If you’re new to End User Computing (EUC), or you’ve landed here from an adjacent IT role and keep hearing terms like “UEM,” “co-management,” and “modern management” without a clear definition, this post is for you. It’s the one I wish existed when I started — no assumed background, just the concepts laid out plainly, with the major vendors mapped to where they fit.
I’ll link out to deeper posts on specific tools and certifications as this blog grows. Consider this the map; the rest of the site fills in the terrain.
A quick disclosure since I’ll be naming a lot of vendors: I work at Omnissa, which makes Workspace ONE. I’ve tried to describe every product here fairly and factually — flag it if something reads like marketing.
What “End User Computing” actually means
End User Computing is the umbrella term for everything involved in getting employees the devices, apps, and access they need to do their jobs — and keeping all of it secure, compliant, and manageable at scale. That includes laptops and desktops, phones and tablets, virtual desktops, the identity and security layer wrapped around them, and increasingly, the tools that measure whether the whole experience actually works well for the person using it.
If your job touches provisioning a new hire’s laptop, pushing a patch to 10,000 endpoints, deciding whether a BYOD phone can access email, or figuring out why someone’s Windows 365 Cloud PC is slow — you’re doing EUC.
It sits at the intersection of a few disciplines: endpoint management, identity and access management, security, and (more recently) digital employee experience. None of those are new by themselves. What makes EUC its own field is that someone has to own how they all fit together for the person sitting at the keyboard.
Traditional management vs. modern management
This is the distinction that trips people up most, so it’s worth being precise about it.
Traditional management (sometimes called “legacy” management) assumes devices live on a corporate network, or at least connect to one regularly. Think Active Directory, Group Policy Objects (GPOs), and tools like Microsoft Configuration Manager (formerly SCCM). Policies get pushed when a device checks in with a domain controller or management server, usually over a VPN or while physically on-site. It’s mature, deeply capable technology — a lot of enterprises still run on it — but it was built for a world of company-owned desktops sitting in an office.
Modern management flips the assumption: it treats every device as if it’s on the internet, not the corporate network, because increasingly that’s exactly where it is. Instead of GPOs and domain join, modern management relies on:
- Cloud-based MDM/UEM platforms that talk to devices directly over the internet, no VPN required.
- Identity as the control plane — access decisions are based on who you are and the state of your device, not which network cable you’re plugged into.
- Zero Touch / auto-enrollment provisioning — a new laptop or phone enrolls itself and applies policy the first time it’s turned on, no imaging required (Windows Autopilot, Apple Automated Device Enrollment, Android Zero-Touch Enrollment are the household names here).
- Conditional access — before a device gets to company data, it’s checked against policy in real time: is it compliant, is the user’s identity verified, is this a recognized location or risk level.
Most organizations aren’t purely one or the other — they’re somewhere on a spectrum, often running Configuration Manager and Intune side by side in what Microsoft calls co-management, gradually shifting workloads to the cloud tool as they’re ready. That transition period can last years, and that’s normal.
The vocabulary you’ll keep running into
A few terms show up constantly once you’re in this space. Quick definitions:
MDM (Mobile Device Management) — the original term for managing phones and tablets remotely: enrollment, policy push, remote wipe. The name stuck even as the scope expanded to laptops and desktops.
MAM (Mobile Application Management) — managing and securing individual apps and the data inside them, without necessarily managing the whole device. This matters a lot for BYOD, where a company can’t (and shouldn’t) fully control a personal phone, but still needs to protect corporate data inside, say, Outlook or Teams on that phone.
UEM (Unified Endpoint Management) — the current umbrella term for platforms that manage MDM, MAM, and traditional PC/Mac management from a single console, across Windows, macOS, iOS, Android, and often Linux and rugged/IoT devices too. When people say “UEM platform,” they mean tools like Intune, Workspace ONE UEM, or Ivanti Neurons for UEM.
Zero Trust — a security model built on “never trust, always verify.” Instead of assuming anything inside the corporate network is safe, every access request is evaluated on its own merits — user identity, device health, location, behavior — every time, regardless of network location. It’s less a product than a philosophy that shows up across identity, conditional access, and endpoint compliance policy.
DEX (Digital Employee Experience) — the newer piece of the puzzle: measuring and improving how devices, apps, and networks actually feel to use, not just whether they’re technically compliant. A laptop can pass every security policy and still boot slowly, drop VPN constantly, or run a CPU-choking background process nobody noticed. DEX tooling exists to catch that.
VDI/DaaS (Virtual Desktop Infrastructure / Desktop as a Service) — instead of an app or OS running on the physical device in someone’s hands, it runs in a data center or cloud and gets streamed to the endpoint. Useful for contractors, regulated industries, thin clients, or anywhere you don’t want data leaving the data center. Windows 365 Cloud PC and Omnissa Horizon are examples; Citrix has historically been the other major name here.
Where the major vendors fit
No single vendor covers 100% of EUC, and most organizations run more than one of these tools together. Here’s a rough map of who does what, as of 2026:
Microsoft — Intune & Windows 365. Microsoft Intune is the UEM piece, tightly integrated with Microsoft Entra ID (formerly Azure AD) for identity and conditional access, and with Microsoft Defender for security signal. Windows 365 is Microsoft’s Cloud PC product — a full Windows desktop streamed from the cloud, billed per user. Through 2026 Microsoft has been folding more of the previously add-on “Intune Suite” capabilities (like Advanced Endpoint Analytics and remote help) directly into Microsoft 365 E3/E5 licensing, which is worth watching if your org is trying to budget for it. For most enterprises already standardized on Microsoft 365, Intune is the default starting point.
Omnissa — Workspace ONE. Omnissa is the standalone company formed in 2024 when Broadcom spun the former VMware End-User Computing business (Workspace ONE UEM and Horizon VDI) out into its own entity, now owned by KKR. Workspace ONE positions itself as a unified UEM-plus-access platform across every major OS, with a heavier historical emphasis on multi-platform and non-Microsoft-centric environments than Intune.
Jamf. The dominant name in Apple device management specifically. Jamf Pro handles Mac/iOS/iPadOS/tvOS management with a depth of Apple-specific feature support that general UEM platforms often can’t match, since Jamf’s whole roadmap tracks Apple’s. Many organizations run Jamf for Apple devices alongside Intune or Workspace ONE for everything else.
IGEL. Not a UEM platform in the traditional sense — IGEL makes a lightweight, Linux-based OS (IGEL OS) that turns endpoints into secure, centrally managed thin clients, purpose-built for accessing VDI/DaaS environments (Horizon, Windows 365, Citrix, AVD). It’s a common sight in call centers, healthcare, and other environments where the “real” desktop lives elsewhere and the physical device just needs to be a secure, disposable window into it.
ControlUp and Nexthink. Both are DEX platforms — they monitor the real-time and historical experience of end users (boot time, app responsiveness, network quality, VDI session health) and increasingly use that telemetry for automated remediation. ControlUp has strong roots in VDI/DaaS monitoring; Nexthink built its name in broad digital experience analytics across physical and virtual endpoints.
Ivanti. Historically known for IT service management and patch management, Ivanti also offers Neurons for UEM.
This is not an exhaustive list — Citrix, Google (Android Enterprise, ChromeOS), and Apple’s own Business/School Manager tooling all matter too — but it covers the names you’ll hit most often in this space.
Why any of this matters
Modern management isn’t change for its own sake. It exists because the assumptions traditional management was built on — company-owned devices, on a company network, managed by an on-prem server — stopped matching reality years ago. Remote and hybrid work, BYOD, contractors needing access without a corporate laptop, and cloud-first everything all pushed management logic out of the network layer and into identity and device posture instead.
The practical upshot for anyone starting out: you don’t need to memorize every product feature. You need to understand the shape of the problem — get the right access to the right person on the right device, verify it continuously, and make sure it actually works well once they have it — and then learn how each vendor’s tools solve pieces of that.
Where to go from here
Future posts on this blog will go deeper on specific platforms, walk through certification paths (Microsoft Modern Desktop/Endpoint Administrator and Omnissa’s Workspace ONE track, to start), and share real use cases from day-to-day work.