# Setup Guide

Find guides, tutorials, and troubleshooting articles to install, configure, and optimize your Mago devices and software in the official Mago Knowledge Base.

## Select your room experience before you start

Mago turns any room into a modern meeting space. Before installing, it's worth taking a moment to decide how your room will be used. This determines the hardware requirements, the video conferencing licenses involved, and the steps you'll follow.

The two available experiences are BYOM only and Room System (includes BYOM), each suited to different scenarios and levels of room autonomy.

<table data-card-size="large" data-view="cards"><thead><tr><th align="center"></th><th></th><th></th><th align="center"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><h3>BYOM</h3><p>Bring Your Own Meeting</p></td><td>With BYOM (Bring Your Own Meeting), a user device, laptop or mobile, connects to the room to start and manage meetings. The room relies on the user's device for meeting launch and control.</td><td><strong>Best for:</strong> flexible spaces, hot-desking rooms, or quick rollouts where no dedicated room identity is needed.</td><td align="center"><a href="/pages/cpN0g1C5GNtupyuF9mwE">Go to BYOM Setup Guide</a></td><td><a href="/files/Vj4hTcat2FpslenMOA4u">/files/Vj4hTcat2FpslenMOA4u</a></td><td><a href="/pages/cpN0g1C5GNtupyuF9mwE">/pages/cpN0g1C5GNtupyuF9mwE</a></td></tr><tr><td align="center"><h3>Room System + BYOM</h3><p>Room as a host</p></td><td>With Room System, the room has its own identity and can start, host, and manage meetings independently via a touch controller and calendar integration. BYOM is still supported: users can connect their device and take control if needed.</td><td><strong>Best for:</strong> dedicated meeting rooms with high utilization, rooms that need to be bookable via calendar, or scenarios where meetings should start without a user device.</td><td align="center"><a href="/pages/9WVZ9l08kc6MTbFalSop">Go to Room System Setup Guide</a></td><td><a href="/files/Fy1bTUJrFxAv3DUYH6CV">/files/Fy1bTUJrFxAv3DUYH6CV</a></td><td><a href="/pages/9WVZ9l08kc6MTbFalSop">/pages/9WVZ9l08kc6MTbFalSop</a></td></tr></tbody></table>

## Not sure which one you need?

<table><thead><tr><th valign="middle"></th><th align="center">BYOM only</th><th align="center" valign="middle">Room System</th></tr></thead><tbody><tr><td valign="middle">Requires user device (laptop or mobile) to start a meeting</td><td align="center"><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td align="center" valign="middle">❌</td></tr><tr><td valign="middle">Requires touch controller (or Interactive Flat Panel)</td><td align="center">❌</td><td align="center" valign="middle">✅</td></tr><tr><td valign="middle">Room Calendar integration</td><td align="center">❌</td><td align="center" valign="middle">✅</td></tr><tr><td valign="middle">Room can host meetings independently</td><td align="center">❌</td><td align="center" valign="middle">✅</td></tr></tbody></table>


# BYOM

With Mago configured as BYOM (Bring Your Own Meeting), the room relies on a user device to start and manage meetings. When a user enters the room, they connect their laptop or mobile to the room system, which provides the display, audio, and video. No room identity, calendar, or dedicated video conferencing license is required.

### Choose your hardware

Select your room hardware to get started with the installation.

<table><thead><tr><th width="206.703125">Hardware</th><th width="289.640625">→ Go to</th><th>OS</th><th>Display</th><th>AV peripherals</th></tr></thead><tbody><tr><td><strong>Windows (PC / OPS)</strong></td><td><a data-mention href="/pages/9Vt7pJeh8hRInjSq3Asu">/pages/9Vt7pJeh8hRInjSq3Asu</a></td><td>Windows 11</td><td>External, passive or interactive</td><td>USB (camera, mic, speaker)</td></tr><tr><td><strong>Neat Bar Gen 2,</strong><br><strong>Neat Bar Pro</strong></td><td><a data-mention href="/pages/dHsfNLHddHltqzUl0ZpS">/pages/dHsfNLHddHltqzUl0ZpS</a></td><td>Neat OS (Neat Pulse)</td><td>External, passive</td><td>Integrated in the bar</td></tr><tr><td><strong>Neat Board 50,</strong><br><strong>Neat Board Pro</strong></td><td><a data-mention href="/pages/dHsfNLHddHltqzUl0ZpS">/pages/dHsfNLHddHltqzUl0ZpS</a></td><td>Neat OS (Neat Pulse)</td><td>Integrated, interactive</td><td>Integrated in the board</td></tr><tr><td><strong>All-in-One Interactive Flat Panel</strong></td><td><a data-mention href="/pages/OvOHGII45iQ5LPwsDwtz">/pages/OvOHGII45iQ5LPwsDwtz</a></td><td>Android</td><td>Integrated, interactive</td><td>Integrated in the unit</td></tr><tr><td><strong>Android Display,</strong><br><strong>Smart TV</strong></td><td><a data-mention href="/pages/eJIatRsSTDi2t9ggXMo1">/pages/eJIatRsSTDi2t9ggXMo1</a></td><td>Android, GoogleTV, FireTV</td><td>Integrated, passive</td><td>USB (camera, mic, speaker)</td></tr></tbody></table>


# Install on Windows

With BYOM, Mago runs on a Windows device connected to a passive or interactive display. Users connect their laptop or mobile to start and manage meetings. No calendar integration or room license is required.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

You will use a certified Windows device from the Certified [Windows Devices](/mago/certified-devices/windows-devices) list, or your own Windows hardware that meets the minimum specifications. Connect the display via HDMI or DisplayPort and attach all USB audio and video peripherals (camera, microphone, speaker) before launching Mago so they are detected correctly on first startup.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

Mago on Windows supports two wireless screen sharing methods:

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).

**Native screen sharing** is available via **Miracast**, **Google Cast**, and **AirPlay** directly from the operating system of the user device. All methods are installed automatically with Mago and do not require additional software. However, the network must be configured to allow mDNS and multicast traffic for device discovery. Verify that these requirements are met before proceeding. See [Wireless Screen Sharing](/mago/requirements/presentation/wireless-screen-sharing).
{% endstep %}

{% step %}

### Prepare video conferencing

By default, Mago joins meetings **as a guest** with no additional setup.

If BYOM users should join as **authenticated participants**, bypassing the lobby and appearing with their own identity, additional configuration is required depending on the provider.&#x20;

Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**User Join (BYOM Authenticated Calls)**

To enable User Join (BYOM Authenticated Calls), which allow users to bypass the lobby and appear with their own identity, you will need to:

* Authorize the **Mago app** in your organization. Follow this link to add the Mago app and grant admin consent: [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365)
* Install the **Azure Communication Services service principal** in the tenant. Follow this guide to setup the ACS service: [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams)

Each user who connects with their device will also require a Microsoft Teams license.

{% hint style="info" %}
Each user will sign in with their video call provider account in the Mago app on their personal device, and their authenticated identity is passed automatically to the room when connected.
{% endhint %}

<figure><img src="/files/bzEEIicE31FrRRTEKm8v" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare Windows

If you are using a certified Mago Core device, it comes with Mago pre-installed and you can skip to the next step.

If you are using your own Windows hardware, follow the full preparation procedure described in [How to Prepare Your Own Windows Hardware](/mago/certified-devices/windows-devices/how-to-prepare-your-own-windows-hardware). This includes a fresh installation of Windows 11, system updates, power and display configuration, removal of unnecessary components, Mago installation, and Mago user configuration. Once the preparation is complete, continue with the next step.

{% hint style="danger" %}
Do not use vendor images such as Microsoft Teams Rooms or Zoom Rooms, as these are not supported.
{% endhint %}
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Install Mago

{% hint style="info" %}
If you already completed the [How to Prepare Your Own Windows Hardware](/mago/certified-devices/windows-devices/how-to-prepare-your-own-windows-hardware), Mago is installed and you can skip to the next step.
{% endhint %}

If you are using a certified Windows device, download the Mago installer from [admin.mago.io/download-software](https://admin.mago.io/download-software) and run it on the device. During installation, Mago creates a dedicated Windows user account named "Mago" configured for automatic logon. Do not run Mago from an administrator account or any other Windows profile.

For large-scale rollouts, Mago can also be deployed silently via Intune, SCCM, or PDQ Deploy. See [How to Install Using Software Distribution (Silent Install)](/mago/certified-devices/windows-devices/deploy-valarea-pod-with-software-distribution-silent-install).
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Skip calendar setup.* BYOM does not use a room calendar. Skip the calendar configuration step when prompted.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable Guest Join with meeting ID and Passcode. Connect the provider account where required (Zoom).
  {% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test USB peripherals

{% hint style="success" %}
The room is now ready for BYOM use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Neat (Neat Pulse)

With BYOM, Mago runs on a Neat device managed via Neat Pulse. Users connect their laptop or mobile to start and manage meetings. No calendar integration or room license is required.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

You will use a Neat Bar or Neat Bar Pro connected to a passive external display via HDMI, or a Neat Board or Neat Board Pro with integrated display and AV peripherals. See [Neat Devices](/mago/certified-devices/neat-devices) for the list of certified Neat devices.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Prepare video conferencing

By default, Mago joins meetings **as a guest** with no additional setup.

If BYOM users should join as **authenticated participants**, bypassing the lobby and appearing with their own identity, additional configuration is required depending on the provider.&#x20;

Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**User Join (BYOM Authenticated Calls)**

To enable User Join (BYOM Authenticated Calls), which allow users to bypass the lobby and appear with their own identity, you will need to:

* Authorize the **Mago app** in your organization. Follow this link to add the Mago app and grant admin consent: [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365)
* Install the **Azure Communication Services service principal** in the tenant. Follow this guide to setup the ACS service: [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams)

Each user who connects with their device will also require a Microsoft Teams license.

{% hint style="info" %}
Each user will sign in with their video call provider account in the Mago app on their personal device, and their authenticated identity is passed automatically to the room when connected.
{% endhint %}

<figure><img src="/files/bzEEIicE31FrRRTEKm8v" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Enroll the device in Neat Pulse

Make sure the Neat device is already enrolled in your Neat Pulse account. If it is not, follow the Neat onboarding flow to add it before proceeding. See <https://neat.no/pulse/>
{% endstep %}

{% step %}

### Install Mago from Neat AppHub

On your Neat device, open the Neat Pulse management portal and navigate to the AppHub. Search for Mago and install it. Alternatively, you can push the app remotely to one or more devices directly from Neat Pulse.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, and local discovery. Grant all permissions when prompted. These are required for video conferencing, pairing, and screen sharing to function correctly.
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Skip calendar setup.* BYOM does not use a room calendar. Skip the calendar configuration step when prompted.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable Guest Join with meeting ID and passcode. For Zoom, an account is required.
  {% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test AV peripherals

{% hint style="success" %}
The room is now ready for BYOM use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Android (All-in-One Interactive Flat Panel)

With BYOM, Mago runs natively on an Android interactive all-in-one device. The display, camera, microphone, and speaker are integrated in the unit. Users connect their laptop or mobile to start and manage meetings. No calendar integration or room license is required.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

Verify that your device is on the [Android All-in-One Interactive Flat Panels](/mago/certified-devices/android-all-in-one-interactive-flat-panels) devices list.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Prepare video conferencing

By default, Mago joins meetings **as a guest** with no additional setup.

If BYOM users should join as **authenticated participants**, bypassing the lobby and appearing with their own identity, additional configuration is required depending on the provider.&#x20;

Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**User Join (BYOM Authenticated Calls)**

To enable User Join (BYOM Authenticated Calls), which allow users to bypass the lobby and appear with their own identity, you will need to:

* Authorize the **Mago app** in your organization. Follow this link to add the Mago app and grant admin consent: [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365)
* Install the **Azure Communication Services service principal** in the tenant. Follow this guide to setup the ACS service: [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams)

Each user who connects with their device will also require a Microsoft Teams license.

{% hint style="info" %}
Each user will sign in with their video call provider account in the Mago app on their personal device, and their authenticated identity is passed automatically to the room when connected.
{% endhint %}

<figure><img src="/files/bzEEIicE31FrRRTEKm8v" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Install Mago

{% hint style="info" %}
Some All-in-One Interactive Flat Panels come with Mago pre-installed by the manufacturer. Check with your device vendor before proceeding. If Mago is already present, skip the installation and launch the app directly.
{% endhint %}

If Mago is not pre-installed, install it using one of the following methods depending on what is available on your device:

* **Google Play Store** — available on GoogleTV and AndroidTV devices, search for "Mago for Display" and install (Google Play store link [here](https://play.google.com/store/apps/details?id=com.remago.receiver))
* **Amazon Appstore** — available on FireTV devices, search for "Mago for Display" and install (Amazon Appstore link [here](https://www.amazon.com/gp/product/B0F19DGJB2))
* **Direct APK** — download the APK from [admin.mago.io/download-software](https://admin.mago.io/download-software) and sideload it on the device

After installation, launch the Mago app.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, local discovery, and display over other apps. Grant all permissions when prompted. You can review permissions later via Settings → Apps → Mago → Permissions.
{% endstep %}

{% step %}

### Disable "Pause app activity if unused"

Android may automatically restrict apps that have not been used recently, revoking permissions or suspending background services. To prevent this from interrupting screen sharing, pairing, or meeting startup, disable this option on the device via Settings → Apps → Mago.
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Skip calendar setup.* BYOM does not use a room calendar. Skip the calendar configuration step when prompted.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable Guest Join with meeting ID and Passcode. For Zoom, an account is required.
  {% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test AV peripherals

{% hint style="success" %}
The room is now ready for BYOM use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Android (Display / Smart TV)

With BYOM, Mago runs on an Android display or Smart TV connected to USB audio and video peripherals. Users connect their laptop or mobile to start and manage meetings. No calendar integration or room license is required.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

Verify that your device is on the [Android Displays / Smart TVs](/mago/certified-devices/android-displays-smart-tvs) devices list.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Prepare video conferencing

By default, Mago joins meetings **as a guest** with no additional setup.

If BYOM users should join as **authenticated participants**, bypassing the lobby and appearing with their own identity, additional configuration is required depending on the provider.&#x20;

Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**User Join (BYOM Authenticated Calls)**

To enable User Join (BYOM Authenticated Calls), which allow users to bypass the lobby and appear with their own identity, you will need to:

* Authorize the **Mago app** in your organization. Follow this link to add the Mago app and grant admin consent: [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365)
* Install the **Azure Communication Services service principal** in the tenant. Follow this guide to setup the ACS service: [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams)

Each user who connects with their device will also require a Microsoft Teams license.

{% hint style="info" %}
Each user will sign in with their video call provider account in the Mago app on their personal device, and their authenticated identity is passed automatically to the room when connected.
{% endhint %}

<figure><img src="/files/bzEEIicE31FrRRTEKm8v" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**User Join (BYOM Authenticated Calls)**

{% hint style="info" %}
Coming soon
{% endhint %}
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Install Mago

If Mago is not pre-installed, install it using one of the following methods depending on what is available on your device:

* **Google Play Store** — available on GoogleTV and AndroidTV devices, search for "Mago for Display" and install (Google Play store link [here](https://play.google.com/store/apps/details?id=com.remago.receiver))
* **Amazon Appstore** — available on FireTV devices, search for "Mago for Display" and install (Amazon Appstore link [here](https://www.amazon.com/gp/product/B0F19DGJB2))
* **Direct APK** — download the APK from [admin.mago.io/download-software](https://admin.mago.io/download-software) and sideload it on the device

After installation, launch the Mago app.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, local discovery, and display over other apps. Grant all permissions when prompted. You can review permissions later via Settings → Apps → Mago → Permissions.
{% endstep %}

{% step %}

### Disable "Pause app activity if unused"

Android may automatically restrict apps that have not been used recently, revoking permissions or suspending background services. To prevent this from interrupting screen sharing, pairing, or meeting startup, disable this option on the device via Settings → Apps → Mago.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Skip calendar setup.* BYOM does not use a room calendar. Skip the calendar configuration step when prompted.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable Guest Join with meeting ID and Passcode. For Zoom, an account is required.
  {% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test AV peripherals

{% hint style="success" %}
The room is now ready for BYOM use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Room System

With Mago configured as Room System, the room has its own identity and can start, host, and manage meetings independently via a Touch Controller and Calendar integration. BYOM is still supported. Users can connect via the Mago app on their laptop or mobile to transfer their identity and take control of the meeting if needed.

### Choose your hardware

Select your room hardware to get started with the installation.

<table><thead><tr><th width="198.8359375">Hardware</th><th width="290.0703125">→ Go to</th><th>OS</th><th>Display</th><th>AV peripherals</th></tr></thead><tbody><tr><td><strong>Windows (PC / OPS)</strong></td><td><a data-mention href="/pages/5ZU1tfeVejYvooNH1AOc">/pages/5ZU1tfeVejYvooNH1AOc</a></td><td>Windows 11</td><td>External, passive or interactive</td><td>USB (camera, mic, speaker)</td></tr><tr><td><strong>Neat Bar Gen 2,</strong><br><strong>Neat Bar Pro</strong></td><td><a data-mention href="/pages/qK0JXa5czSnDZeO0ip7Z">/pages/qK0JXa5czSnDZeO0ip7Z</a></td><td>Neat OS (Neat Pulse)</td><td>External, passive</td><td>Integrated in the bar</td></tr><tr><td><strong>Neat Board 50,</strong><br><strong>Neat Board Pro</strong></td><td><a data-mention href="/pages/qK0JXa5czSnDZeO0ip7Z">/pages/qK0JXa5czSnDZeO0ip7Z</a></td><td>Neat OS (Neat Pulse)</td><td>Integrated, interactive</td><td>Integrated in the board</td></tr><tr><td><strong>All-in-One Interactive Flat Panel</strong></td><td><a data-mention href="/pages/f4q6mdUVJN0LwKymFGmN">/pages/f4q6mdUVJN0LwKymFGmN</a></td><td>Android</td><td>Integrated, interactive</td><td>Integrated in the unit</td></tr><tr><td><strong>Android Display,</strong><br><strong>Smart TV</strong></td><td><a data-mention href="/pages/LtX6ACqJm8Ivs2IpWVW8">/pages/LtX6ACqJm8Ivs2IpWVW8</a></td><td>Android, GoogleTV, FireTV</td><td>Integrated, passive</td><td>USB (camera, mic, speaker)</td></tr></tbody></table>


# Install on Windows

With Room System, Mago turns a Windows device into a fully independent meeting room. The room calendar is displayed on screen, meetings can be joined or started with a single tap, and a wired or wireless touch controller lets anyone in the room manage the session.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

You will use a certified Windows device from the Certified [Windows Devices](/mago/certified-devices/windows-devices) list, or your own Windows hardware that meets the minimum specifications. Connect the display via HDMI or DisplayPort and attach all USB audio and video peripherals (camera, microphone, speaker) before launching Mago so they are detected correctly on first startup.
{% endstep %}

{% step %}

### Prepare the Touch Controller

**Wired Touch Controller**

Use a wired touch controller connected via USB / Ethernet (USB over IP) / PoE to the Windows device. See the full list of Certified Controllers here: [Wired touch controllers](/mago/certified-devices/windows-devices/wired-touch-controllers).&#x20;

**Wireless Touch Controller**

Alternatively, you can use an iPad (iPadOS 13+) or Android tablet (Android 10.0+, minimum resolution 1024x600) as a wireless touch controller by installing the Mago Controller app from the App Store or Google Play. See [Wireless touch controllers](/mago/requirements/wireless-touch-controllers) for instructions. The wireless touch controller tablet requires an active Wi-Fi internet connection.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

Mago on Windows supports two wireless screen sharing methods:

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).

**Native screen sharing** is available via **Miracast**, **Google Cast**, and **AirPlay** directly from the operating system of the user device. All methods are installed automatically with Mago and do not require additional software. However, the network must be configured to allow mDNS and multicast traffic for device discovery. Verify that these requirements are met before proceeding. See [Wireless Screen Sharing](/mago/requirements/presentation/wireless-screen-sharing).
{% endstep %}

{% step %}

### Authorize the Mago app in your organization

Before Mago can access **room calendars** and **video conferencing services** on behalf of your organization, a tenant administrator must grant consent to the Mago application in your identity or services provider, such as Microsoft 365 or Google Workspace.

This is a one-time operation that authorizes Mago to request the permissions it requires, such as reading calendar events and authenticating meeting participants.

{% hint style="warning" %}
Without this consent, devices will not be able to display room calendars or join meetings as authenticated participants.
{% endhint %}

Select your provider below and follow the setup steps.

{% tabs %}
{% tab title="Microsoft 365" %}
When using Mago with Microsoft 365 room resources and users, the Mago app for display and Mago mobile app access Microsoft 365 services through the Microsoft Graph and Azure Communication Services APIs. To enable these features, a tenant administrator must grant consent to the Mago enterprise application.

{% hint style="success" %}
Mago is a verified enterprise application in the **Microsoft Entra app gallery** (application ID `17781659-6867-4c77-9ba3-40670305181c)` and it is listed under the official **Azure Marketplace**.
{% endhint %}

#### Add the Mago application to your tenant

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Microsoft 365 account that has **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator privileges**. When prompted, review the requested permissions and select "Accept" on behalf of your organization. The Mago application is now registered in your tenant.

<figure><img src="/files/zYDsjC6FpYfqqvHKspyf" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="/files/pZDSSpiZNi1BvrBgggSw" alt="" width="375"><figcaption></figcaption></figure>

#### Grant admin consent to the required scopes

To review and grant admin consent to the required scopes in the Mago application permissions:

* Open the [**Azure portal**](https://portal.azure.com/) and sign in with a Microsoft 365 Administrator account.
* Go to Microsoft Entra ID > Enterprise Applications (or search directly for "**Enterprise Applications**").

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

* Under the Application list, search for "**Mago**" (Application ID `17781659-6867-4c77-9ba3-40670305181c`).

<figure><img src="/files/6n1ZFExh43Mn61i3ZanR" alt=""><figcaption></figcaption></figure>

* Enter the Mago application, go to **Security** > **Permissions** and verify that admin consent has been granted to the required scopes. To grant admin consent to all the required scopes, click the "Grant admin consent for *YourCompanyName*" button.

<figure><img src="/files/HAUOhfV9oMhJEHxje7O7" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
See [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365) for **Advanced consent options** and the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}

{% tab title="Google Workspace" %}
When using Mago with Google Workspace room resources and users, the Mago app for display and Mago mobile app access Google services through Google APIs. To enable these features, a Google Workspace administrator must authorize the Mago application in the domain.

{% hint style="success" %}
Mago is a Google OAuth verified application.
{% endhint %}

#### Authorize the Mago application

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Google Workspace account that has Super Admin privileges. When prompted, review the requested permissions and approve. The Mago application is now authorized in your domain.

<figure><img src="/files/JycqEF5Pdkgt3wPrTonE" alt="" width="351"><figcaption></figcaption></figure>

<figure><img src="/files/Lmgbfv07psrnkMlpanLv" alt="" width="375"><figcaption></figcaption></figure>

#### Verify third-party app access and allow the Mago application if restricted

When room resources or users sign in later during device activation, Google will prompt them to approve additional scopes (such as calendar and meeting access).

{% hint style="warning" %}
If your domain restricts third-party application access, these prompts will be blocked with a **`400 admin_policy_enforced`** error.
{% endhint %}

#### Check third-party app access policy

To check if your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > **API controls**
* Click on **Settings**

<figure><img src="/files/scU5osjMXg2qleVURWbj" alt=""><figcaption></figcaption></figure>

* Under "Unconfigured third-party apps", verify which access level is selected. If it is set to "Allow users to access any third-party apps", no further action is required. If access is restricted, proceed with the next step to pre-authorize the Mago application at domain level.

<figure><img src="/files/V7AMHnrYiutyh9Rarfod" alt=""><figcaption></figcaption></figure>

#### Pre-authorize the Mago application

If your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > API controls > **Manage App Access**

<figure><img src="/files/KmB42Xv2P4qNWBYP3ew4" alt=""><figcaption></figcaption></figure>

* Click on "Configure new app"

<figure><img src="/files/qZcBDl3F0eUT42QcCozO" alt=""><figcaption></figcaption></figure>

* Search for the following Mago app client IDs and add them as trusted app (one by one).

<table><thead><tr><th width="148.30078125">Application</th><th>Client ID</th></tr></thead><tbody><tr><td>Mago app for display / web</td><td><code>436832489008-nl03st57foo9su4qg5mddnadhl7ql5oe.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for Android</td><td><code>436832489008-5ie2c8hme7jucfh4vn4hul7sdkm8mhuk.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for iOS</td><td><code>436832489008-l3lejr6nqvgmevau7u999gm6c17jdci2.apps.googleusercontent.com</code></td></tr></tbody></table>

<figure><img src="/files/ZEs6FAoCJt14ssEVIFFA" alt=""><figcaption></figcaption></figure>

* Set your desired Scope and click **Continue**

<figure><img src="/files/DW7syJpDxyoPXgkQkO4u" alt=""><figcaption></figcaption></figure>

* Set the app as **Trusted**, then click **Continue**

<figure><img src="/files/hHyucF3r4dAJtgfjZ55o" alt=""><figcaption></figcaption></figure>

* Review and click **Finish**

<figure><img src="/files/RwB2XBMUSRZkguHxjmUC" alt=""><figcaption></figcaption></figure>

* Make sure to repeat the steps to configure all 3 Mago app client IDs.

<figure><img src="/files/pyf1dl5sYIUqyBs2D9SD" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
This ensures that users and room resources are not blocked when Mago requests additional scopes (such as calendar access) during device activation or configuration.
{% endhint %}

{% hint style="info" %}
See [Google Workspace](/mago/requirements/third-party-providers/google-workspace) for the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare the room resource and calendar

A room resource account is required for calendar integration and instant meeting hosting. Create and provision the account in your calendar provider before proceeding.

* **Microsoft 365** — create and provision a room resource account, grant the required OAuth scopes, and run the PowerShell command to correctly display meeting titles — see the full guide here: [Microsoft 365 calendar](/mago/requirements/calendar/microsoft-365-calendar)
* **Google Workspace** — create a service account for conference room calendars and configure resource delegation — see the full guide here: [Google Workspace calendar](/mago/requirements/calendar/google-workspace-calendar)
* **Microsoft Exchange on-premises** — create and provision service accounts and room resources — see the full guide here: [Microsoft Exchange calendar (On Premises)](/mago/requirements/calendar/microsoft-exchange-calendar-on-premises)
  {% endstep %}

{% step %}

### Prepare video conferencing

With Room System, the room has its own identity and can join meetings independently. The configuration depends on the video conferencing provider you plan to use. BYOM User Join is also available to users connected to the room. Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will configure the following:

* Install the **Azure Communication Services service principal** in the tenant
* Provision the room resource with a Microsoft Teams **license**

See [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams) for the full procedure.

**User Join (BYOM Authenticated Calls)**

Regardless of the room configuration, User Join (BYOM Authenticated Calls) is always available.

{% hint style="info" %}
When a user connects to the room with their personal device and starts a meeting, their user identity takes precedence over the room identity for the duration of the connection. Once the user disconnects, the room reverts to its own join mode.
{% endhint %}

<figure><img src="/files/Tkw904EfEN4URfTOYjCK" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will assign the appropriate host license to the room resource Zoom account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Webex account with host license is required (Free, Starter, Business, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Google Workspace account is required (Free, Business Starter, Business Standard, Business Plus, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare Windows

If you are using a certified Mago Core device, it comes with Mago pre-installed and you can skip to the next step.

If you are using your own Windows hardware, follow the full preparation procedure described in [How to Prepare Your Own Windows Hardware](/mago/certified-devices/windows-devices/how-to-prepare-your-own-windows-hardware). This includes a fresh installation of Windows 11, system updates, power and display configuration, removal of unnecessary components, Mago installation, and Mago user configuration. Once the preparation is complete, continue with the next step.

{% hint style="danger" %}
Do not use vendor images such as Microsoft Teams Rooms or Zoom Rooms, as these are not supported.
{% endhint %}
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Install Mago

{% hint style="info" %}
If you already completed the [How to Prepare Your Own Windows Hardware](/mago/certified-devices/windows-devices/how-to-prepare-your-own-windows-hardware), Mago is installed and you can skip to the next step.
{% endhint %}

If you are using a certified Windows device, download the Mago installer from [admin.mago.io/download-software](https://admin.mago.io/download-software) and run it on the device. During installation, Mago creates a dedicated Windows user account named "Mago" configured for automatic logon. Do not run Mago from an administrator account or any other Windows profile.

For large-scale rollouts, Mago can also be deployed silently via Intune, SCCM, or PDQ Deploy. See [How to Install Using Software Distribution (Silent Install)](/mago/certified-devices/windows-devices/deploy-valarea-pod-with-software-distribution-silent-install).
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Connect the calendar.* Select the calendar provider (Microsoft 365 or Google Workspace) and connect the room resource account you prepared in Step 6. Complete the authentication flow and continue to the next step.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable the features that apply to your deployment: Guest Join with meeting ID and Passcode, Authenticated Calls, and Host Instant Meetings. The provider credentials and licenses you prepared in step 7 are required to complete this configuration.
  {% endstep %}

{% step %}

### Pair the Touch Controller

*Wired Touch Controller.* A wired controller is detected automatically as an extended display on Windows. No pairing is required. Open Mago Settings on the room PC, go to Display, and verify that the display configuration is correct. If the controller display is not assigned correctly, adjust the settings and recalibrate touch if necessary.

*Wireless Touch Controller.* On the iPad or Android tablet, open the Mago Controller app and follow the pairing instructions. The app discovers the room device automatically when both are on the same network. After pairing, the tablet displays the room calendar and meeting controls.
{% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test one-tap join from the touch controller
* Test USB peripherals

{% hint style="success" %}
The room is now ready for Room System use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Neat (Neat Pulse)

With Room System, Mago turns a Neat device into a fully independent meeting room. The room calendar is displayed on screen, meetings can be joined or started with a single tap, and a Neat Pad or Wireless Touch Controller lets anyone in the room manage the session.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

You will use a Neat Bar or Neat Bar Pro connected to a passive external display via HDMI, or a Neat Board or Neat Board Pro with integrated display and AV peripherals. See [Neat Devices](/mago/certified-devices/neat-devices) for the list of certified Neat devices.
{% endstep %}

{% step %}

### Prepare the Touch Controller

If you are using a Neat Bar Gen 2 with a Neat Pad, the Pad serves as the Touch Controller and no additional hardware is required.

