Key Features
Secureframe Federal MDM is a FedRAMP Moderate authorized device management solution for organizations working toward CMMC. It monitors enrolled endpoints against NIST 800-171 and CMMC security requirements and sends that posture into Secureframe.
FedRAMP Moderate Authorized
Federal MDM runs in a FedRAMP Moderate environment, so it can support Controlled Unclassified Information (CUI) workloads as part of your CMMC program.
Automated Device Compliance Monitoring
Hard drive encryption verification: automatically checks that enrolled devices have full-disk encryption enabled
Firewall status monitoring: verifies the local firewall is active
Antivirus/anti-malware detection: confirms security software is installed and running
Operating system patch status: tracks OS update compliance across your fleet
Multi-factor authentication (MFA): validates MFA is configured on devices
Integration with Secureframe
Device compliance data from Federal MDM flows into your Secureframe dashboard and maps to relevant CMMC tests and controls, so you spend less time gathering endpoint evidence by hand.
Pricing
$15 per device per month, billed upfront.
Contact your Customer Success Manager or [email protected] to add Federal MDM to your subscription.
Getting Started
Prerequisites
Active Secureframe Defense subscription
Devices running Windows 10/11, macOS 12+, or supported Linux distributions
Enrollment Steps
Enable Federal MDM: Contact your CSM to enable Federal MDM on your account and confirm the number of devices. Once added, Secureframe Federal MDM appears as connected on the Integrations page.
Specify groups: Go to Personnel Settings → Onboarding → Secureframe device management and choose the groups that should use Secureframe Federal MDM. You can confirm who is included from the Groups tab in Onboarding. Example with installation enabled and the user group "Employees" included:
Download and install the agent: Personnel in the designated groups see a Secureframe Federal MDM step in Employee Onboarding. From there, download and install the device agent for your operating system.
Verify enrollment: Enrolled devices appear in your Asset Inventory within about 15 minutes.
Uninstalling the Secureframe Federal MDM
For Admins
Important: The Delete device option in Asset Inventory is only available for devices whose Source is Secureframe Federal MDM. It does not appear for Secureframe Agent devices, third-party MDM integrations, or CSV-uploaded devices. You must have an Admin role to delete devices.
For admins, the easiest way to uninstall Secureframe Federal MDM from a device is to delete the device from the Asset Inventory page.
To delete a single device, open the three-dot menu next to the device, then click Delete device. To delete multiple devices, select them with the checkboxes in the left column, then click Delete.
For Individual Users
Note: Prefer deleting the device in the Secureframe app when you can. Use the scripts below only if that is not an option.
Uninstallation scripts are attached to this article for each operating system.
Windows
Download the attached zip uninstall-secureframe-federal-mdm.zip and extract it to get the PowerShell script uninstall-secureframe-federal-mdm.ps1. Open PowerShell as Administrator, navigate to the folder with the extracted script, and run:
powershell -ExecutionPolicy Bypass -File .\uninstall-secureframe-federal-mdm.ps1
macOS
Download the attached Bash script uninstall-secureframe-federal-mdm.sh. Open Terminal, navigate to the folder with the script, and run:
chmod +x uninstall-secureframe-federal-mdm.shsudo ./uninstall-secureframe-federal-mdm.sh
Linux
A Bash script named linux-uninstall-secureframe-federal-mdm.sh is attached to this article. On the device, go to /opt/NinjaRMMAgent/programfiles/ and run the uninstall command that matches your distribution:
sudo ./ninja-deb-uninstall.shsudo ./ninja-deb-harakiri.shsudo ./ninja-rpm-uninstall.sh
Troubleshooting
Device not appearing in inventory
Verify the agent is running on the device
Check that the device has internet connectivity
Allow up to 15 minutes for the initial sync
Compliance check showing as failed
Review the specific check details in the device view
Some checks require a device restart after remediation
Contact support if the issue persists after remediation
Frequently Asked Questions (FAQ)
What data does Secureframe Federal MDM collect?
Federal MDM collects device security posture information only, including encryption status, firewall status, antivirus status, and OS version. No user files or personal data are accessed.
Can I use Federal MDM for non-CMMC compliance?
Yes. It is built for CMMC, and the same device compliance data can support other frameworks including FedRAMP, NIST 800-53, and StateRAMP.
How do I remove a device from Federal MDM?
Confirm the device Source shows Secureframe Federal MDM, then delete it from Asset Inventory using the three-dot menu or bulk delete. This also uninstalls the Federal MDM agent. For other device types, see Removing devices from Asset Inventory.
Need help? Contact [email protected] or use the Help widget in the Secureframe app.
