Documentation

SynGuard · Documentation

Everything you need to roll SynGuard out across your fleet: multi-OS enrollment, configuration policies, supervision, ZRS integration.

Quick start

Prerequisites: an active SynGuard account, admin access to app.synguard.ch, and a list of devices you want to enroll (Apple, Windows, Linux, Android, all supported).

Create your organisation: sign in to app.synguard.ch with your ZRS-Holding account (or request one via /contact). Set the organisation name, primary domain, and invite your first admins by email (roles: Admin, Operator, Read-only).

First enrollment: pick the method that fits the OS (see next section). Once enrolled, the device shows up in the Fleet console within minutes with its status, OS version and compliance score. You can then apply a policy.

Enrollment by OS

Apple (macOS + iOS): link your Apple Business Manager (ABM) or Apple School Manager (ASM) tenant to SynGuard with an MDM token. Devices purchased via your Apple account are then supervised automatically (zero-touch) on first boot. Available commands: wipe, lock, restart, install profile.

Windows: use Windows Autopilot with a SynGuard enrollment profile. Policies are applied through the Configuration Service Providers (CSP) framework. Coexists with an existing Intune setup during migration. Linux (Ubuntu / Debian / Fedora): a signed one-liner curl | sh installs the agent and enrolls the device in under 60 seconds. GPG-signed for integrity.

Android: Android Enterprise enrollment in Work Profile mode (containerised work/personal separation for BYOD) or zero-touch for corporate devices. Compatible with competing EMMs for staged migration.

MDM policies

A policy bundles: application restrictions (allow-list / block-list), pre-provisioned WiFi/VPN profiles, trusted certificates, encryption settings (FileVault, BitLocker, LUKS), PIN/biometric requirements. Create a profile in the console, pick its target (a device group), publish, propagation takes a few minutes.

Device groups: organise your fleet by OS (macOS, Windows…), department (HR, Tech, Finance) or free-form tag. A device can belong to multiple groups. Policies stack with explicit priority for conflict resolution.

Certificates: SynGuard supports SCEP, ACME and an internal CA for automatic renewal. Compliance: define rules (minimum OS version, encryption on, no jailbreak/root). Non-compliant devices trigger an alert; you can block their SSO conditional access.

Fleet management

Fleet inventory: filterable list view by OS, status (online / offline / unknown), last-seen (1h / 24h / 7d), compliance level, tag. CSV/JSON export available at any time.

Alerts: SynGuard monitors continuously and notifies by email + webhook when a device has been offline for over 24 hours, when a certificate expires in under 30 days, or when a device falls out of compliance. Thresholds are configurable per organisation.

Bulk actions: select multiple devices and trigger push config, remote wipe, lock, restart in one operation. Destructive actions (wipe) require 4-eyes approval on Pro+ and MSP. Reports: one-click CSV inventory export, signed monthly PDF compliance report audit-ready.

SynGuard Managed

How it works: the ZRS team actively supervises your fleet from its MSP console fleet.synguard.ch. You keep access to your own console; we operate alongside, not on top.

Included (+CHF 199/month ex. VAT): active supervision 5d/7 during business hours, proactive alerts on offline devices / compliance KO / expiring certificates, light corrective interventions up to 2 hours per month, signed monthly PDF fleet report.

Beyond 2 hours of intervention in a month, additional time is billed at CHF 150/hour ex. VAT. To activate the option or ask a question, email contact@synguard.ch.

FAQ

Need help?

Commercial question, partnership, technical topic, we reply in under 24 business hours.

Contact us