# Mobile Device Management
Mobile device management is the administration of enrolled devices, configuration, applications, security policy, and lifecycle state; it matters here as the institutional-control layer over phones and tablets.
## Historical and Technical Context
This page compares the **factory-to-enterprise onboarding chain**. Samsung KME is a cloud enrollment service that lets supported Samsung devices configure themselves for enterprise management during initial setup. Android zero-touch performs the analogous Android Enterprise function across participating manufacturers and resellers: on first boot, an assigned device retrieves its enterprise configuration and installs the designated device-policy controller. [S04][S05] Samsung E-FOTA adds lifecycle control after enrollment by allowing administrators to test, schedule, and enforce approved firmware versions. [S06] The AT&T Business Console reference likely reflects a reseller/carrier portal used to register devices into these enrollment ecosystems. [S07] The author was not merely comparing MDM brands; he was tracing the **supply-chain moment at which a retail device becomes institutionally governed**.
## Role in Scanned_20260730-1802
The primary identifying evidence appears on PDF page 5. Large black-marker text arranged in a vertical comparison. A long brace encloses the principal enterprise-enrollment technologies. “Zero Touch” is oversized. The lower half shifts to model-like alphanumeric fragments. A yellow adhesive or sticky-note remnant touches the bottom edge. Within that page, Mobile Device Management helps the notebook move from a visible name or artifact toward the underlying identity, protocol, ownership, or control structure.
## Notebook Evidence
- `Scanned_20260730-1802.pdf`, PDF page 5: "Samsung Knox Mobile Enrollment"
**Evidentiary status:** Visible evidence: explicit expansion of KME and E-FOTA. Verified fact: KME, zero-touch, and E-FOTA cover enrollment and firmware administration. Strong inference: research into fleet provisioning, reseller assignment, or ownership-state transitions. The two terminal codes may be device models, reseller tokens, or copied identifiers, but are too uncertain to classify.
The canonical name **Mobile Device Management** is normalized outside the quotations. The quoted lines preserve the completed reconstruction's spelling, capitalization, and uncertainty markers.
## Relationships
On PDF page 5, Mobile Device Management appears in the same evidentiary cluster as [[Samsung Knox Mobile Enrollment|Samsung Knox Mobile Enrollment]], [[Android Zero-touch Enrollment|Android Zero-touch Enrollment]], [[AT&T Business Console|AT&T Business Console]], [[Samsung Knox E-FOTA|Samsung Knox E-FOTA]]. These links record page-level proximity and the reconstruction's systems map; they do not by themselves prove corporate ownership or a direct technical dependency.
## Cross-Notebook Significance
Pages 32-34 later generalize the same question from phones to industrial fleets and IoT: how devices are claimed, provisioned, updated, located, and governed at scale. The notebook’s hidden through-line is **administrative custody over distributed hardware**.
## Missed Signals and Open Leads
Identify the exact AT&T portal name visible at the time. Resolve the two model-like codes. Determine whether the author was planning a legitimate deployment, auditing existing enrollment, or investigating why devices arrived preconfigured.
## Sources
- [[Scanned_20260730-1802|Scanned_20260730-1802]], especially PDF page 5.
- `Scanned_20260730-1802.pdf`, cited as a plain archival filename; the PDF is not stored in `wiki-notes`.
- **[S04]** Samsung Knox, “Knox Mobile Enrollment”. https://docs.samsungknox.com/admin/knox-mobile-enrollment/
- **[S05]** Google Android Enterprise, “Zero-touch enrollment”. https://support.google.com/work/android/answer/7514005
- **[S06]** Samsung Knox, “Knox E-FOTA”. https://docs.samsungknox.com/admin/knox-efota/
- **[S07]** AT&T Business Console. https://businessconsole.att.com/
## Scanned_20260730-1230 overlay
[[Scanned_20260730-1230]] demonstrates a manual precursor to device inventory: models, serials, radio/network identifiers, subscription identifiers, colors, and ordinal labels are copied onto paper. This resembles the inventory function later centralized by mobile-device-management systems, but the notebook contains no enrollment profile, management server, administrator, policy payload, or remote command record.
The occurrence should therefore be read as a continuity comparison, not evidence that the listed devices were MDM-enrolled.
## Scanned_20260730-1913 overlay
PDF page 47 of [[Scanned_20260730-1913]] supplies the archive's densest policy-level MDM record: extensible SSO, managed Wi-Fi, PaperCut Print Deploy, web-content filtering, Nudge, Jamf Trust, XCreds, directory services, Apple content caching, TCC, ACME, and SCEP. PDF page 56 separately records a task to remove MDM from a demo device.
This advances the earlier enrollment research from “how a device becomes institutionally claimed” to “which payloads govern identity, network access, certificates, printing, privacy, updates, and content.” It does not establish that the page-47 stack was installed on a particular device or that any management was unauthorized. See [[Apple Device Management]] and [[Index - Stages of Interception#Scanned_20260730-1913 stage coverage|the 1913 stage overlay]].
## Scanned_20260730-1958 overlay
PDF page 7 of [[Scanned_20260730-1958]] records [[Apple Business Manager]] identity, while PDF page 46 records a transferred Chromebook still managed by `chisd.net`. Together they show two points in the administrative-custody lifecycle: organizational assignment and failed or incomplete deprovisioning.
Physical possession and enterprise authority must remain separate. The management banner proves retained enrollment state; it does not by itself establish why the state persisted or whether the transfer was authorized.