IBM MaaS360
IBM MaaS360: mobile device management (MDM/UEM). Control employee phones, laptops, tablets - enforce passwords, encrypt data, remotely wipe lost devices.

Key Features
- MDM - phone and tablet management (iOS, Android)
- UEM - also laptops and desktops (Windows, macOS)
- Corporate container - separation of business and personal data
- Mobile Threat Defense - malware protection
- BYOD - secure use of personal devices for work
Table of Contents
What is IBM MaaS360?
IBM MaaS360 is a mobile device management (MDM) platform - it allows IT to control employee phones, tablets and laptops. You can enforce security policies, install applications, remotely wipe lost devices.
MDM vs UEM:
- MDM (Mobile Device Management) - phone and tablet management
- UEM (Unified Endpoint Management) - MDM + laptops + desktops + IoT
MaaS360 is a UEM solution - it manages everything.
Typical problems it solves:
- Employee lost work phone - you remotely wipe data
- BYOD - employee uses personal phone for work, how to secure company data?
- How to enforce password/PIN on all devices?
- How to install corporate applications on 500 phones?
How does MDM work?
1. Enrollment (device registration)
Employee registers device in MaaS360:
[Employee phone] → MDM profile installation → [MaaS360]
↓
Managed device
(IT sees, can control)
Enrollment methods:
- Email with registration link
- QR code
- Apple DEP / Android Zero-Touch (automatic at first power on)
2. Security policies
IT defines policies, MaaS360 enforces them on devices:
| Policy | What it does |
|---|---|
| Password | Enforces PIN min. 6 digits |
| Encryption | Enforces disk encryption |
| Jailbreak/Root | Blocks access if detected |
| Applications | Prohibits installation from unknown sources |
| VPN | Automatically connects to corporate VPN |
3. Application management
[IT Admin] → "Install Microsoft Teams on all iPhones"
↓
[MaaS360] → Push to 500 devices → [Application installed]
Capabilities:
- Application installation (corporate, from store)
- Application configuration (e.g. email settings)
- Application blocking (e.g. TikTok on work devices)
- App catalog - employees choose from approved list
Corporate container (BYOD)
BYOD problem: Employee uses personal phone for work. How to secure company data without interfering with personal photos?
Solution - container:
[Employee personal phone]
├── Personal zone (photos, Facebook, games)
│ └── IT doesn't see, doesn't control
└── Corporate container (email, Teams, documents)
└── IT controls, can wipe
MaaS360 container:
- Separate “space” on phone
- Company data encrypted
- IT can wipe ONLY container (not entire phone)
- Employee cannot copy data from container to personal space
Mobile Threat Defense (MTD)
MaaS360 has built-in mobile threat protection:
| Threat | How it protects |
|---|---|
| Malware | Scans applications, blocks malicious |
| Phishing | Detects fake sites/SMS |
| Man-in-the-middle | Detects dangerous WiFi networks |
| Jailbreak/Root | Detects and reports |
Threat response:
- Alert to IT
- Automatic blocking of access to company data
- Device quarantine
Supported devices
| Platform | Devices |
|---|---|
| iOS/iPadOS | iPhone, iPad |
| Android | Samsung, Google Pixel, others |
| Windows | Laptops, desktops |
| macOS | MacBook, iMac |
| Chrome OS | Chromebook |
| Rugged | Zebra, Honeywell (warehouses, production) |
MaaS360 vs competition
| Feature | MaaS360 | Microsoft Intune | Omnissa Workspace ONE |
|---|---|---|---|
| MDM | Yes | Yes | Yes |
| UEM | Yes | Yes | Yes |
| Built-in MTD | Yes | Partial | No (requires add-on) |
| AI/Watson | Yes | Copilot | No |
| BYOD container | Yes | Yes | Yes |
| Price | Medium | Cheaper with M365 | Higher |
When MaaS360?
- You have IBM (integration with QRadar, Verify)
- You need MTD in one tool
- Rugged devices (warehouses, production)
- FedRAMP/government compliance
When Intune?
- Mainly Microsoft 365 (you have it in package)
- Simpler integration with Azure AD
For whom?
MaaS360 makes sense when:
- You have >100 mobile devices to manage
- BYOD - employees use personal phones
- You need MTD (malware protection)
- Rugged devices (scanners, terminals)
- Compliance (HIPAA, FedRAMP, GDPR)
MaaS360 does NOT make sense when:
- Small company (<50 devices) - may be overkill
- Full Microsoft stack - Intune may suffice
- Only Windows laptops - SCCM/Intune simpler
How much does it cost?
SaaS model, per device per month:
| Variant | What’s included | Approximate price |
|---|---|---|
| Essentials | Basic MDM | ~$4/device/month |
| Deluxe | MDM + container + apps | ~$7/device/month |
| Premier | UEM + MTD + identity | ~$10/device/month |
Example: 500 devices × $7 × 12 months = ~$42,000/year
Specifications
| Deployment | SaaS (cloud) |
| Platforms | iOS, Android, Windows, macOS, Chrome OS |
| Integrations | Azure AD, Okta, ServiceNow, QRadar |
| Compliance | FedRAMP, HIPAA, SOC 2, ISO 27001 |
| AI | Watson powered insights |
FAQ
How is MDM different from UEM? MDM = mobile only (phones, tablets). UEM = everything (mobile + laptops + desktops + IoT).
Does employee see what IT does with their phone? Depends on configuration. IT can e.g. install applications, but not read private messages. BYOD container isolates company data.
What happens when employee leaves? IT remotely wipes corporate container (data, email, applications). Personal data remains.
Can I remotely wipe a lost phone? Yes. You can wipe only container (BYOD) or entire phone (corporate).
How long does deployment take? Basic MDM: days. Full UEM with policies: weeks.
Does MaaS360 integrate with Azure AD? Yes. SSO, conditional access, user synchronization.
What about employee privacy? MaaS360 distinguishes corporate and personal data. In BYOD IT doesn’t see personal data.
Does nFlo deploy MaaS360? Yes. Policy configuration, enrollment, integration with identity (Azure AD, Okta), training for IT.
Inquire about IBM MaaS360
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Comprehensive IBM i (AS/400) Services
IT Infrastructure
Maintain IBM i system stability without costly migration. Administration and modernization from specialists with 20+ years experience.
IBM watsonx - Enterprise AI Platform
AI and Automation
AI for business, not for hype. IBM watsonx implementations with ROI from month one.
IBM Power Services
IT Infrastructure
Maintain critical IBM Power systems without downtime. Specialists with 15+ years experience.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
From Our Knowledge Base
Articles related to this solution
CVE-2026-10561: IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python...
Security Alert - CVE-2026-10561 (IBM Langflow OSS). CVSS: 10 (critical).
CVE-2026-7664: IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected...
Security Alert - CVE-2026-7664 (IBM Langflow OSS). CVSS: 9.8 (critical).
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist