, getting all the various tasks completed was mostly obvious. The other MDM products could learn from AirWatch’s workflow and setup process.
AirWatch has an impressive collection of granular policy settings, down to the minimum sub-version of Android OS allowed, being able to disable a device’s camera, adding geo-fencing or being able to restrict a device to a particular Wi-Fi network.
It has a particularly rich passcode policy that can override the device OS defaults. These various elements are spread across about a dozen sub-menus in the policy section of the product, where you would set up specific policies for each particular device type. When you create a policy, you can either apply it to the device itself or to a group of users, which is nice. When you are finished, you save and publish your profile settings to your device collection in one click.
As we said, there are three different services for AirWatch: the base MDM and a second service to secure files (called Content Locker) and a third to run protected apps. Each service works with its own downloaded app on your device. That’s a lot of apps to download and add to your phone, and it can get confusing to keep switching among them. One caveat: these supplementary apps will require at least iOS v5 or later, although the base AirWatch MDM works on iOS v4 devices.
The content locker has its own policy settings, and can set up files that can’t be printed or edited for example. It will also keep track of previous file versions.
You can protect your email servers, just as long as they are Microsoft Exchange, Lotus Notes, Novell Groupwise and Google Apps for Business (which means the free Google Apps isn’t supported).
AirWatch supplies yet another downloaded app to use your email securely. There are other connective pieces to integrate with Active Directory (to enroll users and propagate policies, a mobile access gateway to connect to internal servers, and to exchange certificates).
AirWatch’s pricing is very transparent and published on its website. Each of the three modules (MDM, content, and apps) are priced a la carte either as a perpetual license with a one-time, per-device fee, or on a subscription basis, also on a per-device but monthly fee.
The MDM starts at $48 per device per year and the other modules can triple this annual cost. There is also a free 30-day trial for 50 devices that offers full functionality. AirWatch plans to begin selling a lighter-weight version called Pro that will have fewer features and be lower priced.
Apperian EASE
As you might guess from its name, Apperian is all about the apps. While it sells its product with its own MDM, it is very lightweight in terms of device and user control. If you have a lot of corporate mobile apps and you want to wrap them in a very secure mechanism to keep track of who uses them on what particular devices, then this is the product for you.
Apperian has two separate functional modules: an application control system and a built-in MDM. The MDM module doesn’t support BlackBerries – they are just supported on the app module. It has fewer features than the other MDM products we reviewed, although you can do the basics including wiping data from you phone, rootkit detection, controlling copy/paste from the mobile’s clipboard, and some rudimentary password control on your devices.
Initially, you don’t download anything to your phone, instead you use your phone’s Web browser to bring up the enrollment link and download a customized app store for your particular device and user name. However, this simple process is balanced with a tedious app wrapping process to add your security layer.
Each app can have its own security policies and they are very clearly spelled out in the policy screen on the Web management console. You need to make use of a corporate app certificate to wrap each app: Apperian prevents you from using individually signed certificates to distribute your own enterprise apps. Once you have created a customized app, you can’t delete it remotely from IOS without an MDM enrollment.
Its app catalog comes in different versions for native iOS or Android devices, along with another catalog that supports HTMLv5 and can be displayed in the device’s Web browser, which is how BlackBerry can access its app catalog.
Apperian has some basic reports on app usage but doesn’t really provide the kind of details on your devices that other MDM products have. It also has solid online context-aware help screens.
Apperian’s pricing is $48 per user per year. This means that if you have users who own many devices, they don’t pay anything extra, as some of the other MDM products charge by device.
BlackBerry Enterprise Server (BES) v10.1
BES always was one of the more solid and secure MDMs and the BlackBerry was almost synonymous with protected mobile email back when the company was called Research in Motion (RIM). Until recently, BlackBerry could only manage its own devices. Now it is capable of managing both Android and iOS too, via a new Universal Device Service. The extension into the brave new world of managing its competitors is intriguing, full of solid advantages, but somewhat complex to administer.
First, BES, along with Good, are probably the two best MDM solutions that we tested that really lock down your mobile email. If this is a big concern then you should consider this product just on that alone. Second, BES has a solid collection of iOS/Android device management policies that you wouldn’t expect from a v1 product.
