Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

4 Commits

Folders and files

Repository files navigation

MDM (Mobile Device Management) Client

Python client library for managing iOS and Android devices through MDM protocols with multiple authentication methods.

✨ Features

πŸ” Device Control

  • πŸ”’ Remote Lock - Lock devices remotely with optional passcode
  • πŸ”“ Remote Unlock - Unlock devices
  • πŸ—‘οΈ Wipe Device - Factory reset and erase all data
  • πŸ”„ Restart - Restart device remotely
  • πŸ›‘ Shutdown - Shutdown device remotely

πŸ“² Application Management

  • πŸ“¦ Install Apps - Install applications on devices
  • ❌ Remove Apps - Remove applications from devices
  • ⬆️ Update Apps - Update applications to new versions

βš™οΈ Configuration Management

  • πŸ” Security Configuration - Set PIN requirements, auto-lock, encryption
  • 🌐 Network Configuration - Configure WiFi, VPN, proxy settings
  • 🚫 Device Restrictions - Restrict features and allowed applications
  • πŸŽ›οΈ Custom Configurations - Apply custom device settings

πŸ”‘ Authentication Methods

  • πŸ”“ API Key - Simple API key authentication
  • πŸ” OAuth2 - OAuth2 bearer token authentication with auto-refresh
  • πŸ›‘οΈ SSL/TLS Certificates - Mutual TLS (mTLS) authentication
  • πŸ”— Hybrid - Combination of multiple authentication methods

πŸ“± Device Management

  • πŸ“ Device Enrollment - Enroll new devices into MDM
  • πŸšͺ Unenrollment - Remove devices from MDM
  • πŸ“‹ Device List - Get list of enrolled devices with filters
  • ℹ️ Device Information - Get detailed device information

πŸš€ Batch Operations

  • ⚑ Batch Processing - Execute multiple commands efficiently
  • πŸ“¦ Command Queue - Queue and execute commands in sequence

πŸ“¦ Installation

# Clone repository
git clone https://github.com/gmmblspprt-ai/mdm-controller.git
cd mdm-controller

# Install dependencies
pip install -r requirements.txt

πŸš€ Quick Start

Example 1: Using API Key

from mdm_client_advanced import MDMClient, AuthCredentials, AuthMethod

credentials = AuthCredentials(
    method=AuthMethod.API_KEY,
    api_key='your-api-key',
    verify_ssl=True
)

client = MDMClient(
    mdm_server_url='https://mdm.example.com',
    credentials=credentials
)

# Get devices
devices = client.get_device_list(platform='ios')

# Lock a device
client.lock_device('device-001', passcode='1234')

Example 2: Using OAuth2

credentials = AuthCredentials(
    method=AuthMethod.OAUTH2,
    oauth2_client_id='your-client-id',
    oauth2_client_secret='your-client-secret',
    oauth2_token_url='https://oauth.example.com/token',
    oauth2_scope=['mdm:read', 'mdm:write'],
    verify_ssl=True
)

client = MDMClient(
    mdm_server_url='https://mdm.example.com',
    credentials=credentials
)

Example 3: Using SSL/TLS Certificates

credentials = AuthCredentials(
    method=AuthMethod.SSL_CERTIFICATE,
    ssl_cert='/path/to/client-cert.pem',
    ssl_key='/path/to/client-key.pem',
    verify_ssl=True
)

client = MDMClient(
    mdm_server_url='https://mdm.example.com:8443',
    credentials=credentials
)

Example 4: Using Hybrid Authentication

credentials = AuthCredentials(
    method=AuthMethod.HYBRID,
    ssl_cert='/path/to/client-cert.pem',
    ssl_key='/path/to/client-key.pem',
    api_key='your-api-key',
    verify_ssl=True
)

client = MDMClient(
    mdm_server_url='https://mdm.example.com',
    credentials=credentials
)

πŸ’‘ Common Operations

Remote Lock/Unlock

# Lock device
client.lock_device(
    device_id='device-001',
    passcode='1234',
    message='Device locked for security'
)

# Unlock device
client.unlock_device(device_id='device-001')

Wipe Device

client.wipe_device(
    device_id='device-001',
    pin='1234',
    preserve_data=False  # Complete wipe
)

Install/Remove Applications

from mdm_client_advanced import AppConfig

# Install app
app = AppConfig(
    app_id='com.example.app',
    app_name='Example App',
    app_url='https://example.com/app.ipa',
    version='1.0.0',
    required=True,
    auto_update=True
)
client.install_application('device-001', app)

# Remove app
client.remove_application('device-001', 'com.example.app')

# Update app
client.update_application('device-001', 'com.example.app', '2.0.0')

Security Configuration

security_settings = {
    'require_pin': True,
    'pin_length': 6,
    'auto_lock_minutes': 5,
    'disable_camera': False,
    'disable_screenshots': False,
    'enable_firewall': True,
    'require_encryption': True
}

client.apply_security_config('device-001', security_settings)

