What is endpoint management?

Endpoint management is the process of controlling endpoint devices connected to a network. Organizations use endpoint management software to administer network access for remote devices and to enforce security policies that protect the IT environment.

Core capabilities of endpoint management

Endpoint management software gives IT administrators a central way to control endpoint devices across an organization. Its core capabilities are:

  • Device enrollment - registering and provisioning new devices onto the management platform
  • Configuration management - applying consistent settings, Wi-Fi, and VPN profiles across devices
  • Patching - deploying security patches and software updates to keep devices current
  • Compliance monitoring - checking devices against security policies and flagging non-compliance
  • Remote support - troubleshooting, locking, or wiping devices remotely

Why is endpoint management important today?

Endpoint management is important because it helps to ensure endpoint health and security through active authentication, management, and updating. With proper endpoint management IT can provision a fleet of devices, which helps ensure their health and security. It also allows IT and security teams to protect employee devices, which helps enable today's hybrid workplaces.

What are the benefits of endpoint management?

The benefits of endpoint management include:

  • Simplified device control
  • Streamlined application deployment
  • Dynamically enforced access
  • Compliance with security policies
  • Enhanced control over security patches and device updates
  • Scalability to enhancements and automation
  • Wi-Fi and VPN configurations

How are endpoint management systems set up?

Setting up an endpoint management system starts with choosing an IT or IT-security vendor to provide endpoint management software. Once the software is deployed, IT administrators remotely enroll devices on the management platform, automate network policy enforcement, configure Wi-Fi and VPN settings, and more.

Endpoint security policies are commonly aligned to control frameworks such as NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations.

Key endpoint-management strategies

Mobile device management

Mobile device management (MDM) is a monitoring and management solution designed to enable secure mobile devices such as smartphones and tablets. MDM solutions like Cisco Meraki Systems Manager equip organizations to enforce security policies on mobile endpoints, control access to corporate data, and remotely wipe stolen devices.

Unified endpoint management

A unified endpoint management (UEM) solution manages and authenticates a variety of endpoint devices, including PCs, laptops, smartphones, and tablets. UEM solutions like Meraki Systems Manager allow for device, application, and user management through a single, unified security platform.

Endpoint detection and response

Endpoint detection and response (EDR) solutions detect and respond to advanced threats that evade traditional antivirus and anti-malware software. Endpoint management solutions such as Meraki Systems Manager enhance EDR capabilities to defend endpoint devices against sophisticated threats.

Endpoint protection platforms

Endpoint protection platforms (EPPs) stop attacks using multifaceted techniques such as machine learning, behavioral protection, and file reputation. For instance, Meraki Systems Manager works with endpoint security solutions such as Cisco Secure Endpoint—which includes EPP and EDR capabilities—to prevent, detect, and respond to threats.

Network access control

Network access control (NAC) solutions are used to regulate access to network applications based on defined policies and device security posture. For example, Meraki Systems Manager allows for dynamic NAC with customizable security policies that manage access to the network based on device posture, location, installed or running software, user identity, and more.

Endpoint security

Endpoint management and endpoint security work together but serve different purposes:

AspectEndpoint managementEndpoint security
Primary purposeDeploy, configure, monitor, and maintain endpoint devicesPrevent, detect, and respond to threats on endpoints
FocusDevice health, provisioning, policy enforcementThreat prevention and incident response
RoleEnables security policies and safeguards device integrityActively defends devices against attacks
TogetherProvisions and maintains devices in a known-good stateStops threats that target those devices

Endpoint management and endpoint security are most effective when paired. For detail on threat defense, see the endpoint security page.

What is an endpoint?

An endpoint is any device that connects to a network system or its applications. Examples of endpoints are mobile devices, laptops, desktop computers, tablets, Internet of Things (IoT) devices, digital printers, and switches.

What is endpoint security?

Endpoint security uses multifaceted prevention techniques, deep visibility, advanced threat detection and response, and rich threat intelligence to rapidly block, detect, analyze, and contain threats automatically. Types of endpoint security solutions include EPP and EDR.

Why is endpoint security important?

Endpoint security is important for protecting users from sophisticated attacks such as ransomware while helping organizations swiftly recover from breaches. Endpoint security solutions that offer deep visibility, advanced detection, and simplified response are key to protecting an organization and its workforce.

Is endpoint security enough on its own?

Endpoint security and endpoint management are most effective when paired together to prevent and defend against attacks. Endpoint management helps prevent attacks by enabling security policies and safeguarding endpoint integrity, while endpoint security actively defends organizations against attacks.

How can Cisco help with secure endpoint management?

Meraki Systems Manager—simplifies endpoint device management with it’s cloud-based Meraki dashboard, supporting easy monitoring, authentication, and provisioning. It also supports seamless integration with Cisco Catalyst SD-WAN powered by Meraki for enterprise network security.

Common questions about endpoint management

Endpoint management is the process of controlling endpoint devices connected to a network. Organizations use endpoint management software to deploy, configure, monitor, and maintain devices, and to enforce the security policies that protect the IT environment.

Endpoint management deploys, configures, monitors, and maintains endpoint devices, while endpoint security prevents, detects, and responds to threats on those devices. Management keeps devices in a known-good, compliant state; security actively defends them. The two are most effective when used together.

Unified endpoint management (UEM) manages and authenticates a range of endpoint devices — PCs, laptops, smartphones, and tablets — through a single platform. It combines device, application, and user management so IT can apply consistent policies across all device types.

Endpoint management supports Zero Trust by enforcing device health checks, compliance policies, and access controls before a device connects. By ensuring only managed, compliant devices reach resources, it provides the device-posture signals a Zero Trust model relies on.

The core capabilities are device enrollment, configuration management, patching, compliance monitoring, and remote support. Together they let IT administrators provision a fleet of devices and keep them secure, current, and compliant from a central platform.