QS-WAN · User Management

Mobile device management that counts devices, not people

Mobile device management in QS-WAN runs from the person down. A profile is a person, that person carries several devices, and each device gets its own certificate and its own membership of one or more gateways. The licence counter counts active devices, not profiles, so what is in use is always on screen next to what your tier allows.

What it is

MDM software has to answer one question first: whose device is this?

Most MDM software hands you a list of devices and attaches people afterwards. QS-WAN runs the other way round: you create a profile, a profile is a person, and devices hang off it.

Each device owns three things

A certificate

Generated on the device itself. The private half never leaves it, so the credential cannot be copied off a laptop and used somewhere else.

An enrollment state

PQ pending until the device registers its public halves, PQ enrolled afterwards. You can read where a device stands without asking anybody.

The gateways it may reach

Membership is per device, not per person. Two laptops on one profile can sit on different gateways.

The difference shows the first time somebody swaps a laptop. The person stays, the profile stays, the old device is revoked and deleted, the replacement enrolled, and the counter drops then climbs back. Revoking one device says nothing about the other. That independence is the whole design, and the next section lets you try it.

The mechanism

Revoke one device, and the others carry on

Press a button on the panel and watch what happens to the rest of the profile. This is the behaviour a device list cannot give you.

Laptop ML-DSA-65 Gateway 1 PQ enrolled Revoked Workstation ML-DSA-65 Gateway 1 PQ enrolled Revoked Phone ML-DSA-65 Gateway 2 PQ enrolled Revoked One profile A person, not a device 3 active devices The licence counter counts devices, not profiles
3 of 3 devices connected

The diagram shows one profile holding three devices: a laptop and a workstation on Gateway 1, and a phone on Gateway 2. Each device carries its own ML-DSA-65 certificate. Revoke one and that device alone loses its certificate and drops off, while the other two stay connected. Revoke all and every device under the profile stops at once. Reinstate brings them back without re-enrolling.

A certificate proves a machine holds a private key that was generated on that machine and never sent anywhere. Revoking it ends that one credential. The person keeps their profile, their other devices keep their own certificates, and the licence counter follows the devices rather than the headcount.

Why this exists

Four things that go wrong without it

The spreadsheet of who has what

It is right the day somebody writes it and wrong the week after. Nobody can tell you, from the file alone, which laptop was replaced in March.

A folder of config files nobody can date

A working credential that sits in a downloads folder is a credential you cannot age, cannot attribute and cannot withdraw.

The expiry you hear about from whoever cannot connect

Certificate expiry is the failure nobody notices until it happens, and it always happens to somebody who is travelling.

The Friday leaver whose devices still work

Offboarding that depends on remembering every machine a person carried is offboarding that eventually misses one.

What you gain

Unified endpoint management, from a console you already open

If you run the network

Every action sits on the device row

Revoke, Revoke all, Reinstate, Reissue cert, Resend enrollment, Delete device and Export CSV all act on the device, not on the person. A Device locations widget puts the fleet on a map, and a Devices at risk panel names the certificates about to expire.

You stop reconstructing the answer. The console already knows which device belongs to whom, what credential it holds and which gateways it may reach.

If you sign for it

Invoice and screen agree on a number

The counter counts active devices, so the fleet side and the finance side read the same screen. The bill is the tier you bought, so there is nothing to reconcile and no surprise at renewal.

And you are buying one console rather than a fifth. Devices sit beside the gateways, the users and the policy you already manage, which is one supplier, one login and one place an auditor has to be shown.

How it works

Three steps to a managed device

You create the person, then send one token

Create the profile, add a device, and send the enrollment token by email. It is single use, stored hashed, valid for 48 hours and burned on use, so forwarding it does nothing.

The device enrolls itself

The device generates its post-quantum key pair locally and registers the public halves. Its badge moves from PQ pending to PQ enrolled. The .ovpn package is encrypted to that device ML-KEM-768 public key, so a config file in a downloads folder is not a working credential.

You act on the device, not on the person

The device now has its own row, certificate and badges. Revoke one and the other devices carry on. Revoke all and every device on the profile stops. Reinstate brings one back without re-enrolling.

Before you start

You need an SMTP server configured, because the enrollment token goes out by email, and the QNova Client on the device. Nothing else is installed, and no hardware is required to manage devices you already have.

