Factorial IT manages macOS, Windows, Linux, iOS, iPadOS, Android and ChromeOS from one place. This article lists the minimum version for each platform and what you can and cannot do on it, so you know what to expect before you enrol a device.
Overview
Check this article before you enrol a new platform or promise a capability to your team. Coverage is not identical everywhere: some limits come from the operating system itself, not from Factorial IT, and no configuration will work around them.
What each platform supports
| macOS | Windows | Linux | iOS, iPadOS | Android | ChromeOS | |
| Minimum version | 14+ | 10+ (Pro/Enterprise) | Ubuntu 20.04+ | 17+ | 13+ | 112+ |
| Enrol and monitor | Yes | Yes | Yes | Yes | Yes | Yes |
| Encrypt disks | Yes | Yes | Yes (see below) | Native | Native | Yes |
| Remote lock and wipe | Yes | Yes | Yes | Yes | No | Yes |
| Apply controls | Yes | Yes | No | Yes | Yes | Via Google Admin |
| Install software | Yes | Yes (see below) | Yes | Yes | Yes | Via Google Admin |
| Run scripts | Yes | Yes (see below) | Yes | Not available | Not available | No |
How to use
Work through these before enrolling a platform for the first time:
- Check the minimum version. Devices below it cannot enrol
- Check the capabilities you actually need in the table above, not the ones you assume are there. Remote wipe on Android and controls on Linux are the two that surprise people most often
- Read the platform note below if you are enrolling Windows, Linux, ChromeOS, or mobile
Windows
Windows Home is not supported. The edition has no MDM capability, so disk encryption management, remote lock and remote wipe are all unavailable.
ARM devices work, with limits. Software installation is supported, but the maintained app catalogue holds mostly 64-bit x86 builds. Deploying those to an ARM device can fail or install something unexpected.
Linux
You can report on encryption status across your Linux fleet and escrow recovery keys, so you keep access if a device locks. What you cannot do is manage encryption from the dashboard — Linux has no mechanism to encrypt a disk after installation, so it has to be configured when the operating system is installed.
| Distribution | Minimum version |
| Ubuntu | 20.04+ |
| Debian | 11+ |
| CentOS | 7.1+ |
| Fedora | 38+ |
| Amazon Linux | 2+ |
| Red Hat Enterprise Linux (RHEL) | 7+ |
| openSUSE | 15.6+ |
| Arch Linux | Supported |
| Omarchy | Supported |
| Alpine | Not supported (APK format) |
iOS, iPadOS and Android
These devices are encrypted by the operating system. There is nothing to switch on and nothing to manage — encryption cannot be toggled through MDM on either platform. Scripts and osquery are also unavailable, which is a platform limitation rather than a gap in Factorial IT.
ChromeOS
You can enrol ChromeOS devices for monitoring, but controls, software installation and policy enforcement run through your Google Admin console, not through Factorial IT. Contact support to set this up.
Tips and best practices
- Audit editions before a Windows rollout. Windows Home devices cannot enrol at all, and finding out one machine at a time is slower than checking up front
- Decide Linux disk encryption at build time. It cannot be applied retroactively, so a device that ships unencrypted stays that way until it is rebuilt
- Do not plan a remote-wipe process that depends on Android. Remote wipe is unavailable there, so an Android device needs a different offboarding path.
- Test ARM software deployments on one device first, since the catalogue is mostly x86
Troubleshooting and FAQ
Troubleshooting
- A Windows device will not enrol. Check the edition. Pro, Enterprise and Education enrol; Home does not, and no setting changes that.
- A Linux device reports no encryption. Encryption was not configured when the operating system was installed. The dashboard reports on Linux encryption but cannot apply it, so the device has to be rebuilt with encryption enabled.
- Controls are not applying to a Linux device. Controls are not supported on Linux. Use scripts instead.
FAQ
-
Can we manage encryption on iPhones and Android devices?
No, and you do not need to. Both platforms encrypt at the operating system level and the setting cannot be managed through MDM.
-
Why can I not run scripts on mobile devices?
iOS, iPadOS and Android do not expose script execution to MDM. It is a platform limitation.
-
Is ChromeOS fully managed by Factorial IT?
Only monitoring. Controls, software and policy enforcement stay in your Google Admin console.