CIOPages
All RFP packages

RFP Package · IT Management & Governance

Unified Endpoint Management (UEM) RFP questions and template

129 questions, 10 demo scenarios and a five-vendor scorecard for choosing Unified Endpoint Management (UEM) software, in one Excel workbook.

What this package is for

Use it to run a Unified Endpoint Management (UEM) software selection, from the first long list to the final scorecard.

What the category covers. 126 questions in 12 areas test how a unified endpoint management product enrolls, configures, secures, patches and supports Windows, macOS, iOS, Android, Linux and rugged devices, and how it moves devices off the incumbent MDM. Ten demo scenarios have the vendor perform the hardest cases live: a personal iPhone and Android phone, a rugged shared scanner, an emergency patch, a threat alert that revokes access and a live migration.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 25 questions screen out products that lack something you need.
  • RFP, to the shortlist. 69 questions ask how each product does the work.
  • Deep dive, to the finalists. 35 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 90 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. List the corporate enrollment programs your product integrates with for each OS in [OS versions in scope], including any OEM enrollment programs.

Why it matters. Devices bought through a program the product does not support must be enrolled by hand or by the user. Those devices can then be removed from management.

Good answer
  • A per-OS table that names each program, such as Apple Business Manager with Automated Device Enrollment, Windows Autopilot and Android zero-touch
  • States the integration type for each program, such as API sync or manual token upload
  • Names the device brands and models each OEM enrollment program covers
Red flags
  • Lists program names without per-OS or per-device-type detail
  • Treats user-initiated agent enrollment as equivalent to program enrollment
  • Presents roadmap integrations as available

2. Which Declarative Device Management configuration types does your product deliver to macOS, iOS and iPadOS devices running [OS versions in scope]?

Why it matters. Apple delivers some newer management settings only through declarations. Gaps in a product's declaration coverage leave those settings unmanaged on the buyer's Apple devices.

3. List the Android Enterprise management modes your product supports for company-owned devices, such as fully managed, dedicated and work profile on a company-owned device, with the Android versions in [OS versions in scope] supported for each mode.

Why it matters. If a mode the buyer needs is missing or limited to some Android versions, part of the corporate Android fleet cannot be enrolled the way the buyer intends. Those devices end up on a weaker mode or on a second tool.

Capability areas

Enrollment & Zero-Touch Provisioning (12)

Corporate enrollment through Apple Business Manager (Automated Device Enrollment), Windows Autopilot and Android zero-touch or OEM enrollment programs, the out-of-box setup experience, staging, re-provisioning, and retirement of a device (wipe, release from the enrollment program, reassignment). BYOD privacy controls and migration off an incumbent MDM are covered in their own areas.

macOS & iOS/iPadOS Management Depth (13)

Supervision, Declarative Device Management, configuration profiles, macOS identity and login integration, FileVault and Activation Lock handling, shared iPad, and how quickly new Apple management features become available after each OS release. Apple enrollment mechanics are covered in ENR, and app distribution is covered in APP.

Android Enterprise, Rugged & Shared Devices (11)

Android Enterprise work profile, fully managed and dedicated device modes, OEMConfig and OEM-specific controls, kiosk and multi-app lockdown, shared-device sign-in, and wearables or vehicle-mounted devices. BYOD privacy policy is covered in BYO.

Windows & Linux Management (10)

Windows configuration through MDM policy, co-management with existing on-premises tooling, Group Policy migration, BitLocker and local admin account handling, and the depth of Linux distribution support. OS patching is covered in PAT.

BYOD & Ownership Models (9)

User-enrolled and account-driven enrollment, separation of work and personal data, what the admin can and cannot see on personal devices, selective wipe, and app-protection policies for unenrolled devices. Corporate zero-touch enrollment is covered in ENR.

Identity, Certificates & Conditional Access (12)

Identity provider integration for device-based conditional access, how compliance state reaches access decisions, certificate issuance and renewal (SCEP, PKCS, ACME), and Wi-Fi, VPN and per-app VPN provisioning. Defining compliance rules is covered in SEC; generic admin SSO and SCIM are covered in the integration module.

Security Convergence & Compliance Enforcement (12)

Compliance rules and the automated actions taken on non-compliance, lost or stolen device actions (lock, lost mode, locate, wipe), mobile threat defense, endpoint privilege management, disk encryption enforcement, attack-surface controls, and exchange of device risk signals with EDR/XDR. Passing compliance state to the identity provider is covered in IDA; the vendor's own platform security is covered in the security module.

OS & Third-Party Patch Management (11)

OS update deployment and deferral across Windows, macOS, iOS/iPadOS and Android, the third-party application patch catalog and its update cadence, emergency out-of-band patching, and patch compliance reporting. App packaging and first-time deployment are covered in APP.

App Deployment & Configuration Lifecycle (11)

App packaging and deployment for each OS (including macOS packages, Apple Apps and Books (VPP) licenses, and managed Google Play), managed app configuration, configuration baselines, policy targeting, and policy conflict resolution. Patch cadence for those apps is covered in PAT.

Migration from Incumbent MDM (9)

Tooling and methods for moving live devices off another MDM, including whether devices can migrate without a wipe on current OS versions, policy and profile mapping, wave sequencing, and rollback. General implementation methodology is covered in the implementation-onboarding module.

Administration, RBAC & Fleet Reporting (10)

Role-based and delegated administration, multi-tenancy and scoping by region or business unit, the admin audit trail and approval controls on destructive bulk actions, fleet inventory and reporting, and console performance at the buyer's device count. Hosting location and data residency are covered in the deployment-hosting module.

Remote Support, Self-Service & DEX (9)

Remote view and remote control, the end-user self-service portal, device health and experience telemetry, and scripted or automated self-healing remediation. Compliance-driven security actions are covered in SEC.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. New corporate Mac set up with no IT touch
  2. Personal iPhone enrolled then selectively wiped
  3. Personal Android phone blocked then restored
  4. Rugged scanner as a shared shift kiosk
  5. Emergency patch for an out-of-band vulnerability
  6. Threat alert revokes access through conditional access
  7. Live Apple devices moved from the incumbent MDM
  8. Regional admin limited to one business unit
  9. Slow Windows laptop fixed by help desk
  10. Newest Apple declarative feature on a test device

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Unified Endpoint Management (UEM) RFP questions are there?

129 solution questions in 12 capability areas: 25 for the RFI, 69 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Unified Endpoint Management (UEM)