In detail

What you are looking at, once the fleet is running

Badges

What the badge on a device is telling you

A device carries one of six badges: online, VPN connected, pending removal, revoked, post-quantum enrolled and post-quantum pending. It picks up an asset badge as well once you link it to declared infrastructure.

You never have to work out which one wins, because the order is fixed:

  1. Pending removal beats revoked
  2. Revoked beats an expired certificate
  3. Expired beats online
  4. Online beats VPN connected

So a badge answers one question at a time, and the most urgent one.

Receipts

Where you check that a device actually got the policy

The Devices table inside Company Policy is where a policy stops being an intention. Each row names the device and the person carrying it, whether it is protected, which gateway it uses, the USB policy it was given and what it reported back, the agent version it is running, whether the policy is mandated, and when it last acknowledged and last reported.

Along the top you get counts: how many devices are unprotected, how many are managed, how many returned an acknowledgement error, how many are running with USB blocked, and how many are non-compliant.

Watch the acknowledgement column. It is the device telling you it received the policy, rather than the console telling you it sent one. That is the difference between believing a fleet is covered and seeing that it is.

Where this earns its place

Four mornings this changes

The laptop swap

The person stays, the profile stays. Revoke and delete the old device, enroll the replacement, and the counter drops then climbs back. Nothing to reconcile afterwards.

The Friday leaver

Revoke all on that profile. Every device under it loses its certificate, and one that was asleep during the revocation comes back revoked rather than trusted.

The contractor with a short engagement

Give them a profile with the gateways their work needs and nothing else. When the engagement ends you revoke a profile, not a list of machines somebody has to remember.

A fleet you cannot see from one desk

The Device locations widget puts the fleet on a map and the Devices at risk panel names the certificates that expire next, which is how a site you never visit stops being a blind spot.

Works better together

Where this sits in the rest of the console

These are not a related-links box. Each one owns a piece of the same device row, and the order is the order a device meets them.

01

Puts the first certificate on the device and keeps the private half local. It is step one of everything on this page.

02

Owns the object each device row carries: issue, renew, repair, revoke, and rotating the authority above all of them.

03

Signs the policy and pushes it to the fleet, which is what gives each device row a managed state and an acknowledgement worth reading.

04

Turns a fleet with expiring certificates into a number that moves, so a gap has a price you can point at.

The protection half of the same device is a use case of its own, endpoint protection, and every feature is listed in one place.

What this does not do

The limits, because they are what make the rest believable

It is not mobile application management

No app catalogue, no per-app policy, no containerization splitting work data from personal data on a phone. What is managed is the device, its certificate, its gateways and its policy.

It does not claim a device obeyed you

A saved action is a recorded intention. The acknowledgement column is where the device confirms it, and a machine that is off gets the instruction when it wakes up. That is why pending removal outranks a green state rather than the other way round.

It does not replace your identity provider

These are VPN profiles and device certificates, and they sit under Entra ID or a local Active Directory. Deleting a profile here does not delete anybody company account.

Nobody here watches your fleet

It is a product, not a service. The console shows you the gaps; it does not staff them, and neither do we.

Questions people ask

The ones that come up first

What is mobile device management?

Mobile device management is controlling the devices your people use from one place: which device belongs to whom, what credential it holds, what it may reach, and how you take that away. In QS-WAN it runs on profiles and devices.

What happens when somebody leaves on a Friday?

Revoke all on that profile. Every device under it loses its certificate, and one that was asleep during the revocation comes back revoked rather than trusted.

Which platforms does it cover?

The QNova Client carries the tunnel and the policy on Windows, where it is complete, on Linux as a genuine port with gaps we declare, and on macOS and Android. The eleven detection engines are Windows only, and we would rather say that than tick a row. iOS is next and is not available yet, so a fleet of iPhones is not something this manages.

Does it containerize work data on personal phones?

No. There is no work profile and no app management. If splitting personal and corporate data on a phone is the requirement, look elsewhere.

Do I need any hardware to manage devices?

No. You need an SMTP server configured so the enrollment token can be emailed, and the QNova Client on each device. Managing devices you already own adds no hardware.

Bring us your fleet. We will enroll a device live.

An engineer, a console shaped like yours, and as long as you need. You watch a device enroll, then watch it get revoked while the others stay up. It is free and there is nothing to sign.

Scroll to Top