If you are using a Neat Bar Gen 2 in BYOD mode without a Neat Pad, or a Neat Board (optionally), you will use an iPad (iPadOS 13+) or Android tablet (Android 10.0+, minimum resolution 1024x600) as a wireless Touch Controller. See [Wireless touch controllers](/mago/requirements/wireless-touch-controllers) for instructions. The wireless touch controller tablet requires an active Wi-Fi internet connection.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Authorize the Mago app in your organization

Before Mago can access **room calendars** and **video conferencing services** on behalf of your organization, a tenant administrator must grant consent to the Mago application in your identity or services provider, such as Microsoft 365 or Google Workspace.

This is a one-time operation that authorizes Mago to request the permissions it requires, such as reading calendar events and authenticating meeting participants.

{% hint style="warning" %}
Without this consent, devices will not be able to display room calendars or join meetings as authenticated participants.
{% endhint %}

Select your provider below and follow the setup steps.

{% tabs %}
{% tab title="Microsoft 365" %}
When using Mago with Microsoft 365 room resources and users, the Mago app for display and Mago mobile app access Microsoft 365 services through the Microsoft Graph and Azure Communication Services APIs. To enable these features, a tenant administrator must grant consent to the Mago enterprise application.

{% hint style="success" %}
Mago is a verified enterprise application in the **Microsoft Entra app gallery** (application ID `17781659-6867-4c77-9ba3-40670305181c)` and it is listed under the official **Azure Marketplace**.
{% endhint %}

#### Add the Mago application to your tenant

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Microsoft 365 account that has **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator privileges**. When prompted, review the requested permissions and select "Accept" on behalf of your organization. The Mago application is now registered in your tenant.

<figure><img src="/files/zYDsjC6FpYfqqvHKspyf" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="/files/pZDSSpiZNi1BvrBgggSw" alt="" width="375"><figcaption></figcaption></figure>

#### Grant admin consent to the required scopes

To review and grant admin consent to the required scopes in the Mago application permissions:

* Open the [**Azure portal**](https://portal.azure.com/) and sign in with a Microsoft 365 Administrator account.
* Go to Microsoft Entra ID > Enterprise Applications (or search directly for "**Enterprise Applications**").

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

* Under the Application list, search for "**Mago**" (Application ID `17781659-6867-4c77-9ba3-40670305181c`).

<figure><img src="/files/6n1ZFExh43Mn61i3ZanR" alt=""><figcaption></figcaption></figure>

* Enter the Mago application, go to **Security** > **Permissions** and verify that admin consent has been granted to the required scopes. To grant admin consent to all the required scopes, click the "Grant admin consent for *YourCompanyName*" button.

<figure><img src="/files/HAUOhfV9oMhJEHxje7O7" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
See [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365) for **Advanced consent options** and the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}

{% tab title="Google Workspace" %}
When using Mago with Google Workspace room resources and users, the Mago app for display and Mago mobile app access Google services through Google APIs. To enable these features, a Google Workspace administrator must authorize the Mago application in the domain.

{% hint style="success" %}
Mago is a Google OAuth verified application.
{% endhint %}

#### Authorize the Mago application

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Google Workspace account that has Super Admin privileges. When prompted, review the requested permissions and approve. The Mago application is now authorized in your domain.

<figure><img src="/files/JycqEF5Pdkgt3wPrTonE" alt="" width="351"><figcaption></figcaption></figure>

<figure><img src="/files/Lmgbfv07psrnkMlpanLv" alt="" width="375"><figcaption></figcaption></figure>

#### Verify third-party app access and allow the Mago application if restricted

When room resources or users sign in later during device activation, Google will prompt them to approve additional scopes (such as calendar and meeting access).

{% hint style="warning" %}
If your domain restricts third-party application access, these prompts will be blocked with a **`400 admin_policy_enforced`** error.
{% endhint %}

#### Check third-party app access policy

To check if your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > **API controls**
* Click on **Settings**

<figure><img src="/files/scU5osjMXg2qleVURWbj" alt=""><figcaption></figcaption></figure>

* Under "Unconfigured third-party apps", verify which access level is selected. If it is set to "Allow users to access any third-party apps", no further action is required. If access is restricted, proceed with the next step to pre-authorize the Mago application at domain level.

<figure><img src="/files/V7AMHnrYiutyh9Rarfod" alt=""><figcaption></figcaption></figure>

#### Pre-authorize the Mago application

If your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > API controls > **Manage App Access**

<figure><img src="/files/KmB42Xv2P4qNWBYP3ew4" alt=""><figcaption></figcaption></figure>

* Click on "Configure new app"

<figure><img src="/files/qZcBDl3F0eUT42QcCozO" alt=""><figcaption></figcaption></figure>

* Search for the following Mago app client IDs and add them as trusted app (one by one).

<table><thead><tr><th width="148.30078125">Application</th><th>Client ID</th></tr></thead><tbody><tr><td>Mago app for display / web</td><td><code>436832489008-nl03st57foo9su4qg5mddnadhl7ql5oe.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for Android</td><td><code>436832489008-5ie2c8hme7jucfh4vn4hul7sdkm8mhuk.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for iOS</td><td><code>436832489008-l3lejr6nqvgmevau7u999gm6c17jdci2.apps.googleusercontent.com</code></td></tr></tbody></table>

<figure><img src="/files/ZEs6FAoCJt14ssEVIFFA" alt=""><figcaption></figcaption></figure>

* Set your desired Scope and click **Continue**

<figure><img src="/files/DW7syJpDxyoPXgkQkO4u" alt=""><figcaption></figcaption></figure>

* Set the app as **Trusted**, then click **Continue**

<figure><img src="/files/hHyucF3r4dAJtgfjZ55o" alt=""><figcaption></figcaption></figure>

* Review and click **Finish**

<figure><img src="/files/RwB2XBMUSRZkguHxjmUC" alt=""><figcaption></figcaption></figure>

* Make sure to repeat the steps to configure all 3 Mago app client IDs.

<figure><img src="/files/pyf1dl5sYIUqyBs2D9SD" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
This ensures that users and room resources are not blocked when Mago requests additional scopes (such as calendar access) during device activation or configuration.
{% endhint %}

{% hint style="info" %}
See [Google Workspace](/mago/requirements/third-party-providers/google-workspace) for the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare the room resource and calendar

A room resource account is required for calendar integration and instant meeting hosting. Create and provision the account in your calendar provider before proceeding.

* **Microsoft 365** — create and provision a room resource account, grant the required OAuth scopes, and run the PowerShell command to correctly display meeting titles — see the full guide here: [Microsoft 365 calendar](/mago/requirements/calendar/microsoft-365-calendar)
* **Google Workspace** — create a service account for conference room calendars and configure resource delegation — see the full guide here: [Google Workspace calendar](/mago/requirements/calendar/google-workspace-calendar)
  {% endstep %}

{% step %}

### Prepare video conferencing

With Room System, the room has its own identity and can join meetings independently. The configuration depends on the video conferencing provider you plan to use. BYOM User Join is also available to users connected to the room. Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will configure the following:

* Install the **Azure Communication Services service principal** in the tenant
* Provision the room resource with a Microsoft Teams **license**

See [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams) for the full procedure.

**User Join (BYOM Authenticated Calls)**

Regardless of the room configuration, User Join (BYOM Authenticated Calls) is always available.

{% hint style="info" %}
When a user connects to the room with their personal device and starts a meeting, their user identity takes precedence over the room identity for the duration of the connection. Once the user disconnects, the room reverts to its own join mode.
{% endhint %}

<figure><img src="/files/Tkw904EfEN4URfTOYjCK" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will assign the appropriate host license to the room resource Zoom account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Webex account with host license is required (Free, Starter, Business, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Google Workspace account is required (Free, Business Starter, Business Standard, Business Plus, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Enroll the device in Neat Pulse

Make sure the Neat device is already enrolled in your Neat Pulse account. If it is not, follow the Neat onboarding flow to add it before proceeding. See <https://neat.no/pulse/>
{% endstep %}

{% step %}

### Install Mago from Neat AppHub

On your Neat device, open the Neat Pulse management portal and navigate to the AppHub. Search for Mago and install it. Alternatively, you can push the app remotely to one or more devices directly from Neat Pulse.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, and local discovery. Grant all permissions when prompted. These are required for video conferencing, pairing, and screen sharing to function correctly.
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Connect the calendar.* Select the calendar provider (Microsoft 365 or Google Workspace) and connect the room resource account you prepared. Complete the authentication flow and continue to the next step.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable the features that apply to your deployment: Guest Join with meeting ID and Passcode, Authenticated Calls, and Host Instant Meetings. The provider credentials and licenses you prepared are required to complete this configuration.
  {% endstep %}

{% step %}

### Pair the Touch Controller

*Neat Pad Controller.* Input the 6-digit code displayed on the Neat device to pair the Neat Pad.

*Wireless Touch Controller.* On the iPad or Android tablet, open the Mago Controller app and follow the pairing instructions. The app discovers the room device automatically when both are on the same network. After pairing, the tablet displays the room calendar and meeting controls.
{% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test video calls

{% hint style="success" %}
The room is now ready for Room System use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Android (All-in-One Interactive Flat Panel)

With Room System, Mago turns an Android interactive all-in-one device into a fully independent meeting room. The display, camera, microphone, and speaker are integrated in the unit. The room calendar is displayed on screen, meetings can be joined or started with a single tap, and a wireless Touch Controller lets anyone in the room manage the session.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

Verify that your device is on the [Android All-in-One Interactive Flat Panels](/mago/certified-devices/android-all-in-one-interactive-flat-panels) devices list.
{% endstep %}

{% step %}

### Prepare the Touch Controller (optional)

**Wireless Touch Controller**

You will use an iPad (iPadOS 13+) or Android tablet (Android 10.0+, minimum resolution 1024x600) as a wireless touch controller by installing the Mago Controller app from the App Store or Google Play. See [Wireless touch controllers](/mago/requirements/wireless-touch-controllers) for instructions. The wireless touch controller tablet requires an active Wi-Fi internet connection.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

Mago on Android supports two wireless screen sharing methods:

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Authorize the Mago app in your organization

Before Mago can access **room calendars** and **video conferencing services** on behalf of your organization, a tenant administrator must grant consent to the Mago application in your identity or services provider, such as Microsoft 365 or Google Workspace.

This is a one-time operation that authorizes Mago to request the permissions it requires, such as reading calendar events and authenticating meeting participants.

{% hint style="warning" %}
Without this consent, devices will not be able to display room calendars or join meetings as authenticated participants.
{% endhint %}

Select your provider below and follow the setup steps.

{% tabs %}
{% tab title="Microsoft 365" %}
When using Mago with Microsoft 365 room resources and users, the Mago app for display and Mago mobile app access Microsoft 365 services through the Microsoft Graph and Azure Communication Services APIs. To enable these features, a tenant administrator must grant consent to the Mago enterprise application.

{% hint style="success" %}
Mago is a verified enterprise application in the **Microsoft Entra app gallery** (application ID `17781659-6867-4c77-9ba3-40670305181c)` and it is listed under the official **Azure Marketplace**.
{% endhint %}

#### Add the Mago application to your tenant

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Microsoft 365 account that has **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator privileges**. When prompted, review the requested permissions and select "Accept" on behalf of your organization. The Mago application is now registered in your tenant.

<figure><img src="/files/zYDsjC6FpYfqqvHKspyf" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="/files/pZDSSpiZNi1BvrBgggSw" alt="" width="375"><figcaption></figcaption></figure>

#### Grant admin consent to the required scopes

To review and grant admin consent to the required scopes in the Mago application permissions:

* Open the [**Azure portal**](https://portal.azure.com/) and sign in with a Microsoft 365 Administrator account.
* Go to Microsoft Entra ID > Enterprise Applications (or search directly for "**Enterprise Applications**").

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

* Under the Application list, search for "**Mago**" (Application ID `17781659-6867-4c77-9ba3-40670305181c`).

<figure><img src="/files/6n1ZFExh43Mn61i3ZanR" alt=""><figcaption></figcaption></figure>

* Enter the Mago application, go to **Security** > **Permissions** and verify that admin consent has been granted to the required scopes. To grant admin consent to all the required scopes, click the "Grant admin consent for *YourCompanyName*" button.

<figure><img src="/files/HAUOhfV9oMhJEHxje7O7" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
See [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365) for **Advanced consent options** and the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}

{% tab title="Google Workspace" %}
When using Mago with Google Workspace room resources and users, the Mago app for display and Mago mobile app access Google services through Google APIs. To enable these features, a Google Workspace administrator must authorize the Mago application in the domain.

{% hint style="success" %}
Mago is a Google OAuth verified application.
{% endhint %}

#### Authorize the Mago application

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Google Workspace account that has Super Admin privileges. When prompted, review the requested permissions and approve. The Mago application is now authorized in your domain.

<figure><img src="/files/JycqEF5Pdkgt3wPrTonE" alt="" width="351"><figcaption></figcaption></figure>

<figure><img src="/files/Lmgbfv07psrnkMlpanLv" alt="" width="375"><figcaption></figcaption></figure>

#### Verify third-party app access and allow the Mago application if restricted

When room resources or users sign in later during device activation, Google will prompt them to approve additional scopes (such as calendar and meeting access).

{% hint style="warning" %}
If your domain restricts third-party application access, these prompts will be blocked with a **`400 admin_policy_enforced`** error.
{% endhint %}

#### Check third-party app access policy

To check if your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > **API controls**
* Click on **Settings**

<figure><img src="/files/scU5osjMXg2qleVURWbj" alt=""><figcaption></figcaption></figure>

* Under "Unconfigured third-party apps", verify which access level is selected. If it is set to "Allow users to access any third-party apps", no further action is required. If access is restricted, proceed with the next step to pre-authorize the Mago application at domain level.

<figure><img src="/files/V7AMHnrYiutyh9Rarfod" alt=""><figcaption></figcaption></figure>

#### Pre-authorize the Mago application

If your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > API controls > **Manage App Access**

<figure><img src="/files/KmB42Xv2P4qNWBYP3ew4" alt=""><figcaption></figcaption></figure>

* Click on "Configure new app"

<figure><img src="/files/qZcBDl3F0eUT42QcCozO" alt=""><figcaption></figcaption></figure>

* Search for the following Mago app client IDs and add them as trusted app (one by one).

<table><thead><tr><th width="148.30078125">Application</th><th>Client ID</th></tr></thead><tbody><tr><td>Mago app for display / web</td><td><code>436832489008-nl03st57foo9su4qg5mddnadhl7ql5oe.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for Android</td><td><code>436832489008-5ie2c8hme7jucfh4vn4hul7sdkm8mhuk.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for iOS</td><td><code>436832489008-l3lejr6nqvgmevau7u999gm6c17jdci2.apps.googleusercontent.com</code></td></tr></tbody></table>

<figure><img src="/files/ZEs6FAoCJt14ssEVIFFA" alt=""><figcaption></figcaption></figure>

* Set your desired Scope and click **Continue**

<figure><img src="/files/DW7syJpDxyoPXgkQkO4u" alt=""><figcaption></figcaption></figure>

* Set the app as **Trusted**, then click **Continue**

<figure><img src="/files/hHyucF3r4dAJtgfjZ55o" alt=""><figcaption></figcaption></figure>

* Review and click **Finish**

<figure><img src="/files/RwB2XBMUSRZkguHxjmUC" alt=""><figcaption></figcaption></figure>

* Make sure to repeat the steps to configure all 3 Mago app client IDs.

<figure><img src="/files/pyf1dl5sYIUqyBs2D9SD" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
This ensures that users and room resources are not blocked when Mago requests additional scopes (such as calendar access) during device activation or configuration.
{% endhint %}

{% hint style="info" %}
See [Google Workspace](/mago/requirements/third-party-providers/google-workspace) for the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare the room resource and calendar

A room resource account is required for calendar integration and instant meeting hosting. Create and provision the account in your calendar provider before proceeding.

* **Microsoft 365** — create and provision a room resource account, grant the required OAuth scopes, and run the PowerShell command to correctly display meeting titles — see the full guide here: [Microsoft 365 calendar](/mago/requirements/calendar/microsoft-365-calendar)
* **Google Workspace** — create a service account for conference room calendars and configure resource delegation — see the full guide here: [Google Workspace calendar](/mago/requirements/calendar/google-workspace-calendar)
  {% endstep %}

{% step %}

### Prepare video conferencing

With Room System, the room has its own identity and can join meetings independently. The configuration depends on the video conferencing provider you plan to use. BYOM User Join is also available to users connected to the room. Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will configure the following:

* Install the **Azure Communication Services service principal** in the tenant
* Provision the room resource with a Microsoft Teams **license**

See [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams) for the full procedure.

**User Join (BYOM Authenticated Calls)**

Regardless of the room configuration, User Join (BYOM Authenticated Calls) is always available.

{% hint style="info" %}
When a user connects to the room with their personal device and starts a meeting, their user identity takes precedence over the room identity for the duration of the connection. Once the user disconnects, the room reverts to its own join mode.
{% endhint %}

<figure><img src="/files/Tkw904EfEN4URfTOYjCK" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will assign the appropriate host license to the room resource Zoom account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Webex account with host license is required (Free, Starter, Business, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Google Workspace account is required (Free, Business Starter, Business Standard, Business Plus, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Install Mago

{% hint style="info" %}
Some All-in-One Interactive Flat Panels come with Mago pre-installed by the manufacturer. Check with your device vendor before proceeding. If Mago is already present, skip the installation and launch the app directly.
{% endhint %}

If Mago is not pre-installed, install it using one of the following methods depending on what is available on your device:

* **Google Play Store** — available on GoogleTV and AndroidTV devices, search for "Mago for Display" and install (Google Play store link [here](https://play.google.com/store/apps/details?id=com.remago.receiver))
* **Amazon Appstore** — available on FireTV devices, search for "Mago for Display" and install (Amazon Appstore link [here](https://www.amazon.com/gp/product/B0F19DGJB2))
* **Direct APK** — download the APK from [admin.mago.io/download-software](https://admin.mago.io/download-software) and sideload it on the device

After installation, launch the Mago app.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, local discovery, and display over other apps. Grant all permissions when prompted. You can review permissions later via Settings → Apps → Mago → Permissions.
{% endstep %}

{% step %}

### Disable "Pause app activity if unused"

Android may automatically restrict apps that have not been used recently, revoking permissions or suspending background services. To prevent this from interrupting screen sharing, pairing, or meeting startup, disable this option on the device via Settings → Apps → Mago.
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Connect the calendar.* Select the calendar provider (Microsoft 365 or Google Workspace) and connect the room resource account you prepared. Complete the authentication flow and continue to the next step.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable the features that apply to your deployment: Guest Join with meeting ID and Passcode, Authenticated Calls, and Host Instant Meetings. The provider credentials and licenses you prepared are required to complete this configuration.
  {% endstep %}

{% step %}

### Pair the Touch Controller (optional)

On the iPad or Android tablet, open the Mago Controller app and follow the pairing instructions. The app discovers the room device automatically when both are on the same network. After pairing, the tablet displays the room calendar and meeting controls.
{% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test USB peripherals

{% hint style="success" %}
The room is now ready for Room System use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Install on Android (Display / Smart TV)

With Room System, Mago turns an Android display or Smart TV into a fully independent meeting room. USB audio and video peripherals provide the conferencing hardware. The room calendar is displayed on screen, meetings can be joined or started with a single tap, and a wireless Touch Controller lets anyone in the room manage the session.

### Installation steps

{% stepper %}
{% step %}

### Check hardware and peripherals

Verify that your device (Android display, Smart TV, GoogleTV, AndroidTV, or FireTV) is on the [Android Displays / Smart TVs](/mago/certified-devices/android-displays-smart-tvs) devices list. Connect a USB videobar or separate USB camera, microphone, and speaker before launching Mago so they are detected correctly on first startup.
{% endstep %}

{% step %}

### Prepare the Touch Controller

**Wireless Touch Controller**

You will use an iPad (iPadOS 13+) or Android tablet (Android 10.0+, minimum resolution 1024x600) as a wireless touch controller by installing the Mago Controller app from the App Store or Google Play. See [Wireless touch controllers](/mago/requirements/wireless-touch-controllers) for instructions. The wireless touch controller tablet requires an active Wi-Fi internet connection.
{% endstep %}

{% step %}

### Prepare the network

Connect the device to wired Gigabit Ethernet. Verify that the connection provides at least 2 Mbps of internet bandwidth. Configure firewall rules and FQDN allowlisting according to the [Network](/mago/requirements/network) requirements. Proxy connections are not supported.
{% endstep %}

{% step %}

### Prepare wireless screen sharing

**Mago Link** allows any user to share their screen by visiting [magolink.com](https://magolink.com) from a browser on their laptop or mobile. No app install is required. Verify that the network meets the requirements described in [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link).
{% endstep %}

{% step %}

### Authorize the Mago app in your organization

Before Mago can access **room calendars** and **video conferencing services** on behalf of your organization, a tenant administrator must grant consent to the Mago application in your identity or services provider, such as Microsoft 365 or Google Workspace.

This is a one-time operation that authorizes Mago to request the permissions it requires, such as reading calendar events and authenticating meeting participants.

{% hint style="warning" %}
Without this consent, devices will not be able to display room calendars or join meetings as authenticated participants.
{% endhint %}

Select your provider below and follow the setup steps.

{% tabs %}
{% tab title="Microsoft 365" %}
When using Mago with Microsoft 365 room resources and users, the Mago app for display and Mago mobile app access Microsoft 365 services through the Microsoft Graph and Azure Communication Services APIs. To enable these features, a tenant administrator must grant consent to the Mago enterprise application.

{% hint style="success" %}
Mago is a verified enterprise application in the **Microsoft Entra app gallery** (application ID `17781659-6867-4c77-9ba3-40670305181c)` and it is listed under the official **Azure Marketplace**.
{% endhint %}

#### Add the Mago application to your tenant

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Microsoft 365 account that has **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator privileges**. When prompted, review the requested permissions and select "Accept" on behalf of your organization. The Mago application is now registered in your tenant.

<figure><img src="/files/zYDsjC6FpYfqqvHKspyf" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="/files/pZDSSpiZNi1BvrBgggSw" alt="" width="375"><figcaption></figcaption></figure>

#### Grant admin consent to the required scopes

To review and grant admin consent to the required scopes in the Mago application permissions:

* Open the [**Azure portal**](https://portal.azure.com/) and sign in with a Microsoft 365 Administrator account.
* Go to Microsoft Entra ID > Enterprise Applications (or search directly for "**Enterprise Applications**").

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

* Under the Application list, search for "**Mago**" (Application ID `17781659-6867-4c77-9ba3-40670305181c`).

<figure><img src="/files/6n1ZFExh43Mn61i3ZanR" alt=""><figcaption></figcaption></figure>

* Enter the Mago application, go to **Security** > **Permissions** and verify that admin consent has been granted to the required scopes. To grant admin consent to all the required scopes, click the "Grant admin consent for *YourCompanyName*" button.

<figure><img src="/files/HAUOhfV9oMhJEHxje7O7" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
See [Microsoft 365](/mago/requirements/third-party-providers/microsoft-365) for **Advanced consent options** and the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}

{% tab title="Google Workspace" %}
When using Mago with Google Workspace room resources and users, the Mago app for display and Mago mobile app access Google services through Google APIs. To enable these features, a Google Workspace administrator must authorize the Mago application in the domain.

{% hint style="success" %}
Mago is a Google OAuth verified application.
{% endhint %}

#### Authorize the Mago application

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Google Workspace account that has Super Admin privileges. When prompted, review the requested permissions and approve. The Mago application is now authorized in your domain.

<figure><img src="/files/JycqEF5Pdkgt3wPrTonE" alt="" width="351"><figcaption></figcaption></figure>

<figure><img src="/files/Lmgbfv07psrnkMlpanLv" alt="" width="375"><figcaption></figcaption></figure>

#### Verify third-party app access and allow the Mago application if restricted

When room resources or users sign in later during device activation, Google will prompt them to approve additional scopes (such as calendar and meeting access).

{% hint style="warning" %}
If your domain restricts third-party application access, these prompts will be blocked with a **`400 admin_policy_enforced`** error.
{% endhint %}

#### Check third-party app access policy

To check if your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > **API controls**
* Click on **Settings**

<figure><img src="/files/scU5osjMXg2qleVURWbj" alt=""><figcaption></figcaption></figure>

* Under "Unconfigured third-party apps", verify which access level is selected. If it is set to "Allow users to access any third-party apps", no further action is required. If access is restricted, proceed with the next step to pre-authorize the Mago application at domain level.

<figure><img src="/files/V7AMHnrYiutyh9Rarfod" alt=""><figcaption></figcaption></figure>

#### Pre-authorize the Mago application

If your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > API controls > **Manage App Access**

<figure><img src="/files/KmB42Xv2P4qNWBYP3ew4" alt=""><figcaption></figcaption></figure>

* Click on "Configure new app"

<figure><img src="/files/qZcBDl3F0eUT42QcCozO" alt=""><figcaption></figcaption></figure>

* Search for the following Mago app client IDs and add them as trusted app (one by one).

<table><thead><tr><th width="148.30078125">Application</th><th>Client ID</th></tr></thead><tbody><tr><td>Mago app for display / web</td><td><code>436832489008-nl03st57foo9su4qg5mddnadhl7ql5oe.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for Android</td><td><code>436832489008-5ie2c8hme7jucfh4vn4hul7sdkm8mhuk.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for iOS</td><td><code>436832489008-l3lejr6nqvgmevau7u999gm6c17jdci2.apps.googleusercontent.com</code></td></tr></tbody></table>

<figure><img src="/files/ZEs6FAoCJt14ssEVIFFA" alt=""><figcaption></figcaption></figure>

* Set your desired Scope and click **Continue**

<figure><img src="/files/DW7syJpDxyoPXgkQkO4u" alt=""><figcaption></figcaption></figure>

* Set the app as **Trusted**, then click **Continue**

<figure><img src="/files/hHyucF3r4dAJtgfjZ55o" alt=""><figcaption></figcaption></figure>

* Review and click **Finish**

<figure><img src="/files/RwB2XBMUSRZkguHxjmUC" alt=""><figcaption></figcaption></figure>

* Make sure to repeat the steps to configure all 3 Mago app client IDs.

<figure><img src="/files/pyf1dl5sYIUqyBs2D9SD" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
This ensures that users and room resources are not blocked when Mago requests additional scopes (such as calendar access) during device activation or configuration.
{% endhint %}

{% hint style="info" %}
See [Google Workspace](/mago/requirements/third-party-providers/google-workspace) for the full list of **Required features and scopes**.
{% endhint %}
{% endtab %}
{% endtabs %}

### Prepare the room resource and calendar

A room resource account is required for calendar integration and instant meeting hosting. Create and provision the account in your calendar provider before proceeding.

* **Microsoft 365** — create and provision a room resource account, grant the required OAuth scopes, and run the PowerShell command to correctly display meeting titles — see the full guide here: [Microsoft 365 calendar](/mago/requirements/calendar/microsoft-365-calendar)
* **Google Workspace** — create a service account for conference room calendars and configure resource delegation — see the full guide here: [Google Workspace calendar](/mago/requirements/calendar/google-workspace-calendar)

### Prepare video conferencing

With Room System, the room has its own identity and can join meetings independently. The configuration depends on the video conferencing provider you plan to use. BYOM User Join is also available to users connected to the room. Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will configure the following:

* Install the **Azure Communication Services service principal** in the tenant
* Provision the room resource with a Microsoft Teams **license**

See [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams) for the full procedure.

**User Join (BYOM Authenticated Calls)**

Regardless of the room configuration, User Join (BYOM Authenticated Calls) is always available.

{% hint style="info" %}
When a user connects to the room with their personal device and starts a meeting, their user identity takes precedence over the room identity for the duration of the connection. Once the user disconnects, the room reverts to its own join mode.
{% endhint %}

<figure><img src="/files/Tkw904EfEN4URfTOYjCK" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will assign the appropriate host license to the room resource Zoom account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Webex account with host license is required (Free, Starter, Business, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Google Workspace account is required (Free, Business Starter, Business Standard, Business Plus, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Prepare video conferencing

With Room System, the room has its own identity and can join meetings independently. The configuration depends on the video conferencing provider you plan to use. BYOM User Join is also available to users connected to the room. Complete the steps for each provider that applies to your deployment.

{% tabs %}
{% tab title="Microsoft Teams" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest and always goes to the lobby. No additional setup is required.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will configure the following:

* Install the **Azure Communication Services service principal** in the tenant
* Provision the room resource with a Microsoft Teams **license**

See [Authenticated Calls with Microsoft Teams](/mago/requirements/video-conferencing/authenticated-calls/authenticated-calls-with-microsoft-teams) for the full procedure.

**User Join (BYOM Authenticated Calls)**

Regardless of the room configuration, User Join (BYOM Authenticated Calls) is always available.

{% hint style="info" %}
When a user connects to the room with their personal device and starts a meeting, their user identity takes precedence over the room identity for the duration of the connection. Once the user disconnects, the room reverts to its own join mode.
{% endhint %}

<figure><img src="/files/Tkw904EfEN4URfTOYjCK" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Zoom" %}
**Guest Join (ID and Passcode)**

{% hint style="warning" %}
Since March 2026, Zoom no longer allows unauthenticated participants to join meetings from room systems.
{% endhint %}

* A Zoom account is required for all join modes, including Guest Join. Any Zoom account type is supported (Free, Pro, Business, Enterprise). Have the Zoom account credentials ready, as they will be entered during the activation wizard.
* The "Mago Room" app from the Zoom Marketplace must also be approved on the Zoom tenant or on the individual user account. See [Zoom](/mago/requirements/third-party-providers/zoom) for the approval procedure.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, you will assign the appropriate host license to the room resource Zoom account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Webex" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Webex account with host license is required (Free, Starter, Business, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}

{% tab title="Google Meet" %}
**Guest Join (ID and Passcode)**

Guest Join is available out of the box. The room joins as a guest with no additional setup.

**Room Join (Authenticated Calls) and Host Instant Meetings**

To enable Room Join and Host Instant Meetings, which allow the room to bypass the lobby, appear with its own identity, and start new meetings as a host, a Google Workspace account is required (Free, Business Starter, Business Standard, Business Plus, or Enterprise). Assign the appropriate license to the room resource account according to the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) table.
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Sign in or Sign up to Mago Admin Center

If you do not already have an account, register at [admin.mago.io](https://admin.mago.io). You will also need a valid Mago license key. If you do not have one, you can select a free trial during device activation.
{% endstep %}

{% step %}

### Install Mago

Install Mago on the device using one of the following methods depending on your device type:

* **Google Play Store** — available on GoogleTV and AndroidTV devices, search for "Mago for Display" and install (Google Play store link [here](https://play.google.com/store/apps/details?id=com.remago.receiver))
* **Amazon Appstore** — available on FireTV devices, search for "Mago for Display" and install (Amazon Appstore link [here](https://www.amazon.com/gp/product/B0F19DGJB2))
* **Direct APK** — download the APK from [admin.mago.io/download-software](https://admin.mago.io/download-software) and sideload it on the device

After installation, launch the Mago app.
{% endstep %}

{% step %}

### Grant required permissions

On first launch, Mago will request permissions for microphone, camera, networking, local discovery, and display over other apps. Grant all permissions when prompted. You can review permissions later via Settings → Apps → Mago → Permissions.
{% endstep %}

{% step %}

### Disable "Pause app activity if unused"

Android may automatically restrict apps that have not been used recently, revoking permissions or suspending background services. To prevent this from interrupting screen sharing, pairing, or meeting startup, disable this option on the device via Settings → Apps → Mago.
{% endstep %}

{% step %}

### Activate the device and complete the setup wizard

On first launch, Mago displays an activation screen with a QR code or a 6-digit code. Open [admin.mago.io](https://admin.mago.io) in a browser, go to Devices > Activate, and follow the on-screen steps to activate. Name the device when prompted. The device will appear under Devices in the Admin Center once activation is complete.

