Windows MDM + Monitor

Windows PCs,
managed from the same desk

Enrol a PC with the Monitor installer or straight into Windows MDM with a code. Set password and update rules, Defender, firewall, BitLocker, accounts, apps and kiosk by group. Wipe or reset it from the console. And when you choose, understand the workday with Monitor, an agent that shows itself.

A Windows profile in the console: visibility, activity and snapshot rules, then the device settings sections, Password, Windows Update, Microsoft Defender, Firewall, BitLocker, Sign-in message, USB storage, Accounts, Kiosk and Protection.

Device management

One Windows profile per group, applied at the next check-in

Device settings live in the Windows profile beside the monitoring rules, so a group of PCs gets one policy. Each setting reports back per device, and the profile page shows which workstations could not apply it and why.

Password and Windows Update rules

Minimum length, complexity and expiry for local accounts; how and when Windows Update installs, so a fleet patches on your schedule, not Microsoft's.

Defender, firewall and BitLocker

Real-time protection, the firewall on every network, and drive encryption with the recovery keys kept in the console, shown on demand and recorded under the viewer's name.

Accounts on the PC

Who can sign in, as administrator or standard user. Add or remove accounts, reset passwords, block Microsoft accounts, and keep DeviceDesk's own administrator account with a password only the console knows.

Apps by group

Upload an MSI or EXE once and choose the groups whose PCs get it. Each device reports installed, not installed with Windows' reason, or waiting. Store apps go over Windows MDM.

Kiosk

Microsoft Edge on a web address, one Store app, or a set of apps with its own Start pins, under a kiosk account Windows signs in by itself.

Wipe, reset, restart

Erase everything, reinstall Windows keeping people's files, or take a cloud reset, each offered only where the PC can take it. Restart, shut down or put a message on the screen in between.

Inventory

Hardware, the full software list, edition and activation, and security posture, sent a few minutes after Monitor starts and then daily. Software changes land on the workstation's timeline.

Sign-in message and USB storage

A notice on the sign-in screen, and removable storage allowed or blocked, applied by group and reported back per device.

Results across the fleet

Every setting's outcome on every workstation on one page, with the ones that could not apply it and why, so a policy is a fact rather than a hope.

Enrolment

Two doors in, one workstation

Run the Monitor installer with your workspace token, or enrol the PC into Windows MDM with a code and no Monitor at all. Either way it is one workstation in the console, and Monitor can be installed later over Windows MDM without touching the PC.

  • The installer checks the token with DeviceDesk before it installs, so a wrong one is caught on the spot
  • Manage only, without monitoring: a front desk, a kiosk or a shared PC with nothing captured and no tray icon
  • Windows MDM enrolment renews its own certificate; the console says what to do if it hasn't
  • Monitor stays put: uninstall is blocked and a reinstall can be sent from the console
Enroll → Windows in the console: the enrolment token with Reveal, Copy and Rotate, the four steps from installer to first report, and the manage-only command line for a PC without monitoring.
A workstation's day in the console: 6h 52m active, 42m idle, a 9:10 AM to 4:42 PM day span, the hour-by-hour chart, who used it, and where the active time went by application and website.

Monitor

See the workday.
Respect the worker.

Switch monitoring on per workstation and Monitor records which app had focus, the website's domain, and whether someone was there, hour by hour. Never what was typed, never window titles, never full addresses.

Activity timelines

Active and idle by the hour, per person and per workstation, with the day span and yesterday's comparison.

Apps and sites

Where the hours went by application and domain. Exported as CSV from the People page.

Live view, announced

Look at a screen when you need to; the person sees it in their status window, and control stays off.

Lock and sign out

Lock Screen or sign out a PC from the console, and sign out idle sessions automatically after a warning.

Visible by design

The person being monitored can read the same list you can

Monitor's status window sits in the tray of every workstation it runs on. It shows when activity and snapshots were last sent, whether a manager is viewing the screen, and what is and isn't recorded. Everything is attributed to the Windows account that was signed in when it was captured.

Recorded
  • Foreground app name
  • Website domain only
  • Idle or active presence
  • Screenshots on a schedule
Never recorded
  • Window titles
  • Full web addresses
  • Keystrokes or clipboard
  • Remote control of the PC
The Monitor status window: Live view active, a workspace manager is viewing this screen and keyboard and mouse control are disabled, the times activity and snapshots were last sent, and the list of what this Monitor records and what it does not.
The Monitor status window showing Needs attention: the enrolment token was not accepted, with Fix enrollment, Retry now and Open log folder actions, and no activity sent yet.

Background monitoring

Stays out of the way, and says so when it can't

Choose how Monitor appears on your team's workstations. Quiet mode suppresses the local status window, menu and routine notifications, including live-view alerts. The tray icon and status tooltip remain, and when enrolment or capture breaks, the window turns red and explains the fix.

Tray status indicator

The DeviceDesk tray icon and status tooltip remain available while the agent runs, including in Quiet mode. Windows may place the icon in the tray overflow.

Managed through profiles

Administrators choose Quiet mode per Windows profile and apply that profile to workstation groups.

No keystroke logging

We record which app had focus, never what was typed into it. There is no keylogger to enable.

Retention, stated

Activity is kept for 90 days, screenshots for 30 and workstation timelines for 90, then swept nightly. Forgetting a workstation removes it from the fleet.

Put your PCs on the desk

Seven days free on the full product, then one device free forever. Enrol a PC with the installer or a Windows MDM code, and it appears in the console at its first check-in.