They cover the waterfront, from a very granular collection of password policies to turning off specific phone peripherals (and not just disabling the camera itself but more subtle things like being able to hide the icon on your phone desktop or disable screen captures). There are policies to wipe your phone or require particular iOS or Android versions. For each policy, you can see which version of iOS or Android is relevant right on the screen: that is a nice touch and we wish other vendors were as forthcoming in documenting this.
To get started, you’ll need to install the various bits and pieces to a Windows Server (we tested a version that was already setup for us). There are three Web-facing consoles: one for your overall situation that is more of a dashboard with seven nice summary reports, one for managing just BlackBerry devices, and one for managing Android and iOS devices.
Each of the three consoles has different user interfaces and collections of tools. So if you want a single policy that can cover your entire installation, you are out of luck here: you’ll have to create a BlackBerry policy for password complexity, and then go over to the Android console to create the same thing again for those devices. We hope that eventually all can be melded into one unified console, because that is this product’s biggest drawback.
A second drawback is the complex process to setup app protection with nested menus upon menus that need to be completed. But to balance this complexity there are lots of online help videos and some pretty sophisticated and granular security policies.
Once you have your server setup, you next need to download the client app to your phone before you can activate each device. The activation is the easiest of all of the MDMs we tested, you just enter your email address and, like AirWatch, the software automatically steps you through the process. You have a series of apps that are downloaded to your phone: one that is a secure browser, one for the secure container, what BES calls its workspace, and one that is the client app that keeps track of things.
BES wants to remake your Android and iOS phones as close to the security model of the BlackBerry as it can and they have two scenarios: one called “Balanced” which divides the phone into personal and business sections, and one called Secure that locks the phone 100% into a corporate and protected device. The Balanced selection is only available on more recent vintage devices and BES10 servers, with the exception of iOS7. All communication is encrypted between the device and BES, and then from BES to the appropriate enterprise services, so no VPN is required. If BES detects a rooted/jailbroken device, it will shut down all communications, similar to how other MDMs operate.
BES10 is priced at $19 per device per year, with an additional $99 per user per year for its secure workspace features for Android and iOS devices. BlackBerry offers BES10 as a 60-day free trial including 50 secure workspace licenses and 50 device licenses. The company will offer a subset of the on-premises BES features in a cloud version in November.
Divide
Divide (the company recently changed its name from Enterproid) supports both iOS and Android devices but nothing else. Getting each device enrolled is very straightforward and involves downloading the app from iTunes or Google Play and registering your email address that will be used for that phone. Multiple devices can use the same email address, which is handy if you want to share information (such as contacts or files) among them.
However, Divide is somewhat particular about its iOS and Android support: while it appeared to have installed successfully on our older Android phone (running v2.3.4), the app wouldn’t execute at all, and didn’t even install on the Kindle Fire. It did work fine on an Android phone running v4.3. It supports devices running at least iOS v6.
Divide creates a separate and protected container and workspace on your phone where all business-related apps are launched. These include a wide range of their own contact manager, email, calendar, task list, and other items that share content with each other but not outside the protected environment. One of the more useful apps it has for Android (but not iOS) is called Timecard, which allows you to manage all your notifications so your phone isn’t buzzing in the middle of the night. IOS v7 has its Do Not Disturb feature. Speaking of buzzing, from its management console you can have a particular phone start ringing in case a user has lost it.
You are limited to a single container per device. If you use a cloud-based email service for your business and you don’t want your end users to download messages to an unprotected device, you will have to set your email provider to disable Web, POP and IMAP access and use a proxy server that points to the MDM server.
It doesn’t support the free version of Google Apps, you will have to make use of the paid accounts because they are the only ones to support use of Active Synch. This is how Divide distributes its policies and apps. You can bulk add users via uploading a CSV, and download a list via a CSV as well.
Divide can also connect to the F5 VPN concentrator, with links to Cisco and Juniper VPN endpoints in the works. The advantage of this approach is that you can securely connect via VPN within the MDM app, rather than dealing with a separate app.
