Skip to main content
December 18, 2025

MDM Controls and Software Management

MDM policies are now Controls

MDM policies are now called Controls, with a dedicated space in Primo. The goal is to make policies easier to find, easier to understand, and easier to manage at scale. Naming has also been simplified:
  • Profiles are now Device Groups
  • Installed Apps is now Software

Target devices directly

Instead of relying on MDM Profiles, you can now assign Controls directly to devices.Create a Control based on the platform, configure it once, then choose where it applies:
  • a device group
  • specific devices
  • or your entire fleet
This makes rollouts faster, clearer, and much easier to reason about.

One place to see every policy deployed

You now get a single view of all Controls applied across your fleet, so you can quickly answer: what is deployed, where, and to whom?

Duplicate policies with confidence

Duplicating a policy is now more obvious and frictionless — the fastest way to reuse a setup and adapt it for another group or exception case.

Profiles become Device Groups

Device Groups are now what they should have always been: a clean way to organize your fleet, not a requirement for deploying policies.

Installed Apps becomes Software

Installed Apps is now Software, with a clearer experience and a dedicated section. This is the first step in bringing more of Fleet’s software management capabilities into Primo.
December 10, 2025

Tags for SaaS

Tags are now available on all SaaS apps Primo discovers through SaaS Mapping and the Chrome extension. Add and edit tags manually to group tools by team, owner, sensitivity, risk level, and more.To have Primo handle this automatically, enable AI auto-tagging under Settings > SaaS. Primo will review your existing and newly discovered apps and apply the most relevant tags.Once your apps are tagged, you can filter by tag, create focused views for audits or renewals, and spot security risks more quickly.