During the activation wizard, complete the following configuration steps.

* *Connect the calendar.* Select the calendar provider (Microsoft 365 or Google Workspace) and connect the room resource account you prepared. Complete the authentication flow and continue to the next step.
* *Configure video call providers.* For each video conferencing provider you plan to use (Microsoft Teams, Zoom, Cisco Webex, Google Meet, Mago Meet), enable the features that apply to your deployment: Guest Join with meeting ID and Passcode, Authenticated Calls, and Host Instant Meetings. The provider credentials and licenses you prepared are required to complete this configuration.
  {% endstep %}

{% step %}

### Configure policies

In Mago Admin Center, go to Policies and create or assign a policy for the device. Configure appearance, device settings, and any restrictions as needed. The device will update over the air.
{% endstep %}

{% step %}

### Verify

* Confirm date and time are correct
* Verify network connectivity
* Test wireless screen sharing
* Test AV peripherals

{% hint style="success" %}
The room is now ready for Room System use!
{% endhint %}
{% endstep %}
{% endstepper %}


# Certified Devices

Mago is available on Windows and Android hardware. Select your platform below to see the full list of certified devices and minimum specifications. Devices not listed may still work if they meet the minimum specifications, but support for non-certified installations is limited.

<table><thead><tr><th width="200.80859375">Platform</th><th width="199.5">→ Go to</th><th>OS</th><th>Display</th><th>AV peripherals</th></tr></thead><tbody><tr><td><strong>Windows (PC / OPS)</strong></td><td><a data-mention href="/pages/iH9GiZIEqK1qYjRnmYjS">/pages/iH9GiZIEqK1qYjRnmYjS</a></td><td>Windows 11</td><td>External, passive or interactive</td><td>USB (camera, mic, speaker)</td></tr><tr><td><strong>Neat</strong></td><td><a data-mention href="/pages/dy9edNGOS8bWaUc8vytF">/pages/dy9edNGOS8bWaUc8vytF</a></td><td>Neat OS (Neat Pulse)</td><td>External passive (Bar) or integrated interactive (Board)</td><td>Integrated</td></tr><tr><td><strong>All-in-One Interactive Flat Panel</strong></td><td><a data-mention href="/pages/D3Si8zWGgg1qB1auChM4">/pages/D3Si8zWGgg1qB1auChM4</a></td><td>Android 10+</td><td>Integrated, interactive</td><td>Integrated in the unit</td></tr><tr><td><strong>Display / Smart TV</strong></td><td><a data-mention href="/pages/zTr65QIdWlWdSKGsw6sS">/pages/zTr65QIdWlWdSKGsw6sS</a></td><td>Android, GoogleTV, FireTV</td><td>Integrated, passive</td><td>USB (camera, mic, speaker)</td></tr><tr><td><strong>Video Bar (MDM)</strong></td><td><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Coming soon</p></div></td><td>Android</td><td>External, passive</td><td>Integrated in the bar</td></tr></tbody></table>


# Windows Devices

### Certified PC / Mini PC / NUC / Room Kits

| Brand      | Model                                     |
| ---------- | ----------------------------------------- |
| Mago       | Core Pro S104C OPS/NUC (MH-CORE-PRO)      |
| HP         | ProDesk 4 Mini G1i Desktop AI PC          |
| HP         | Elite Mini 400 G9                         |
| HP         | Elite Mini 600 G9                         |
| HP         | Elite Mini 800 G9                         |
| ASUS       | NUC 14 PRO (NUC14RVH, Ultra Core 5)       |
| Yealink    | MCore PC (MVC400, MVC840, MVC860)         |
| Lenovo     | ThinkSmart One                            |
| Lenovo     | ThinkSmart Core Kit                       |
| Lenovo     | ThinkSmart HUB 500                        |
| Lenovo     | ThinkSmart HUB Gen2                       |
| TERRA      | PC-Micro 6000 (i1135G7)                   |
| SiComputer | Embedded OPS for Ricoh IFP                |
| XATROM     | System OPS Intel 12 Core (Alder Lake-U/P) |

Any OPS module included in a certified interactive display also qualifies as a certified Windows device.

***

### Certified Interactive Displays with Integrated OPS

| Brand               | Model                        |
| ------------------- | ---------------------------- |
| Mago                | One 55"                      |
| Huawei              | IdeaHub B2                   |
| Huawei              | IdeaHub B3                   |
| Huawei              | IdeaHub S                    |
| Huawei              | IdeaHub S2                   |
| Huawei              | IdeaHub Pro                  |
| Huawei              | IdeaHub G2                   |
| Huawei              | IdeaHub ES2                  |
| Huawei              | IdeaHub ES2 Plus             |
| Yealink             | MeetingBoard 65"             |
| Yealink             | MeetingBoard 86"             |
| LG                  | ONE:QUICK WORKS 55"          |
| LG                  | ONE:QUICK FLEX 43"           |
| LG                  | CreateBoard                  |
| Jupiter             | Pana 34"                     |
| Jupiter             | Pana 81"                     |
| Jupiter             | Pana 105"                    |
| Ricoh               | IWB A6500                    |
| Ricoh               | IWB A6510                    |
| Ricoh               | IWB A7500                    |
| Ricoh               | IWB A7510                    |
| Ricoh               | IWB A8600                    |
| Ricoh               | IWB A8610                    |
| Newline Interactive | SDM-L Module (Gen11 i5 / i7) |

***

### Minimum specifications for non-certified Windows hardware

{% hint style="warning" %}
Installing Mago on a non-certified Windows device does not guarantee correct functionality and performance. Support for non-certified installations is limited.
{% endhint %}

| Specification  | Requirement                                                        |
| -------------- | ------------------------------------------------------------------ |
| OS             | Windows 11 version 24H2 or later (Pro, Enterprise, IoT Enterprise) |
| CPU            | Intel Core i7, 11th generation or newer                            |
| RAM            | 8 GB (16 GB recommended)                                           |
| Storage        | 128 GB SSD                                                         |
| Network        | Ethernet and Wi-Fi, NDIS 6.3 or later                              |
| Display output | Miracast-compatible graphics card                                  |
| Peripherals    | USB camera and USB microphone                                      |
| GPU memory     | 1 GB dedicated DVMT (for shared GPU systems)                       |


# How to Prepare Your Own Windows Hardware

This page describes how to prepare a non-certified Windows device for Mago. If you are using a certified Mago Core device, it comes with Mago pre-installed and you can skip this page entirely.

{% hint style="danger" %}
**A fresh installation of Windows is mandatory**. Installing Mago on modified OEM images, collaboration appliance images (such as Microsoft Teams Rooms or Zoom Rooms), or preconfigured firmware is **not supported**.
{% endhint %}

{% stepper %}
{% step %}

### Install Windows 11

1. Create a Windows 11 installation USB using the Microsoft Media Creation Tool. Refer to this guide: <https://support.microsoft.com/en-us/windows/create-installation-media-for-windows-99a58364-8c02-206f-aa6f-40c3b507420d>
2. Boot from the USB key using BIOS or Advanced Recovery options.
3. When prompted, delete **all partitions** until only “Unallocated space” remains, then install Windows.
4. Complete OOBE:
   * Select region and keyboard
   * At the account step, **create a local Administrator user**
   * If Windows forces online login, disconnect all network connections (Ethernet and WiFi), reboot, press **SHIFT + F10** to open the Command Prompt and run "**OOBE\BYPASSNRO**" (without quotes)
5. Once on the desktop, connect to the internet.
6. Activate Windows with a valid Windows 11 Pro, IoT or Enterprise license.
7. Rename the PC (room name or device name) and restart.
   {% endstep %}

{% step %}

### Update the system

1. Install all Windows Updates.
2. Install **Optional Updates** (drivers, firmware, .NET components).
3. Open Device Manager and confirm that **no devices** are missing drivers.
4. Install any required vendor clients for peripherals (Jabra, Logitech, Poly).
   {% endstep %}

{% step %}

### Configure Windows 11

#### Power and performance

* Control Panel → Power Options → set to Ultimate Performance (preferred) or High Performance.
* Optional: Enable Fast Startup (if available on the hardware).

#### Security settings

* User Access Control (UAC): set to **Always notify** (highest level).
* Add Mago and all files inside *Program Files\Mago* to Antivirus and Firewall **exclusions**.
* Ensure the admin account is able to create a local unprivileged user (required during installation).

#### System and language

* Enable **Location Services** and allow apps to use location.
* Set Language, Region, and Time Zone correctly.
* Enable automatic Date & Time and NTP sync (time.windows.com).

#### Display configuration

* Windows Settings → System → Display:
  * Set the main display as **Primary**
  * Set additional displays (including wired tabletop touch controllers) as **Extended**
  * Refresh rate: **60 Hz or higher**, where possible
  * Recommended scale for main screen: **250 percent**
* For touch controllers:
  * Control Panel → Tablet PC Settings → **Calibrate touch** for each screen

Restart the PC.
{% endstep %}

{% step %}

### Enable Bluetooth for Proximity Join

* Enable Bluetooth on the device (BLE 4.0 or higher required).
* Bluetooth is used only for proximity detection using **ADV\_NONCONN\_INT** beacons.
* No pairing is required.
* All data transfer occurs through secure E2E encrypted HTTPS signaling.
  {% endstep %}

{% step %}

### Remove unnecessary components

* Uninstall Microsoft Teams (any preinstalled variant).
* Remove unwanted OEM apps or bloatware.
* Remove OneDrive (optional, improves boot speed).
  {% endstep %}

{% step %}

### Install and activate Mago

1. Log in as the Administrator.
2. Download the latest Mago release from: [**https://admin.mago.io**](https://admin.mago.io) **→ Downloads**.
3. Run the installer.
4. When prompted, launch the **Mago Configuration Wizard**.
5. Activate Mago (locally or online)

{% hint style="info" %}
At the Local User step, choose a username and optional password. Complete all remaining steps and restart.
{% endhint %}

{% hint style="success" %}
Windows will automatically log into the new **Mago** local user and launch Mago.
{% endhint %}
{% endstep %}

{% step %}

### Configure the Mago user

1. Close the Mago app:
   * If kiosk mode is enabled, disable it via “Mago Settings → Advanced” as Admin user (<kbd>CTRL+ALT+DEL</kbd> → Logout → Login as Admin → Open Mago Room Settings) or via Admin Center policy.
   * If kiosk mode is disabled: long-press the top Mago logo for 5 seconds and confirm exit.
2. Set audio input/output devices correctly under Windows Settings.
3. Confirm Google Chrome is the default browser. If not, set it manually.
4. Disable all Windows notifications.

Optional performance tuning

* Unpin all taskbar icons.
* Disable Search, Widgets and Task View.
* Set Dark mode theme.
  {% endstep %}

{% step %}

### Optional (up to Mago v7.0): Install and configure the Microsoft Teams desktop client

1. Login with the Mago local user.
2. Close the Mago app (disable kiosk mode, if enabled, and long-press the Mago logo for 5 seconds).&#x20;
3. Uninstall any preinstalled Teams or Teams Personal.
4. Download the latest Teams desktop client using Chrome.
5. Sign in with the **same room resource account** used in Mago settings (Calendar and Instant Meetings).
6. Apply these Teams settings:
   * Disable Auto-start
   * Enable Open in background
   * Enable Keep running when closed
   * Enable Turn off animations
7. Start a Meet Now and check microphone, speaker and camera settings.
8. Close Teams.
9. Enable “Use Teams Desktop Client” in Mago Settings → Advanced, and save.
10. Restart the PC.
    {% endstep %}

{% step %}

### First-use validation

Verify that the room behaves correctly.

1. Automatic login to the Mago user.
2. Launch a Teams meeting from Mago and verify:
   * Auto-join
   * Camera works
   * Microphone works
   * Speaker output is correct
3. Repeat with Zoom, Google Meet and Webex, or any preferred provider.
4. Test all configured screen sharing methods:
   * HDMI ingest
   * Miracast
   * AirPlay
   * Google Cast
   * Mago Link (magolink.com)
5. Test Mago whiteboard (offline and online).
6. Test installed apps (e.g. Chrome).
7. End the meeting and confirm full session cleanup.
   {% endstep %}
   {% endstepper %}


# How to Install Using Software Distribution (Silent Install)

{% hint style="warning" %}
**IMPORTANT**\
Before performing silent installations, it is recommended to:

* Sign in to the Admin Portal at [**https://admin.mago.io**](https://admin.mago.io/)
* Pre-configure the global and room-specific Mago policies
* Add all license keys to your tenant in advance

This ensures that newly installed Mago instances will apply the correct configuration immediately after activation.
{% endhint %}

{% stepper %}
{% step %}

### Prepare for software distribution

1. Download the latest **Mago installer** (.exe) from the Admin Portal.
2. Copy the installer to your deployment system or file repository.
3. Ensure the deployment is executed with **administrator privileges** on the target machine.
4. Confirm that the device meets the required Windows 11, hardware and driver requirements.
   {% endstep %}

{% step %}

### Silent installation commands

The following commands perform a fully silent installation with no visible UI or prompts.

All commands must be executed in an elevated **cmd.exe** or by a software distribution tool running as Administrator.

**Option A) Install with default configuration (no local Mago user created)**

`Magoroom_installer.exe /KEY {Serial} /DEFAULT-CONFIG /S`&#x20;

Use this when your environment manages user accounts separately or when using Azure AD/Intune-based device provisioning.

**Option B) Install with default configuration and creation of local Mago user**

`Magoroom_installer.exe /KEY {Serial} /DEFAULT-CONFIG /LOCAL-USER /S`&#x20;

Creates a default **Mago** local user account automatically during installation.

**Option C) Install with default configuration and creation of custom local user with password**

`Magoroom_installer.exe /KEY {Serial} /DEFAULT-CONFIG /LOCAL-USER-USERNAME {username} /LOCAL-USER-PASSWORD {password} /S`&#x20;

Use this when your security policies require custom-defined local account names or passwords.
{% endstep %}

{% step %}

### Post-installation behavior

After a successful silent installation:

* The Mago application will be installed and registered as the primary shell for the Mago user
* The system will be ready to auto-login to the local Mago user (if created)
* Upon first launch, Mago will automatically activate using the provided license key
* The device will immediately apply all policies configured in the Admin Portal
  {% endstep %}

{% step %}

### Notes for mass deployments

* Ensure all required Windows 11 updates and hardware drivers are installed before pushing Mago.
* For environments with strict firewalls, validate that Mago required ports and URLs are whitelisted.
* Use the Admin Portal to centrally manage policies and room settings across all deployed devices.
* Reboots may be required depending on software distribution platform behavior.
  {% endstep %}
  {% endstepper %}


# Supported display types

## Supported display types

* Passive display (e.g. LCD/OLED screen)
* Interactive displays (e.g. multitouch whiteboards)
* Video wall (with multitouch frame)
* Passive projector
* Interactive projector (e.g. with touch pen)
* Dual projectors with edge blending

## Supported Resolutions

* Full HD, 16:9 aspect ratio (1920 x 1080 pixels)
* 4K, 16:9 aspect ratio (3840 x 2160 pixels)
* 5K, 21:9 aspect ratio (5120 x 2160 pixels)

## Recommended settings

* On interactive displays, for a smooth writing experience, set the refresh rate of your video card to 60 Hz or higher (please note that generally only one video input port can support this setting. If in doubt, check the hardware manual).
* Use HDMI 2.0+ cables

## Consumer Electronics Control (CEC)

Configure the settings of your Front of Room displays to support Consumer Electronics Control (CEC) or enable PC mode.\
If you want the room display to automatically switch to Mago when it wakes up from standby mode, certain conditions must be met. This feature is optional but supported by the Mago software, as long as the underlying hardware supports the feature. A consumer TV used as a display in the living room must support the Consumer Electronics Control (CEC) feature of HDMI. Depending on the dock or console selected (which may not support CEC, refer to the manufacturer's support documentation), a controller such as the Crestron HD-RX-4K-201-C-E, Liberty's DL-UHDILC, or the Extron HD CTL 100 may be required to enable the desired behavior.


# Wired touch controllers

### Certified devices

The following interactive, wired tabletop controllers are certified for Mago on Windows.

* Mimo Myst Capture USB My-1090CP (SKU MI-MY-1090CP-G)
* Mimo Myst Capture IP My-1090VP (SKU MI-MY-1090CV)
* Poly GC8 (SKU 2200-30780-001)
* Lenovo ThinkSmart Controller
* Yealink MTouch II Controller (MVC400, MVC840, MVC860)
* Logitech TAP USB (SKU 939-001796), firmware 1.1.15 or higher
* Logitech TAP with CAT5e kit (SKU 939-001950), firmware 1.1.15 or higher

### Configurations

Mago on Windows supports dual display configurations with both passive and interactive screens. In a dual display setup, the system automatically assigns the role of each screen to provide the best meeting and collaboration experience.

The main screen is used for all interactive and content based activities. This includes:

* Mago Launcher UI
* Mago Whiteboard
* UCC content gallery
* Wireless screen sharing
* HDMI ingest
* Applications

The extended screen is dedicated to the UCC video layout to keep remote participants visible at all times during collaboration, content viewing or whiteboarding.

An optional touch controller can be added to the room, available either as a wireless tablet or as a certified USB or USB-C hardware console. The touch controller allows users to operate the room system without touching the front displays.

<figure><img src="/files/4ir132kjGyG8Ycxj42A0" alt=""><figcaption></figcaption></figure>


# (Optional) HDMI capture cards and Third-party BYOD / BYOM systems

## HDMI Capture cards

The following HDMI capture cards are certified for use with Mago:

* INOGENI 4K2USB3 USB 3.0 Capture Card (<https://inogeni.com/product/4k2usb3/>)
* Capture cards integrated into wired tabletop controllers

## Third-party BYOD / BYOM systems

The following third-party systems for Bring Your Own Device (content presentation) and Bring Your Own Meeting (videoconferencing from your own device, with virtualization of room peripherals) are tested for Mago:

* Barco ClickShare Present
* Barco ClickShare Conference
* AirServer Connect
* Crestron AirMedia
* Evoko MPX200 (in MTR Mode)

{% hint style="info" %}
Any other third-party system with HDMI output can be used as a source for the ingest HDMI in Mago on Windows.
{% endhint %}


# Neat Devices

### Certified Neat devices

| Device         | Type            | Display                            |
| -------------- | --------------- | ---------------------------------- |
| Neat Bar Gen 2 | Video bar       | External passive display via HDMI  |
| Neat Bar Pro   | Video bar       | External passive display via HDMI  |
| Neat Board 50  | All-in-one      | Integrated 50" interactive display |
| Neat Board Pro | All-in-one      | Integrated interactive display     |
| Neat Frame     | Personal device | Integrated display                 |

Neat Bar Gen 2 and Neat Bar Pro can be paired with a Neat Pad as a Touch Controller. If no Neat Pad is available, an iPad or Android tablet with the Mago Controller app can be used as an alternative wireless Touch Controller.


# Android All-in-One Interactive Flat Panels

### Certified devices

| Brand              | Model                   | Size            |
| ------------------ | ----------------------- | --------------- |
| BenQ               | RE8604                  | 86"             |
| Clevertouch        | Edge                    | Various         |
| Clevertouch        | Impact Lux              | Various         |
| Clevertouch        | Impact Max 2Gen         | Various         |
| Huawei             | IdeaHub S2 65 / 75 / 86 | 65" / 75" / 86" |
| LG                 | CreateBoard             | Various         |
| Ricoh              | A6510 / A7510 / A8610   | 65" / 75" / 86" |
| SMART Technologies | MX QX V2, MX V4, MX V5  | Various         |
| ViewSonic          | IFP8652-1C              | 86"             |
| Yealink            | MeetingBoard 65         | 65"             |

***

### Minimum system requirements

| Specification | Requirement                                                                      |
| ------------- | -------------------------------------------------------------------------------- |
| OS            | Android 10 or newer, 64-bit only                                                 |
| Network       | Wired Ethernet (recommended) or Wi-Fi 802.11ac with signal stronger than -60 dBm |


# Android Displays / Smart TVs

### Certified devices

| Brand              | Model        | Type                    |
| ------------------ | ------------ | ----------------------- |
| Amazon             | FireTV       | Streaming device        |
| Amazon             | FireTV Stick | Streaming device        |
| Philips            | 4650D        | Digital signage display |
| Samsung            | WEX          | Display                 |
| SMART Technologies | AM60         | OPS appliance           |

***

### Supported USB videobars

A USB videobar or separate USB camera, microphone, and speaker must be connected to the display for video conferencing.

| Brand      | Model             |
| ---------- | ----------------- |
| Jabra      | PanaCast 50       |
| Logitech   | MeetUp 2          |
| Huddly     | IQ                |
| Sennheiser | TeamConnect S / M |

***

### Minimum system requirements

| Specification | Requirement                                                                      |
| ------------- | -------------------------------------------------------------------------------- |
| OS            | Android 10 or newer, 64-bit only                                                 |
| Network       | Wired Ethernet (recommended) or Wi-Fi 802.11ac with signal stronger than -60 dBm |


# Android Video Bars (MDM)

{% hint style="info" %}
Coming soon
{% endhint %}

Support for Android-based video bars managed via MDM is coming soon. Check back for updates.


# Requirements


# Network

### Network Requirements

{% content-ref url="/pages/h3g48sU4qwoaLe0eRu6c" %}
[FQDN whitelisting](/mago/requirements/network/fqdn-whitelisting)
{% endcontent-ref %}

{% content-ref url="/pages/Pixa1augjXcsw1rw3ezF" %}
[Ports and services](/mago/requirements/network/ports-and-services)
{% endcontent-ref %}

{% content-ref url="/pages/CaZ4Cny5NtgJvsxiCJ5O" %}
[DNS and NTP](/mago/requirements/network/dns-and-ntp)
{% endcontent-ref %}

### Network and Internet access

It is recommended to use a Gigabit Ethernet network or higher, or a WiFi network, over a dedicated VLAN. Minimum internet bandwidth: 2 Mbps.

{% hint style="warning" %}
Proxy connections are not supported
{% endhint %}

### WiFi Network Tips

Wireless networks can be subject to network interference that leads to degradation in quality. We recommend following your wireless equipment vendor's best practices when setting up a wireless connection to improve video and audio quality and the smoothest possible visual collaboration user experience.

Here are some examples of best practices for setting up your wireless network recommended by various manufacturers:

Deploy wireless equipment, such as access points and routers, that can manage and distribute the bandwidth load across all connected devices in the network.

* Use, as far as possible, access points and routers from a single manufacturer to avoid further congesting the radio spectrum.
* Make sure that the wireless equipment is installed in a manner that reduces or eliminates interference from objects and other equipment.
* Make sure the wireless network shows strong signal strength (a Wi-Fi signal that shows full bars is preferred) on Mago and other devices' screens.
* By default, 5 GHz coverage is prioritized for devices to maximize the highest bandwidth.
* Enable band control to ensure that the 5GHz band is always given higher priority when sharing

  the same network name (SSID) as the 2.4 GHz band.
* Keep wireless channel usage below 50%.
* Keep the firmware of your access point and router up to date with the latest firmware  versions

  and hotfixes.
* Verify that Mago devices and at least one access point are seen with a signal strength of -60

  dBm or greater. A dBm value closer to zero is preferred. Follow the equipment manufacturer's

  recommendations.
* Implement QoS whenever possible to enable real-time monitoring and troubleshooting.

  For additional best practices specific to your wireless network hardware, see the manufacturer's documentation.

### Bandwidth

Minimum bandwidth: 2 Mbps

{% hint style="info" %}
When using third-party video conferencing applications, you will need more bandwidth. Users should refer to the guidelines recommended by each manufacturer.
{% endhint %}

#### Bandwidth for Video Conferencing

{% hint style="warning" %}
A 1080p video stream requires sufficient bandwidth on both the sending and receiving end for every participant.
{% endhint %}

<table><thead><tr><th width="130.13671875">Resolution</th><th width="124.8125">Min framerate</th><th width="125.03125">Max framerate</th><th>Max bitrate (downstream and upstream</th></tr></thead><tbody><tr><td>1080p</td><td>30</td><td>30</td><td>4 M</td></tr><tr><td>720p</td><td>30</td><td>30</td><td>2.5 M</td></tr><tr><td>540p</td><td>30</td><td>30</td><td>2 M</td></tr><tr><td>360p</td><td>30</td><td>30</td><td>1 M</td></tr><tr><td>240p</td><td>15</td><td>15</td><td>650 K</td></tr><tr><td>180p</td><td>7.5</td><td>15</td><td>250 K (350 K if 15 FPS)</td></tr></tbody></table>


# FQDN whitelisting

#### Licensing and Activation

```
license.remago.com
api.remago.com
activation.airserver.com
```

#### Mago Agent and Mago Admin Center

```
admin.mago.io
admin-hub.mago.io (HTTPS and WSS protocols, on port 443)
admin-api.mago.io
pod-pmc-production-signalr.azurewebsites.net
api.mago.io
pmc.mago.io
rms.mago.io
prd-rms.mago.io
vmc-api.valarea.com
pmc.valarea.com
prd-rms.valarea.com
rms.valarea.com
```

#### Mago Link Service (Mago Cast protocol)

```
r.magolink.com (HTTPS and WSS protocols, on 443)
magolink.com
share.mago.io (HTTPS and WSS protocols, on 443)
cast.mago.io (HTTPS and WSS protocols, on 443)
cast-turn.mago.io
cast-whip.mago.io
magocast.com
vc.mago.io (HTTPS and WSS protocols, on 443)
```

#### Video Conferencing

```
call.mago.io
vc-sdk.mago.io
meet.mago.io (HTTPS and WSS protocols, on 443)
```

**Microsoft Teams**\
For MS365 and Teams Services: [Office 365 URLs and IP address range](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide#skype-for-business-online-and-microsoft-teams)\
For Azure Communication Services: <https://learn.microsoft.com/en-us/azure/communication-services/concepts/voice-video-calling/network-requirements>​

**Zoom**\
See: <https://support.zoom.us/hc/en-us/articles/201362683-Zoom-network-firewall-or-proxy-server-settings>​

**Google Meet**\
See: <https://support.google.com/a/answer/1279090?hl=en>​

**Cisco Webex**\
See: <https://help.webex.com/en-us/article/WBX000028782/Network-Requirements-for-Webex-Services>

#### Mago Whiteboard and Mago mobile (iOS / Android) and web apps

```
wb.mago.io
app.mago.io
chat1.mago.io
chat1.valarea.com
globalchat1.azurewebsites.net
meet1.mago.io
meet1.valarea.com
arcrop.mago.io
rgo.li
```

#### Third-party Services

<pre><code><strong>oauth-apple.valarea.com
</strong>oauth-apple.mago.io
oauth-google.valarea.com
oauth-google.mago.io
oauth-msft.valarea.com
oauth-msft.mago.io
oauth-webex.valarea.com
oauth-webex.mago.io
oauth-zoom.valarea.com
oauth-zoom.mago.io
graph.microsoft.com
inputtols.google.com
googleapis.com
autodraw.com
dropbox.com
eu.docusign.net
account.docusign.com
</code></pre>


# Ports and services

Please note that all required network ports for Mago must be **allowed at the VLAN infrastructure level**, not just on individual client devices. This ensures proper communication between Mago and user devices across the network. Make sure your network switches, firewalls, and access points are configured to permit the necessary traffic within and across VLANs.

## Generic ports

<table><thead><tr><th width="99.5625">Port</th><th width="122.33203125">Type</th><th width="142.59765625">Direction</th><th>Service</th></tr></thead><tbody><tr><td>80</td><td>TCP</td><td>Outbound</td><td>HTTP</td></tr><tr><td>443</td><td>TCP</td><td>Outbound</td><td>HTTPS</td></tr><tr><td>53</td><td>TCP/UDP</td><td>Outbound</td><td>DNS (internal or external)</td></tr><tr><td>123</td><td>UDP</td><td>Outbound</td><td>NTP (internal or external)</td></tr></tbody></table>

## Screen sharing protocols

### Mago Link

See [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link)

### Miracast

See [Miracast](/mago/requirements/presentation/wireless-screen-sharing/miracast)

### AirPlay

See [AirPlay](/mago/requirements/presentation/wireless-screen-sharing/airplay)

### Google Cast

See [Google Cast](/mago/requirements/presentation/wireless-screen-sharing/google-cast)

## Local discovery service of Mago devices (optional)

To use the local discovery service, enable the following ports on the Mago device and network.

Discover more about the discovery service for Mago mobile apps here: [Proximity connection](/mago-mobile-apps/proximity-connection)

<table><thead><tr><th width="99.2890625">Port</th><th width="102.0859375">Type</th><th width="164.1953125">Direction</th><th>Service</th></tr></thead><tbody><tr><td>8034</td><td>TCP</td><td>Both</td><td>Local Discovery Service</td></tr><tr><td>8035</td><td>UDP</td><td>Both</td><td>Local Discovery Service</td></tr></tbody></table>


# DNS and NTP

Mago Essential requires access to DNS services to resolve domain names for functions such as software updates, authentication, and cloud-based services (e.g., magolink.com, admin.mago.io). Accurate time synchronization is also critical for certificate validation and secure communication. Ensure the device can access a reliable NTP server (e.g., time.windows.com or a local NTP source) to maintain correct system time.


# Third-party providers


# Microsoft 365

## How add the Mago enterprise application in your Microsoft 365 tenant and grant admin consent

When using Mago with Microsoft 365 room resources and users, the Mago app for display and Mago mobile app access Microsoft 365 services through the Microsoft Graph and Azure Communication Services APIs. To enable these features, a tenant administrator must grant consent to the Mago enterprise application.

{% hint style="success" %}
Mago is a verified enterprise application in the **Microsoft Entra app gallery** (application ID `17781659-6867-4c77-9ba3-40670305181c)` and it is listed under the official **Azure Marketplace** (see <https://marketplace.microsoft.com/nb-no/product/saas/aad.valarea?tab=overview>).
{% endhint %}

{% stepper %}
{% step %}

### Add the Mago application to your tenant

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Microsoft 365 account that has **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator privileges**. When prompted, review the requested permissions and select "Accept" on behalf of your organization. The Mago application is now registered in your tenant.

<figure><img src="/files/zYDsjC6FpYfqqvHKspyf" alt="" width="375"><figcaption><p>Mago Admin Center (https://admin.mago.io)</p></figcaption></figure>

<figure><img src="/files/pZDSSpiZNi1BvrBgggSw" alt="" width="375"><figcaption><p>Mago app Permission Request</p></figcaption></figure>
{% endstep %}

{% step %}

### Grant admin consent to the required scopes

To review and grant admin consent to the required scopes in the Mago application permissions:

* Open the [**Azure portal**](https://portal.azure.com/) and sign in with a Microsoft 365 Administrator account.
* Go to Microsoft Entra ID > Enterprise Applications (or search directly for "**Enterprise Applications**").

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

* Under the Application list, search for "**Mago**" (Application ID `17781659-6867-4c77-9ba3-40670305181c`).

<figure><img src="/files/6n1ZFExh43Mn61i3ZanR" alt=""><figcaption></figcaption></figure>

* Enter the Mago application, go to **Security** > **Permissions** and verify that admin consent has been granted to the required scopes. To grant admin consent to all the required scopes, click the "Grant admin consent for *YourCompanyName*" button.

<figure><img src="/files/HAUOhfV9oMhJEHxje7O7" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

## Advanced consent options

Below are the official Microsoft guides to grant consent to the Mago app in different ways.

### Tenant-wide consent

{% embed url="<https://learn.microsoft.com/azure/active-directory/manage-apps/grant-admin-consent>" %}

### Single user consent

{% embed url="<https://learn.microsoft.com/entra/identity/enterprise-apps/grant-consent-single-user?pivots=msgraph-powershell>" %}

### Microsoft Intune

In case the device is managed through **Microsoft Intune**, check the app access policies in the Intune settings and allow access to the "Mago" app. Refer to the following guide:

{% embed url="<https://learn.microsoft.com/entra/identity/enterprise-apps/configure-user-consent?pivots=portal>" %}

## Required features and scopes

### Permissions requested by the Mago room app

All permissions are **delegated** permissions, granted on behalf of the Microsoft 365 account linked to the room. Mago requests no application (app only) permissions, so the room can never access data the linked account cannot already access.

Permissions are requested **per capability**. When an administrator enables a capability in the Mago console, the consent screen carries only that capability's scopes. Capabilities left disabled are never requested.

Every capability includes the baseline scopes `openid`, `profile` and `offline_access`.

#### Capabilities and their scopes

<table><thead><tr><th width="165.3984375">Capability</th><th width="184.75">Mago Admin Center</th><th width="231.59765625">Additional scopes</th><th>API</th></tr></thead><tbody><tr><td><strong>Account connection</strong></td><td>"Connect"</td><td><p><code>User.ReadBasic.All</code> <code>Calendars.ReadWrite</code></p><p><code>Mail.Read</code></p><p><code>Mail.Send</code></p></td><td>Graph</td></tr><tr><td><strong>Calendar</strong></td><td>"Calendar"</td><td><p><code>User.ReadBasic.All</code></p><p><code>Calendars.ReadWrite</code></p><p><code>Mail.Read</code></p><p><code>Mail.Send</code></p></td><td>Graph</td></tr><tr><td><strong>Join with connected account (*)</strong></td><td>"Join meetings using the connected account"</td><td><p><code>Teams.ManageCalls</code></p><p><code>Teams.ManageChats</code></p></td><td>Azure Communication Services</td></tr><tr><td><strong>Instant meetings</strong></td><td>"Enable instant meetings"</td><td><p><code>User.ReadBasic.All</code></p><p><code>OnlineMeetings.ReadWrite</code></p></td><td>Graph</td></tr><tr><td><strong>Meeting chat</strong></td><td>"Enable chat"</td><td><p><code>User.ReadBasic.All</code></p><p><code>Chat.ReadWrite</code></p><p><code>ChatMessage.Send</code></p></td><td>Graph</td></tr><tr><td><strong>Join by ID and passcode</strong></td><td>"Join meetings via ID and Passcode"</td><td>none, no account required</td><td>—</td></tr></tbody></table>

(\*) "Join meetings using the connected account" must be enabled before "Enable instant meetings" and "Enable chat", and disabling it also disables both. It requires the linked account to hold a Teams license (see [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements)).

#### What each scope is used for

<table data-search="false"><thead><tr><th width="236.80859375">Scope</th><th>Purpose</th></tr></thead><tbody><tr><td><code>openid</code>, <code>profile</code></td><td>Sign in with the room account and read its name and email address</td></tr><tr><td><code>offline_access</code></td><td>Keep the room signed in without an administrator reauthorizing it every 60 minutes</td></tr><tr><td><code>Calendars.ReadWrite</code></td><td>Read the room agenda to display upcoming meetings, create the event when a meeting is booked from the room, write the join link into the event, extend the event when a meeting runs longer than scheduled, and release the room when a meeting ends early</td></tr><tr><td><code>Mail.Read</code></td><td>Read invitation messages in the room mailbox to recover the meeting join link. This runs as part of the ordinary calendar refresh: for the events in the displayed time window the room also reads the matching invitation, because a forwarded or accepted invitation frequently carries the join link only in the mail body and not in the calendar item</td></tr><tr><td><code>Mail.Send</code></td><td>Send meeting material and invitations from the room account</td></tr><tr><td><code>User.ReadBasic.All</code></td><td>Look up participants in the organization directory when inviting them to a meeting, and resolve participant names and addresses in the call roster. Reads basic directory profile data only, never mailbox content</td></tr><tr><td><code>OnlineMeetings.ReadWrite</code></td><td>Create an ad hoc Teams meeting when an instant meeting is started from the room</td></tr><tr><td><p><code>Chat.ReadWrite</code></p><p><code>ChatMessage.Send</code></p></td><td>Read and send messages in the chat of the meeting in progress</td></tr><tr><td><p><code>Teams.ManageCalls</code></p><p><code>Teams.ManageChats</code></p></td><td>Azure Communication Services scopes: Join Teams meetings as the connected account</td></tr></tbody></table>

#### Notes for administrators

* Connecting the Microsoft 365 account already consents to the calendar and mail scopes, before any individual capability is enabled.
* At runtime the room's access token carries every scope consented for the Mago application, not only those of the capability in use. The per capability separation applies at consent time.
* Disabling a capability in the Mago console updates the Mago configuration only. It does not revoke the consent or the refresh token, which must be revoked in Microsoft Entra ID.
* **Mago Whiteboard for Windows (version <= 7.5)** additionally uses `Files.ReadWrite.All` and `User.Read` to open and save whiteboard recaps and session documents on OneDrive and SharePoint document libraries.
* A room calendar can also be connected through **Microsoft Exchange on premises** (EWS with a service account), which requires no OAuth scopes at all.

### Permissions requested by the Mago mobile app (iOS / Android)

All permissions are **delegated** permissions, granted on behalf of the signed in Microsoft 365 user. The app requests them **incrementally**: each scope is requested when the user first uses the capability that needs it, not all at sign in.

<table><thead><tr><th width="220.54296875">Capability</th><th width="211.00390625">Scope</th><th>API</th></tr></thead><tbody><tr><td>Sign in</td><td><code>User.Read</code></td><td>Graph</td></tr><tr><td>Personal calendar</td><td><code>Calendars.ReadWrite</code></td><td>Graph</td></tr><tr><td>OneDrive files</td><td><code>Files.ReadWrite.All</code></td><td>Graph</td></tr><tr><td>SharePoint document libraries</td><td><code>Sites.Read.All</code></td><td>Graph</td></tr><tr><td>Join Teams meetings</td><td><p><code>Teams.ManageCalls</code></p><p><code>Teams.ManageChats</code></p></td><td>Azure Communication Services</td></tr></tbody></table>

<table><thead><tr><th width="243.421875">Scope</th><th>Purpose</th></tr></thead><tbody><tr><td><code>User.Read</code></td><td>Sign in and read the signed in user's own profile</td></tr><tr><td><code>Calendars.ReadWrite</code></td><td>Read the user's calendar to list meetings, and create or update an event when a meeting is booked from the app</td></tr><tr><td><code>Files.ReadWrite.All</code></td><td>Browse, open, import and save documents on the user's OneDrive</td></tr><tr><td><code>Sites.Read.All</code></td><td>Browse and open documents in SharePoint document libraries the user can access</td></tr><tr><td><p><code>Teams.ManageCalls</code></p><p><code>Teams.ManageChats</code></p></td><td>Join Teams meetings and take part in the meeting chat as the signed in user</td></tr></tbody></table>


# Google Workspace

## How to add the Mago application in your Google Workspace domain and grant access

When using Mago with Google Workspace room resources and users, the Mago app for display and Mago mobile app access Google services through Google APIs. To enable these features, a Google Workspace administrator must authorize the Mago application in the domain.

{% hint style="success" %}
Mago is a Google OAuth verified application.
{% endhint %}

{% stepper %}
{% step %}

### Authorize the Mago application

Open [admin.mago.io](https://admin.mago.io/) and sign in with a Google Workspace account that has Super Admin privileges. When prompted, review the requested permissions and approve. The Mago application is now authorized in your domain.

<figure><img src="/files/JycqEF5Pdkgt3wPrTonE" alt="" width="351"><figcaption></figcaption></figure>

<figure><img src="/files/Lmgbfv07psrnkMlpanLv" alt="" width="375"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Verify third-party app access and allow the Mago application if restricted

When room resources or users sign in later during device activation, Google will prompt them to approve additional scopes (such as calendar and meeting access).

{% hint style="warning" %}
If your domain restricts third-party application access, these prompts will be blocked with a **`400 admin_policy_enforced`** error.
{% endhint %}

#### Check third-party app access policy

To check if your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > **API controls**
* Click on **Settings**

<figure><img src="/files/scU5osjMXg2qleVURWbj" alt=""><figcaption></figcaption></figure>

* Under "Unconfigured third-party apps", verify which access level is selected. If it is set to "Allow users to access any third-party apps", no further action is required. If access is restricted, proceed with the next step to pre-authorize the Mago application at domain level.

<figure><img src="/files/V7AMHnrYiutyh9Rarfod" alt=""><figcaption></figcaption></figure>

#### Pre-authorize the Mago application

If your domain restricts third-party application access:

* Open the [Google Admin console](https://admin.google.com/)
* Go to Security > Access and data control > API controls > **Manage App Access**

<figure><img src="/files/KmB42Xv2P4qNWBYP3ew4" alt=""><figcaption></figcaption></figure>

* Click on "Configure new app"

<figure><img src="/files/qZcBDl3F0eUT42QcCozO" alt=""><figcaption></figcaption></figure>

* Search for the following Mago app client IDs and add them as trusted app (one by one).

<table><thead><tr><th width="148.30078125">Application</th><th>Client ID</th></tr></thead><tbody><tr><td>Mago app for display / web</td><td><code>436832489008-nl03st57foo9su4qg5mddnadhl7ql5oe.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for Android</td><td><code>436832489008-5ie2c8hme7jucfh4vn4hul7sdkm8mhuk.apps.googleusercontent.com</code></td></tr><tr><td>Mago mobile app for iOS</td><td><code>436832489008-l3lejr6nqvgmevau7u999gm6c17jdci2.apps.googleusercontent.com</code></td></tr></tbody></table>

<figure><img src="/files/ZEs6FAoCJt14ssEVIFFA" alt=""><figcaption></figcaption></figure>

* Set your desired Scope and click **Continue**

<figure><img src="/files/DW7syJpDxyoPXgkQkO4u" alt=""><figcaption></figcaption></figure>

* Set the app as **Trusted**, then click **Continue**

<figure><img src="/files/hHyucF3r4dAJtgfjZ55o" alt=""><figcaption></figcaption></figure>

* Review and click **Finish**

<figure><img src="/files/RwB2XBMUSRZkguHxjmUC" alt=""><figcaption></figcaption></figure>

* Make sure to repeat the steps to configure all 3 Mago app client IDs.

<figure><img src="/files/pyf1dl5sYIUqyBs2D9SD" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
This ensures that users and room resources are not blocked when Mago requests additional scopes (such as calendar access) during device activation or configuration.
{% endhint %}
{% endstep %}
{% endstepper %}

## Required features and scopes

| Mago – Feature                                                                                                                     | Required Scope Permissions                                                              |
| ---------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| Log in with room account and view room name and email address                                                                      | `auth/userinfo.email`                                                                   |
| Select the room calendar to list upcoming meetings on the display                                                                  | `auth/calendar.readonly`                                                                |
| Create a new instant meeting as a Host and book the room calendar                                                                  | `auth/calendar.events`                                                                  |
| Search for Google Directory contacts to add recipients to meeting invitations                                                      | <p><code>auth/contacts.readonly</code><br><code>auth/contacts.other.readonly</code></p> |
| Browse, import, open and view cloud storage files (Google Drive) during a Mago Workspace or Mago Stage session (file presentation) | <p><code>auth/drive</code></p><p><code>auth/drive.file</code></p>                       |

| Mago Workspace app – Feature                                                                                                       | Required Scope Permissions                                        |
| ---------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| Log in to Mago Workspace via a personal Google account, view the account name and email address                                    | `auth/userinfo.email`                                             |
| Choose a personal calendar to list your personal meetings in the app and start them in the meeting room                            | `auth/calendar.readonly`                                          |
| Create a new instant meeting as a Host and book the room calendar                                                                  | `auth/calendar.events`                                            |
| Browse, import, open and view cloud storage files (Google Drive) during a Mago Workspace or Mago Stage session (file presentation) | <p><code>auth/drive</code></p><p><code>auth/drive.file</code></p> |


# Zoom

## Verified Mago App for Zoom Marketplace

If you want to activate the instant meeting feature and Host access to Zoom meetings, you need to authorize the verified Mago app on the Zoom Marketplace.

{% hint style="success" %}
Note: It is not required for **guest access** to Zoom meetings.
{% endhint %}

The app can be reached at the following link:

{% embed url="<https://marketplace.zoom.us/apps/b_8zLZb8QQa-_ray1PWAKg>" %}

## Required features and scopes

| Mago – Feature                                                                                     | Required Scope Permissions                                        |
| -------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| Search for directory users to invite when starting an instant Zoom meeting from the room calendar. | <p>View user contacts</p><p><code>contact:read</code></p>         |
| Start or end an instant Zoom meeting directly from the room calendar.                              | <p>View and manage meetings</p><p><code>meetings:write</code></p> |
| View the room user's email and revoke a token when requested by the user (account logout).         | <p>View user information</p><p><code>user:read</code></p>         |
| Receive a ZAK token when requested by the user.                                                    | <p>View user's ZAK token</p><p><code>user\_zak:read</code></p>    |

{% hint style="info" %}
Before integrating your account in Mago Room it is required to approve the install of the Mago app in the Zoom marketplace, as explained below:
{% endhint %}

1. Visit [**https://marketplace.zoom.us**](https://marketplace.zoom.us) and sign in with the Zoom account used by the room.
2. Search for the "Mago" app and **Approve the install of the app** by activating the corresponding switch.

{% hint style="warning" %}
For Mago **4.1 and above**, please refer to the "Mago Room" app:

<https://marketplace.zoom.us/apps/b_8zLZb8QQa-_ray1PWAKg>

For Mago **4.0 and below (formerly "Valarea")**, please refer to the "Valarea Room 4" app:

<https://marketplace.zoom.us/apps/rYVYMDRKTXm0jc-O1_na7w>
{% endhint %}

<figure><img src="/files/l7zae1U99pXp9F2HEBBz" alt=""><figcaption></figcaption></figure>

### How to disconnect a Zoom account from Mago Room (Token revocation)&#x20;

If you want to disconnect a Zoom account from Mago Room, please follow these steps:

* Open the Mago Room Wizard or Settings
* Navigate to the "Instant Meeting" step or section
* Locate the Zoom option and press "Disconnect"

{% hint style="info" %}
Mago Room will automatically revoke the authorization token. In order to enable Zoom instant meetings again, you will have to connect to your account and complete the OAuth process again.
{% endhint %}

### How to deauthorize the app

If you want to deauthorize the Mago or Mago Room app, please follow these steps:

* Visit [**https://marketplace.zoom.us**](https://marketplace.zoom.us) and sign in with the Zoom account used by the room.
* Deauthorize by turning the switch off (see image)

{% hint style="info" %}
You can also manage authorization for single users under the "Manage" section
{% endhint %}


# Webex

## Verified Mago App for Webex App Hub

If you want to turn on the instant meeting feature and host access to Webex meetings, you must authorize the verified Mago app on the Webex Hub app. You can authorize and add the app by logging in with your room account in the Mago Settings, Instant Meetings section (see dedicated chapter).

{% hint style="success" %}
Note: It is not required for **guest access** to Webex meetings.
{% endhint %}

## Required features and scopes

| Mago – Feature                                                                                                                    | Required Scope Permissions                                                                                                                                                                                                                |
| --------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>Start or end an instant Webex meeting directly from the room calendar.<br>Log in as a Guest via the external meeting link.</p> | <p><code>meeting:schedules\_read</code><br><code>meeting:schedules\_write</code><br><code>meeting:preferences\_read</code></p>                                                                                                            |
| View meeting controls                                                                                                             | `meeting:controls_read`                                                                                                                                                                                                                   |
| View meeting participants                                                                                                         | `meeting:participants_read`                                                                                                                                                                                                               |
| Use the built-in JavaScript Web Client (official)                                                                                 | <p><code>spark:all spark:calls\_read</code><br><code>spark:devices\_read</code><br><code>spark:devices\_write</code><br><code>spark:organizations\_read</code><br><code>spark:places\_read</code><br><code>analytics:read\_all</code></p> |


# Apple

## Verified Mago App for Apple Sign in

When using Mago iOS / MacOS app with access via Apple account, simply log in via "Sign in with Apple" and authorize the reading of the full name and email address (in plain text or via Apple relay).

## Required features and scopes

| Mago mobile app – Feature                                  | Required Scope Permissions |
| ---------------------------------------------------------- | -------------------------- |
| Display your name and email, which you can use to register | `.fullName.email`          |


# Dropbox

## Verified Mago app for Dropbox

In the Mago digital Whiteboard, both on Mago and on Mago mobile app for iOS / Android, it is possible to import files as objects and/or save PDF whiteboard recaps on a Dropbox account. Simply log in with any account and authorize the necessary scopes.

## Required features and scopes

| Mago Pro / Mago app – Feature                                                                                          | Required Scope Permissions                                                      |
| ---------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| View account name                                                                                                      | `account_info.read`                                                             |
| <p>Browse files, view, and import files to the whiteboard<br>Save PDF recaps of the whiteboard to a desired folder</p> | <p><code>files.metadata.write</code></p><p><code>files.content.write</code></p> |
|                                                                                                                        |                                                                                 |


# Calendar

## Supported providers

Mago supports the following room calendar providers:

* Microsoft 365
* Google Workspace
* Microsoft Exchange (On Premises)
  * Exchange 2016 (default)
  * Exchange 2015, 2015 10 05
  * Exchange 2013, 2013 SP1
  * Exchange 2010, 2010 SP1, 2010 SP2
  * Exchange 2007 SP1


# Microsoft 365 calendar


# Setup a room resource

## 1. Login to Microsoft 365 Admin Center

Go to <https://admin.microsoft.com> and login with an administrator account.

![Microsoft Admin Center Login](/files/-MXhnIwm8guNu9Q2FGR4)

## 2. Access **Rooms** & Equipment and Add a New Resource

1. Choose "Rooms & equipment" in the "Resources" menu from the left sidebar
2. Select "Add resource"

![Rooms & equipment page](/files/-MXhoqAhhf_4WJe0VFkm)

## 3. Add a New Resource

1. Enter the required resource's Name
2. Enter the required resource's Email
3. Enter optional fields, such as Capacity, Location and Phone number
4. Press "Save"

![Add a new resource](/files/-MXhpOCRLl6tQk9zYghY)

## 4. Check Booking Options

After the new resource has been created, press "Edit booking options"

![Resource created](/files/-MXhpfMt1mHzoSFSwegX)

Check that the "Auto accept meeting requests" option is selected. This will ensure the proper functioning of the Room resource

![Auto accept meeting requests](/files/-MXhq2OjSROnDYC1l1IM)

## 5. Set a Room Password

From the left sidebar:

1. Select Users > Active Users&#x20;
2. Find the newly created room resource and press the key icon ("Reset password")

![Reset password (1)](/files/-MXhqhIlW6vPAQxpImP8)

1. Set a room password
2. Check that, "Require this user to change their password when they first sign in" option is not selected
3. Press "Reset password"

![Reset password (2)](/files/-MXhr3ZkPxciBwmXjszG)

When the password has been reset, you can choose to close or to email the sign-in info to your email. In this case:

1. Check the "Email the sign-in info to me" option
2. Add your email or multiple emails (divided by ";")
3. Press "Send email and close"

![Send sign-in details](/files/-MXhrd798lbCu1Dn7kwT)


# Configure a room resource

This page will help you fix event titles and accept resource requests automatically for room resource calendars.

## How to enable the display of meeting titles

By default events scheduled on the meeting room calendars in Exchange and Microsoft 365 will show the name of the organizer instead of the actual event title, for privacy reasons (see Microsoft KB here <https://docs.microsoft.com/en-us/exchange/troubleshoot/client-connectivity/calendar-shows-organizer-name>). To make the most of Mago Room, you will want more descriptive titles. This is easily fixed through some administrative configuration via Powershell.

{% hint style="warning" %}
**You'll need to create your room resources before you can apply the fix. For newly created room resources, you will need to repeat this process again.**
{% endhint %}

{% stepper %}
{% step %}

#### Run the Azure Powershell or Azure Cloud Shell as an administrator.

{% endstep %}

{% step %}

#### Sign in with Modern Authentication

Enter the following command and follow the instructions:

```
Connect-ExchangeOnline
```

{% endstep %}

{% step %}

### Run the following command

Lastly, run this command, replacing `{RESOURCEMAILBOX}` with the room resource UPN or email (e.g. <room@company.com>)

* For Exchange Server 2016, Exchange Server 2013 or Exchange Server 2010

`Set-CalendarProcessing -Identity {RESOURCEMAILBOX} -DeleteSubject $False -AddOrganizerToSubject $False -DeleteComments $false -RemovePrivateProperty $false`

* For Exchange Server 2007

`Set-MailboxCalendarSettings -Identity {RESOURCEMAILBOX} -AutomateProcessing AutoAccept -AddOrganizerToSubject $False -DeleteSubject $False -DeleteComments $false -RemovePrivateProperty $false`

This will allow Mago to correctly retrieve an event's title and description for every room resource. Events scheduled on the room calendar will now show up in with the correct name. Private events will remain flagged as private.
{% endstep %}
{% endstepper %}

## How to enable meeting invitations from people outside your organization (optional)

To enable the receipt of invitations to room resources from users in domains not belonging to your tenant, simply set the "`-ProcessExternalMeetingMessages`" parameter to `$true` for the room resource, using PowerShell. Example PowerShell command, replacing `{RESOURCEMAILBOX}` with the room resource UPN or email (e.g. <room@company.com>):

`Set-CalendarProcessing -Identity {RESOURCEMAILBOX} -ProcessExternalMeetingMessages $true`

Refer to this guide for more information:

{% embed url="<https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/set-calendarprocessing?view=exchange-ps>" %}

## How to disable chat history for meeting room resources in Microsoft Teams for security and privacy reasons

Follow this guide to create a messaging policy and apply it to the room resources used within Mago.

{% embed url="<https://learn.microsoft.com/en-us/answers/questions/1320897/i-want-to-disable-chatting-function-in-microsoft-t>" %}


# Google Workspace calendar

### Create and configure a room resource

To create buildings and rooms in your Google Workspace admin account, follow the official guide:

{% embed url="<https://support.google.com/a/answer/1033925?hl=en>" %}

After you created the resource, see the guide on how to share its calendar with the service user for meeting rooms:

{% embed url="<https://support.google.com/a/answer/1034381?hl=en>" %}

### Choose the account pattern based on how the room will be used

Mago needs a Google account (with permission on the room's resource calendar) to read events, book the resource, and, if enabled, host instant meetings (Google Meet calls started directly from the room).

Two account patterns are supported. The right one depends on whether **Instant meeting** is enabled on the room.

#### Pattern A, calendar only: single shared service account

If the room will only display and join scheduled meetings, and **no instant meetings** will be started from the room, a single shared account (e.g. `rooms@mydomain.com`) with access to the resource calendars of all rooms is sufficient.

In the Mago calendar settings, log in once with this account and select the correct resource calendar for each room.

This is the simplest pattern to deploy and maintain when instant meetings are not in scope.

#### Pattern B, with Instant meeting: dedicated account per room

When the **Instant meeting** feature is enabled for Google Meet, the account signed in on the room becomes the **host** of any instant Meet call started from that room. For this reason, each room must have its own dedicated Google account (for example `meetingroom-london@mydomain.com`), with permission on that specific resource calendar.

{% hint style="warning" %}
Sharing a single account across multiple rooms in this scenario is not supported: the same Google user cannot cleanly host two concurrent Meet calls, and the shared identity would appear as participant in every meeting started from any room at the same time.
{% endhint %}

A dedicated account per room avoids this and also gives each room its own host identity in Meet: the display name of the per-room Google account is what other participants see as the meeting host.

#### What users see in both patterns

Three distinct names are involved, each coming from a different source:

| Where it appears                                              | Where it comes from                                       |
| ------------------------------------------------------------- | --------------------------------------------------------- |
| Room display (screen of the room)                             | **Device name**, configured in Mago from the Admin Center |
| Meeting invitations and booking UX (when users book the room) | **Resource name**, from Google Workspace                  |
| Host / participant identity inside Google Meet                | **Display name of the signed-in Google account**          |

These three names are independent and can be set separately. Admins typically align them for consistency, but there is no technical requirement to do so.

The account pattern (A or B) only affects the third one, the **host identity of instant meetings**: in Pattern A the shared service account is the host, in Pattern B the per-room dedicated account is the host.

#### Summary

| Scenario on the room                                        | Recommended account pattern                                          |
| ----------------------------------------------------------- | -------------------------------------------------------------------- |
| Calendar only (display and join scheduled meetings)         | Single shared service account with access to all resource calendars  |
| Instant meeting enabled (Google Meet started from the room) | Dedicated account per room, with permission on the resource calendar |


# Microsoft Exchange calendar (On Premises)

## How to create a room resource

Follow the official guide at the following link, to create a room resource:

{% embed url="<https://learn.microsoft.com/en-us/exchange/recipients/room-mailboxes?view=exchserver-2016>" %}


# Video Conferencing


# Supported providers

Mago supports joining meetings from many videoconferencing providers. This is possible through official SDK integrations as well as through the providers’ web or desktop clients.

{% hint style="info" %}
Mago does not include any desktop clients from third-party video conferencing providers. If you prefer to use a desktop client instead of the web client, your IT administrator is responsible for installing it.
{% endhint %}

{% hint style="warning" %}
For video conferencing providers that are already integrated into Mago through an official SDK, such as Zoom, there is no need to install the desktop client. Installing the desktop client can conflict with the SDK and may cause unexpected issues.
{% endhint %}

By integrating with the official clients, whether web, desktop or SDK, Mago provides all available features for supported video conferencing providers, always kept up to date. The table below summarizes the supported providers and the available options to join or host meetings.

{% hint style="success" %}
**Guest join** is free and **does not require any user or room license**.

Starting a meeting as a **host (instant meeting)**, however, **requires a user or room license** for the specific video conferencing system. See the [Licensing requirements](/mago/requirements/video-conferencing/licensing-requirements) page for more details.
{% endhint %}

|                       | <p><strong>Guest join</strong></p><p><strong>from calendar or direct link</strong></p> | <p><strong>Guest join</strong></p><p><strong>with meeting ID and password</strong></p> | **Start a meeting as host (instant meeting)** | **Client integration and support** |
| --------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | --------------------------------------------- | ---------------------------------- |
| **Mago Meet**         | Yes                                                                                    | Yes                                                                                    | Yes                                           | Web Client                         |
| **Microsoft Teams**   | Yes                                                                                    | Yes                                                                                    | Yes (requires license)                        | Azure Communication Services (\*)  |
| **Zoom**              | Yes (requires authenticated Zoom user)                                                 | Yes (requires authenticated Zoom user)                                                 | Yes (requires license)                        | SDK (Windows or Web)               |
| **Cisco Webex**       | Yes                                                                                    | Yes                                                                                    | Yes (requires license)                        | Web SDK                            |
| **Google Meet**       | Yes                                                                                    | Yes                                                                                    | Yes (requires license)                        | Web Client                         |
| **GoTo**              | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Lifesize**          | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **BlueJeans**         | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **GoToMeeting**       | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Join.me**           | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Ring Central**      | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Dialpad**           | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Zoho Meetings**     | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Whereby**           | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **InFocus ConX**      | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **ClearOne**          | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Collaborate Space** | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Skype**             | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **Cisco Jabber**      | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |
| **BigBlueButton**     | Yes                                                                                    | No                                                                                     | No                                            | Web Client                         |

(\*) Some Teams features are not available, either to start them or to see them when another participant uses them. This includes Microsoft Whiteboard, PowerPoint Live, live transcription and captions. If a participant needs to present slides to the room, sharing the screen (or the PowerPoint window) works normally and supports any content.


# Licensing requirements

## Joining meetings as a guest

With Mago, joining meetings as a guest with the supported video conferencing providers is free and does not require any user or room license.

{% hint style="info" %}
Beginning March 2, 2026, joining Zoom meetings from Mago will require a connected and authorized Zoom user account. This applies to all join methods, including Meeting ID and passcode, as well as starting new meetings. Make sure a Zoom user is connected in your organization settings to ensure uninterrupted access.
{% endhint %}

## Joining meetings as a host

With Mago, starting or joining a meeting as a host requires a license assigned to the account for the specific video conferencing provider.