Network Configuration

network_settings = {
    'wifi_networks': [
        {
            'ssid': 'Company-WiFi',
            'password': 'secure-password',
            'auto_connect': True
        }
    ],
    'vpn_config': {
        'enabled': True,
        'server': 'vpn.example.com',
        'protocol': 'IKEv2'
    },
    'proxy_settings': {
        'enabled': False
    }
}

client.apply_network_config('device-001', network_settings)

Device Restrictions

restrictions = {
    'disable_app_store': True,
    'disable_settings': False,
    'disable_camera': False,
    'allowed_apps': ['com.app1', 'com.app2'],
    'disable_icloud_sync': False
}

client.apply_device_restrictions('device-001', restrictions)

Batch Operations

from mdm_client_advanced import MDMCommandBatch

batch = MDMCommandBatch(client)

batch.add_lock('device-001', '1234') \
     .add_lock('device-002', '5678') \
     .add_install_app('device-003', app_config) \
     .add_remove_app('device-004', 'com.old.app')

results = batch.execute()

Device Enrollment

# Enroll device
client.enroll_device(
    device_id='new-device',
    platform='ios',
    enrollment_token='token-xyz',
    device_name='John\'s iPhone'
)

# Unenroll device
client.unenroll_device(device_id='new-device-001')

Get Device Information

# Get all devices
devices = client.get_device_list()

# Get iOS devices
ios_devices = client.get_device_list(platform='ios')

# Get device details
info = client.get_device_information('device-001')

# Get security information
security_info = client.get_security_info('device-001')

# Get command status
status = client.get_command_status('command-123')

πŸ–₯️ Supported Platforms

  • iOS - Apple iPhone, iPad
  • Android - Android Enterprise devices

πŸ“Š Authentication Methods Comparison

Method Security Ease of Use Refresh Best For
API Key Medium Easy Manual Simple integrations
OAuth2 High Medium Auto Production systems
SSL/TLS Very High Hard N/A High-security environments
Hybrid Very High Medium Auto Enterprise deployments

πŸ“š API Reference

MDMClient

Initialization

MDMClient(mdm_server_url, credentials, timeout=30)

Device Control Methods

  • lock_device(device_id, passcode=None, message=None)
  • unlock_device(device_id, pin=None)
  • wipe_device(device_id, pin=None, preserve_data=False)
  • restart_device(device_id)

Application Management

  • install_application(device_id, app_config)
  • remove_application(device_id, app_id)
  • update_application(device_id, app_id, new_version)

Configuration

  • update_configuration(device_id, config)
  • apply_security_config(device_id, settings)
  • apply_network_config(device_id, settings)
  • apply_device_restrictions(device_id, restrictions)

Device Information

  • get_device_list(platform=None, status=None)
  • get_device_information(device_id)
  • get_security_info(device_id)

Enrollment

  • enroll_device(device_id, platform, enrollment_token=None, device_name=None)
  • unenroll_device(device_id)

Command Management

  • get_command_status(command_id)

⚠️ Error Handling

try:
    client.lock_device('device-001')
except requests.exceptions.RequestException as e:
    print(f"Request failed: {e}")
except ValueError as e:
    print(f"Invalid input: {e}")

πŸ“ Logging

Enable debug logging:

import logging

logging.basicConfig(level=logging.DEBUG)

πŸ”’ Security Best Practices

  1. Never hardcode credentials - Use environment variables or config files
  2. Use HTTPS - Always use verify_ssl=True in production
  3. Rotate API keys - Regularly rotate and update API keys
  4. Certificate validation - Properly validate SSL/TLS certificates
  5. Audit logging - Log all MDM operations for audit trails
  6. Least privilege - Use minimal required permissions
  7. Rate limiting - Implement rate limiting for API calls

🌍 Environment Variables

MDM_SERVER_URL=https://mdm.example.com
MDM_API_KEY=your-api-key
MDM_OAUTH_CLIENT_ID=your-client-id
MDM_OAUTH_CLIENT_SECRET=your-client-secret
MDM_SSL_CERT=/path/to/cert.pem
MDM_SSL_KEY=/path/to/key.pem

🀝 Contributing

Contributions are welcome! Please ensure:

  • Code follows PEP 8 style guide
  • All functions have docstrings
  • Error handling is comprehensive
  • Tests are included for new features

πŸ“„ License

MIT License

πŸ’¬ Support

For issues and questions:

  1. Check existing issues in the repository
  2. Create a new issue with detailed information
  3. Contact the development team

πŸ“‹ Changelog

Version 2.0.0

  • Added OAuth2 authentication with auto-refresh
  • Added hybrid authentication support
  • Added batch command processing
  • Added device configuration management
  • Improved error handling and logging

Version 1.0.0

  • Initial release
  • API key authentication
  • Basic device control (lock, wipe, restart)
  • Application management
  • Device enrollment

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages