Health, inventory, and patch state for Windows, macOS, and Linux machines, with mobile device management for tablets and phones.
billed monthly
Web security, content filtering, and bandwidth monitoring, with visibility of programmatic and browser activity including private windows.
billed monthly
Unified Apple management: real-time monitoring, configuration enforcement, software deployment, security baselines, and automated compliance for macOS and iOS.
billed monthly
On-device AI protection for Android and iOS against mobile malware, phishing, jailbreak and root state, hostile wireless, and risky app store downloads.
billed monthly
| Remote Monitoring scope | Windows, macOS, and Linux health, inventory, and patch status, plus MDM for tablets and phones |
|---|---|
| Web Protection scope | Site categories and reputation, bandwidth accounting, and visibility of incognito browsing |
| Web Protection dependency | Installs on devices already carrying the Remote Monitoring agent |
| Apple Control scope | Configuration profiles, software deployment, security baselines, inventory, and remote remediation for macOS and iOS |
| Mobile Defense model | Behavioral models running on the device, with no reliance on cloud connectivity |
| Mobile Defense coverage | Zero-day mobile malware, phishing, jailbroken and rooted devices, machine-in-the-middle and rogue wireless, risky applications |
| Relationship to detection | Hygiene and control. None of these lines include SOC monitoring |
| Billing units | Per managed device, per Apple device, per mobile device |
Why hygiene is priced away from detection
Patch state, inventory accuracy, and configuration drift are not detection problems, and bundling them into a detection tier would blur a line worth keeping sharp. They are the variables that determine how large your detection workload is in the first place.
An estate with current patches, a known inventory, and enforced baselines generates fewer genuine incidents and dramatically fewer ambiguous ones. Buy these because they lower the number of bad days, not because they replace the tiers that handle the bad days.
What each of the four is actually for
- Remote Monitoring. The visibility layer: what machines exist, what is installed on them, whether they are patched, and whether they are healthy. It also carries mobile device management for tablets and phones. Most organizations discover their real device count here rather than in a spreadsheet.
- Web Protection. Category and reputation filtering with full visibility of online activity, including private browsing sessions, plus bandwidth accounting. It installs on devices that already carry the Remote Monitoring agent, so treat it as an extension of that line rather than a standalone purchase.
- Apple Device Control. Configuration profiles, software deployment, security baselines, inventory, and remote remediation for macOS and iOS. Apple fleets managed by Windows-shaped tooling drift quietly; this is the line that stops that.
- Mobile Threat Defense. Behavioral protection running on Android and iOS devices themselves, covering mobile malware, phishing, jailbreak and root detection, hostile wireless and communication tampering, and applications carrying more risk than their store listing suggests.
Mobile is where the identity lives and the agent does not
Your detection tier watches endpoints. It does not watch the phone that receives the multi-factor prompt, holds the mail session, and travels through every untrusted network its owner walks past.
Mobile Threat Defense runs its models on the device, which is what allows it to keep working when connectivity is absent or actively hostile. Machine-in-the-middle attacks and rogue wireless are network conditions that no cloud-dependent check can evaluate honestly, because the network is the thing under attack. If your access model treats a phone as a trusted second factor, this is the line that makes that assumption defensible.
Where these modules stop
None of the four is a detection tier and none carries SOC monitoring. Remote Monitoring will show you an unpatched machine; it will not tell you that something is currently executing on it. Web Protection filters and reports; it does not investigate. Read these as controls that reduce your exposure, then buy the watch separately.
Counting is per device, and mobile devices are counted apart from your endpoint total. Web Protection depends on the Remote Monitoring agent being present, so the two lines move together in practice even though they are billed apart.