<table><thead><tr><th width="169.296875">Provider</th><th>Supported account types</th><th>Supported licenses</th></tr></thead><tbody><tr><td><strong>Mago Meet</strong></td><td>Mago room<br>Mago app user</td><td>Mago room Pro license<br>Mago app user Pro license</td></tr><tr><td><strong>Microsoft Teams</strong></td><td>Microsoft Azure Communication Services: anonymous guest join or authenticated (licensed) user</td><td><p>Microsoft Teams Essentials</p><p>Microsoft Teams Enterprise</p><p>Microsoft 365 Business Basic Microsoft 365 Business Standard</p><p>Microsoft 365 Business Premium</p></td></tr><tr><td><strong>Zoom</strong></td><td>Standard user account (not a room account)</td><td><p>Basic (with limitations)</p><p>Pro<br>Business<br>Business Plus</p><p>Enterprise</p><p>Zoom Rooms</p></td></tr><tr><td><strong>Cisco Webex</strong></td><td>Standard user</td><td><p>Free (with limitations)</p><p>Starter<br>Business<br>Enterprise</p></td></tr><tr><td><strong>Google Meet</strong></td><td>Standard user</td><td><p>Free<br>Business Starter</p><p>Business Standard</p><p>Business Plus</p><p>Enterprise</p></td></tr></tbody></table>


# Authenticated Calls

This article explains the requirements needed to enable Authenticated Calls in Mago, allowing meetings to be joined using an authenticated user or room account instead of as a guest.

## Authenticated Calls in Mago

Authenticated Calls allow Mago to join video conferencing meetings using a verified identity instead of joining as a generic guest participant.

Depending on the platform configuration, meetings can be joined using:

• an authenticated user account\
• an authenticated account associated with the meeting room

This allows the meeting system to appear as a recognized participant within the conferencing platform.

Authentication is supported across multiple conferencing platforms, including Microsoft Teams, Google Meet, Zoom, and Webex. The available authentication methods may vary depending on the platform.

## Benefits of Authenticated Calls

### Recognized participant identity

When joining a meeting with authentication, the participant appears with the correct user or room name instead of a generic device name.

### Reduced lobby or waiting room interruptions

Authenticated participants from the same organization can often join meetings directly without waiting for manual approval, depending on the platform’s meeting policies.

### Better integration with conferencing platforms

Authentication allows the conferencing platform to treat the participant as a trusted identity, improving compatibility with meeting features and organizational policies.

### Flexible deployment options

Authenticated calls can be configured using individual user accounts or dedicated accounts associated with meeting rooms, depending on the room setup and conferencing platform capabilities.

## Authentication modes supported by Mago

### Authenticated user join

In this mode, a user signs in with their conferencing account on their personal device, such as a smartphone or laptop.

Once authenticated, the user connects their device to the meeting room system. This can be done, for example, by scanning a QR code displayed on the room screen.

The authentication is then securely transmitted to the room system, allowing the meeting to be joined using the user’s identity.

This model is commonly used in:

• BYOM environments\
• shared meeting spaces\
• scenarios where users temporarily authenticate the room for the duration of a meeting

In this configuration, the meeting participant appears as the authenticated user.

### Authenticated room join

In some deployments, the meeting room itself can authenticate using a dedicated account associated with the room.

In this configuration, the meeting system joins meetings using the identity assigned to the room, allowing scheduled meetings to be joined with a consistent room identity.

This approach is commonly used in permanent meeting spaces where the room regularly joins meetings as a recognized participant.

{% hint style="info" %}
Note that support for room resource authentication depends on the conferencing platform.
{% endhint %}


# Authenticated Calls with Microsoft Teams

## Prerequisites

{% hint style="warning" %}
**An active Azure subscription is required.**\
Registering the Azure Communication Services (ACS) service principal in your tenant only works if the tenant has an **active Azure subscription** linked. If you don't have one, create/activate a subscription in the [Azure portal](https://portal.azure.com/) before proceeding. Otherwise the service principal creation will fail.

If your tenant doesn't have one, follow the official Microsoft guide to create it: <https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/create-subscription>
{% endhint %}

You will also need:

* **Global Administrator** (or Privileged Role Administrator) rights on the Microsoft 365 tenant
* Your **Tenant ID** (Entra ID → Overview)
* PowerShell 5.1 or PowerShell 7+

## Requirements

To enable authenticated calls with Microsoft Teams, the following prerequisites must be met.

{% stepper %}
{% step %}

### Azure Communication Services service principal

Microsoft Teams interoperability for third party applications relies on **Azure Communication Services (ACS)**.

To allow authenticated calls, the Microsoft tenant must contain the **Azure Communication Services service principal**. This component allows applications to authenticate Teams identities and join meetings through the Microsoft communication APIs.

#### 🔍︎ Check if the Azure Communication Services service principal is installed

An administrator can verify whether the ACS service principal already exists in the tenant.

1. Sign in to the [Azure portal](https://portal.azure.com/)
2. Go to Microsoft Entra ID > Enterprise Applications > **All Applications**

<figure><img src="/files/fbkeFIefBSuxKz3Zripn" alt=""><figcaption></figcaption></figure>

3. Clear any filters that may be applied

<figure><img src="/files/VLNFF0vvYjPPdpthGfbb" alt=""><figcaption></figcaption></figure>

4. In the search field, search for "Azure Communication Services"

<figure><img src="/files/RAcDIUJVtlYlv9cHRKJf" alt=""><figcaption></figcaption></figure>

If the application appears in the list, the **ACS service principal is already installed** and no further action is required.

If the application does not appear in the list, follow the next steps to **proceed with the installation**.

#### ✅ Installing the Azure Communication Services service principal

If the ACS service principal is not present in the tenant, it must be created by an administrator.

#### Step 1. Open PowerShell

Open the Azure Portal and start a PowerShell session with administrative privileges.

<figure><img src="/files/01GmaLz0Qj3KZrYX6fVT" alt=""><figcaption></figcaption></figure>

#### Step 2. Install the Microsoft Graph module (if not already installed)

```
Install-Module Microsoft.Graph -Scope CurrentUser
```

#### Step 3. Connect to your tenant

Replace `TENANT_ID` with your tenant ID. Find your tenant ID [here](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/TenantOverview.ReactView).

```
Connect-MgGraph -TenantId "TENANT_ID" -Scopes "Application.ReadWrite.All"
```

A Microsoft authentication URL or window will appear where the administrator must sign in.

#### Step 4. Create the Azure Communication Services service principal

Run the following command:

```
New-AzureADServicePrincipal -AppId "1fd5118e-2576-4263-8130-9503064c837a"
```

This registers the **Azure Communication Services service principal** in the tenant and enables authenticated Teams calls for supported applications.

#### (Optional) Using Azure CLI instead

If you prefer not to install PowerShell modules, you can achieve the same with the Azure CLI:

```
az login --tenant TENANT_ID
az ad sp create --id 1fd5118e-2576-4263-8130-9503064c837a
```

{% endstep %}

{% step %}

### Microsoft Teams license

An account with an active Microsoft Teams license is required in order to authenticate and join Teams meetings. The specific license type depends on the organization’s Microsoft 365 subscription.
{% endstep %}
{% endstepper %}

## Setup scenarios

<figure><img src="/files/7f6Gxi0FeyXZodocxW9j" alt=""><figcaption></figcaption></figure>

## When authentication is not configured

If authentication is not enabled, Mago can still join meetings as a guest participant.

In this scenario:

• the system may enter the meeting lobby\
• the participant appears as a generic device name\
• some meeting features may behave differently depending on the host organization’s policies


# Network requirements

## Third-party Video Conferencing providers

Generally, Mago has the same network requirements as any PC running video conferencing applications like Microsoft Teams, Zoom, Cisco Webex, Google Meet. Specific to Mago, the categories listed as "required" for the video conferencing systems must be open on your firewall. Mago also needs access to Windows Update and Microsoft Intune (if you use Microsoft Intune to manage your devices). For the full list of IPs and URLs required for Mago Room, see:

* **Microsoft Teams** [Office 365 URLs and IP address range](https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide#skype-for-business-online-and-microsoft-teams)
* **Zoom** <https://support.zoom.us/hc/en-us/articles/201362683-Zoom-network-firewall-or-proxy-server-settings>
* **Google Meet** <https://support.google.com/a/answer/1279090?hl=en>
* **Cisco Webex** <https://help.webex.com/en-us/article/WBX000028782/Network-Requirements-for-Webex-Services>
* **Windows Update** [Configure WSUS](https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus#211-connection-from-the-wsus-server-to-the-internet)
* **Microsoft Intune** [Network Endpoints for Microsoft Intune](https://docs.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints)

## Mago Meet

Mago Meet uses WebRTC. WebRTC requires a small set of standard signaling and media ports. These ports must be accessible for reliable video conferencing.

Mago Meet works via meet.mago.io or an on-premises hosted domain, and is supported on all modern browsers. It also works with the Mago app for iOS and Android.

## Required ports

<table><thead><tr><th width="109.31640625">Port</th><th width="112.30078125">Type</th><th width="126.7578125">Direction</th><th>Service</th></tr></thead><tbody><tr><td>80</td><td>TCP</td><td>Outbound</td><td>HTTP service for initial access and redirection</td></tr><tr><td>443</td><td>TCP</td><td>Outbound</td><td>HTTPS service for signaling, authentication and coordination</td></tr><tr><td>3478</td><td>UDP</td><td>Both</td><td>STUN server used for NAT traversal and ICE candidate gathering</td></tr><tr><td>5349</td><td>TCP</td><td>Both</td><td>TURN fallback (media relay) for environments where UDP is restricted</td></tr><tr><td>10000</td><td>UDP</td><td>Both</td><td>Encrypted A/V media transport (SRTP via WebRTC)</td></tr></tbody></table>

## Technical notes

**80/TCP and 443/TCP**\
Used for accessing the Mago Link webpage, exchanging signaling messages and establishing secure WebRTC sessions. These ports must be reachable by the sender device.

**3478/UDP (STUN)**\
Allows WebRTC clients to discover their public IP and negotiate NAT traversal paths. This improves connectivity on restrictive enterprise networks.

**5349/TCP (TURN over TLS, fallback media transport)**\
Used only when UDP media is blocked by network firewalls or when NAT traversal is not possible.\
If UDP is unavailable, media traffic automatically switches to 5349/TCP.

**10000/UDP (media transport)**\
Primary port used for sending audio and video over WebRTC using encrypted SRTP.\
This port must be open in both directions between the sender and the Mago device to achieve optimal low-latency performance.

When UDP 10000 is blocked, Mago Meet will fall back to TCP 5349, which works but with reduced performance.


# Presentation


# Wireless Screen Sharing

## Overview

Mago supports multiple screen sharing technologies to provide the best possible experience across all devices, networks and meeting scenarios. Each protocol has different capabilities and network requirements, allowing Mago to work reliably in modern enterprise environments as well as guest networks.

Mago offers the following screen sharing options:

**Mago Link**\
A universal browser based screen sharing method that works on any modern device without installing apps. It uses secure WebRTC communication and works even in networks where traditional casting methods are restricted.

See requirements here: [Mago Link](/mago/requirements/presentation/wireless-screen-sharing/mago-link)

Each protocol has its own strengths and ideal use cases. Mago automatically provides the best available option to ensure reliable and seamless screen sharing in meeting rooms, classrooms and collaborative spaces.

**Miracast (Currently available for Mago on Windows only)**\
A wireless display technology built into Windows and many hardware devices. It connects either through a direct peer to peer link or through the enterprise network using infrastructure mode.

See requirements here: [Miracast](/mago/requirements/presentation/wireless-screen-sharing/miracast)

**AirPlay (Currently available for Mago on Windows only)**\
Apple’s native wireless streaming protocol for macOS, iOS and iPadOS. It uses Bonjour discovery and provides high quality audio and video mirroring.

See requirements here: [AirPlay](/mago/requirements/presentation/wireless-screen-sharing/airplay)

**Google Cast (Currently available for Mago on Windows only)**\
A discovery based screen sharing technology commonly used on Android, ChromeOS and Chrome browser. It uses a combination of multicast and unicast communication to connect to receivers.

See requirements here: [Google Cast](/mago/requirements/presentation/wireless-screen-sharing/google-cast)

## Connectivity Diagram

<figure><img src="/files/LIZjBw27El4tkjgzSNdg" alt=""><figcaption></figcaption></figure>


# Mago Link

For laptop screen sharing (via magolink.com or on-prem hosted domain) or mobile screen sharing (Mago app for iOS / Android).

## Overview

Mago Link uses the Mago Cast protocol to establish a secure WebRTC session between the sender device and the Mago on Windows / on Android device. WebRTC requires a small set of standard signaling and media ports. These ports must be accessible for reliable screen sharing.

Mago Link works via magolink.com or an on-premises hosted domain, and is supported on all modern browsers. It also powers mobile screen sharing through the Mago app for iOS and Android.

## Required ports

<table><thead><tr><th width="109.31640625">Port</th><th width="112.30078125">Type</th><th width="126.7578125">Direction</th><th>Service</th></tr></thead><tbody><tr><td>80</td><td>TCP</td><td>Outbound</td><td>HTTP service for initial access and redirection</td></tr><tr><td>443</td><td>TCP</td><td>Outbound</td><td>HTTPS service for signaling, authentication and coordination</td></tr><tr><td>3478</td><td>UDP</td><td>Both</td><td>STUN server used for NAT traversal and ICE candidate gathering</td></tr><tr><td>5349</td><td>TCP</td><td>Both</td><td>TURN fallback (media relay) for environments where UDP is restricted</td></tr><tr><td>10000</td><td>UDP</td><td>Both</td><td>Encrypted A/V media transport (SRTP via WebRTC)</td></tr></tbody></table>

## Technical notes

**80/TCP and 443/TCP**\
Used for accessing the Mago Link webpage, exchanging signaling messages and establishing secure WebRTC sessions. These ports must be reachable by the sender device.

**3478/UDP (STUN)**\
Allows WebRTC clients to discover their public IP and negotiate NAT traversal paths. This improves connectivity on restrictive enterprise networks.

**5349/TCP (TURN over TLS, fallback media transport)**\
Used only when UDP media is blocked by network firewalls or when NAT traversal is not possible.\
If UDP is unavailable, media traffic automatically switches to 5349/TCP.

**10000/UDP (media transport)**\
Primary port used for sending audio and video over WebRTC using encrypted SRTP.\
This port must be open in both directions between the sender and the Mago device to achieve optimal low-latency performance.

When UDP 10000 is blocked, Mago Link will fall back to TCP 5349, which works but with reduced performance.

## Key advantages

Mago Link does not require:

* mDNS
* Bonjour
* SSDP
* Multicast
* WiFi Direct
* AP isolation disabled

This makes it ideal for restrictive enterprise networks and guest WiFi environments.


# Miracast

For screen sharing via Windows or Android devices.

{% hint style="warning" %}
This feature is currently available only for **Mago on Windows**.
{% endhint %}

## Overview

Miracast is a wireless display technology that works in two different modes. Mago supports both modes automatically. The mode used depends entirely on how the network is configured and how the user device is connected.

### Miracast over WiFi Direct

This is the original Miracast technology. The connection forms a direct peer to peer link between the user device and Mago. It does not use the corporate WiFi network, does not rely on access points and does not require any VLAN or firewall configuration. Miracast over WiFi Direct is especially useful when the user device is connected on a different network or not connected to any WiFi network at all.

### Miracast over Infrastructure

This mode is designed for enterprise environments. Discovery still uses WiFi, but the actual media traffic flows over the existing network infrastructure (WiFi or Ethernet) instead of a direct peer connection. This mode uses the corporate network, DNS resolution, VLAN routing and specific ports that must be opened on the firewall. Miracast over infrastructure is also known as MS MICE.

### How Windows chooses the Miracast mode

Windows prefers Miracast over infrastructure when the sending device and the Mago device are on the same enterprise network and the required ports and multicast traffic are allowed.\
If these conditions are not met, **Windows automatically falls back to Miracast over WiFi Direct**.\
If both modes fail, Miracast will not connect.

In summary:

* When the network supports MS MICE, Miracast over infrastructure will be used.
* If the corporate network blocks the requirements for MS MICE, Miracast over WiFi Direct will be used automatically.
* If WiFi Direct is disabled by policies or drivers, Miracast may not work in any mode.

## Common requirements for all Miracast modes

{% stepper %}
{% step %}

### Hardware and driver support

Miracast requires compatible hardware on both the sending device and the Mago device.\
This includes the following.

**Graphics adapter**

* Windows Display Driver Model WDDM 1.3 or newer

To check WDDM:

1. Press Windows key and R, type `dxdiag` and press Enter.
2. Let the DirectX Diagnostic Tool finish.
3. Select Save All Information.
4. Open the saved text file and search for "WDDM".

**WiFi adapter**

* Supports Miracast
* Supports WiFi Direct
* Uses a driver with NDIS 6.3 or newer

To check Miracast support:

1. Open a Command Prompt window.
2. Type `netsh wlan show driver` and press Enter.
3. Check the Miracast line in the output.
   {% endstep %}

{% step %}

### WLAN AutoConfig service is running

Miracast requires the WLAN AutoConfig service (wlansvc) to be operating.\
If this service is disabled, WiFi Direct and MS MICE cannot start.

To enable the service:

1. Press Windows key and R, type `services.msc` and press Enter.
2. Find WLAN AutoConfig in the list.
3. Right click, select Properties.
4. Select Start and set the startup type to Automatic.
5. Restart the computer.
   {% endstep %}

{% step %}

### Windows Firewall configuration

Windows Firewall must allow the Windows User Mode Driver Framework Host Process, which handles Miracast communication.

Allow the following:

`C:\Windows\System32\WUDFHost.exe`

Inbound and outbound traffic, TCP and UDP on all ports. If this process is blocked by a local or third party firewall, Miracast pairing or streaming may fail.
{% endstep %}

{% step %}

### Group Policy permissions

Local or domain security policies must allow the creation and use of WiFi Direct. If blocked, Miracast will not work in either mode.

Check the following policy:

Computer Configuration > Windows Settings > Security Settings > Wireless Network (IEEE 802.11) Policies

Within Network Permissions:

1. Allow everyone to create all user profiles
2. Uncheck any setting that disables WiFi Direct groups

{% hint style="info" %}
These policies must allow Windows to create a Microsoft WiFi Direct Virtual Adapter and a DIRECT-XXXXXX temporary network.
{% endhint %}
{% endstep %}

{% step %}

### Drivers are up to date

Miracast is sensitive to driver compatibility. Keep the following updated:

* Chipset drivers
* Graphics adapter drivers
* WiFi adapter drivers

Outdated drivers are one of the most common causes of unstable or failing Miracast sessions.
{% endstep %}
{% endstepper %}

## Miracast over Infrastructure (MS MICE) mode specific requirements

Miracast over infrastructure transports the media stream over the existing network, usually enterprise WiFi or Ethernet. Discovery still uses WiFi but the session is routed through the network.

{% stepper %}
{% step %}

### Network reachability and VLAN routing

The user device and Mago must be reachable across the network.

Requirements:

* Devices in the same enterprise network or routed VLAN
* DNS records for Mago resolvable by the client
* Firewall rules allowing bidirectional traffic
  {% endstep %}

{% step %}

### Required firewall and network ports

The following ports must be allowed in both directions between the client device and Mago:

* UDP 5353 for mDNS discovery
* TCP / UDP 7236 for RTSP Control Port
* TCP 7250 for Miracast Sink
* UDP 32768-65536 for Ephemeral ports for Return traffic

These ports enable session negotiation, discovery and continuous streaming.

| Port          | Type      | Direction | Service                            |
| ------------- | --------- | --------- | ---------------------------------- |
| 5353          | UDP       | Both      | mDNS Discovery                     |
| 7236          | TCP / UDP | Both      | RTSP Control Port                  |
| 7250          | TCP       | Both      | Miracast Sink                      |
| 32768-65536   | UDP       | Both      | Ephemeral ports for Return traffic |
| {% endstep %} |           |           |                                    |

{% step %}

### AP isolation disabled

Since Miracast over infrastructure uses the access point and VLANs, the AP must allow client to client communication. AP isolation or client isolation must be disabled on the SSID used by the sender. If enabled, Miracast over the network cannot function.
{% endstep %}

{% step %}

### Multicast and broadcast traffic allowed

Miracast over infrastructure relies on mDNS discovery. Ensure that the network does not block the following:

* UDP 5353
* Multicast forwarding between VLANs if required
* IGMP snooping causing excessive filtering

If multicast discovery is blocked, MS MICE cannot initialize.
{% endstep %}
{% endstepper %}

## Miracast over WiFi Direct mode specific requirements

Miracast over WiFi Direct creates a dedicated peer to peer wireless link between the user device and Mago. It is not routed through the corporate network.

{% stepper %}
{% step %}

### 2.4 GHz wireless availability

Discovery and pairing always use the 2.4 GHz band on channels 1, 6 or 11. Even if the sending device is connected to 5 GHz or not connected to any WiFi network, pairing begins on 2.4 GHz. Ensure that the 2.4 GHz radio is enabled in the environment. If 2.4 GHz is disabled, Miracast over WiFi Direct cannot initialize.
{% endstep %}

{% step %}

### WiFi Direct Virtual Adapter must be created

During pairing, Windows must create the following:

* Microsoft WiFi Direct Virtual Adapter
* A temporary wireless network named DIRECT-XXXXXX

If these do not appear in Network Connections during an attempted Miracast session, Group Policies or drivers are blocking WiFi Direct.
{% endstep %}
{% endstepper %}

## Quick summary

1. **Confirm Miracast support**\
   • Windows 10 or later\
   • Graphics adapter with WDDM 1.3 or newer\
   • WiFi adapter supporting Miracast, WiFi Direct and NDIS 6.3 or newer\
   Check using `netsh wlan show driver`.
2. **Enable required Windows services**\
   • WLAN AutoConfig service must be running\
   • Group Policies must allow WiFi Direct and creation of DIRECT-XXXXXX networks
3. **Allow Miracast through Windows Firewall**\
   • Allow C:\Windows\System32\WUDFHost.exe for inbound and outbound TCP and UDP
4. **Update drivers**\
   • Update chipset, graphics and WiFi drivers to the latest versions
5. **If using Miracast over Infrastructure (MS MICE)**\
   • User device and Mago must be reachable across VLANs\
   • Required ports open\
   • AP isolation must be disabled\
   • Multicast discovery (mDNS) must be allowed
6. **If using Miracast over WiFi Direct**\
   • 2.4 GHz WiFi must be enabled\
   • AP isolation does not affect this mode\
   • WiFi Direct Virtual Adapter and DIRECT-XXXXXX network must appear during pairing

## Troubleshooting flowchart

{% stepper %}
{% step %}

### Check Miracast hardware support

1. Run `netsh wlan show driver`
2. Check WDDM version with dxdiag

{% hint style="danger" %}
If Miracast not supported → **Stop**. **Update drivers or hardware required.**
{% endhint %}

{% hint style="success" %}
If supported → **Continue**
{% endhint %}
{% endstep %}

{% step %}

### Check WLAN AutoConfig service

1. Ensure **wlansvc** is running

{% hint style="warning" %}
If stopped → **Enable and restart PC**
{% endhint %}

{% hint style="success" %}
If running → **Continue**
{% endhint %}
{% endstep %}

{% step %}

### Attempt Miracast connection

Do DIRECT-XXXXXX network and WiFi Direct Virtual Adapter appear?

{% hint style="warning" %}
No → Group Policy or drivers are blocking WiFi Direct. **Fix GPO and update drivers**.
{% endhint %}

{% hint style="success" %}
Yes → WiFi Direct is functioning → **Continue**
{% endhint %}

If DIRECT network appears, but connection fails.

* Check Windows Firewall for WUDFHost.exe
* Update graphics and WiFi drivers
  {% endstep %}

{% step %}

### Determine connection mode

Is the device on same VLAN and required ports open?

**Yes** → Windows will use Miracast over Infrastructure

**No** → Windows will fall back to WiFi Direct
{% endstep %}

{% step %}

### If using Miracast over Infrastructure

1. Check firewall ports (TCP 7236, 7250, UDP 7236, 5353)
2. Check that AP isolation is disabled
3. Confirm mDNS multicast works across VLAN

{% hint style="warning" %}
If blocked → **Fix network settings**
{% endhint %}

{% hint style="success" %}
If working → **Great! Miracast will work in over Infrastructure mode**
{% endhint %}
{% endstep %}

{% step %}

### If using WiFi Direct

1. Ensure 2.4 GHz radio is enabled
2. Check for RF congestion
3. Test connection again

{% hint style="warning" %}
If issues persist → **Update all chipset, WiFi and graphics drivers**
{% endhint %}

{% hint style="success" %}
If working → **Great! Miracast will work in WiFi Direct mode**
{% endhint %}
{% endstep %}
{% endstepper %}

## Miracast over WiFi Direct vs Miracast over Infrastructure

<table><thead><tr><th width="230.1640625">Aspect</th><th>Miracast over Infrastructure (MS MICE)</th><th>Miracast over WiFi Direct</th></tr></thead><tbody><tr><td><strong>Connection type</strong></td><td>Routed through enterprise network</td><td>Peer to peer WiFi Direct link</td></tr><tr><td><strong>Uses access point</strong></td><td>Yes</td><td>No</td></tr><tr><td><strong>VLANs required</strong></td><td>Yes, if endpoints are on different subnets</td><td>No</td></tr><tr><td><strong>DNS required</strong></td><td>Yes</td><td>No</td></tr><tr><td><strong>Firewall rules required</strong></td><td>Yes, ports 7236, 7250, 5353</td><td>No</td></tr><tr><td><strong>AP isolation impact</strong></td><td>Must be disabled</td><td>No impact</td></tr><tr><td><strong>2.4 GHz requirement</strong></td><td>Not required once infrastructure mode is active</td><td>Required for negotiation (channels 1, 6, 11)</td></tr><tr><td><strong>WiFi Direct Virtual Adapter creation</strong></td><td>Still required for negotiation</td><td>Required</td></tr><tr><td><strong>Discovery mechanism</strong></td><td>mDNS (UDP 5353)</td><td>WiFi Direct beaconing</td></tr><tr><td><strong>Stability in enterprise WiFi</strong></td><td>Better for managed enterprise deployments</td><td>Good for isolated or guest scenarios</td></tr><tr><td><strong>Best use cases</strong></td><td>Corporate networks with proper routing and firewall setup</td><td>Guest devices, unmanaged networks, fallback mode</td></tr><tr><td><strong>Mode priority</strong></td><td>Preferred if infrastructure is correctly configured</td><td>Used when MS MICE is not possible</td></tr></tbody></table>


# AirPlay

For screen sharing via Apple iOS / iPadOS / MacOS devices.

{% hint style="warning" %}
This feature is currently available only for **Mago on Windows**.
{% endhint %}

## Overview

AirPlay relies on Apple Bonjour (mDNS) for discovery and uses several TCP and UDP ports for audio, video, control and event channels. The network must allow discovery and communication between the sending device and the Mago device.

## Requirements

The following requirements must be met for AirPlay to function reliably.

{% stepper %}
{% step %}

### Bonjour (mDNS) must be enabled

AirPlay discovery depends on mDNS, which uses multicast traffic on the following:

* UDP 5353 (mDNS)
* Multicast address 224.0.0.251

For AirPlay to work:

* Multicast traffic must be allowed on the WiFi network
* IGMP Snooping must not block or suppress mDNS packets
* IGMP Querier must be active on VLANs when using snooping
* mDNS must not be rate-limited or filtered by the AP

If mDNS is blocked, Apple devices will not see the Mago device in the AirPlay menu.
{% endstep %}

{% step %}

### AirPlay across multiple VLANs requires mDNS forwarding

In single-VLAN environments, no special configuration is typically needed.

In networks with multiple subnets or VLANs, AirPlay will **not** work unless multicast discovery is forwarded between VLANs. Most enterprise networks block multicast between VLANs by default.

To enable AirPlay across VLANs, your network must support one of the following:

* mDNS reflector / mDNS gateway
* Bonjour gateway (Cisco, Aruba, Meraki, UniFi, Extreme, etc.)
* Avahi reflector (Linux-based networks)
* Multicast forwarding between specific VLANs
* AirGroup-style service registration

This configuration is vendor-specific and must be performed on your switches or wireless controllers.

If your network does not forward mDNS between VLANs, AirPlay will only work when client devices and Mago are on the same VLAN.
{% endstep %}

{% step %}

### Required AirPlay ports must be open

<table><thead><tr><th width="102.96875">Port</th><th width="108.40234375">Type</th><th width="119.5234375">Direction</th><th>Service</th></tr></thead><tbody><tr><td>554</td><td>TCP/UDP</td><td>Both</td><td>Real Time Streaming Protocol</td></tr><tr><td>3689</td><td>TCP</td><td>Both</td><td>Digital Audio Access Protocol</td></tr><tr><td>5350</td><td>UDP</td><td>Both</td><td>NAT Port Mapping Announcements</td></tr><tr><td>5351</td><td>UDP</td><td>Both</td><td>NAT Port Mapping Announcements</td></tr><tr><td>5353</td><td>UDP</td><td>Both</td><td>mDNS Discovery</td></tr><tr><td>7000*</td><td>TCP</td><td>Both</td><td>AirPlay Server Port</td></tr><tr><td>7100*</td><td>TCP</td><td>Both</td><td>AirPlay Data Port</td></tr><tr><td>2001*</td><td>UDP</td><td>Both</td><td>AirPlay Timing Port</td></tr><tr><td>29053*</td><td>TCP</td><td>Both</td><td>AirPlay Events</td></tr><tr><td>61875*</td><td>UDP</td><td>Both</td><td>AirPlay Audio Data Port</td></tr></tbody></table>

(\*) Dynamic ports automatically selected by AirServer\
AirServer announces these ports via Bonjour/mDNS.

Firewall rules must not block these ports, or AirPlay will fail after discovery or result in black screen / audio-only mirroring.
{% endstep %}

{% step %}

### Requires Bonjour service types

AirPlay relies on Bonjour (mDNS) to advertise receiver capabilities.\
The following Bonjour service types must be visible to the client device:

* \_airplay.\_tcp
* \_raop.\_tcp
* \_airserver.\_tcp

If your network uses multiple VLANs, your mDNS gateway or Bonjour reflector must forward these service types between VLANs.\
If any of these are filtered or missing, AirPlay devices may not discover the Mago device or may fail during session setup.
{% endstep %}

{% step %}

### Multicast configuration on WiFi access points

Most enterprise WiFi systems include multicast control features that can unintentionally break AirPlay. Ensure the following:

* Multicast is allowed on the SSID used by client devices
* Broadcast/multicast filtering is disabled or relaxed
* Proxy ARP does not interfere with mDNS packets
* DTIM intervals are not excessively high
* Band steering does not block multicast on 2.4 GHz (if used)

Apple recommends enabling multicast on both bands, although 5 GHz is preferred for performance.
{% endstep %}

{% step %}

### AP Isolation must be disabled

AirPlay requires direct communication between the sender device and the Mago device. If AP isolation (client isolation) is enabled, devices cannot see each other, even if mDNS is working. Make sure AP isolation is disabled on the SSID used by client devices.
{% endstep %}

{% step %}

### Device and OS requirements

Sending device must be:

* iPhone or iPad with iOS 11 or later
* macOS 10.11 or later
* Windows devices using iTunes or compatible AirPlay apps

The receiving device (Mago) must:

* Be on the same VLAN as the AirPlay clients unless mDNS forwarding is configured
  {% endstep %}

{% step %}

### Network stability and performance considerations

AirPlay streaming uses a mixture of TCP and UDP channels. For best results:

* Ensure strong signal strength on the WiFi network
* Ensure low latency and minimal packet loss
* Avoid congested 2.4 GHz networks when possible
* Prefer 5 GHz or WiFi 6 for high-quality mirroring
  {% endstep %}
  {% endstepper %}


# Google Cast

For screen sharing via Android, ChromeOS devices, Chrome web browsers.

