ProcessExtended Reality (XR)
Running an enterprise XR headset fleet: enrollment, updates, security and support
Headsets look like phones to an IT team until the first rollout. They are shared between faces, map the rooms they are used in, ship with consumer defaults and depend on one vendor's business program. This process covers the seven stages of running a fleet, from choosing devices with management in mind to wiping and retiring them, with the controls each stage needs and a readiness checklist.
On this page
What makes headsets different from phones and laptops
A headset is a computer that sits on someone's face, films the room around it and is often shared by a whole shift. That combination breaks assumptions built into most device policies. Sign-in is awkward without a keyboard. Consumer defaults nudge users toward personal accounts and public stores. Boundary set-up is tied to a physical room. Batteries, controllers and face interfaces wear out on their own schedules, and cleaning between users becomes a standing task.
The commercial ground moves too. Vendors open, rename and close their business programs, and a fleet strategy has to survive that. Meta, for example, stopped selling Horizon managed services and commercial Quest models from February 20, 2026, made the licenses free and committed support for existing customers until January 4, 20301. ColdAI plans device management alongside the application in its XR and VR work5, because those choices shape the software as well.
The lifecycle of a managed headset
- Select and procure
Shortlist models by management route and vendor support window.
- Enroll and configure
Apply one baseline profile at unboxing, before anyone signs in.
- Distribute content
Push OS, runtime and app updates through tested release rings.
- Operate shared sessions
Sign-in, cleaning, charging and spares at every site.
- Support and monitor
Watch device health and handle the common help-desk calls.
- Wipe and retire
Remove data, accounts and room maps, then recycle and replace.
Seven steps from purchase order to retirement
Choose devices with management in mind
Before comparing displays, check whether the model has an enterprise or managed mode, which management tools can enroll it, how long the vendor commits to security updates, and whether its business offering is sold in your countries. Ask what happens to enrolled devices if the program ends.
Enroll and configure every device the same way
Enroll devices at unboxing, not after users have signed in with personal accounts. Android-based headsets may be enrolled in a general device-management tool, an XR-specific platform or the vendor's console; Apple Vision Pro supports Automated Device Enrollment through Apple's device management framework2. Apply one baseline: certificate-based Wi-Fi, restrictions, approved apps and, for single-purpose devices, kiosk or single-app mode.
Release content and updates in rings
Treat the device OS, the XR runtime and your applications as separate release streams, and move each through the same rings: a lab group, a pilot site, then everyone. Defer automatic OS updates where the platform allows until the application has been tested on the new version, and keep the previous build ready for rollback.
Design for shared use
Decide whether devices are personal or shared. Shared devices need a session model: anonymous kiosk use, quick sign-in with a badge or code, or profiles that clear on sign-out. Plan the physical routine as well: charging stations, labeled devices, cleaning between users with methods the manufacturer approves, replaceable face covers and spares for flat batteries mid-shift.
Secure the network and the sensors
Place headsets on a segmented network, limit the services they can reach and route application traffic to your own back end. Then classify sensor data: passthrough video, room scans, hand and eye tracking and voice. Switch off what the task does not need, process on the device where possible and set retention periods for anything uploaded.
Support and monitor the fleet
Track battery health, storage, OS and app versions, crash reports and last check-in for each device. Give the help desk scripts for common calls: lost tracking, a drifted boundary, controllers that will not pair, a forgotten kiosk exit code. Make it easy to report discomfort or a damaged face interface, not only software faults.
Wipe, recycle and replace
When a device is lost, retired or sent for repair, wipe it and remove it from management, then confirm that linked cloud accounts and stored room maps are deleted. Recycle through your e-waste process, and schedule replacements before the vendor's update commitment ends, not after.
Three kinds of tool for managing headsets
| Question | General device management | XR-specific platform | Vendor's own console |
|---|---|---|---|
| Fit with existing IT | Same tool and policies as phones and laptops | A separate console, usually linked to your identity provider | Separate, and limited to one vendor's devices |
| Device coverage | Depends on whether the headset exposes standard management interfaces | Often several headset brands | One brand |
| XR-specific settings | Often thin: boundary, passthrough and controller settings may be missing | Usually aimed at boundaries, kiosk launchers and shared sessions | Deepest for its own hardware |
| Large content delivery | Fine for small apps; big builds and media can strain it | Usually designed to push large builds and media to sites | Tied to the vendor's store or release channel |
| Exposure to vendor change | Low for the tool itself | Depends on the platform keeping up with new headsets | High; ends when the program ends |
Products differ and change often. Treat the rows as questions to ask, then confirm each answer for the exact headset model and software version.
Sensor data rules to check before switching features on
Headset fleet readiness checklist
Questions and answers
Can consumer headsets be used at work?
They can, but check the vendor's terms and management options first. Some vendors sell business editions or management programs, and others allow consumer models to be enrolled in a management tool. Without management you cannot enforce updates, block personal accounts or wipe a lost device, which most security teams will not accept for anything beyond a short trial.
How do we stop users installing their own apps on work headsets?
Enroll devices in a management tool before first use, block personal accounts and public stores through restrictions, and push only approved applications. For single-purpose devices, kiosk or single-app mode goes further by launching straight into the work app and hiding the rest of the system. Keep a supervised way out of kiosk mode for administrators, and test it, because a forgotten exit code can strand a whole site's devices.
Who owns the data a work headset collects?
The employer is normally responsible for data collected on devices it issues, but the vendor may also receive telemetry under its own terms, and application developers may store session data. Map all three before rollout: what the device sends to the vendor, what your applications store and where, and what users are told. Under laws such as the GDPR, the organization deciding why data is collected carries the obligations, whoever runs the servers.
How should shared headsets be cleaned between users?
Follow the manufacturer's cleaning guidance, because some disinfectants and ultraviolet cabinets can damage lenses, foam or coatings. Most programs combine wipeable or replaceable face interfaces, disposable covers, cleaning at every handover and a visible record that it was done. Keep devices out of direct sunlight, which can damage displays through the lenses. Make it part of the site procedure, with supplies stocked and a named person checking it.
What should we do if our headset vendor ends its business program?
Read the notice for three dates: end of sale, end of new enrollments and end of security updates or support. Keep using enrolled devices while they receive updates, stop buying under that program and start testing replacement hardware early. Applications built on OpenXR or WebXR move more easily; management, enrollment and distribution usually have to be rebuilt. The runtime comparison covers the application side.
Sources
- An update on Meta for Work — Meta · checked 10 October 2026
- Deploy Apple Vision Pro (Apple Platform Deployment) — Apple · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Virtual Reality (VR): scenario design, comfort and managed headset fleets — ColdAI