Skip to main content

Secureframe Federal MDM

Written by Brady Price

What Federal MDM is

Secureframe Federal MDM is compliance-focused device management for organizations working toward CMMC, built on a FedRAMP-authorized federal platform and managed by Secureframe. It monitors and enforces CMMC-required security settings on your Windows, macOS, and Linux computers, and it is the right fit when your team's own computers will handle Controlled Unclassified Information (CUI).


What it does

Once the agent is installed, each device is continuously checked against CMMC requirements, and results feed into your Secureframe dashboard mapped to the relevant controls. You get centralized visibility into device status, software inventory, antivirus status, and compliance posture.

Controls are enforced or monitored per platform, including:

  • Password policy: Strong password requirements with minimum length, complexity, and lockout protections

  • Screen lock: Automatic locking after inactivity, and automatic login disabled

  • Disk encryption: Validation using the operating system's native encryption, with help enabling it

  • Firewall and antivirus: Native OS firewall enablement and antivirus presence and status validation

  • Warning banner: An authorized-use notice enforced before login

  • Remote access restrictions: Detection and restriction of remote access to managed devices

  • Application execution control: Validation using the platform's native controls

  • Audit logging: Capture of security-relevant activity on each device

  • Software and patch visibility: Update status monitoring across the fleet

The security policies applied to your devices are a hardened CMMC baseline managed by Secureframe, so your devices can't quietly drift from the compliant configuration. Where a device falls out of line on a setting that supports it, remediation runs automatically.


Platform coverage

  • Windows: Broadest coverage, with native event logging, near real-time monitoring, and the fullest enforcement.

  • macOS: Enforcement for key controls, with some limits imposed by the operating system.

  • Linux: Selected control enforcement, with some items requiring manual remediation.

Compliance is evaluated consistently across platforms even where implementation differs.


Device lifecycle

  • Delete: Removes a device from management with best-effort cleanup of the agent and settings.

  • Wipe: For lost or stolen devices, performs a best-effort lockout or destructive action, with behavior that varies by operating system. Contact support before using wipe if you are unsure.


Licensing

Each managed device uses one Federal MDM license at $15 per device per month. The devices page shows your usage against your allocation, and devices beyond your license limit may be removed from management automatically. Managed devices appear in Asset Inventory tagged as Secureframe Federal MDM.


Data privacy

Federal MDM collects device security posture information only: device metadata, security settings status, software inventory, compliance states, and security-relevant audit events. It does not access user files or personal data.


Frequently Asked Questions (FAQ)

Does Federal MDM make my devices CMMC compliant?

  • It enforces and monitors the device-level requirements, which is a major piece. Full compliance also requires the rest of your program: policies, training, personnel processes, and documentation, which Defense Navigator walks you through.

We use GCC High conditional access. Do Federal MDM devices count as compliant devices?

  • Not currently. GCC High conditional access policies that require a "compliant device" evaluate Intune-managed compliance, and Federal MDM enrollment does not register devices as compliant in Microsoft Entra today. If you plan to combine GCC High conditional access with Federal MDM, talk to your CSM about the right configuration.

Can we access the underlying device management platform directly?

  • Device management happens in your Secureframe dashboard: viewing devices and their compliance posture, approving USB devices, and removing or wiping devices.

Questions? Contact [email protected] or reach out to your CSM.

Did this answer your question?