Everything you need to manage Apple devices

From enrollment to compliance, Visir gives you complete control over your iPhone, iPad, and Mac fleet.

Product capabilities built for Apple operations

Enrollment

Device Enrollment

Multiple enrollment paths to fit any deployment scenario. From zero-touch with Apple Business Manager to manual QR-code enrollment for BYOD.

Enrollment Queue
iPad-Sales-01
Enrolled
iPhone-HQ-03
Enrolled
MacBook-Eng-07
Pending

Configuration

Configuration Profiles & DDM

Manage devices with traditional MDM profiles or modern Declarative Device Management. Build configurations visually — no XML editing needed.

Declaration Types
Wi-Fi
VPN
Passcode
Certificate
Managed App
OS Update
DDM Ready

Apps

App Management

Deploy and manage applications across your fleet. Integration with Apple's VPP and Apps & Books for licensed app distribution.

App Deployment
SlackInstalled
SalesforceInstalled
ZoomPending

Supporting capabilities for day-two operations

Beyond the core workflows, Visir gives teams the organizational controls and policy depth needed to run Apple operations reliably at scale.

Operations

Remote Commands

Execute commands on any managed device instantly. Every command is tracked from request through completion with full audit trail.

  • Device Information query
  • Lock, Restart, Shutdown, Erase/Wipe
  • Return to Service (erase + auto-re-enroll)
  • Install/remove profiles and apps remotely
Command History
DeviceInformationCompleted
DeviceLockCompleted
RestartDeviceSent

Organization

Smart Tags & Blueprints

Organize devices dynamically with rule-based smart tags. Create policies that automatically apply to devices matching your criteria.

  • Smart tags with dynamic rule evaluation
  • Manual tags for explicit device grouping
  • System tags seeded per tenant
  • Tag-based profile and app assignment
Tag Rules
IFOS VersioncontainsiPadOS
ANDModelisiPad Pro
12 devices matched

Security

Device Restrictions

Enforce granular security policies with 130+ Apple restriction keys. Full supervision awareness — know exactly which restrictions require supervised mode.

  • 130+ restriction keys from Apple's MDM spec
  • Supervision requirement indicators
  • Organized by category: functionality, apps, media, network
  • Restriction profiles assigned via tags or locations
Active Restrictions
Camera Disabled
AirDrop Disabled
App Install Restricted

Audit Logging

Every admin action is recorded with structured metadata. Know who did what, when, and to which device — with full resource tracking.

  • Structured events with resource type, ID, and name
  • JSONB metadata for rich context
  • Dashboard activity feed for at-a-glance monitoring
  • Location-scoped audit entries
  • Filterable by resource type, user, and date range
Audit Log
Profile assignedWi-Fi Corp → iPad-Fleet
admin2m ago
Device lockediPad-Warehouse-04
helpdesk15m ago
Tag evaluated"All iPads" — 68 devices
system1h ago
Enrollment completediPhone-Field-19
system2h ago

Certificate Management

Automated certificate lifecycle management. SCEP CA auto-initializes, certs renew before expiry, and you get alerts before anything breaks.

  • SCEP CA with auto-initialization
  • Certificate expiry detection and alerting
  • Guided renewal workflow for APNs and push certs
  • All private keys encrypted at rest (AES-256-GCM)
  • Token lifecycle tracking for ABM/ADE
Certificate Status
APNs Push CertificateExpires Apr 21, 2027
Active
SCEP CA RootExpires Mar 15, 2031
Active
Identity CertificateExpires Jun 08, 2027
Active
ABM Server TokenExpires Dec 01, 2026
Renew Soon

Multi-Network Management

Manage devices across multiple locations or networks from a single console. Scope policies, profiles, and views by network.

  • Location-based organizational scoping
  • Network-specific profile and policy assignment
  • Per-location check-in health intervals
  • Consolidated or filtered fleet views
Network Overview
Headquarters64 devices
Healthy
Tampa Office38 devices
Healthy
Field Operations29 devices
2 overdue
Retail Stores20 devices
Healthy

RBAC & Multi-tenancy

Enterprise-grade access control with four built-in roles and complete tenant isolation. Every query is tenant-scoped — no data leaks, guaranteed.

  • Four roles: Owner, Admin, Helpdesk, ReadOnly
  • Location-scoped user access
  • Complete tenant isolation at the database level
  • MFA/TOTP for admin accounts
  • Platform admin for multi-tenant management
Access Control
sarah@company.coAll Networks
Owner
mike@company.coHeadquarters
Admin
jessica@company.coTampa Office
Helpdesk
david@company.coAll Networks
ReadOnly

Ready to modernize your Apple device management?

See how Visir fits your enrollment, policy, compliance, and operations workflow.