Deploying Devices in Codeproof: Greenfield vs. Fielded

Satish Shetty Updated by Satish Shetty

This article explains how to deploy new (Greenfield) and existing (Fielded) devices in Codeproof, step by step. It also covers migration from another MDM, along with a post-deployment checklist.

🔹 Definitions

  • Greenfield Devices – Brand-new or factory-reset devices, provisioned through zero-touch programs (Apple ADE/ABM, Android Zero-Touch/KME, Windows Autopilot).
  • Fielded Devices – Devices already in use by employees, which may or may not be enrolled in another MDM.

🚀 Greenfield Deployment (New/Factory Reset)

Best for: Corporate-owned devices, out-of-the-box setup, kiosk use cases.

Steps:

  1. Assign devices to Zero-Touch (Android), ABM/ADE (Apple), or Autopilot (Windows).
  2. Create and assign an enrollment profile with policies, apps, and security baselines.
  3. Prepare logistics: asset tagging, SIM/eSIM, accessories.
  4. End user powers on the device → enrollment happens automatically.
  5. Verify enrollment, compliance, apps, and security settings in the Codeproof dashboard.

🔄 Fielded Deployment (Devices Already in Use)

Best for: Existing devices with users and data.

Options:

  • BYOD / Personal Devices
    • User-initiated enrollment via QR code or link.
    • Creates a Work Profile (Android) or User Enrollment (Apple).
  • Corporate-owned (Full Control)
    • Schedule a backup + wipe.
    • Reassign device in ABM/Zero-Touch/Autopilot to Codeproof.
    • On reset, device auto-enrolls with the new profile.
  • Limited / Legacy (not recommended)
    • Device Admin (Android) or manual MDM profile (Apple/macOS).

📦 Migrating from Another MDM (AirWatch, Intune, Jamf, etc.)

  1. Export device inventory (serials, users, OS versions).
  2. Recreate apps, policies, and restrictions in Codeproof.
  3. Choose migration model:
    • Clean reset + auto-enroll (preferred).
    • User-driven enrollment (BYOD or time-sensitive).
  4. Run a pilot batch → then expand in waves.
  5. Decommission old MDM when all devices are moved.

More detailed MDM migration steps are here.

✅ Post-Deployment Checklist

  • Device shows in correct group with owner mapped.
  • Compliance status = Compliant.
  • Required apps installed and working.
  • Wi-Fi, VPN, and certificates applied.
  • Passcode, encryption, firewall, and antivirus enforced.
  • Remote actions (lock, wipe, locate) tested.
  • User sign-off complete.

💡 Tips for Success

  • Start with a pilot group before full rollout.
  • Use smart groups/tags for targeting policies.
  • Stagger large app deployments to reduce network spikes.
  • Maintain runbooks for each platform.
  • Always keep a recovery path (admin account, kiosk bypass code).

How did we do?

Migrating Supervised iPhones Between MDMs (ABM/ADE) — Zero‑Drama Runbook

Contact