Glossary
Device-management glossary
ABM, ADE, VPP, ESP, APNs, D-U-N-S… every acronym in the setup guides, in plain English.
Every acronym in the Decolla setup guides, defined once. Hover any term inside a guide to see its meaning; this is the same source of truth, as one page. 39 terms.
ABMActivation LockADEAndroid EnterpriseAPNsASMAutopilotBootstrap tokenBYODCOBOCompany PortalConditional AccessCOPECSRD-U-N-SDEPEntraESPFileVaultFRPGraphGroup TagIMEIntuneKMEKSPManaged Apple IDManaged Google PlayMDMMFAOEMConfigOOBESetup AssistantSupervisedTPMVPPWinPEZero TouchZTDId
- ABM
- Apple Business Manager - Apple's free web portal where an organisation owns its device tokens and buys app licences.
- Activation Lock
- Apple's anti-theft lock tied to an Apple ID; can strand a wiped device without the bypass code.
- ADE
- Automated Device Enrolment - Apple's programme that makes corporate iPhones, iPads and Macs enrol into management automatically at first boot (formerly DEP).
- Android Enterprise
- Google's framework for managing Android devices (work profile, fully managed, dedicated/kiosk).
- APNs
- Apple Push Notification service - the channel Apple uses to reach managed devices; the MDM Push certificate authorises Intune to use it.
- ASM
- Apple School Manager - the education equivalent of Apple Business Manager.
- Autopilot
- Windows Autopilot - Microsoft's service for provisioning new Windows PCs straight into management from the out-of-box experience.
- Bootstrap token
- A macOS token that lets management authorise secure actions (like enabling FileVault) after enrolment.
- BYOD
- Bring Your Own Device - a personally-owned device enrolled with only a managed work profile.
- COBO
- Corporate-Owned, Business-Only - a fully managed company Android device with no personal profile.
- Company Portal
- Microsoft's app that enrols a device and lets a user install assigned apps and see compliance.
- Conditional Access
- Entra policies that allow or block sign-in based on conditions such as device compliance.
- COPE
- Corporate-Owned, Personally-Enabled - a company Android device that also carries a separate personal work profile.
- CSR
- Certificate Signing Request - a file you generate and send to a certificate authority (here Apple) to have a certificate issued.
- D-U-N-S
- Dun & Bradstreet's unique nine-digit business identifier; Apple uses it to verify your organisation legally exists.
- DEP
- Device Enrolment Program - Apple's original name for what is now called Automated Device Enrolment (ADE).
- Entra
- Microsoft Entra ID - Microsoft's cloud identity service (formerly Azure Active Directory), which holds users, groups and sign-in.
- ESP
- Enrollment Status Page - the Windows Autopilot screen that blocks first sign-in until required apps and policies have installed.
- FileVault
- Apple's macOS full-disk encryption; its recovery key can be escrowed to Intune.
- FRP
- Factory Reset Protection - Google's anti-theft lock that can block a wiped Android from re-enrolling.
- Graph
- Microsoft Graph - the API through which tools (including Decolla) read and change Intune and Entra.
- Group Tag
- A label attached to an Autopilot device (also called OrderID) used to target it with a dynamic group.
- IME
- Intune Management Extension - the on-device agent that installs Win32 apps and runs scripts.
- Intune
- Microsoft Intune - Microsoft's cloud device-management service, part of Microsoft 365.
- KME
- Knox Mobile Enrolment - Samsung's programme for auto-enrolling Samsung devices, similar to Apple ADE.
- KSP
- Knox Service Plugin - Samsung's OEMConfig app that exposes Knox-specific device settings to Intune.
- Managed Apple ID
- An Apple account created and owned by the organisation in Apple Business Manager, separate from any personal Apple ID.
- Managed Google Play
- The business version of the Google Play store that Intune uses to approve and deploy Android apps.
- MDM
- Mobile Device Management - the standard by which a service like Intune configures and controls a device.
- MFA
- Multi-Factor Authentication - requiring a second proof of identity beyond a password at sign-in.
- OEMConfig
- An Android standard that lets a device maker expose its own settings to any MDM through a configuration app.
- OOBE
- Out-of-Box Experience - the first-run setup screens a device shows when it is switched on new or freshly wiped.
- Setup Assistant
- The Apple first-run wizard; with modern authentication it runs the user through Entra sign-in during enrolment.
- Supervised
- A heightened Apple management state (automatic under ADE) that unlocks stricter controls and silent app install.
- TPM
- Trusted Platform Module - a security chip; Autopilot self-deploying mode needs TPM 2.0 with attestation.
- VPP
- Volume Purchase Program - Apple's system for buying and silently deploying App Store apps in bulk, with no personal Apple ID on the device.
- WinPE
- Windows Preinstallation Environment - the minimal Windows that runs during setup, before the full OS.
- Zero Touch
- Google's programme for auto-enrolling corporate Android devices bought through an authorised reseller.
- ZTDId
- Zero-Touch Deployment ID - the attribute stamped on a device once it is registered with Windows Autopilot.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access