{% hint style="warning" %}
This feature is currently available only for **Mago on Windows**.
{% endhint %}

## Overview

Google Cast uses a combination of mDNS, SSDP, and TCP/UDP streams to discover and communicate with receiver devices. The following network requirements must be met for reliable mirroring from Android, ChromeOS, and Chrome browser clients.

## Requirements

{% stepper %}
{% step %}

### mDNS and SSDP discovery must be enabled

Google Cast discovery relies on two protocols:

**mDNS**

* UDP 5353
* Multicast address 224.0.0.251
* Bonjour service: \_googlecast.\_tcp

**SSDP**

* UDP 190
* Multicast address 239.255.255.250
* ST/URN tags for Google Cast receivers

Requirements

* Multicast must be allowed on the WiFi network
* IGMP Snooping must not block SSDP or mDNS
* IGMP Querier required if snooping is enabled
* mDNS and SSDP must not be filtered, rate-limited, or converted to unicast in incompatible ways
* AP isolation must be disabled

If mDNS or SSDP is blocked, the sender will not see the Mago device in the Cast menu.
{% endstep %}

{% step %}

### Google Cast across VLANs requires multicast forwarding

In single-VLAN networks Google Cast works without special configuration.

In multi-VLAN networks, Google Cast will not work unless multicast discovery is forwarded between VLANs.

You must enable one of the following (vendor-specific):

* mDNS gateway / Bonjour reflector
* SSDP multicast forwarding between VLANs
* Layer 3 multicast routing between specific VLANs
* Vendor “cast/airgroup multicast proxy” features (Cisco, Aruba, UniFi, Meraki, etc.)

If mDNS and SSDP packets do not cross VLAN boundaries, Google Cast will only work when clients and Mago are on the same VLAN.
{% endstep %}

{% step %}

### Required Google Cast ports must be open

These are the ports used by Google Cast:

<table><thead><tr><th width="134.9921875">Port</th><th width="108.35546875">Type</th><th width="107.71484375">Direction</th><th>Service</th></tr></thead><tbody><tr><td>8008-8019</td><td>TCP</td><td>Both</td><td>GoogleCast Listener Ports</td></tr><tr><td>1900</td><td>UDP</td><td>Both</td><td>SSDP Discovery</td></tr><tr><td>5353</td><td>UDP</td><td>Both</td><td>mDNS Discovery</td></tr><tr><td>32768-61000</td><td>TCP/UDP</td><td>Both</td><td>Ephemeral ports for client / server traffic</td></tr></tbody></table>

Requirements

* Both sender and Mago must be able to communicate over the ports above
* Firewall rules must allow inbound and outbound traffic
* NAT must not rewrite multicast packets (breaks SSDP/mDNS)

If ports 8008–8019 are blocked, Cast may appear but refuse to connect.\
If ephemeral ports are blocked, connection may start but fail mid-stream.
{% endstep %}

{% step %}

### WiFi network configuration for Google Cast

Google Cast requires stable multicast behavior on the access point.

Check that:

* Multicast is enabled on the SSID
* Broadcast/multicast filtering is disabled or set to “unrestricted”
* Proxy ARP does not block or transform mDNS/SSDP packets
* DTIM settings are reasonable (DTIM 1–3 recommended)
* 5 GHz is available for high-bandwidth casting
* Client load on AP is not excessive

Chromecast and Android devices do not retry failed mDNS/SSDP packets aggressively, so multicast reliability is critical.
{% endstep %}

{% step %}

### AP isolation must be disabled

Access point isolation (client isolation) prevents devices on the same SSID from communicating. Because Google Cast requires peer-to-peer communication:

* AP isolation must be disabled on the SSID used by client devices
* Wireless client privacy modes on the controller must be disabled
* Isolation in guest networks must be removed for the SSID used for casting

If isolation is enabled, devices may discover Mago (depending on broadcast bridging), but the connection will always fail.
{% endstep %}

{% step %}

### Device and OS requirements

Google Cast requires compatible senders:

* Android 4.4+
* ChromeOS devices
* Chrome browser with Cast extension or built-in Cast support
* Some Windows/macOS apps support casting via Chrome browser

Receiver (Mago):

* Must be connected via Ethernet or a high-quality WiFi connection
* Must be reachable through firewall and VLAN configuration
  {% endstep %}

{% step %}

### Best practices for network reliability

To ensure smooth casting:

* Prefer Ethernet for the Mago device
* Use 5 GHz WiFi for sending devices
* Avoid DFS channels if Android devices have limited support
* Keep packet loss below 1 percent for stable video
* Minimize interference and channel congestion
* Ensure roaming between APs is not too aggressive
  {% endstep %}

{% step %}

### Bonjour service types required

Google Cast relies on mDNS to advertise available receivers. AirServer broadcasts the following Bonjour service types:

* \_googlecast.\_tcp
* \_display.\_tcp
* \_airserver.\_tcp

These service types must be visible to the client device.\
If your network uses multiple VLANs, your mDNS gateway or Bonjour reflector must allow these service types to be forwarded.

If they are filtered or missing, clients may not discover the Mago device or may fail to connect during session negotiation.
{% endstep %}
{% endstepper %}


# Wired screen sharing (HDMI)

For screen sharing via laptops.

{% hint style="warning" %}
This feature is currently available only for **Mago on Windows**.
{% endhint %}

Mago supports screen sharing through an HDMI cable. An HDMI input port on the room device is required to enable HDMI ingest. For the list of devices with built-in HDMI input and supported capture cards and third-party BYOD or BYOM systems, refer to the chapter titled [(Optional) HDMI capture cards and Third-party BYOD / BYOM systems](/mago/certified-devices/windows-devices/optional-hdmi-capture-cards-and-third-party-byod-byom-systems) and the Mago configuration section under Settings > Presentation.


# Whiteboard

Mago Whiteboard is designed to deliver a natural and responsive writing experience. For the best performance, an interactive display is required so that users can write, draw and interact directly on the screen with a pen or with touch input.

Mago supports all common interaction types provided by certified interactive displays, including pen input, finger touch, hand gestures and punch interactions. These capabilities are available on all devices listed in the “Certified Room Devices” chapter.

For optimal smoothness, we recommend setting the display refresh rate to **60 Hz or higher** when available. A higher refresh rate reduces latency and improves the natural feel of ink strokes during fast writing.

Depending on the display model, the automatic detection mode for pen input and hand or finger touch may need to be configured on the device. Mago fully supports the advanced pen features offered by the interactive displays included in the certified list, such as pressure sensitivity, palm rejection and rear-pen erasing (when available on the hardware). See list here [Broken mention](broken://pages/RBSMgKdWFsCdN0hpolFG).


# Wireless touch controllers

## Apple devices

{% hint style="warning" %}
Apple iPad, minimum required iPadOS version: 13.0
{% endhint %}

**Minimum iPad model required**\
Any model that supports iPadOS 13.0

{% embed url="<https://support.apple.com/guide/ipad/ipad213a25b2/13.0/ipados/13.0>" %}

**Link Mago Controller App for iOS**

{% embed url="<https://apps.apple.com/app/mago-controller/id1630363629>" %}

## Android devices (tablets)

{% hint style="warning" %}
Minimum Android version required: 10.0
{% endhint %}

**Minimum tablet screen resolution**\
1024 x 600 mdpi

**Mago Controller App for Android**

{% embed url="<https://play.google.com/store/apps/details?id=com.remago.valarea.wtc>" %}


# Requirements

The Mago mobile app allows users to connect to Mago Room devices, start meetings, launch personal content, access cloud drives, control the room remotely and interact with the display. The app is available for both iOS and Android.

## Apple devices

The Mago mobile app is compatible with the following Apple operating systems:

* iOS: minimum version 13.0
* macOS with Apple Silicon (M1 or newer): minimum version 13.0 (Ventura)

Download link (Apple App Store):

{% embed url="<https://apps.apple.com/app/mago-workspace/id1408732971>" %}

## Android devices

The Mago mobile app is compatible with Android devices running:

* Android OS: minimum version 8.0

Download link (Google Play Store):<br>

{% embed url="<https://play.google.com/store/apps/details?id=com.remago.workspace>" %}


# Authentication

To use the Mago mobile app, users must authenticate using one of the following methods:

* Third-party OAuth (Microsoft 365, Google, Apple)
* Email and password

For more information, refer to [Third-party providers](/mago/requirements/third-party-providers)


# Proximity connection

## Overview

The Mago mobile app can connect to a Mago display to enable the following features:

* Start a meeting from My Calendar
* Launch personal Mago whiteboards
* Present files from cloud drives (OneDrive, Google Drive)
* Open personal apps and web links
* Remote meeting control (volume, microphone, camera)
* Remote control using trackpad, mouse or keyboard mode

The connection can be established by:

* Scanning the QR code displayed on the Mago Room screen
* Entering the six-digit alphanumeric room code

## Bluetooth requirements

To authenticate user proximity securely, Bluetooth Low Energy (BLE) must be enabled on both the mobile device and the Mago Room device.

* Minimum BLE version required: 4.0
* Bluetooth is used only for proximity verification
* No data is transferred via Bluetooth
* Devices do not need to be paired

All operational data exchanged between the mobile app and the Mago display is transmitted securely through Mago’s end-to-end encrypted HTTPS signaling service.

## Automatic disconnection

When the mobile device moves beyond the allowed proximity range, the app stops receiving packets and automatically disconnects cloud drives, personal calendars and session-bound links from the Mago display.


# Mago app for Android - Data safety notice

Know more about Data Safety on the Mago app for Android

## Data collection and security

### Data types

The Mago app for Android (Google Play Store link: <https://play.google.com/store/apps/details?id=com.remago.workspace>) may collect the following user data types:

* Personal info
  * Name
  * Email address
  * User ID
  * Date of birth
  * Profile picture
  * Address
* Files and docs
  * Photos and videos
  * Audio files
* App Activity
  * App interactions
* App info and performance
  * Crash logs
* Device ID

#### Data purposes

The user data is collected for the following purposes:

* App functionality
  * User authentication
  * User profile name visibility
  * App features such as whiteboard, room connection, calendar event launch, file presentation
* Analytics
  * Monitor app health
  * Diagnose and fix bugs or crashes

## How to manage or delete your user data

### Update or delete your profile information

1. Open the Mago app and sign in to your account.
2. Go to the "Account" section, by tapping the user icon.
3. Update or delete your data such as Nickname, Name, Surname, Profile picture, Address, Date of Birth.
4. When you update or delete any of your user profile data, the old data is deleted immediately.

### Update or delete your whiteboard contents

1. Open the Mago app and sign in to your account.
2. Go to Whiteboards, choose an item from the list.
   * To update: Enter the whiteboard and edit any whiteboard item or object.
   * To delete: Tap the three dots icon and choose "Delete". Tap to confirm.
3. When you update or delete any of your whiteboard data, the old data is deleted immediately.

### Delete your account and associated data completely

### Update or delete your profile information

{% hint style="warning" %}
Once you delete your account and associated data, all data is deleted immediately. No retention period is applied to any of your data.
{% endhint %}

1. Open the Mago app and sign in to your account.

<figure><img src="/files/yMJyuUoAVhWJpeyLCWyG" alt="" width="375"><figcaption></figcaption></figure>

2. Go to the "Account" section, by tapping the user icon.

<figure><img src="/files/Yj1wmMeViAfcMkVuUsby" alt="" width="375"><figcaption></figcaption></figure>

3. Scroll down and tap "Delete account". Tap "OK" to confirm.

<figure><img src="/files/osMI1d4IcHVaxkKtFpYN" alt="" width="375"><figcaption></figcaption></figure>

## More information

Additionally, you can contact us to ask via email at support \[at] mago.io for one of the following:

* Receive a list of the data we collected, associated with your user account
* Edit any of the data associated with your user account
* Delete any of the data associated with your user account
* Completely delete your user and all the data associated with your user account

We will answer your requests within 72 hours and process them within 7 days.


# Introduction

Turn any screen into your stage. Present wirelessly from your iPhone or iPad to a video wall - files, video calls, screen share and live annotation in seconds.

Your content, on the big screen instantly.\
Transform any tablet or mobile device into a wireless presentation hub. Scan a QR code or enter a connection code and start presenting to a large video wall in seconds. No cables, no setup, no fuss.\
Everything you put on screen stays perfectly in sync. Interact on one device and watch it update live on the other upload, arrange, annotate and navigate naturally, while your audience follows along in real time.

Built for showrooms, classrooms and retail floors.

Key Features:

* Wireless presentation - Connect in seconds with a QR code or short code. Start sharing immediately.
* Flexible display layouts - Arrange content in clean grid layouts (1x1, 2x1, 2x2, 3x2) or build a custom layout with up to 12 cells. Tap to expand and focus on any item.
* Live, two-way sync - Files and content update instantly on every connected device. Change it on one, see it everywhere.
* Rich content support - Present documents, images, office files, video files and more from your mobile device.
* Video calling & screen share - Bring people into the room with built-in video calls, and share your screen directly into the call.
* Magic annotation - Draw, highlight and mark up your content live to guide your audience.
* Remote device control - Control connected Windows devices straight from the app (with the remote agent installed).
* File sync across devices - Your content travels with you and stays consistent everywhere you present.

Perfect for:

* Showrooms & sales demos
* Education & training
* Retail & in-store experiences
* Meeting rooms & collaboration spaces

Pick up your device. Scan. Present. It's that simple.

{% embed url="<https://youtu.be/IRTQLbo5fsQ?si=L-kbk6FzD_Lw1lqJ>" %}


# Mago Stage Client Apps

The Mago Stage client app allows users to connect to Mago Stage displays, launch presentation content, control the room remotely and interact with the display. The app is available for both iOS,  Android, and Windows.

## Apple devices

The Mago Stage client app is compatible with the following Apple operating systems:

* iOS: minimum version 18.0
* macOS with Apple Silicon (M1 or newer): minimum version 13.0 (Ventura)

Download link (Apple App Store):

{% embed url="<https://apps.apple.com/us/app/mago-stage/id6742988201>" %}

## Android devices

The Mago Stage client app is compatible with Android devices running:

* Android OS: minimum version 13.0

Download link:

* Please contact us on <https://mago.io/book-a-demo>

## Windows devices

The Mago Stage client app is compatible with Windows devices running:

* Windows: minimum version 11

Download link:

* Please contact us on <https://mago.io/book-a-demo>


# User Guide

This guide explains how to create a stage, connect to a display, add content, configure layouts, present information, and manage presentation modes.

## Home Screen

The Home Screen allows you to access existing stages, create a new stage, access user settings, or connect to a display.

<figure><img src="/files/fhiAGRbYOj4YitgKmz8W" alt=""><figcaption></figcaption></figure>

## Connect to a Display

Select the Connect button to open the connection dialog. You can scan a QR code, select a display from the list, or enter a six-digit code manually.

<figure><img src="/files/pY93tmLYQBsnlHhxcUra" alt=""><figcaption></figcaption></figure>

### Connecting to a display (Manual Code Entry)

Use the Enter Code option to manually enter a six-digit connection code.

<figure><img src="/files/iDJA24NpYT0408L3mJhg" alt=""><figcaption></figcaption></figure>

## Create a Stage

Create a new stage by entering a name and optionally selecting an image.

<div><figure><img src="/files/X9k2hIJBmOtQ1eCqPpxC" alt=""><figcaption></figcaption></figure> <figure><img src="/files/WJMugNn7FPy97feHtqlv" alt=""><figcaption></figcaption></figure></div>

### Create a Stage (Created)

Example of a completed stage name after creation.

<figure><img src="/files/kJeIAS8bi6Oq3TknBAlz" alt=""><figcaption></figcaption></figure>

## Using a Stage

### Opening a Stage

Select a stage from the home screen to open it. A new stage opens in its default configuration with an empty layout ready for content.

### Adding Content

Press the + button to add content. You can add content from the following sources:

* Photo Library
* Camera
* Files
* Scan Documents
* Notes
* Websites
* YouTube links

<div><figure><img src="/files/tqGk9qXcbzdaMaU1d1c8" alt=""><figcaption></figcaption></figure> <figure><img src="/files/eSjSCeQtIspdvcS0NBow" alt=""><figcaption></figcaption></figure></div>

### Choosing a Layout

Tap the layout selector to choose how content is arranged on stage. Available grid options are **1, 2, 4, 6**, or a **custom** configuration.

<div><figure><img src="/files/365zPYbab25rzHIyP8Fy" alt=""><figcaption></figcaption></figure> <figure><img src="/files/yvQKZNpHaWWvuXwdPJkp" alt=""><figcaption></figcaption></figure></div>

### Placing Content in the Grid

Once a layout is selected, you can add content to individual grid cells in two ways:

* Tap the content in the content bar, then tap **Add to Stage**
* Long-press and drag content directly into a grid cell

### Magic Annotation

Enable **Magic Annotation** to draw directly over displayed content. Annotations appear in real time on the connected display.

### Expanding Content

Tap the expand icon in any item to allow them to fill the layout area for a larger view.

### Object Controls

Some content types have dedicated controls:

* **3D models:** switch between material options
* **Videos:** rewind, play/pause, and skip
* **PDF/Image Gallery:** next and previous page
* **Note:** pen/eraser size and color with undo and redo

### Navigating Content

Certain content types support interactive navigation:

* **Images:** stack multiple images to create a slideshow.
* **Websites:** scrolling and link navigation are mirrored on connected Android and Windows displays
* **Images, PDFs, remote agents, and notes**: support zoom and pan.

### Play Modes

A stage can operate in three modes:

* **Default:** Full access to upload, remove, and manage content.
* **Player:** Users cannot upload or remove content from the content bar, but the grid and existing content remain accessible and interactive.
* **Showroom:** The content bar is hidden entirely, and items cannot be removed from the grid. Intended for display or presentation use.

To exit Player or Showroom mode, tap the **Stop** button in the top-left corner. If the device has a password, PIN, or biometric lock configured, you will be prompted to authenticate before returning to Default mode.

### Disconnecting from a Display

To disconnect, tap the button in the top-right corner and select **Disconnect from Display.**


# Introduction

Mago Essential is a compact, all-in-one presentation device designed for seamless screen sharing and collaboration in meeting rooms, classrooms, and professional spaces. Running on Windows, it supports a wide range of wireless and wired sharing protocols, including Miracast, AirPlay, Google Cast, Mago Cast (WebRTC), and HDMI.

Key features include:

* Wireless screen sharing via native protocols such as Miracast, AirPlay, Google Cast
* Network-independent Wireless screen sharing via Mago Cast through Magolink.com or the\
  Mago mobile app for iOS / Android
* Network-independent Remote file presenting with remote controls
* Wired screen sharing via HDMI input (requires additional HDMI capture card)
* Customizable UI with logo, background, and digital signage or instructions page
* Flexible deployment: use standalone or integrated with existing room kits (e.g. MTR) via HDMI
* Optional BYOM dongle: USB Wi-Fi extender that connects your meeting and gives you access\
  to room camera, mic, and speakers—no software or memory, TAA compliant
* Cloud-based management via admin.mago.io for status monitoring, policy enforcement, OTA\
  updates, task scheduling, and analytics

Mago Essential brings simplicity, flexibility, and control to your meeting and presentation experience— no cables, no confusion.

{% embed url="<https://www.youtube.com/watch?v=CIpu0BWJ6P8>" %}


# Product Specifications

Mago Core IoT fanless device (MH-CORE-IOT) product specifications

<figure><img src="/files/mMovI2d0EBactuKV6SVL" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/6POP2K5g3hu9HBTqPhJj" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Download the Product specification sheet in PDF below:
{% endhint %}

{% file src="/files/hpE5UeaGyZVomLksiRmU" %}

#### General information

| **Product Name**                | Mago Essential – IOT Device |
| ------------------------------- | --------------------------- |
| **Product SKU**                 | <p>MH-CORE-IOT (fanless)    |
| <br>MH-CORE-IOT2 (with fan)</p> |                             |
| **Product Model No.**           | PCG02Pro-JSP                |

#### CPU

| **Product Collection**       | Intel® Celeron® Processor N Series       |
| ---------------------------- | ---------------------------------------- |
| **Code Name**                | Jasper Lake (11th Gen Intel® Processors) |
| **Processor Number**         | N5105                                    |
| **Processor Base Frequency** | 2.0GHz                                   |
| **Burts Frequency**          | 2.9GHz                                   |
| **Total Cores**              | 4                                        |
| **Total Threads**            | 4                                        |
| **Cache**                    | 4MB L3 Cache                             |
| **TDP**                      | 10W                                      |

#### GPU and Graphics Output

| **Processor Graphics**       | Intel® UHD Graphics                                                                     |
| ---------------------------- | --------------------------------------------------------------------------------------- |
| **Graphics Frequency**       | Base: 450MHz                                                                            |
| **Max Resolution**           | 4096x2160\@60Hz                                                                         |
| **Execution Units**          | 24                                                                                      |
| **N° of Displays Supported** | 2                                                                                       |
| **HDMI Output**              | <p>2x HDMI 2.0<br>Support 4K\@60fps<br>Max Resolution : 4096x2160\@60Hz HDR Support</p> |

#### Memory (RAM)

| **Memory Size**          | 8GB            |
| ------------------------ | -------------- |
| **Maximum Memory Speed** | 2933 MHz       |
| **Memory Type**          | LPDDR4x        |
| **Memory Channels**      | Single Channel |

#### Storage

| **eMMC** | <p>128 GB<br>eMMC 5.1, theoretical data speed 400MB/s</p> |
| -------- | --------------------------------------------------------- |

#### Network and Connectivity

| **WiFi**      | <p>WiFi 5 (802.11ac)<br>Support for 2.4GHz, 5GHz<br>Compatible with 802.11 a/b/g/n<br>Intel® AC9560 (TX/RX Streams 2T2R, Support 160MHz Band, Max Speed 1.7Gbps)</p> |
| ------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Ethernet**  | <p>10/100/1000Mbps<br>1x RJ-45 Jack<br>Realtek RTL8111H</p>                                                                                                          |
| **Bluetooth** | BT5.2 built-in with WiFi module                                                                                                                                      |
| **USB Ports** | 1x USB Type-C (theoretical data speed 5Gbps) 2x USB3.0 Gen2 (theoretical data speed 10Gbps) Support for external HDD / SSD up to 5TB                                 |

#### Audio

| **Audio output** | <p>Intel High Definition Audio via HDMI<br>1x 3.5mm earphone</p> |
| ---------------- | ---------------------------------------------------------------- |
| **Audio input**  | 1x Microphone (Combo with 3.5mm earphone)                        |

#### Software

| **Operating System** | Windows 11 Pro or Windows 11 IOT Enterprise                                                                                               |
| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **BIOS Support**     | <p>Auto power on<br>Boot from Network PXE Boot / iPXE Boot UEFI Boot<br>S5 RTC Wake<br>Wake On Lan<br>Boot order<br>BIOS / CMOS Reset</p> |

#### Power

| **Power button** | <p>1x Power On / Off button<br>Power off: red indicator<br>Power on / sleep: blue indicator</p>                              |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| **CMOS Battery** | 1x Non-rechargeable Lithium-Manganese battery CR20322 220mAh (Wh=3.3x220/1000=0.726)                                         |
| **Power input**  | <p>DC IN 12V/2A<br>1x USB Type-C power supplier</p><p>Operating voltage range: 12V\~20V</p><p>Support for PD3.0 Protocol</p> |

#### Environment

| **Temperature** | <p>Operation Temperature<br>0°C~~30°C (Support CPU full speed running continuously) 30°C~~35°C (Support 4K\@60fps playback by Movie & TV App)</p><p>Storage Temperature<br>-20 \~ 60°C (Restore to operation temperature 2hr before to use)</p> |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Humidity**    | <p>Operating Humidity<br>35% \~ 80% relative humidity, Non-condensing<br>Storage Humidity<br>20% \~ 93% relative humidity, Non-condensing</p>                                                                                                   |

#### Other

| **VESA Mount**        | <p>Support for VESA bracket (included)<br>Support for 75mm and 100mm mounting holes</p>                                                                                            |
| --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Anti-theft**        | Support for Kensington Security Lock Slot                                                                                                                                          |
| **Certification**     | <p>USA:<br>FCC SDoC<br>FCC ID (Contains FCC TX ID: PD9AX201D2)<br><br>EU:<br>CE (LVD & EMC, RED)<br>WEEE<br>EPR<br><br>UK:<br>UKCA (LVD & EMC, RED)<br>WEEE<br>Package Regular</p> |
| **Hardware warranty** | 2 years                                                                                                                                                                            |


# Setup Guide

{% content-ref url="/pages/UlVgAgcM7RIofB45iB0N" %}
[What’s in the box](/mago-essential/setup-guide/whats-in-the-box)
{% endcontent-ref %}

{% content-ref url="/pages/jAGVcgMcKVrSevticr72" %}
[Deployment options](/mago-essential/setup-guide/deployment-options)
{% endcontent-ref %}

{% content-ref url="/pages/RdEuVitqiVieEkj1PbhQ" %}
[Hardware installation](/mago-essential/setup-guide/hardware-installation)
{% endcontent-ref %}

{% content-ref url="/pages/IWGZ1eNqgEWXJ2m0hdFS" %}
[First boot](/mago-essential/setup-guide/first-boot)
{% endcontent-ref %}

{% content-ref url="/pages/3FUYslqi2sz81rcpnUmR" %}
[Activation and First Configuration](/mago-essential/setup-guide/activation-and-first-configuration)
{% endcontent-ref %}

{% content-ref url="/pages/m1qfARMhrAOWyixh9dsp" %}
[Post-Configuration and Automatic Network Check](/mago-essential/setup-guide/post-configuration-and-automatic-network-check)
{% endcontent-ref %}

{% content-ref url="/pages/vawXO1vlF3GCtQT915lO" %}
[Accessing Advanced Settings and Administrative Controls](/mago-essential/setup-guide/accessing-advanced-settings-and-administrative-controls)
{% endcontent-ref %}

{% content-ref url="/pages/r3vPdApH78xs4Qn0bOeW" %}
[Remote Management (Mago Admin Center)](/mago-essential/setup-guide/remote-management-mago-admin-center)
{% endcontent-ref %}


# What’s in the box

* **Mago Essential IOT Device**, with pre-installed Windows 11 and Mago Essential software
* Region-specific **USB-C power adapter** (EU, UK, US, other where applicable)
* **VESA mounting plate** (75x75mm and 100x100mm compatible)
* Quick **installation guide**

<figure><img src="/files/NbX1oVc0ZI4nMUEMbOw3" alt=""><figcaption><p>Mago Essential powered by the Mago Fanless Mini PC</p></figcaption></figure>


# Deployment options

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><h4>Standalone</h4></td><td data-object-fit="contain"><a href="/files/wTA264D3fVmjW8W0ZIAk">/files/wTA264D3fVmjW8W0ZIAk</a></td><td><a href="/pages/HoYAXuZF2dk73uE3UQ0w">/pages/HoYAXuZF2dk73uE3UQ0w</a></td></tr><tr><td align="center"><h4>Standalone with BYOM Kit</h4></td><td><a href="/files/E3mjCWvB2UlBW40yMXlh">/files/E3mjCWvB2UlBW40yMXlh</a></td><td><a href="/pages/1Lu5ZUtdgLVtDT1hd8ev">/pages/1Lu5ZUtdgLVtDT1hd8ev</a></td></tr><tr><td align="center"><h4>Integrated with a Room System</h4></td><td><a href="/files/EtgGvQDVIuT2XoARgGZN">/files/EtgGvQDVIuT2XoARgGZN</a></td><td><a href="/pages/eH4QpE5jQbiRmDNNxHMh">/pages/eH4QpE5jQbiRmDNNxHMh</a></td></tr></tbody></table>


# Standalone

Connect directly to any display or projector via HDMI. Ideal for open areas, classrooms, or meeting rooms without dedicated video systems.

<figure><img src="/files/wTA264D3fVmjW8W0ZIAk" alt=""><figcaption></figcaption></figure>

## Connection Schemas

### Single Passive Display

<figure><img src="/files/0dnlP0enMrXPYjG10n5V" alt=""><figcaption></figcaption></figure>

### Dual Passive Display

<figure><img src="/files/dflqDi4fdKNcBI4OT9AN" alt=""><figcaption></figcaption></figure>

### Single Interactive Display

<figure><img src="/files/xGVMmEt3Isf9U6Vnrkyw" alt=""><figcaption></figcaption></figure>


# Standalone with BYOM Kit

The Mago BYOM Kit enhances your Mago Essential experience by integrating the room's AV peripherals (e.g., camera, microphone, speakers, or all-in-one bars) for a seamless meeting experience.

<figure><img src="/files/E3mjCWvB2UlBW40yMXlh" alt=""><figcaption></figcaption></figure>

Follow these steps to connect and deploy the Mago BYOM Kit:

1. **Power the BYOM Receiver**
   * Connect the Mago BYOM Receiver to a power outlet using the included power adapter.
   * Ensure that the receiver is powered on before proceeding.
2. **Connect Room Peripherals to the Receiver**
   * Connect your room’s camera, microphone, speakers, or all-in-one AV bar to the appropriate ports on the BYOM Receiver.
   * Ensure the peripherals are properly connected and powered on.
3. **Place the BYOM Transmitter**
   * &#x20;Position the Mago BYOM Transmitter on a table or another area where users will have access to it during the meeting.
   * The transmitter can be placed up to 25 meters (about 82 feet) away from the receiver, ensuring the wireless connection remains stable.

## Connection Schema

<figure><img src="/files/5XkQtxsF0Imza0q8yiFR" alt=""><figcaption></figcaption></figure>


# Integrated with a Room System (MTR, Zoom Rooms, ...)

Connect to an existing room system (e.g., Microsoft Teams Rooms, Zoom Rooms, etc.) via HDMI input (HDMI ingest). Mago Essential becomes a content source that integrates seamlessly with the room's AV infrastructure.