It also has its own protected file system and it integrates with Box.com so you can download files from your Box account that could be viewed on the protected client. However, to make this work properly, you need a helper app to view the files, such as Mobi.office. Some readers might feel this compromises Divide’s security, given how insecure Box could be.
Divide uses a cloud-based manager to handle all devices, apps, and enterprise settings. The screens are clean and easy to navigate, with most of the MDM action happening under its Policy tab. For example, you can set which of the built-in Divide apps to load in your protected workspace, which third-party apps to whitelist or blacklist, what to do if your device is rooted/jailbroken, block any downloads of email attachments and choose the particular password policies to set for complexity.
You can enforce a particular client version of Divide, so if your users haven’t updated their phones lately they will be forced to do so. But there is no way to enforce a particular OS version to be running on your device.
For many of the security choices, you can ignore the violation, warn the user of it, block them from their protected data after the warning is issued, or wipe the protected data space. That’s a good selection of actions.
You can wipe all enterprise data from the protected areas of your phone either from within the Divide app on your phone, or from the management console. You can also force an automatic data wipe of your protected space if a certain number of failed login attempts occur.
We thought its device password policies weren’t up to the standards of some of the other products we used, such as forcing a device-wide PIN to be used.
Divide’s pricing of $60 per year per user includes unlimited devices for each user, something that may be of interest if your users have a lot of phones and tablets.
Fixmo
Fixmo came from the government compliance reporting space and it shows with its approach to device security. Its software is part of the Android Knox platform that Samsung uses on most of its smartphones. It also supports iOS, although didn’t have an iOS7 client at the time of our tests, and it only works on iOS v5 or v6.
Setup is relatively straightforward via Fixmo’s cloud service. There is also an on-premises Windows server that has additional features, with a web front end. You add users and devices and services via the menus, and these produce a series of emails with QR codes and URLs that direct the user to install the necessary configuration profiles for each device. Fixmo uses three profiles: one for MDM, one for passcodes, and one for its self-service portal.
This can get a bit tedious, compared to some of the other MDM products, but like others you can also bulk import and export users using CSV files. We had some problems with reading the QR codes because the Fixmo server wants to see the link sent coming from the phone’s Web browser. Some of the QR readers open their own browser – we needed to use an app that allowed us to open the URL in Safari or Chrome.
The cloud server doesn’t support end-to-end secure sessions, so with it you’ll need to use a supplemental VPN. The on-premises server has this additional security built-in, which makes it more useful. The Fixmo server can be tied to your Active Directory instance and will then use Active Synch to match up with your users. If you are using the on-premise server, it will create a VPN tunnel to Active Synch so that none of your smartphone apps can communicate directly with Active Directory.
Fixmo creates a secure container called SafeZone, which is an app that you download from iTunes or Google Play. It includes its own protected browser, an Office suite, email, calendar, contacts and a SharePoint app all built-in. The trick, like many MDMs, is to create your business-related content from this protected area. You can add apps via a separate series of menus in the management console, and you can get very granular with these and specify particular permissions for each app.
Policies are setup via the Web UI and are quite flexible, but again somewhat convoluted owing to the several different services that you have to manage. For example, there is a password policy for the secure iOS container, another password policy for the entire iPhone. And there are two other policies for Android containers and phones. There are two sets of very granular restrictions – one for iOS and one for Android — for disabling the camera or FaceTime or Siri or to prevent anyone from installing apps. These are somewhat awkwardly grouped in different submenus that will take some time to navigate.
Each policy can have one of three actions: send an email alert to an administrator, lock the device, or wipe the device. The Fixmo client automatically does a jailbreak/root detection upon launch. If it finds your phone has been compromised, it won’t allow you access to its secure container. There is also a feature where you can automatically wipe the container with a time bomb if it hasn’t called home within a certain interval, which is nice for lost or stolen phones.
Fixmo has services that it licenses separately, including the SafeZone secure container for iOS/Android, its MDM and security service called Integrity (which is also available for BlackBerries). Fixmo pricing for a full 250-user configuration is $18,000 per year. Each device is licensed separately starting at one service at $12 per month with quantity discounts and multiple-service discounts available.
