Forrester retired the name Unified Endpoint Management after its Q4 2019 Wave and returned to the market under a different one. The Forrester Wave: Endpoint Management Platforms, Q2 2026, published on 11 June 2026 and authored by Michele Pelino, says so in its own summary: it covers providers "previously known as unified endpoint management." Seven years passed between the two editions, the vendor field turned over almost completely, and the criteria changed enough that the older document would be misleading to use as a baseline.

Eight providers were scored against thirty-four criteria spanning current offering, strategy and customer feedback. Three were named Leaders: Microsoft, Omnissa and Tanium.

The Forrester Wave: Endpoint Management Platforms, Q2 2026, and a name Forrester retired seven years ago

The gap is the story. The Q4 2019 Wave under the old name evaluated thirteen providers, required at least fifteen million dollars in annual unified endpoint management revenue, and treated support for both mobile and desktop endpoints as a threshold question rather than a differentiator. That framing belonged to a market where the hard part was reaching a device at all.

The 2026 edition assumes reach. What it grades instead is what a platform does once it is already everywhere: real-time intelligence, agentic AI, just-in-time access, and the ability to run IT and security operations on a single platform rather than two. Forrester's own summary of the evaluation puts convergence at the center of it.

A buyer who last looked at this market in 2019 and is now reading 2019 material will be making a decision against a category that no longer exists in the form the document describes. The rename is not cosmetic. It marks the point at which the vendors stopped selling device management and started selling a control plane.

Gartner splits this ground into two quadrants, and Forrester does not

This is where the two firms part company, and the difference is structural rather than editorial.

Gartner publishes two documents over the ground Forrester covers in one. The Magic Quadrant for Endpoint Management Tools, published on 5 January 2026, is the first Gartner quadrant for that market and covers eighteen vendors. The Magic Quadrant for Endpoint Protection, published on 26 May 2026 and credited to Deepak Mishra, Evgeny Mirolyubov and Nikul Patel, is a separate evaluation with a separate roster. Its confirmed Leaders are CrowdStrike, Sophos, Palo Alto Networks and Trend Micro.

None of those four appears anywhere in Forrester's eight-vendor field. None of Forrester's three Leaders appears on Gartner's endpoint protection rung. That is not an oversight by either firm. It is the boundary question, answered two different ways.

Forrester's answer is that the buyer has already merged the two jobs, so the evaluation should merge too: one agent, one console, one set of criteria that includes both the operations work of patching and healing and the security work of detecting and responding. Gartner's answer is that management and protection are bought by different people with different budgets and different replacement cycles, so they are graded separately.

Both positions are defensible. The practical consequence is that a vendor can be a Leader in one document and absent from another, and neither result is wrong.

Thirty-four criteria, and the ones that were not in this category seven years ago

Two criteria do most of the work of showing what changed.

Self-Healing is now a named criterion. Seven years ago the question was whether a platform could reach a device and apply a policy. The question now is whether it can notice a device degrading and repair it without a ticket, which requires telemetry the 2019 products did not collect. Omnissa scored the highest possible mark in Self-Healing and in Innovation, and ManageEngine scored five out of five in self-healing alongside shared devices and telemetry monitoring.

Frontline Worker and Vertical Market Enablement is the other one, and Omnissa scored the highest possible mark there too. This criterion is about the fleet that the mobile device management era handled badly: shared terminals in retail and healthcare, shift workers who never log into the same device twice, and vertical-specific compliance obligations. Calling it out as a scored criterion rather than an implementation detail tells you which buyers the vendors are now competing for.

The rest of the scored set names Vision, Innovation and Adoption, which are strategy and customer-feedback criteria rather than product features. Tanium took the highest possible score in fifteen criteria across the whole evaluation, including all three of those.

Three Leaders, four Strong Performers, and one provider that is not named

Microsoft's placement rests on a vision built around integration across Entra ID, Defender, Windows and Windows 365, on AI-enabled admin assistance and Security Copilot agents, and on the adoption advantage that comes with bundling into Microsoft 365 E3 and E5. The published cautions are specific: midsize-enterprise support is often delivered through cloud solution providers rather than directly, unattended remote access has gaps, the third-party patch catalog is limited, and Linux and operational technology device support is incomplete.

Tanium's placement rests on the highest possible score in fifteen criteria including Vision, Innovation and Adoption, on Tanium Ask for agentic workflows, on Jump Gate for just-in-time access, and on native compatibility validation for patching. The cautions are equally specific: no shared-device support, limited operating system and bring-your-own-device coverage, and customer concerns about cost and pricing structure.

Omnissa's placement rests on Workspace ONE, a vision for autonomous workspaces, AI-enabled issue detection, strong self-service and telemetry, and broad operating system support. The cautions are less pricing transparency, thinner supporting services than the top of the field, and inconsistent support and feature cadence reported by customers.

