Managing IoT Devices with AirWatch: Use Cases and Limitations

Connected devices are becoming part of everyday operations across Australian organisations. Retail sensors, vehicle telematics, healthcare equipment, smart lockers and industrial gateways all generate useful data, yet each endpoint can also create a security and support burden. Managing these devices requires more than installing an application or checking whether a unit is online.

AirWatch, now associated with VMware and commonly connected with Workspace ONE UEM, gives IT teams a framework for enrolling, configuring and monitoring endpoints. Its mobile device management heritage makes it familiar to organisations already supporting laptops, tablets and smartphones, while its policy engine can also assist with selected internet of things deployments.

The platform is most useful when an IoT device has an operating system, a network connection and a manageable interface. It can help enforce settings, distribute certificates, control applications and provide remote support. It is less suitable for small sensors with limited firmware, irregular connectivity or no agent support.

Australian conditions make planning especially important. A mining operation in Western Australia may manage equipment across huge distances, while a healthcare provider in Melbourne must account for privacy obligations and clinical continuity. A retailer with stores in Sydney, Brisbane and regional New South Wales may need a consistent policy that still works during temporary network outages.

Capability AirWatch or Workspace ONE UEM Specialist IoT platform
Device enrolment Strong for supported operating systems and corporate endpoints Often designed for large sensor fleets
Policy management Effective for security, apps, certificates and restrictions Usually focused on telemetry and device commands
Remote support Useful for managed screens and user-facing devices Varies by hardware and protocol
Fleet scale Suitable when devices are standardised and connected Better for highly diverse, low-power deployments
Data and analytics Endpoint-focused reporting Usually stronger for sensor data and operational analytics
Main limitation Requires compatible agents, APIs or management protocols May offer less support for ordinary employee devices

Where AirWatch Adds Practical Value

A common use case is managing rugged tablets and handheld terminals used by field workers. Transport companies, utilities and maintenance contractors can enrol devices, apply Wi-Fi and VPN settings, restrict access to approved applications and deploy updates remotely. A technician travelling between Perth and remote mine sites does not need to visit an office each time a configuration changes.

Retailers can use the platform to control point-of-sale companions, stocktaking tablets, digital signage players and click-and-collect kiosks. Locking a device into a single application or a small approved set reduces accidental misuse. If a store device is lost, administrators can lock or wipe it, depending on the operating system and the organisation’s policy.

Healthcare is another relevant setting. Hospitals and aged-care providers may manage shared tablets, medication carts, barcode scanners and nurse-call companion devices. AirWatch can help separate work data from personal use, apply passcode rules and deliver certificates. Any deployment in this sector needs careful validation, since a remote action or forced update must not interrupt a critical clinical workflow.

The platform can also support connected vehicles and mobile assets where a conventional endpoint operating system is present. Fleet operators may use managed tablets inside trucks, mobile routers or driver inspection devices, while councils can oversee smart kiosks and public information terminals. These deployments benefit from central visibility, especially when equipment is distributed across regional Queensland, South Australia or the Northern Territory.

Building A Secure IoT Operating Model

Security starts with knowing exactly what has been deployed. An administrator should record the device type, owner, location, operating system, firmware version, SIM or network identity and business purpose. AirWatch can then place endpoints into groups based on risk, geography or function. A camera at a suburban depot should not automatically receive the same policy as a tablet used by a finance executive.

Certificates, strong authentication and restricted network access are valuable controls for connected equipment. Policies can require approved Wi-Fi configurations, block unnecessary services and prevent users from changing key settings. Where supported, compliance rules can flag outdated firmware, disabled encryption or a missing security agent. Integration with identity and access tools can add another layer before a device reaches corporate applications.

Application control is particularly useful for kiosks and shared endpoints. Administrators can publish approved software, remove unauthorised applications and configure a locked-down display mode. Teams familiar with desktop administration can also review Windows UEM guidance when deciding how Windows-based gateways and rugged computers should fit into a broader endpoint management model.

However, an endpoint management platform should not be treated as a complete security architecture. It does not replace network segmentation, vulnerability management, secure coding, physical protection or a process for handling supplier access. A poorly secured device may remain risky even when it appears compliant in the console.

Deployment And Day-To-Day Administration

A successful rollout usually begins with a narrow pilot. Select a few device models, test enrolment over the networks used in the field and confirm that policies behave correctly after reboot, loss of connectivity and battery failure. For an Australian organisation, this might mean testing both a Melbourne office and a remote site where bandwidth is expensive or intermittent.

Zero-touch enrolment can reduce manual work when a supplier supports the required operating system and provisioning method. New devices can be shipped directly to a branch or contractor, then configured when they first connect. For existing equipment, IT teams may need a staging process involving QR codes, serial numbers, factory resets or technician-led registration.

Operational ownership should be clear. The service desk may handle passwords and lost devices, while a security team owns compliance rules and an operations group manages firmware windows. Dashboards are most useful when they show actionable information, such as devices that have not checked in, rather than producing a large volume of alerts that nobody reviews.

Updates require special care for IoT equipment. A failed firmware installation can disable a kiosk, vehicle gateway or monitoring unit. Teams should define maintenance windows, backup settings and rollback procedures. They should also decide how long an endpoint can remain offline before it is treated as a security issue rather than a normal consequence of remote work.

Limits Worth Planning Around

The biggest limitation is compatibility. AirWatch works best with mainstream operating systems and devices that expose management APIs or support an agent. Many low-power sensors, proprietary controllers and embedded products do not provide those capabilities. An organisation may see that a sensor is connected through another system but still be unable to apply detailed policies from the UEM console.

IoT fleets are often more varied than ordinary corporate endpoints. A business could have several generations of gateways, different manufacturers and local firmware modifications. Standardising policies across such a fleet can be difficult. In some cases, AirWatch should manage the gateway or tablet that connects to the sensor, while a specialist platform manages telemetry, commands and device health.

Connectivity is another constraint. Devices in underground facilities, rural areas and transport environments may be offline for long periods. Remote wipe, certificate renewal and application deployment cannot always happen immediately. Policies need sensible grace periods, local caching and an escalation process for devices that miss several check-ins.

Licensing and administration also deserve attention. A trial can help an organisation test enrolment, policy enforcement and reporting, but a production design should account for device numbers, editions, integrations and support requirements. Pricing comparisons should include the cost of field visits, replacement hardware, network services and the staff time needed to maintain exceptions.

Privacy requires a local lens. Australian employers should be transparent about what information a managed device collects, particularly location, usage and personal data in bring-your-own-device arrangements. Organisations should align the deployment with the Privacy Act, relevant health privacy rules and contractual obligations, while documenting retention and access practices.

Practical Checks For A Reliable Rollout

Before selecting a management policy, confirm that the device and its business process can tolerate remote administration. The following checks help separate a manageable endpoint from a device that needs a different control layer:

Governance should continue after deployment rather than ending when the fleet appears in the console. Review exceptions, remove inactive endpoints and compare reported inventory with physical assets. A quarterly audit can expose devices that were replaced, sold, moved between branches or left in a contractor’s possession.

Useful operating habits include:

AirWatch is a strong fit when IoT equipment resembles a managed business endpoint: it has a supported operating system, needs controlled applications and benefits from central security policies. It is a weaker fit for tiny sensors, proprietary controllers and fleets where telemetry is more important than endpoint configuration. The right architecture may combine UEM with an IoT gateway, network controls and an operational data platform.

Australian organisations can validate that balance through a controlled pilot rather than relying on feature lists. Start with a defined device group, use the available free trial where appropriate, test real field conditions and compare administration effort against the security and support benefits. A well-scoped deployment can give IT teams practical control without forcing every connected device into a system designed for a different job.