BIOS-Based Pre-Enrollment for MDM Device Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the PC ecosystem, there is no centralized way to track device ownership and configuration, making it difficult to enroll non-APPLE devices into Enterprise Mobility Management systems, leading to inefficient and resource-intensive setup processes, security vulnerabilities, and challenges in managing device configurations and ownership.

Innovation Solution

A system that enables automatic enrollment of computing devices by using a BIOS process to contact a vendor server, which determines enrollment into an MDM system, downloads a pre-enrollment installer, and retrieves ownership information to configure the device with appropriate OS images and management policies, ensuring secure and efficient setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual device setup and enrollment is performed for each computing device, then device configuration and MDM enrollment can be completed, but significant IT manpower and time are required, increasing organizational costs and reducing workforce efficiency

Engineering Contradiction:
Improvedevice enrollment completionVSAvoidsetup time per device
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by having the BIOS automatically contact the vendor server during device boot-up to retrieve enrollment information and configurations before the operating system loads. This pre-enrollment process eliminates the need for manual setup after device delivery, as the device is automatically enrolled in the MDM system and configured with appropriate policies before the user first uses it.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The computing device performs self-service enrollment by automatically contacting the vendor server through its BIOS, retrieving its own enrollment information, and completing MDM enrollment without requiring manual intervention from IT personnel. The device independently configures itself with the appropriate MDM agent and enrollment tokens, transforming a manual task into an automated self-service process.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If each PC device uses different hardware and software combinations from multiple vendors, then device versatility and user choice are improved, but there is no centralized way to track ownership and configuration, making MDM enrollment difficult

Engineering Contradiction:
Improvedevice configuration varietyVSAvoidenrollment management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The vendor server acts as an intermediary between the diverse PC ecosystem and the MDM system. It maintains a centralized database that maps device identifiers (such as serial numbers or BIOS IDs) to enrollment information, allowing the system to handle various hardware and software combinations from multiple vendors through a single unified interface. This intermediary resolves the complexity by translating device diversity into standardized enrollment processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The enrollment system achieves universality by designing a platform-agnostic approach where the BIOS-based enrollment mechanism works across different PC vendors, hardware configurations, and operating system versions. The vendor server provides a universal interface that can retrieve and apply appropriate enrollment configurations for any PC device, making the MDM enrollment process vendor-agnostic and applicable to the entire PC ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If clean state device imaging is performed for each department and enterprise division, then customized device configurations can be achieved, but creating and maintaining multiple golden images becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvedepartment-specific device configurationVSAvoiddevice provisioning speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system performs preliminary action by having the vendor server pre-configure enrollment information and MDM policies for different departments and enterprise divisions in advance. When a device boots up, the BIOS automatically retrieves the appropriate department-specific configuration from the vendor server based on the device identifier, eliminating the need to manually create and maintain separate golden images for each department while still achieving customized configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The enrollment system transitions from static golden images to dynamic configuration retrieval. Instead of requiring pre-baked department-specific images, the system dynamically fetches and applies the appropriate MDM enrollment configuration and policies based on the device identifier and department information stored in the vendor server database. This dynamic approach allows flexible configuration assignment without the overhead of maintaining multiple static images.

Inventive Principle:
Principle #15Dynamics

4Ease of operation

If user login is required before EMM system enrollment, then users can access the device initially, but users may circumvent management policies that are not yet installed

Engineering Contradiction:
Improvedevice accessibilityVSAvoidpolicy enforcement security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary enrollment action during the BIOS boot-up phase, before the operating system loads and before any user login opportunity arises. The BIOS automatically contacts the vendor server, retrieves enrollment information, and completes MDM system enrollment and policy installation in advance. This ensures management policies are already in place and enforced before the user can log in and potentially circumvent them.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by pre-installing MDM agents and management policies during BIOS-based enrollment before user access is granted. This preemptive measure counteracts the potential harmful action of users circumventing policies by ensuring policies are already active and enforced. The MDM system can then restrict user capabilities and enforce policies from the moment the device is first used, eliminating the security window that would exist if enrollment occurred after login.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10620965B2Internet recovery of a windows configuration
Publication Date: 2020.04.14 OMNISSA LLC
  • US10620965B2 patent drawing
  • US10620965B2 patent drawing
  • US10620965B2 patent drawing

AI summary

Systems and methods are included for causing a computing device to assemble and boot from a managed operating system. When the computing device is powered on, it can execute firmware that specifies a server to contact. The server can identify a base operating system (OS) image to boot, and the location of a pre-enrollment installer for installing the base OS image. The pre-enrollment installer can download the base OS image in one or more pieces from multiple locations. This can include base OS images related to enterprise management and company-specific applications and drivers. Once the pre-enrollment OS has combined the base OS images, the computing device reboots using the combined image.