### Single Screen setup

<figure><img src="/files/EtgGvQDVIuT2XoARgGZN" alt=""><figcaption></figcaption></figure>

### Dual Screen setup

<figure><img src="/files/pvaj8OKe2LsugYOzsVfX" alt=""><figcaption></figcaption></figure>

## Connection Schema

<figure><img src="/files/Mn8O2mnJ6WWr8ca96BXp" alt=""><figcaption></figcaption></figure>


# Hardware installation

Follow these steps to install the MRE hardware

## Guide for Mago Fanless IoT Mini PC - MRE Certified device (MH-CORE-IOT)

### Setup steps

1. **Unbox** your Mago Essential IoT device
2. **Connect** all the cables properly, based on your [deployment option](/mago-essential/setup-guide/deployment-options)
3. **Connect** the device via Ethernet cable (or skip if you are using WiFi for the internet connection)

{% hint style="info" %}
**Ethernet** connection is strongly recommended for a better experience
{% endhint %}

4. **Connect** a keyboard and mouse (required only for Mago Essential v6.x or earlier for [Manual Activation and First Configuration (up to version 6.x)](/mago-essential/setup-guide/activation-and-first-configuration/manual-activation-and-first-configuration-up-to-version-6.x))
5. **Install** the device on the wall using the special brackets contained in the package, or place it behind the display or on the table


# (Optional) Setting Up HDMI Capture for Wired Screen Sharing

To enable the HDMI input capabilities of Mago Essential for wired screen sharing, you need to use a certified HDMI capture card. Follow these steps:

1. **Obtain a Certified Capture Card**
   * Ensure you have a certified capture card that supports HDMI input, such as the INOGENI 4K2USB3 USB 3.0 Capture Card or any other approved models from the supported list.
2. **Connect the Capture Card**
   * Plug the HDMI capture card into one of the available USB or USB-C ports on the Mago Essential device.
   * Ensure the card is securely connected and recognized by the device.
3. **Connect HDMI Cable**
   * Take an HDMI 2.0+ cable and connect one end to the HDMI output of the Mago Essential device.
   * Route the other end of the cable to the designated location in the room, such as a table or another area where users will have access to it.
4. **Next Steps**\
   The software configuration for HDMI input and screen sharing will be detailed in the First

   Configuration section of this guide.


# First boot

Follow these steps to run the first configuration wizard of Mago Essential

## Automatic login

Turn on Mago Essential for the first time and wait for the system to boot.

Mago Essential starts and logs in automatically with the default local Windows user named "Admin".

{% hint style="info" %}
The password for the default "**Admin**" user is **`mre`**&#x20;
{% endhint %}

After the login, the Configuration Wizard opens automatically.

## Windows settings and updates

Before completing the configuration wizard, make sure you set the correct **language**, **keyboard**, **date and time** according to your preferences via Windows Settings.

Also, make sure all the latest **Windows updates** are installed correctly.

Now you can proceed to [Activation and First Configuration](/mago-essential/setup-guide/activation-and-first-configuration)


# Activation and First Configuration

Follow these steps to run the first configuration wizard of Mago Essential

Choose your Activation and First Configuration mode, based on the Mago software version.

<table data-view="cards"><thead><tr><th align="center"></th><th align="center"></th><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td align="center"><h4>Online activation</h4></td><td align="center">For <strong>Mago 7.x</strong> and later versions</td><td align="center">Requires a browser</td><td><a href="/pages/h7ealOM2gHhlkf7vlI0m">/pages/h7ealOM2gHhlkf7vlI0m</a></td><td><a href="/files/bVDDvFRC8J59GMi3k7jM">/files/bVDDvFRC8J59GMi3k7jM</a></td></tr><tr><td align="center"><h4>Manual activation</h4></td><td align="center">For <strong>Mago 6.x</strong> and earlier versions</td><td align="center">Requires keyboard / mouse</td><td><a href="/pages/2EYoPp7OKaOLRozggd5d">/pages/2EYoPp7OKaOLRozggd5d</a></td><td><a href="/files/6CIKdyY0yRzlrB7ac9f8">/files/6CIKdyY0yRzlrB7ac9f8</a></td></tr></tbody></table>


# Online Activation and First Configuration (version 7.0+)

Activate and configure Mago Essential online at admin.mago.io from your phone or laptop.

{% hint style="danger" %}
Online activation is available starting from **Mago version 7.x**, released on July 29th 2025. From version 7.x onward, only online activation is supported and [Manual activation](/mago-essential/setup-guide/activation-and-first-configuration/manual-activation-and-first-configuration-up-to-version-6.x) is no longer available.
{% endhint %}

Activate Mago Essential using an activation code entered via your phone or laptop for online configuration and activation. A signed-in user account on admin.mago.io is required. You can sign up or sign in using Microsoft 365, Google Workspace, Apple ID, or a standard email and password.

1. Sign in to [**https://admin.mago.io/activate**](https://admin.mago.io/activate)
2. Input the **6-digits activation code** to displayed on Mago Essential
3. Follow the steps online to activate and configure Mago Essential
4. Save and apply

<figure><img src="/files/bVDDvFRC8J59GMi3k7jM" alt=""><figcaption></figcaption></figure>

{% embed url="<https://www.youtube.com/watch?v=-vUIqw02vo8>" %}


# Manual Activation and First Configuration (up to version 6.x)

Activate and configure Mago Essential directly on-screen using a keyboard and mouse for step-by-step setup.

{% hint style="danger" %}
Manual activation is available for all **Mago versions up to 6.x**. Beginning with version 7.x, manual activation is no longer supported and only [Online activation](/mago-essential/setup-guide/activation-and-first-configuration/online-activation-and-first-configuration-version-7.0+) can be used.
{% endhint %}

## Language selection

Choose your preferred language. Press Next.

<figure><img src="/files/5JEhQEHhzfekMNQo0z4Y" alt=""><figcaption><p>Language selection</p></figcaption></figure>

## EULA

Read and accept the EULA. Press Next.

<figure><img src="/files/2ZIVh4ovC8PleAykA7vU" alt=""><figcaption><p>EULA</p></figcaption></figure>

## Network settings

Make sure an Internet connection is available. If not, check the Ethernet cable / interface or set up a WiFi connection via the Windows network settings. Press Next.

<figure><img src="/files/8oqLeEmFIzEpMQTL0lnm" alt=""><figcaption><p>Network settings</p></figcaption></figure>

## License activation

Insert your Mago Essential software license key and press "Activate". If the license activates correctly, press Next to continue. Otherwise, double check your license key, ask your reseller or ask for support here: [Support](/support/mago-helpdesk-and-support)

<figure><img src="/files/msyRMeTbsezwPzVa3AAr" alt=""><figcaption><p>License activation</p></figcaption></figure>

## Display settings

Double check the display configuration here. If your display is passive, check the "Passive display mode" option. If you need to make changes, tap "Open display settings" to access Windows display settings. Press Next.

<figure><img src="/files/PWJSVrmyebgj45mrzYCn" alt="Display Settings"><figcaption><p>Display settings</p></figcaption></figure>

## Local User

Mago Essential requires a dedicated local user to run. In this step, you can choose a name and password (optional) for the Mago user. The default values are user **MagoRoom** with no password.

Whatever username and password is chosen, Mago Essential **will automatically log in to that user the next time you restart**. You will never have to manually enter your password to log in when you start the device.

{% hint style="success" %}
The dedicated local user allows you to maximize security, thanks to the Least-privileged users (LPUs) settings and the Kiosk mode which is automatically set during the first configuration. Kiosk mode inhibits users from accessing the file system, the advanced Windows functions and shortcuts, only allowing access to the Mago Room Essential application.
{% endhint %}

<figure><img src="/files/KwHL80dzer4DQqF4cUQs" alt="Local User"><figcaption><p>Local User</p></figcaption></figure>

## Appearance settings

In this step, you can:

* Set a display name for this device.

{% hint style="info" %}
The display name appears when users screen share via Miracast, AirPlay, Google Cast and when they connect via the Mago mobile app.
{% endhint %}

* Set a custom logo and one or more custom backgrounds.
* Set the WiFi information to be displayed for users and guests.

{% hint style="warning" %}
A properly set WiFi is required for AirPlay and Google Cast to work. See [Broken mention](broken://pages/fMuhV3iZvvhQGSlNL5BU) for more details.
{% endhint %}

<figure><img src="/files/h9OjuYyUmQ6eoEwHQnFY" alt="Mago Essential - Appearance Settings"><figcaption><p>Appearance</p></figcaption></figure>

## Advanced settings

In this step, you can setup the automatic daily restart of Mago Essential.

<figure><img src="/files/mfHlhMy5sFMANTNoofQ1" alt=""><figcaption></figcaption></figure>

## Save and restart

After completing the wizard, you can Save and restart. Mago Essential will automatically log into the newly created local user and run the software.


# Post-Configuration and Automatic Network Check

After completing the configuration process, the device will automatically reboot. Upon startup, the Mago Essential software will **launch automatically**.

If the device **does not detect a network connection**, it will display a QR code on screen. Scanning this QR code with a phone or laptop will allow you to quickly set up a Wi-Fi connection to restore network access.

{% stepper %}
{% step %}

### Connect to the WiFi hotspot

Scan the QR code, or manually connect to the WiFi hotspot using the WiFi SSID and Password displayed on the screen.

<figure><img src="/files/N11Omhj7WFEkgeBEb8Wc" alt=""><figcaption><p>Mago Essential up to <strong>version 6.x</strong></p></figcaption></figure>

<figure><img src="/files/uRSxd4smvZmT1Q5VYQ8N" alt=""><figcaption><p>Mago Essential from <strong>version 7.x</strong></p></figcaption></figure>
{% endstep %}

{% step %}

### Access the configuration URL

Scan the second QR code, or manually browse the URL displayed on the screen.

<figure><img src="/files/ap64bEqFtQFwnXkVDi9s" alt=""><figcaption><p>Mago Essential up to <strong>version 6.x</strong></p></figcaption></figure>

<figure><img src="/files/7alIn921VsLL0B7RTALv" alt=""><figcaption><p>Mago Essential from <strong>version 7.x</strong></p></figcaption></figure>
{% endstep %}

{% step %}

### Select a WiFi network

On your phone or laptop, wait for the list of available Wi-Fi networks to appear. Select your desired Wi-Fi network and enter the password, if required. Then tap or click “Connect”. Mago Essential will attempt to connect to the selected network. Once connected successfully, the Wi-Fi setup prompt will disappear, and Mago Essential will resume normal operation.

<figure><img src="/files/w4EWaKfJBscniZu9ogn9" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Accessing Advanced Settings and Administrative Controls

## How to login as an Admin

By default, Mago Essential operates in Kiosk Mode, a security measure that restricts system access and prevents tampering with the underlying Windows environment. During configuration, a low- privilege local user is created for secure operation.

If you need to modify system settings or perform administrative tasks:

1. **Attach a keyboard** to the device.
2. Press **CTRL + ALT + DEL**, then select “**Sign out**”.
3. **Log in using the Admin account** (username: `Admin`, password: `mre` , unless changed).

Once logged in as Admin, you can open the **Mago Settings** (or **Mago Room Settings**) **application** by double-clicking its desktop icon or searching for it from the Windows taskbar. This will grant you access to all Mago Essential configuration options, as well as full control over the underlying Windows system.

## Mago Advanced Settings

With the Mago Settings application, Administrators can update the Settings as follows.

### Language

Set the interface language.

<figure><img src="/files/QGne8Ln4YnH01K4BXnWJ" alt=""><figcaption></figcaption></figure>

### Network settings

Configure wired or wireless connections. Click “Open Network and Wi-Fi settings” to open the Windows Network Settings.

<figure><img src="/files/aYpZBu3cXBSC8PgnWBXi" alt=""><figcaption></figcaption></figure>

### License

Activate or manage your Mago Essential license.

<figure><img src="/files/fv45ii1qVncwPzpc4bl3" alt=""><figcaption></figcaption></figure>

### Display

Adjust display behavior (passive or interactive). Click “Open Display settings” to open the Windows Display Settings.

<figure><img src="/files/iPr8DcwVpMahxtxxSxHX" alt=""><figcaption></figcaption></figure>

### Appearance

Customize the Mago Essential display name, add a logo and/or one or more backgrounds, toggle the display of Wi-Fi details, enable Digital Signage and its settings, enable voice command support, and set the time format.

<figure><img src="/files/sSGRHXSkMNiOsGnhAfmV" alt=""><figcaption></figcaption></figure>

### Presentation

Enable or disable HDMI input (video and audio) for capture card use, manage wireless presentation protocols (AirPlay, Miracast, Google Cast), and control whether a PIN is required for wireless sharing.

{% hint style="danger" %}
**Important Note – HDMI Input Configuration**

When setting up the HDMI input in Mago Settings, you will be prompted to select both the video and audio input sources from the connected capture card.

It is essential that **no HDMI cable or device is connected** to the capture card during this selection process. The capture card must be in its idle state, as this state is used by Mago Essential to detect when a cable is connected later.

If a signal is already present during configuration, the system may misinterpret the idle baseline, which can prevent automatic HDMI screen sharing from working as expected.
{% endhint %}

<figure><img src="/files/iVBNOSHWpbWLEgD8gEZz" alt=""><figcaption></figcaption></figure>

### Whiteboard (formerly "Workspace")

Configure features and tools related to the Mago whiteboard experience.

<figure><img src="/files/D8068MkFi4jo3x14nNNd" alt=""><figcaption></figcaption></figure>

### Security and Notifications

Manage on-screen notifications and enable BLE-based proximity detection.

<figure><img src="/files/PhmCuVw5yMM9URe9cADp" alt=""><figcaption></figcaption></figure>

### Advanced

Control system-level behaviors such as Kiosk mode activation, auto-start on boot, scheduled restarts, use of a custom SMTP email service, and enforcement of settings on application close.

<figure><img src="/files/5tbrylN8risT9e7bSRJL" alt=""><figcaption></figcaption></figure>


# Remote Management (Mago Admin Center)

The Mago Admin Center can be accessed at [https://admin.mago.io](https://admin.mago.io/).

From there, Mago Essential devices and settings can be monitored and managed remotely.

{% hint style="info" %}
Mago Admin Center User Guide coming soon.
{% endhint %}


# User Guide

### Overview of Mago Essential

Mago Essential is a powerful, all-in-one solution designed to simplify content sharing and presentation in any meeting room or workspace. It allows you to easily share your screen wirelessly from your device, whether you're using a Windows laptop, an Apple device, or an Android phone. You can also connect using an HDMI cable for wired screen sharing (if available). For users who don't have access to the same Wi-Fi network, wireless screen sharing is available independently of your network via magolink.com or via the Mago app for iOS and Android devices.

Mago Essential can be used in different ways:

* [Standalone](/mago-essential/setup-guide/deployment-options/standalone): Mago Essential works by itself, simply displaying the connection instructions on the screen.
* [With BYOM (Bring Your Own Meeting) Kit](/mago-essential/setup-guide/deployment-options/standalone-with-byom-kit): In this mode, you can connect to the room's audio and video peripherals like cameras and microphones for your video calls.
* [Integrated with Room Systems](/mago-essential/setup-guide/deployment-options/integrated-with-a-room-system-mtr-zoom-rooms-...): When integrated into existing room systems like Microsoft Teams or Zoom, Mago Essential becomes accessible via the Share button on the room’s touch controller or the second screen.

Throughout the process, clear on-screen instructions guide you step-by-step in connecting your device, ensuring a hassle-free experience. Whether you're using it in a standalone setup, with the BYOM kit, or as part of a room system, Mago Essential ensures seamless collaboration and easy content sharing in a variety of environments.

### What is the difference between BYOD (Bring Your Own Device) and BYOM (Bring Your Own Meeting)?

<figure><img src="/files/IFnqgdzvftFzUyx1RqXA" alt=""><figcaption></figcaption></figure>

### Screen Mirroring, Presenting, Casting. What’s the difference?

“*I just want to present!*”. That’s a common reaction when trying to show something from your phone or laptop on a larger screen. But when you start searching online, you’re hit with confusing terms like screen mirroring, casting, and wireless presenting. They all seem similar, but they’re not quite the same.

Here’s a simple breakdown:

* **Screen Mirroring / Screen Sharing**: Duplicate your entire screen on another display, including everything you see—apps, notifications, and even incoming messages. It's a live reflection of your device.
* **Wireless Presenting**: Show specific content—like a PDF, video, or image—on a larger screen, while keeping control from your device. Your private notifications and background activity remain hidden.
* **Wireless Casting**: Send content from an app (like YouTube, Spotify, or Chrome) to a bigger screen. Some apps let the receiving device stream directly, while others mirror what you see. It's usually app-based and doesn't always duplicate your whole screen.


# Use cases

## Standalone (BYOD)

In this mode, Mago Essential is used in rooms **without video conferencing equipment**. When you enter the room, you will see a simple **display with Mago Essential instructions** on the screen. You can easily connect your personal device (phone, tablet, or laptop) to the screen via wireless presentation protocols like AirPlay, Miracast, or Google Cast. You can also visit Magolink.com from your browser to cast your screen without installing anything. If you prefer a cable, you can connect your device using the HDMI cable provided in the room. Mago will automatically start showing your screen. There are no video conferencing tools available in this setup. Follow the How To instructions to start.

Check the deployment guide here: [Standalone](/mago-essential/setup-guide/deployment-options/standalone)

## Standalone with BYOM Kit

In this setup, you will see **Mago Essential instructions** on the screen, but video conferencing equipment (such as a camera, microphone, and speaker) will also be available in the room. The **BYOM** (Bring Your Own Meeting) Kit is present, with a small transmitter dongle placed on the table or in a designated area by IT. This dongle allows you to **connect your device to the room’s audio/video system**, enabling seamless video calls, and you can present content from your personal device at the same time.

Check the deployment guide here: [Standalone with BYOM Kit](/mago-essential/setup-guide/deployment-options/standalone-with-byom-kit)&#x20;

## Integrated with Room Systems (MTR, Zoom Rooms, ...)

In rooms with **video conferencing equipment already installed** (e.g., Microsoft Teams Rooms or Zoom Rooms), Mago Essential will be accessible through the Share button on the touch controller if it’s a single display setup. If the room has a dual display, you will see Mago Essential instructions directly on the second screen. In this configuration, Mago Essential works alongside the company’s existing room system and lets you easily share content during video conferences.

Check the deployment guide here: [Integrated with a Room System (MTR, Zoom Rooms, ...)](/mago-essential/setup-guide/deployment-options/integrated-with-a-room-system-mtr-zoom-rooms-...)


# Welcome screen overview

## Default home screen (from Mago version 7)

Starting from version 7, the main screen layout has been updated with the following elements:

* Top Left: The display name of the room or system. This will appear on your device when connecting through Miracast, AirPlay, Google Cast.
* Top Center: The Wi-Fi information (if available) showing the current network status.
* Top Right: The current date and time.
* Center: A slideshow of visual instructions. This slideshow will guide you on how to connect to Mago Essential, with the instructions displayed on the left side (text) and corresponding images on the right side. The slideshow will cover the different ways to connect, including:
  * Windows laptops (Miracast).
  * Apple devices (AirPlay).
  * Android devices (Miracast or Google Cast).
  * HDMI cable for wired connection.
* Bottom Left: A widget showing quick instructions for connecting via magolink.com, with options to scan a QR code or input a 6-digit code.

<figure><img src="/files/IwpaXQfeDaaFkiBdtZOJ" alt=""><figcaption></figcaption></figure>

## Default home screen (up to Mago version 6)

When using Mago Essential (up to version 6), the main screen will show the following elements:

* Top Left: The display name of the room or system. This will appear on your device when connecting through Miracast, AirPlay, Google Cast.
* Top Center: The company or room logo.
* Top Right: The current date and time.
* Center: A background image with a QR code and a 6-digit code displayed at the bottom of the QR code. This code and the QR code are used to connect your device to the Mago Essential system via Magolink.com.
* Bottom: A series of widgets providing quick instructions on how to connect to Mago Essential using different devices:
  * Miracast for Windows devices.
  * AirPlay for Apple devices.
  * Google Cast for Android devices.
  * Wired screen sharing via HDMI cable.
  * *If available, a Wi-Fi widget will also be displayed, showing the current Wi-Fi network information.*

<figure><img src="/files/tYg5VungPnavCIOYlM1d" alt=""><figcaption></figcaption></figure>

## Alternative home screen (Digital Signage)

If you see a different home screen instead of the usual Mago Essential instructions, it may be because your company has set up a custom digital signage page. This page may display company-specific content, such as announcements or other media, instead of connection instructions. If this happens, please refer to your IT admins or follow the company's instructions to understand how to connect and use the system.


# How to Share Screen or Present wirelessly

<table data-card-size="large" data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><h4>Windows devices</h4></td><td><a href="/files/b6ofIC0jiEMITt9EC8lG">/files/b6ofIC0jiEMITt9EC8lG</a></td><td><a href="/pages/6e5dqPzNFcZmcUUvk8fi">/pages/6e5dqPzNFcZmcUUvk8fi</a></td></tr><tr><td align="center"><h4>Apple devices</h4></td><td data-object-fit="contain"><a href="/files/oemooq0KJPPQ2zIVmu4k">/files/oemooq0KJPPQ2zIVmu4k</a></td><td><a href="/pages/zTu6h3vFOZNQPMHXCDHV">/pages/zTu6h3vFOZNQPMHXCDHV</a></td></tr><tr><td align="center"><h4>Android devices</h4></td><td data-object-fit="contain"><a href="/files/2skcIfw9TuJsL38J6NOV">/files/2skcIfw9TuJsL38J6NOV</a></td><td><a href="/pages/48hJk5IFJMcW0DvrMKmC">/pages/48hJk5IFJMcW0DvrMKmC</a></td></tr><tr><td align="center"><h4>ChromeOS devices</h4></td><td data-object-fit="contain"><a href="/files/nXpyq2Q035NxNx8H8PeW">/files/nXpyq2Q035NxNx8H8PeW</a></td><td><a href="/pages/HwXWbtOalOyJC60nBm00">/pages/HwXWbtOalOyJC60nBm00</a></td></tr></tbody></table>


# Windows devices

## Option 1: Screen Sharing with Miracast (same WiFi required)

{% hint style="warning" %}
Note: The minimum supported Windows version is Windows 10 (version 1703 or higher).
{% endhint %}

* Make sure your laptop is connected to the same Wi-Fi network as shown on the Mago screen (or as per the instructions given by your IT admin). Miracast can also work in Wi-Fi Direct mode, without the need to be on the same Wi-Fi network. Refer to the Network Requirements for this option: [Broken mention](broken://pages/8hKbIOZ6WtSzNYtZK8Ah)
* Press **`Windows Key + K`** or open the Cast menu (or “Connect” menu in Windows 10) from the action center. It will be displayed in the bottom right.
* Select the Mago Essential **display name** from the list. It is the name you can find on the display (top left).
* **If prompted, enter the PIN** shown on the Mago screen. Your screen will now be mirrored wirelessly.

<figure><img src="/files/mUAo5uKy7PgGQXC8Or5o" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
**Tip: Enable Touchback (Input Back)**
{% endhint %}

If the room display is a touchscreen and the feature is supported by your laptop, you can control your Windows device directly from the screen (e.g., tapping, swiping).

To enable this:

* After connecting via Miracast, open the Cast menu again (Windows + K)
* Click **“Allow mouse, keyboard, touch input from this device”**&#x20;

This allows you to interact with your laptop through the room’s touchscreen.

<div align="left"><figure><img src="/files/HRg4sC2oYSGSONlu8VCt" alt="" width="442"><figcaption></figcaption></figure></div>

## Option 2: Screen Sharing with Mago Link (any network, no app required)

{% hint style="success" %}
To use Mago Link, your laptop must have an internet connection, but it does not need to be on the same network as the Mago Essential device. No app is required and no dongle needs to be connected.
{% endhint %}

1. **Open your browser and go** to [www.magolink.com](https://www.magolink.com/). (If Mago is deployed on premises, your Mago Link address may use a custom domain).
2. Enter the **6-digit code** shown on the Mago screen or scan the QR code with your device’s camera.
3. Choose one of the following options:
   * **Share Screen**: Select a browser tab, window, or full screen. (Browser tabs can also share audio).
   * **Present File**: Upload a file to present it and control it wirelessly. (Supports PDFs, Word, PowerPoint, Excel, Images, Videos, and .glb 3D files).

<div data-with-frame="true"><figure><img src="/files/92YKEK464R4HPttua13c" alt=""><figcaption></figcaption></figure></div>


# Apple devices (iPhone, iPad, MacBook)

## Option 1: Screen Sharing with AirPlay (same Wi-Fi required)

1. Connect your Apple device to the **same Wi-Fi network** shown on the Mago screen (or as per the instructions given by your IT admin).
2. Access Screen Mirroring
   * On iPhone/iPad: **Swipe down** from the top-right and tap Screen Mirroring.
   * On Mac: **Click the Control Center** icon ![](/files/fVTVwFd7GAVj1yPTqZCU), then Screen Mirroring.
3. Select the Mago Essential **display name**.
4. If prompted, enter the **PIN shown** on the Mago screen.
5. Your screen will now be mirrored wirelessly.

### Steps for MacBook

<figure><img src="/files/4spKOOKThQ0CPiFx59Xp" alt=""><figcaption></figcaption></figure>

#### Steps for iPhone / iPad

<figure><img src="/files/wQFIDbn7JJX6dPKmwD6t" alt=""><figcaption></figcaption></figure>

## Option 2: Screen Sharing with Mago Link (any network, no app required)

{% hint style="success" %}
To use Mago Link, your laptop must have an internet connection, but it does not need to be on the same network as the Mago Essential device. No app is required and no dongle needs to be connected.
{% endhint %}

1. **Open your browser and go** to [www.magolink.com](https://www.magolink.com/). (If Mago is deployed on premises, your Mago Link address may use a custom domain).
2. Enter the **6-digit code** shown on the Mago screen or scan the QR code with your device’s camera.
3. Choose one of the following options:
   * **Share Screen**: Select a browser tab, window, or full screen. (Browser tabs can also share audio).
   * **Present File**: Upload a file to present it and control it wirelessly. (Supports PDFs, Word, PowerPoint, Excel, Images, Videos, and .glb 3D files).

<div data-with-frame="true"><figure><img src="/files/XRw6V7gi6Ln0ojDeguyO" alt=""><figcaption></figcaption></figure></div>

<div data-with-frame="true"><figure><img src="/files/MBSJ0ZgY3iedANQHOZGS" alt=""><figcaption></figcaption></figure></div>

## Option 3: Using the Mago App for iOS or MacOS (iPhone/iPad or MacBook M2+ processor)

1. Download the Mago app on your device:
   * Scan the QR Code: On the Mago display, scan the on-screen QR code with your phone’s camera. It will automatically redirect you to the correct app store (App Store) or
   * Search Manually: Open the App Store (iPhone/iPad) and search for “Mago” app by Re Mago Ltd or
   * Visit the Website: Go to <https://mago.io/download> from your mobile browser and follow the link to download the app.
2. Open the app, scan the QR Code or enter the 6-digit code shown on the screen.
3. You can now wirelessly present files.

{% hint style="success" %}
If you sign up for free or sign in, you’ll unlock additional features like wireless screen sharing, personalized settings, and more ways to interact with Mago.
{% endhint %}


# Android devices (phones / tablets)

## Option 1: Screen Sharing with Cast / Smart View (same Wi-Fi required)

{% hint style="warning" %}
Note: the minimum Android OS Client Version is 8.0
{% endhint %}

1. Connect to the same Wi-Fi network shown on the Mago screen (or as per the instructions given by your IT admin).
2. Open Quick Settings and look for:
   * Smart View (Samsung devices) or
   * Cast (Google devices) or
   * Wireless Projection, Screen Share, etc. (varies by brand)
3. Tap it and select the Mago display name.
4. Enter the PIN if requested.

### Example steps for Android tablet

<figure><img src="/files/Y18orjvaER90AnVF155E" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ubuRWwIMaMvQy8kcdokj" alt=""><figcaption></figcaption></figure>

### Example steps for Android phone

<figure><img src="/files/2N9GfXYtfVhUATqgjTo2" alt=""><figcaption></figcaption></figure>

## Option 2: Screen Sharing with Mago Link (any network, no app required)

{% hint style="success" %}
To use Mago Link, your laptop must have an internet connection, but it does not need to be on the same network as the Mago Essential device. No app is required and no dongle needs to be connected.
{% endhint %}

1. **Open your browser and go** to [www.magolink.com](https://www.magolink.com/). (If Mago is deployed on premises, your Mago Link address may use a custom domain).
2. Enter the **6-digit code** shown on the Mago screen or scan the QR code with your device’s camera.
3. Choose one of the following options:
   * **Share Screen**: Select a browser tab, window, or full screen. (Browser tabs can also share audio).
   * **Present File**: Upload a file to present it and control it wirelessly. (Supports PDFs, Word, PowerPoint, Excel, Images, Videos, and .glb 3D files).

## Option 3: Using the Mago App for Android

1. Download the Mago app on your device:
   * Scan the QR Code: On the Mago display, scan the on-screen QR code with your phone’s camera. It will automatically redirect you to the correct app store (Google Play) or
   * Search Manually: Open the Google Play Store and search for “Mago” app by Re Mago Ltd or
   * Visit the Website: Go to <https://mago.io/download> from your mobile browser and follow the link to download the app.
2. Open the app, scan the QR Code or enter the 6-digit code shown on the screen.
3. You can now wirelessly present files.

{% hint style="success" %}
If you sign up for free or sign in, you’ll unlock additional features like wireless screen sharing, personalized settings, and more ways to interact with Mago.
{% endhint %}


# ChromeOS devices

## Option 1: Screen Sharing with Google Cast (same Wi-Fi required)

1\.     Connect to the same Wi-Fi network shown on the Mago screen (or as per the instructions given by your IT admin).

2\.     Open Quick Settings and look for Cast / Google Cast / Chrome Cast.

3\.     Tap it and select the Mago display name.

4\.     Enter the PIN if requested.

## Option 2: Screen Sharing with Mago Link (any network, no app required)

{% hint style="success" %}
To use Mago Link, your laptop must have an internet connection, but it does not need to be on the same network as the Mago Essential device. No app is required and no dongle needs to be connected.
{% endhint %}

1. **Open your browser and go** to [www.magolink.com](https://www.magolink.com/). (If Mago is deployed on premises, your Mago Link address may use a custom domain).
2. Enter the **6-digit code** shown on the Mago screen or scan the QR code with your device’s camera.
3. Choose one of the following options:
   * **Share Screen**: Select a browser tab, window, or full screen. (Browser tabs can also share audio).
   * **Present File**: Upload a file to present it and control it wirelessly. (Supports PDFs, Word, PowerPoint, Excel, Images, Videos, and .glb 3D files).