Good Technology for Enterprise
Good for Enterprise has been around longer than most MDM solutions and was originally envisioned as a protected messaging environment that expanded into the MDM sphere. You can tell its longevity by the platforms it supports: in addition to Android and iOS devices, Good also supports Windows Mobile and even Palm OS devices. Noticeably absent is any support for BlackBerries, but also notable is its inclusion of the Kindle Fire. They have well developed integrations with Boxtone, Sailpoint and others, showing the maturation of their product.
Good actually has an additional product, like AirWatch, for file sharing called Good Share. This is more of a mobile collaboration tool. We didn’t test it, but it allows you to view files and connect to a SharePoint server. The main Good for Enterprise client has rudimentary file storage, but the files you save to your device aren’t sharable, unlike some of the other MDMs.
Enrollment is very straightforward. Once you add your user and device in the management console, you go to the handhelds tab in the console and retrieve a 12-digit PIN that is used to activate the client software. While typing in this PIN is painful, it is a one-time action that authenticates you to the Good for Enterprise server. Once that is accomplished, you are walked through the process of installing your MDM profile on the device and the secure container. Like other MDMs, you can bulk add users via uploading a CSV.
Good for Enterprise has a very extensive and granular collection of policies, including the ability to turn off the phone’s camera, disable cut and paste from within the Good protected environment, and allow or disallow Siri dictation from within the Good app. It supports a wide variety of phones, starting with Android v2.2 and Kindle Fires, iOS v5 and later, and includes Symbian and Windows Phones too.
Like Fixmo, you can have its client connect with its servers on a regular basis, and wipe the phone clean if the phone isn’t used or is stolen. Other MDMs block file attachments from being downloaded: with Good you can block specific file types as well as set a size limit (up to 32MB). After you make changes to your policies, you are brought to a summary screen that shows you which devices have been affected, which is a nice touch.
Good sells its server for Windows, but it is managed via a Web browser. The UI is very straightforward, although some of the policy details are tucked away in odd places. It has extensive password policies including smartcard support for second factor authentication. It also has solid online help that is quite searchable.
Compliance rules have five actions: quit the Good client, lock the client, wipe the protected data container, send an email notification, or force a new client download. This again shows the software maturity.
One downside is that the Good client has limited app sharing: while it is supported, it isn’t as useful as some of the other products.
Good for Enterprise costs $60 per user per year, which is on par with the other products in this review.
How we tested MDMs
We installed the MDM server and client software and tried to manage our mobile devices for a variety of scenarios. This included provisioning a new device, wiping files and apps from an old device, detecting rooted/jailbroken phones, enforcing policies, managing specific applications and pushing out updates. We looked at a variety of old and new phones and tablets running different vintages of operating systems including Android (along with the Amazon Kindle Fire, just to add a bit of excitement to the mix), iOS and BlackBerry to get a handle on how each software tool managed this collection.
We had each vendor set up an MDM using a cloud-based server to speed our testing process, and gave us administrative access. Then we tried to enroll all of our devices. This involved either downloading the app from iTunes or Google Play Stores or else sending a link via email that would be opened by the phone’s Web or email software browser to complete the enrollment process and set up the portals or apps on the phones for protected access. We also were interested in seeing whether we could map and manage a device to a particular user in our directory services so that an IT department doesn’t need any additional workflow, setup, or policies. Some of the products are more inclusive than others, and some require multiple steps to enroll and control a device.
Once enrolled, we looked at what was inside each vendor’s protected container and how you can add other business apps to the container. We also looked at how a typical enterprise IT manager would handle phones that are lost or stolen, or out of compliance. We examined how each solution protects user data and whether they could handle both company-owned phones as well as personal phones. Finally, we took note of what protection it offers business files and how it protected them on the phone or tablet.
Each product supports some kind of application catalog or portal that can be run from inside its protected container, along with the ability to save and share files securely as well.
While Good and BlackBerry offer on-premises Windows-based servers only, we had them also set up their software in the cloud for our review. We didn’t look at how the MDM manages typical desktops, since only AirWatch offers this ability among the products we tested.




