Back
Frequently Asked Questions
What is MDM Beyond Corp?

MDM stands for Mobile Device Management.

MDM Beyond Corp is a service that gives you the opportunity to register your BYOD device (Win10 and MacOS - in future also Android or iOS) with the device management of TX Group.

If you order a Beyond Corp device in ServiceNow, the service will be included automatically.


After ordering, you can register your device within a few minutes - further information on the procedure will be separately sent by email.


Also, you can have a look at this video, in which our Group CISO explains the concept of Beyond Corp and its significance for TX Group. 

In this interview, the Group CIO talks about what exactly MDM is.

Which data are collected

Data are collected to

  1. detect malicious activities like hacking attempts or malware
  2. give automated feedback to the user on how to increase their security
  3. measure the security maturity in the organization

TX Group is not surveilling personal user activities. The following data are collected:


MDM Data

  • Device information (Firewall settings, UUID, Serial number, Password Policy, Account Policy, Encryption settings, machine name, user name)
  • Installed applications (only for corporate owned devices, for byod just if applications from the Intelligent Hub are installed; e.g. Cybereason)
  • Profiles

Access to the MDM is limited to the needed workplace engineers and security personnel.

Cybereason Data

The Cybereason Endpoint Detection and Response and eXtended Detection and Response platform differentiates malicious detections and normal detections. Detections that are considered normal are deleted after three months automatically. Malicious detections are deleted after one year.

The following types of information are collected by the Cybereason sensor

  • Machine, User and Logon information
  • IP Address, Domain and Network Interface information
  • Services, Drivers, Scheduled Tasks and Autorun information
  • Mount Points, File, File Hash information
  • Processes, Modules and File Events
  • Connections and Requests
  • File Events and Registry Events

Access to the data is strictly limited to the TX Group personnel and the partnering Cybereason Security Operation Center.

How does a Beyond Corp Windows device differ with a standard notebook?

If you order a Windows device in ServiceNow, the hardware is not fundamentally different, but the management of the device:

  • On a Beyond Corp Windows device, the software offering is limited. The device is designed for working primarily with cloud-based software.

  • A standard notebook is required if you depend on a business application for your work that is installed locally on the device.

For more information, check out this video of the Group CIO explaining the TX Group’s workplace strategy. Beyond Corp is an important key player in it.

Why should I register my (private) device?

If a device is regularly used for business purposes it must be registered with MDM Beyond Corp in accordance with the code of conduct.

In addition, it offers you many advantages:

  • protect your device in case of loss of theft
  • defend against malware and know threats in real time
  • ensure the most important security settings are enabled
  • automatic access to the most important public apps. This makes it ideal for you if you primarily work with cloud-based software.
  • connect the device automatically with corporate WiFi (“TX” instead of “TX Guest”)
  • VPN access with Pulse Secure
  • the number of authentication steps required to use the various applications will decrease significantly

From a cyber security perspective, Beyond Corp is hugely important. It is solely about device security and not about monitoring employees, as the Group CISO describes in this short video.

Why is TX Group launching MDM Beyond Corp?

Primarily for your protection, as this also prevents damage to the company. We try to retain as much freedom as possible, which is why "only" the MDM and the antivirus solution are mandatory.

With the MDM, the corporate antivirus solution Cybereason is installed. An antivirus needs access to files (therefore access to all files) and we protect private files with it as well.

All of these measures are set with the purpose to protect the security of the company and its working devices. It is not at all a matter of surveillance what the employees do with their devices. Watch here, what the Group CISO thinks about monitoring employees’ devices - which is not allowed by the code of conduct.

Who has access to the information in MDM or Cybereason?

Generally, access to the MDM is exclusively for individual IT Workplace Admins and to Cybereason for the Security Admins as well as the Cybereason Security Operation Center. The antivirus does not collect the files themselves, but metadata, e.g. hash values, file names and also when, for example, a file reloads and executes something from the Internet. If the files are not classified as malware or hacking, the information is automatically deleted in Cybereason after 3 months. We do this only to prevent hacker attacks. We are not interested in your private data or what you do with your device.

But there is always a grey area. If your device is infected by a private activity e.g. with viruses, then we see such a thing of course. But we do not monitor you or your file contents.

You can also check out this video of an interview with our Group CISO. There, he explains in detail what kind of data is collected and what exactly happens with it.

What happens on the device when I register it?

Depending on the type of device registered, some apps will be installed automatically and the configurations will be transmitted.

What about the admin rights?

Registering your device with Workspace ONE does not affect your existing admin rights. They will be taken over when you register.  Especially if it is your personal device (BYOD), nothing changes for you.

If you use a COPE device provided by TX Group and have a professional reason why you need admin rights, you can order them separately.

Can I register several devices?

You can register up to 3 devices. In order to register another device afterwards, you must first offboard an already registered device via the Hub app.

Can I onboard a Linux device?

Linux is not (yet) supported at MDM Beyond Corp. We expect the Beyond Corp option for Linux in the course of 2022.

How do I connect my device to the "TX" network?

If your device is already registered with MDM Beyond Corp, the device will automatically connect to the company's "TX" network via WiFi or cable.

To perform the initial registration of the device with MDM Beyond Corp, any internet connection can be used.


As a TX Group employee, please refer to these more detailed FAQ's.

Your Question was not answered?
Contact Support