Four Strong Performers were named. HCLSoftware brings broad operating system support, an Agentic AI Studio, hosted cloud and on-premises options, and strong client retention, with narrower vision and innovation and some pricing transparency gaps cited. IBM brings a broad partner ecosystem, public per-user and per-device pricing, and strong bring-your-own-device capabilities, with trailing customer satisfaction and slower delivery of new functions cited. Ivanti is credited with innovation and roadmap work around its Neurons platform for predictive operations. ManageEngine's Endpoint Central is described as an optimal fit for midsize enterprises seeking an all-in-one product, with broad operating system and server support, AI and machine learning security functions, and deployment flexibility across cloud, on-premises and managed service hosting.

One of the eight providers in the evaluation has not been publicly identified. The announced summaries account for seven, and any complete tier list beyond those names would be an inference rather than a fact.

The security half of the same device sits on a different page

The Gartner evaluation of the protection half of this market is on this site at Endpoint Protection, the May 2026 quadrant. Reading the two documents together is more useful than reading either alone, because they disagree about where the boundary runs and each disagreement is a question a buyer has to answer for themselves.

Tanium is the clearest case in the market. It is a Leader in Forrester's endpoint management Wave and an announced Leader in Gartner's Endpoint Management Tools quadrant, which means it holds the top rung under both firms for the same job. NinjaOne announced a Leader placement in that same Gartner quadrant. ManageEngine announced a Challenger placement there while sitting as a Strong Performer in the Forrester Wave, which is what a boundary drawn in two different places looks like when it lands on one company.

The overlap matters at renewal. A platform that leads one evaluation and sits a tier lower in another is usually strong at the job the first evaluation grades and ordinary at the job the second one does. For a buyer deciding between a converged platform and two specialist products, that difference is the decision.

What to ask before you standardize on an endpoint platform

Ask which of the two jobs the platform is actually better at, and expect the answer to differ by vendor. Every product in this field now claims both management and security. The evaluations still separate them, and so do the cautions on the Leaders.

Ask how shared devices are handled. Forrester made Frontline Worker and Vertical Market Enablement a scored criterion, and two of the three Leaders carry published cautions on shared-device or bring-your-own-device support. If a meaningful part of the estate is shift-based, that gap will surface during deployment rather than during the trial.

Ask what the coverage gap is for Linux, operational technology and non-standard operating systems. This shows up as a caution on more than one Leader, and it is the most common reason a converged platform ends up running beside a second tool.

Ask for evidence behind the self-healing claim rather than a demonstration. A named criterion invites a named answer: which failure classes the platform detects on its own, which it remediates without a ticket, and how often the remediation attempt makes a device worse. The vendors that invested here can answer precisely, and the ones that did not will describe the capability in general terms.

Ask whether renewal pricing is tied to a productivity suite. Bundling produces real adoption advantages and real lock-in, and the evaluations credit the first while the cautions describe the second.

Ask who owns the agent in three years. The consolidated platforms in this field are competing with the security agents already installed on the same devices, and one of the two will eventually be removed. Choosing which one is a decision to make deliberately rather than at the end of a contract.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and tier placement in this article draw on Forrester's coverage of endpoint management platforms, evaluated in The Forrester Wave: Endpoint Management Platforms, Q2 2026, published 11 June 2026 and authored by Michele Pelino. Forrester scored eight providers against thirty-four criteria spanning current offering, strategy and customer feedback, and describes the evaluation as covering providers previously known as unified endpoint management, a name Forrester last used in the Q4 2019 Wave, which evaluated thirteen providers. Gartner evaluates this ground as two documents rather than one: the Magic Quadrant for Endpoint Management Tools, published 5 January 2026, covering eighteen providers, and the Magic Quadrant for Endpoint Protection, published 26 May 2026, credited to Deepak Mishra, Evgeny Mirolyubov and Nikul Patel. Those are separate markets at Gartner and one market at Forrester, which is the boundary difference this pair of pages exists to make visible.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.

What the endpoint platform collects is consumed one layer up. End-User Experience Management Solutions covers the tools that turn device telemetry into a measure of whether work is actually happening, and the telemetry a management platform gathers is now their main input. The self-healing criterion in this Wave is the point where the two categories meet: noticing a degraded device is an experience question, and repairing it is a management one.

The convergence Forrester grades here is the same one that produced Zero Trust Platforms, where identity and device posture are evaluated together because neither is trusted on its own. A device that is unpatched fails a posture check, and a platform that reports posture accurately is worth more to a zero trust program than one that reports it late. The two evaluations are asking adjacent questions about the same agent.