Device Management
Keep your Stony Brook University device secure, reliable, and up to date with automated device management.
How Device Management Works
When Stony Brook issues you a computer, phone, or tablet, the device is enrolled in a management service — Microsoft Intune for Windows machines, Jamf Pro for Macs, iPhones, and iPads.
Once enrolled, the device checks in with that service on a regular schedule. Each check-in confirms the required security settings are in place, installs any updates or approved software waiting for it, and reports basic technical information back to the Division of Information Technology. This happens in the background whether you're on campus, at home, or traveling — you don't need to start it or approve each step.
Automatic Updates
Your device receives required security patches and operating system updates automatically
Stronger Data Protection
Encryption, security settings, and threat protection help safeguard university and personal information
Faster IT Support
IT staff can diagnose and resolve many device issues remotely, reducing the need for in-person service
Fewer Disruptions
Device health and security issues can be identified early before they affect your work, teaching, or studies
Easy Access to University Software
Required applications and approved software can be installed and updated through Intune or Jamf
Privacy-Conscious Management
Device management collects technical and security information, not personal data
Microsoft Intune
Intune manages university-owned Windows computers from the cloud, so a device stays covered whether it's on campus, at home, or traveling.
Automatic protection: Required security settings, encryption, and updates apply without you configuring anything.
Software delivery: Applications approved by your department install and update on their own.
Remote support: DoIT and departmental IT teams can spot problems and resolve many of them without the device in hand.
Policy compliance: Intune is how Stony Brook meets SUNY Policy 6900 for centrally managed university devices.
JAMF
Jamf Pro manages university-owned Macs, iPhones, and iPads.
Ready on first startup: University settings, Wi-Fi configurations, and core applications are in place before you begin working.
Ongoing maintenance: macOS and iOS updates, security protections, and approved software arrive without manual setup.
Apple-focused support: IT staff can review device health, correct configuration issues, and assist remotely on Apple hardware.
Policy compliance: Jamf Pro meets the same SUNY Policy 6900 requirements as Intune.
Frequently Asked Questions
About Device Management
Device management allows Stony Brook University to securely configure, update, monitor, and support university-owned computers and mobile devices. Microsoft Intune is used for Windows devices, while Jamf Pro is used for Macs, iPhones, and iPads.
Device management helps Stony Brook meet SUNY Policy 6900 and university security requirements. It ensures university-owned devices receive required security settings, software updates, encryption, and threat protection.
Microsoft Intune is Stony Brook’s management platform for Windows devices. Jamf Pro manages Apple devices, including Macs, iPhones, and iPads. Both platforms apply security settings, install software, and report device compliance.
Company Portal is the application catalog for managed Windows devices. Self Service provides approved applications and support tools for managed Macs. Available software varies by device and department.
Device and Enrollment
The requirement applies to supported university-owned laptops, desktops, tablets, and mobile phones. This includes devices used on campus, at home, while traveling, or in shared and loaner environments.
No. This program applies to university-owned devices, unless separate requirements apply to a specific service or data type.
In most cases, no. DoIT or your departmental IT support team will enroll the device before it is issued or provide instructions for an existing device. You may need to sign in, restart the device, or leave it connected to power and the internet.
Standard enrollment does not normally erase files or applications. Some Apple devices may require a reset to establish full institutional management. IT will notify you before any process that could remove data.
Yes. Intune and Jamf Pro communicate through the internet, allowing devices to receive updates, applications, and security settings when they are away from campus. Devices should connect to the internet regularly.
Privacy and Information
Device management is used to view technical and security information, not the contents of your files, email, photos, or messages. Access to university information remains governed by university policies and authorized procedures.
Authorized IT staff can view information such as the device name, model, serial number, operating system, installed applications, encryption status, security update status, available storage, and compliance results.
Intune and Jamf Pro do not continuously display or record your screen. Screen viewing or remote control requires a separate support tool and an active support session.
Software, Updates, and Performance
Yes. Required security tools, university applications, updates, and configuration settings may be installed automatically. This helps keep software current and reduces the risk created by outdated applications.
Software installation depends on your department and assigned access. Applications must meet university security, licensing, accessibility, and support requirements. Unsupported or unsafe software may be blocked or removed.
Some updates allow a limited postponement period so you can save your work and choose a convenient restart time. Critical security updates may have an enforced deadline and install automatically after that deadline.
Normal management activity should have little effect on performance. You may notice temporary activity while updates, software installations, security scans, encryption, or configuration changes are being completed.
Security and Compliance
A device may be marked non-compliant if it is missing updates, encryption, security software, or required settings. IT may contact you with instructions, and access to some university services may be restricted until the issue is resolved.
Report the device immediately to your supervisor and IT support team. Depending on the device and configuration, IT may disable university access, lock the device, remove university information, or remotely erase it when authorized.
No. Removing Company Portal, Self Service, or a management profile may interrupt updates, software access, security protections, and university services. Contact IT if you believe a management component is causing a problem.