## Option 3: Using the Mago App for Android

1. Download the Mago app on your device:
   * Scan the QR Code: On the Mago display, scan the on-screen QR code with your phone’s camera. It will automatically redirect you to the correct app store (Google Play) or
   * Search Manually: Open the Google Play Store and search for “Mago” app by Re Mago Ltd or
   * Visit the Website: Go to <https://mago.io/download> from your mobile browser and follow the link to download the app.
2. Open the app, scan the QR Code or enter the 6-digit code shown on the screen.
3. You can now wirelessly present files.

{% hint style="success" %}
If you sign up for free or sign in, you’ll unlock additional features like wireless screen sharing, personalized settings, and more ways to interact with Mago.
{% endhint %}


# How to Share Screen via HDMI or USB-C cable

To share your screen using a wired connection:

1\.     Pick up the HDMI / USB-C cable from the table.

2\.     Connect the cable to your device.

3\.     Wait a few seconds. Your screen will automatically appear on the main display.

No additional setup is required. If the display doesn’t show up, ensure your device is set to output video through HDMI or USB-C cable.

Screen sharing using a wired connection requires optional hardware. Please refer to this guide: [(Optional) Setting Up HDMI Capture for Wired Screen Sharing](/mago-essential/setup-guide/hardware-installation/optional-setting-up-hdmi-capture-for-wired-screen-sharing)


# Frequently Asked Question

### How do I turn on automatic logon in Window&#x73;**?**

{% hint style="info" %}
Because Windows 10, like Windows 8, asks you to sign in with a Microsoft account, skipping the log-in screen isn't as simple as simply deleting your password. Instead, you'll need to dig into the User Accounts settings to get rid of this extra step.
{% endhint %}

<mark style="background-color:blue;">**Step 1**</mark>

Open the Run command box (**Start > All apps > Windows System > Run** or press **Windows key + R**). In the text box, type **`netplwiz`** and press **Enter**.

<figure><img src="/files/sXNVaxnDrYqpdcwY6xi0" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Sr5mrLJ7CalBUx6X7hCg" alt=""><figcaption></figcaption></figure>

<mark style="background-color:blue;">**Step 2**</mark>

A User Accounts window will open. Under **Users for this computer:** select your username and then uncheck the box next to "**Users must enter a user name and password to use this computer"**. Click **Apply**.

{% hint style="warning" %}
What to do if the box *"Users must enter a username and password to use this computer"* is not present in the User accounts screen?

**Please follow** [**this FAQ**](#what-to-do-if-the-box-users-must-enter-a-username-and-password-to-use-this-computer-is-not-present-i)
{% endhint %}

<figure><img src="/files/Bna6i5u7Vb9yi2vnRvJQ" alt=""><figcaption></figcaption></figure>

<mark style="background-color:blue;">**Step 3**</mark>

A new window labeled **Automatically sign in** will pop up. Type your password twice and then click **OK**.

{% hint style="info" %}
Your computer will now bypass the log-in page when you turn on your PC, but it will not bypass the login page when you unlock your PC. You can also change your sign-in options so that Windows will never require you to sign in after your PC wakes from sleep by going to **Settings > Accounts > Sign-in options**.
{% endhint %}

## What to do if the box "Users must enter a username and password to use this computer" is not present in the User accounts screen?

<mark style="background-color:blue;">**Step 1**</mark>

Open the Run command box (**Start > All apps > Windows System > Run** or press **Windows key + R**). In the text box, type **`regedit`** and press **Enter**. This will open the Registry Editor.

<mark style="background-color:blue;">**Step 2**</mark>

Navigate to the following key:

`HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PasswordLess\Device`

<mark style="background-color:blue;">**Step 3**</mark>

In the right pane, look for `DevicePasswordLessBuildVersion` DWORD. The value of this DWORD may be set to 2 on your device. Double-click **`DevicePasswordLessBuildVersion`** and update the value to **0**.

<figure><img src="/files/Q9W51wiYCqnBZ36BJ6fn" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
If the checkbox still doesn’t appear after saving the Registry, you may need to restart your computer to apply the changes.
{% endhint %}

## How can I disable Windows and application notifications?

* Navigate to **Settings** > **System** > **Notification & Actions**
* Turn off "**Get notification from apps and other senders**". This turns off notifications from all apps and Windows

<figure><img src="/files/QgRbYcgO8LTh16hBDezt" alt=""><figcaption></figcaption></figure>

## What to do if the following pop-up message from the Taskbar appears on the console when turning off the external display?

<figure><img src="/files/kRIFQsfK9JfMdHj52oAl" alt=""><figcaption></figcaption></figure>

#### How to solve: Step 1

Follow [**this FAQ**](#how-can-i-disable-windows-and-application-notifications) to disable Notifications:

* Navigate to Settings > System > Notification & Actions
* Turn off "Get notification from apps and other senders". This turns off notifications from all apps and Windows

Now turn off the external display and check if the taskbar still gives the error. If the message no longer appears, the problem is probably caused by notifications from one or more applications. Now you can turn on "Get notification from apps and other senders" and manually disable notifications from the app list and check which app is causing the problem.

**How to solve: Step 2**

{% hint style="info" %}
If Step 1 doesn't solve the problem, you can try the following fix.
{% endhint %}

{% hint style="warning" %}
The registry is a database in Windows that contains important information about system hardware, installed programs and settings, and profiles of each of the user accounts on the computer. Windows often reads and updates the information in the registry. Normally, software programs make registry changes automatically. You should not make unnecessary changes to the registry. Changing registry files incorrectly can cause Windows to stop working or make Windows report the wrong information. Please take a backup of the registry first.
{% endhint %}

Follow these steps:

* Open the Run command box (**Start > All apps > Windows System > Run** or press **Windows key + R**). In the text box, type **`regedit`** and press **Enter**. This will open the Registry Editor.
* Navigate to `Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StuckRects3`
* Double click and open the **Settings** key
* Change the data value from the first column, second row to **03** and click on **OK**

  <figure><img src="/files/aVYO3byIeW07y5sIYJKW" alt=""><figcaption></figcaption></figure>
* Reboot the PC to apply the changes

{% hint style="info" %}
If you have to unhide the task bar, follow the above steps again and change the same value to **02**
{% endhint %}

## What to do if the on-screen touch keyboard appears very small on the touch controller?

<figure><img src="/files/PFXhJBwE4gUUxRLifnYF" alt=""><figcaption></figcaption></figure>

#### To ensure the OSK (On-Screen Keyboard) shows on the display while using Mago, you must ensure the appropriate setting is in place as below:

* Go to **Settings** > **Devices** > **Typing**
* Under the Touch Keyboard heading, look for the "*Show the touch keyboard when not in tablet mode and there’s no keyboard attached*" option and turn it On

Your OSK will now open when appropriate while using Mago.

#### To resize the Windows Touch Keyboard, follow these steps:

* Open the Run command box (Start > All apps > Windows System > Run or press Windows key + R). In the text box, type regedit and press Enter. This will open the Registry Editor.
* Navigate to the following path `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer`
* Right-click on the Explorer key and select **New** > **Key** from the context menu
* Rename this key to "**Scaling**". Go to this key by clicking on it.
* In the right pane, right-click in an empty space, and choose **New** > **String** **Value**
* Name this string value as "**MonitorSize**"
* Double click on MonitorSize to modify its value
* Enter the string value **5** for a keyboard that has a width of half the screen
* Restart your Windows 10 device after closing the registry editor

{% hint style="info" %}
If you do not find the value **5** suitable to your needs, adjust the size with a different string value.
{% endhint %}

<figure><img src="/files/2cpKHdKbVFp3rJZ8Dxiv" alt=""><figcaption></figcaption></figure>

**How to Disable Edge Swipe Gesture on Touch Screen in Windows 10**

How to disable the swipe from any edge of the touch screen? Swipe from left edge can open up the Action Center in Windows 10, but some users may find this feature annoying as they end up swiping accidentally. In this tutorial we’ll show you 2 simple methods to disable edge swipe gesture on the touch screen in Windows 10.

Method 1: Disable Touchscreen Edge Swipe Using Group Policy

* [Open Local Group Policy Editor](https://www.top-password.com/blog/open-local-group-policy-editor-in-windows-10/) and navigate to: Computer Configuration/Administrative Templates/Windows Components/Edge UI. In the right pane, double-click the on Allow edge swipe policy.&#x20;

![allow-edge-swipe.png](/files/PX96nofCkHfuOPvyntoM)

* &#x20;To disable touchscreen edge swipe in Windows 10, select the Disabled option. Click Apply and then OK.&#x20;

![disable-edge-swipe-gesture.png](/files/KedQX0esibeKnsHCjLne)

* &#x20;Restart your computer to apply the changes. Now, if you swipe in from the left/right/top/bottom edge of your touch screen, nothing will open up.

<br>

## **How can I setup multiple touch screens in Windows 10?**

Ensure an external keyboard is connected to the PC.

Check Windows is set to **Extended Desktop** for the additional monitor (press Windows Key + P to check or correct).

This should cover all multi-monitor scenarios — each additional monitor being another screen that needs to be touched or skipped with the Enter key:

* Click the Start Menu and start typing "Control Panel"
* Once visible, click on **Control** **Panel**

  <figure><img src="/files/gOvZoqeYkxmuWj88qzn7" alt=""><figcaption></figcaption></figure>
* Within the Control Panel, select **Hardware** **and** **Sound**

  <figure><img src="/files/cxqS1m6TOG881PLGCvmI" alt=""><figcaption></figcaption></figure>
* Within Hardware and Sound, select **Tablet PC Settings**

  <figure><img src="/files/ldt8BuEQ3Qr8M8g22HFn" alt=""><figcaption></figcaption></figure>
* Click on **Setup**

  <figure><img src="/files/pM9buapNAxoGa1mxTcxw" alt=""><figcaption></figcaption></figure>
* Touch the touchscreen displaying the prompt, “Touch this screen to identify it as the touchscreen” (If it is not a touchscreen, press Enter)

  <figure><img src="/files/0YYyODne1iPLlZyp75gK" alt=""><figcaption></figcaption></figure>
* Press **Enter** when prompted
* Touch the next touchscreen when prompted “Touch this screen to identify it as the touchscreen” (press Enter if not a touchscreen)
* The application should close when all connected monitors are accounted for. You can now test whether touch works on all relevant screens.

## How can I enable BLE Proximity if I am unable to see my personal Calendar & Drives?

Check that your hardware supports BLE 4.0 proximity and enable it by following this guide.

### Supported Bluetooth Devices (for Mago) <a href="#id-24-bluetooth-devices-supported-computer" id="id-24-bluetooth-devices-supported-computer"></a>

On your Windows 10 PC, check if your built-in Bluetooth chipset supports Bluetooth Low Energy (BLE). To check this, open **Device Manager** and expand the **Bluetooth** category.

![](/files/-M_6GAfrcV1kevAGbK48)

Right-click on your Bluetooth adapter, click **Properties** and go to the **Details** tab.

Click the drop-down under **Property** and select: **Bluetooth radio supports Low Energy Peripheral Role**. If the value is set to "`true"`, then your Bluetooth device manages BLE and can be used with the Proximity feature. If the Value is set to "`false"`, then you can not use Proximity feature with that computer.&#x20;

![](/files/-M_6GThAN9vLu47k01oT)

### Supported Bluetooth Devices (for mobile apps) <a href="#id-25-bluetooth-devices-supported-smartphone" id="id-25-bluetooth-devices-supported-smartphone"></a>

All smartphones with Bluetooth 4.0 should support BLE. Take a look at your phone model and your phone's Bluetooth specification to see if BLE is managed by your device.

##


# Where are configuration and cache files stored?

All the configuration files of Mago are stored in: **`C:\ProgramData\ValareaPOD\Launcher`**

![](/files/-MZMW3PPV0HR-akqmKJn)


# How can I add an exception to my antivirus application for Mago?

You may have to configure your firewall and/or antivirus software to allow the executions of the files into the folder **C:\Program Files\ValareaPOD\\** and **subfolders**.

Also, ensure the same is done on any secondary firewalls your computer may have (Windows Defender for example).


# What voice commands are available in "Hey Mago"?

Say "Hey Mago" followed by one to four words to trigger the desired command.

E.g. "Join next meeting", "Start new Zoom meeting", "Leave meeting", "Camera ON", "Turn down the volume", "Share my screen".

<table><thead><tr><th width="171">Word 1</th><th width="147">Word 2</th><th width="117">Word 3</th><th width="180">Word 4</th></tr></thead><tbody><tr><td><strong>Start / Open</strong></td><td></td><td></td><td></td></tr><tr><td>Open</td><td>New</td><td>Meeting</td><td>Teams</td></tr><tr><td>Start</td><td>Next</td><td>Session</td><td>Microsoft Teams</td></tr><tr><td>Join</td><td></td><td>Conference</td><td>Google Meet</td></tr><tr><td>Create</td><td></td><td>Video Conference</td><td>Webex</td></tr><tr><td> </td><td></td><td>Video Call</td><td>Cisco Webex</td></tr><tr><td> </td><td></td><td>Call</td><td>Zoom</td></tr><tr><td> </td><td></td><td>Whiteboard</td><td> </td></tr><tr><td> </td><td></td><td>Workspace</td><td> </td></tr><tr><td> </td><td></td><td>Miro</td><td> </td></tr><tr><td> </td><td></td><td>Miro board</td><td> </td></tr><tr><td> </td><td></td><td>Google Maps</td><td> </td></tr><tr><td> </td><td></td><td>Maps</td><td> </td></tr><tr><td> </td><td></td><td>Google Chrome</td><td>and Search "TextToFind"</td></tr><tr><td> </td><td></td><td>Chrome</td><td>and Find "TextToFind"</td></tr><tr><td> </td><td></td><td>Browser</td><td>and Research "TextToFind"</td></tr><tr><td> </td><td> </td><td>YouTube</td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Close / End</strong></td><td></td><td></td><td></td></tr><tr><td>Close</td><td>Meeting</td><td>Teams</td><td> </td></tr><tr><td>End</td><td>Session</td><td>Microsoft Teams</td><td> </td></tr><tr><td>Stop</td><td>Conference</td><td>Google Meet</td><td> </td></tr><tr><td>Finish</td><td>Video Conference</td><td>Webex</td><td> </td></tr><tr><td>Conclude</td><td>Video Call</td><td>Cisco Webex</td><td> </td></tr><tr><td>Terminate</td><td>Call</td><td>Zoom</td><td> </td></tr><tr><td> </td><td>Whiteboard</td><td></td><td> </td></tr><tr><td> </td><td>Workspace</td><td></td><td> </td></tr><tr><td> </td><td>Google Maps</td><td></td><td> </td></tr><tr><td> </td><td>Maps</td><td></td><td> </td></tr><tr><td> </td><td>Google Chrome</td><td></td><td> </td></tr><tr><td> </td><td>Chrome</td><td></td><td> </td></tr><tr><td> </td><td>YouTube</td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Webcam</strong></td><td></td><td></td><td></td></tr><tr><td>Enable</td><td>Camera</td><td> </td><td> </td></tr><tr><td>Activate</td><td>Video Camera</td><td></td><td> </td></tr><tr><td>ON</td><td>Webcam</td><td></td><td> </td></tr><tr><td>Disable</td><td></td><td></td><td> </td></tr><tr><td>OFF</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>QR Code</strong></td><td></td><td></td><td></td></tr><tr><td>Show</td><td>QR Code</td><td> </td><td> </td></tr><tr><td>Hide</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Volume</strong></td><td></td><td></td><td></td></tr><tr><td>Lower volume</td><td> </td><td> </td><td> </td></tr><tr><td>Lower volume by "value"</td><td></td><td></td><td> </td></tr><tr><td>Down volume</td><td></td><td></td><td> </td></tr><tr><td>Down volume by "value"</td><td></td><td></td><td> </td></tr><tr><td>Turn down volume</td><td></td><td></td><td> </td></tr><tr><td>Turn down volume by "value"</td><td></td><td> </td><td></td></tr><tr><td>Raise volume</td><td></td><td></td><td> </td></tr><tr><td>Raise volume by "value"</td><td></td><td></td><td> </td></tr><tr><td>Up volume</td><td></td><td></td><td> </td></tr><tr><td>Up volume by "value"</td><td></td><td></td><td> </td></tr><tr><td>Turn up volume</td><td></td><td></td><td> </td></tr><tr><td>Turn up volume by "value"</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>"How to"</strong></td><td></td><td></td><td></td></tr><tr><td>How to present</td><td> </td><td> </td><td> </td></tr><tr><td>Close how to present</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Sharing</strong></td><td></td><td></td><td></td></tr><tr><td>Share</td><td> </td><td> </td><td> </td></tr><tr><td>Screenshare</td><td></td><td></td><td> </td></tr><tr><td>Screen sharing</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Screenshot</strong></td><td></td><td></td><td></td></tr><tr><td>Screenshot</td><td> </td><td> </td><td> </td></tr><tr><td>Screen capture</td><td></td><td></td><td> </td></tr><tr><td>Snapshot</td><td> </td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Jabra PanaCast</strong></td><td></td><td></td><td></td></tr><tr><td>Jabra</td><td>Active Speaker</td><td> </td><td> </td></tr><tr><td>Panacast</td><td>Virtual director</td><td></td><td> </td></tr><tr><td>Camera mode</td><td>Full Screen</td><td></td><td> </td></tr><tr><td> </td><td>Default</td><td></td><td> </td></tr><tr><td> </td><td>Intelligent Zoom</td><td> </td><td> </td></tr><tr><td></td><td></td><td></td><td></td></tr><tr><td><strong>Mago Whiteboard</strong></td><td></td><td></td><td></td></tr><tr><td>Pen</td><td>Black</td><td> </td><td> </td></tr><tr><td>Highlighter</td><td>Green</td><td></td><td> </td></tr><tr><td>Marker</td><td>Red</td><td></td><td> </td></tr><tr><td>Eraser</td><td>Yellow</td><td></td><td> </td></tr><tr><td>Color</td><td>White</td><td></td><td> </td></tr><tr><td> </td><td>Blue</td><td> </td><td> </td></tr></tbody></table>


# Security White Paper

Last updated: Feb. 24th, 2026


# Introduction

Mago is a software solution for better meetings, whether in the meeting room, on the go or at home. With thousands of users worldwide, we’ve built a platform for modern work to enable collocated, distributed and remote teams to communicate better.\
Mago is trusted by the world’s most successful and innovative companies and is used by teams of all sizes across various industries and verticals. This means that Mago is not only a powerful solution, but it’s also a secure and reliable platform to store confidential data.


# Reliability

Our server infrastructure provides secure data storage and high application availability. All application services are started on multiple servers with a load-balancing/fault-tolerance system to increase redundancy. Cluster topologies are classified by the N+1 level of high availability. User data is replicated to multiple availability regions.

Establishing a consistent uptime track record is impossible without proper monitoring. Our team is ready to react to any incident 24 hours a day, 7 days a week. We’ve developed a reliable system to ensure that select employees are instantly notified of any possible safety risks.

### Regular Backup

User data is stored on a failover cluster, backed up every 60 minutes and encrypted. No matter what happens, your work will stay safe. There are also daily backups of the entire database that are stored separately from the main data centre for a standard retention period of 180 days.

### Incident Response

We have incident handling policies and procedures to address service availability, integrity, security, privacy, and confidentiality issues.

* Promptly respond to alerts of potential incidents
* Determine the severity of the incident
* If necessary, execute mitigation and containment measures
* Notify the stakeholders about the incident and its status
* Gather and preserve evidence for investigative efforts
* Document a postmortem and develop a permanent triage plan

### Disaster Recovery

To address information security requirements during a major crisis or disaster impacting Mago business operations, we maintain a disaster recovery plan.&#x20;

The Mago Infrastructure Team reviews and tests this plan annually. Relevant findings are documented and tracked until resolution.<br>

Our Disaster Recovery Plan (DRP) addresses both durability and availability disasters. A durability disaster is defined as a complete or permanent loss of primary metadata data centres, or lost ability to communicate or serve data from metadata data centres.

We define a Recovery Time Objective (RTO), which is the duration of time and a service level in which business process or service must be restored after a disaster, and a Recovery Point Objective (RPO), which is the maximum tolerable period in which data might be lost from a service disruption. We\
also measure the Recovery Time Actual (RTA) during Disaster Recovery testing; performed at least on an annual basis.

Mago incident response and disaster recovery plans are subject to being tested at planned intervals and upon significant organisational or environmental changes.

### Data Centres

Mago production systems are housed at third-party sub-service organisation data centres and managed service providers located in the EU (Ireland). Sub-service organisation data centre SOC reports are reviewed at a minimum annually for sufficient security controls. These third-party service providers are responsible for the physical, environmental, and operational security controls at the boundaries of Mago infrastructure. Mago is responsible for the logical, network, and application security of our infrastructure housed at third-party data centres.

Our current managed service provider for processing and storage is responsible for the logical and network security of Mago services provided through their infrastructure. Connections are protected through the managed service provider’s firewall, which is configured in a default deny-all mode. Mago restricts access to the environment to a limited number of IP addresses and employees.

### Compliance

Our services are hosted on Microsoft Azure data centres. To know more about Microsoft Azure compliance, please visit <https://docs.microsoft.com/en-us/azure/compliance>

![Azure & Mago Compliance](/files/QLgwivqZxwbcK6U3H6z1)


# Application Security

### User Interfaces

Mago is a cloud-based platform which can be accessed via native apps (Mago for Windows / Android), mobile (Mago App for iOS and Android), and web interface through a number of popular web browsers on both desktop and mobile (Mago App for web, Mago Admin Center).

The Mago software consumes a REST API provided by our Mago API Service which is credential secured over TLS 1.2. All communication with the REST API, and our IIS services, are over TLS (port 443) with 2048-bit asymmetric encryption and 256-bit symmetric encryption. The Hubs are authenticated on our servers using a 4 step authentication process with SASL. All inbound and outbound data from our backend layer is encrypted and transmitted over TLS with 2048-bit asymmetric encryption and 256-bit symmetric encryption using certificates from third party credited authorities. Network communication is protected using the latest in technology to secure all your video, audio and data. Using the TLS cryptography protocol, previously referred to as SSL, we provide protection using a 2048-bit asymmetric key in conjunction with a 256-bit symmetric session key. More information on ports used can be found within this document.

### User Authentication

Mago offers two different authentication methods to its Cloud users:

* Basic username and password authentication
* Third-party Identity Provider authentication (OAuth 2.0)

#### Basic Authentication

The Basic authentication requires a valid email address that undergoes an initial verification process through a confirmation email, and a password that must match our strong password policy.

#### Third-party Identity Providers

Alternatively, Mago supports the following third-party identity providers: Google, Microsoft, Apple. Authentication with third-party identity providers is made via a secure OAuth 2.0 process. Mago has obtained app marketplace / app store certification from all the supported third-party identity providers.

#### Multi-Factor Authentication

Mago users can add an additional security layer by activating the Multi-Factor Authentication. Mago currently supports MFA via Authenticator App OTC, Email OTC, SMS OTC.

#### SSO (On-prem deployment only)

Enterprise On-premises accounts can set up SAML-based SSO giving their team members access to Mago Server through an identity provider (idP) of their choice. A SAML 2.0 ldP like Azure AD can be chosen to set up authentication within your secure network.


# Mago on Windows / Android Security

Mago app for displays (Windows / Android) was designed to be appliance-like, ensuring a consistent, “walk-up” user experience without sacrificing security. Mago works with our partners to deliver a solution that is secure and doesn’t require additional actions to secure Mago. This article discusses many of the security features found in Mago.

{% hint style="info" %}

* Mago should not be treated like a typical end-user workstation. Not only are the use cases vastly different, but the default security profiles are also different. This section applies to Mago devices running on Windows.
* Limited end-user data is stored on Mago. End-user data may be stored in the log files for troubleshooting and support only. At no point can an attendee of a meeting using Mago copy files to the hard drive or sign in as themselves. No end-user data is transferred to, or accessible by, the Mago device.
* Even though end users can’t put files on a Mago hard drive, Microsoft Defender is still enabled. Mago performance is tested with Microsoft Defender. Disabling this or adding endpoint security software can lead to unpredictable results and potential system degradation.
  {% endhint %}

#### Hardware Security

In a Mago environment, there’s a central compute module that runs Windows IoT Ent or Pro editions. Every certified compute module must have a secure mounting solution, a security lock slot (for example, Kensington lock), and I/O port access security measures to prevent the connection of unauthorised devices. You can also disable specific ports via Unified Extensible Firmware Interface (UEFI) configuration.

Every certified compute module must ship with Trusted Platform Module (TPM) 2.0 compliant technology enabled by default. TPM is used to encrypt the login information for the Mago resource account. Secure boot is enabled by default.

Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM). When the PC starts, the firmware checks the signature of each piece of boot software, including UEFI firmware drivers (also known as Option ROMs), EFI applications, and the operating system. If the signatures are valid, the PC boots, and the firmware gives control to the operating system. For more information, see Secure boot. Access to UEFI settings is only possible through attaching a physical keyboard and mouse. This prevents being able to access UEFI via the Mago touch-enabled console as well as any other touch-enabled displays attached to Mago.

Kernel Direct Memory Access (DMA) Protection is a Windows setting that is enabled on Mago. With this feature, the OS and the system firmware protect the system against malicious and unintended DMA attacks for all DMA-capable devices:

* During the boot process
* Against malicious DMA by devices connected to easily accessible internal/external DMA-capable ports, such as M.2 PCIe slots and Thunderbolt 3, during OS runtime

Mago also enables Hypervisor-protected code integrity (HVCI). One of the features provided by HVCI is Credential Guard. Credential Guard provides the following benefits:

* **Hardware Security**&#x20;

  NTLM, Kerberos, and Credential Manager take advantage of platform security features, including Secure Boot and virtualisation, to protect credentials
* **Virtualisation-based Security**&#x20;

  Windows NTLM and Kerberos derived credentials and other secrets run in a protected environment that is isolated from the running operating system
* **Better Protection against Advanced Persistent Threats**&#x20;

  When Credential Manager domain credentials, NTLM, and Kerberos derived credentials are protected using virtualisation-based security, the credential theft attack techniques and tools used in many targeted attacks are blocked. Malware running in the operating system with administrative privileges can’t extract secrets that are protected by virtualisation-based security.

#### Software Security

After Microsoft Windows boots, Mago automatically signs into a local Windows user account named Mago. The Mago account has no password. To make the Mago account session secure, the following steps are taken.

{% hint style="warning" %}
Don’t change the password or edit the local Mago user account. Doing so can prevent Mago from automatically signing in.
{% endhint %}

For Mago to be used in communal spaces such as meeting rooms, its custom OS implements many of the security and lockdown features available in Windows. Mago supports these Windows security features:

* UEFI Secure Boot
* BitLocker Drive Encryption
* Trusted Platform Module (TPM)
* Windows Defender
* User Account Control (UAC) for access to the Mago Settings

**Kiosk Mode**

Mago runs using the less privilege feature that limits the application entry points exposed to the user. This is what enables app launcher kiosk mode. Using standard windows shell UI suppression, Mago is configured as a kiosk device that runs a Windows desktop application as the user interface.&#x20;

Enabling Kiosk Mode in Mago Settings, the traditional Explorer shell does not get launched at all. This greatly reduces the Mago vulnerability surface within Windows. Additionally, lock down policies are applied to limit non-administrative features from being used. A keyboard filter is enabled to intercept and block potentially insecure keyboard combinations that aren’t covered by security enforced policies. Only users with local or domain administrative rights are permitted to sign into Windows to manage Mago. These and other policies applied to Windows on Mago devices are continually assessed and tested during the product lifecycle.

**Session Security and Data Safety**

During a meeting session, users have access to a limited set of directories on Mago:

* Meetings (secure cache available only during live sessions)
* My Documents (optional)

Files saved locally in these directories are deleted when users end the session (e.g. by pressing “End session” or disconnecting the personal device if on BYOD). To save content created during a session, users should save files to a USB drive, a connected personal Cloud drive or using the “send by email” feature.

Post working session, data is wiped from the system to protect sensitive information. Next user or group gets a clean slate to work from.

#### Account Security

Mago devices include an administrative account named “Admin” with a default password. We strongly recommend that you change the default password as soon as possible after you complete setup.

{% hint style="warning" %}
If you delete or disable the Admin account before granting local Administrator permissions to another local or domain account, you may lose the ability to administer and configure the Mago device. If this happens, you’ll need to reset the device back to its original settings and complete the setup process again. Do not grant local Administrator permissions to the Mago user account.
{% endhint %}

#### Network Security

Generally, Mago has the same network requirements as any VC client installed on a standard desktop PC. Access through firewalls and other security devices is the same for Mago as for any other VC client (i.e. Zoom, Google Meet, Microsoft Teams Desktop, Cisco Webex). Mago also needs access to Windows Update, and Microsoft Intune (if you use Microsoft Intune to manage your devices). For the full list of IPs and URLs required for Mago VC systems, see:

<table data-header-hidden><thead><tr><th width="201"></th><th></th></tr></thead><tbody><tr><td>Zoom</td><td><a href="https://support.zoom.us/hc/en-us/articles/201362683-Network-firewall-or-proxy-server-settings-for-Zoom">Zoom services and Ports</a></td></tr><tr><td>Microsoft Teams</td><td><a href="https://docs.microsoft.com/en-us/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide&#x26;viewFallbackFrom=o365-worldwide%23skype-for-business-online-and-microsoft-teams">Office 365 URLs and IP address ranges</a></td></tr><tr><td>Google Meet</td><td><a href="https://support.google.com/a/answer/1279090?hl=en%23zippy=,step-set-up-outbound-ports-for-media-traffic,step-allow-access-to-uniform-resource-identifiers-uris">Google Meet ports</a></td></tr><tr><td>Cisco Webex</td><td><a href="https://help.webex.com/en-US/article/WBX264/How-Do-I-Allow-Webex-Meetings-Traffic-on-My-Network?">Webex ports requirements</a></td></tr><tr><td>Windows Update</td><td><a href="https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus">Configure WSUS</a></td></tr><tr><td>Microsoft Intune</td><td><a href="https://docs.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints">Network Endpoints for Microsoft Intune</a></td></tr></tbody></table>

{% hint style="warning" %}
We strongly recommend to configure to automatically Windows updates policies, including security updates (i.e. every day beginning at 2:00am. There is no need to use additional tools to deploy and apply Windows Updates. Using additional tools to deploy and apply updates can delay the installation of Windows patches and thus lead to a less secure deployment. The Mago app is deployed using the Mago Admin management console (VMC) <https://admin.mago.io>
{% endhint %}

Mago devices work with most 802.1X or other network-based security protocols. However, we’re not able to test Mago against all possible network security configurations. Therefore, if performance issues arise that can be traced to network performance issues, you may need to disable these protocols if they’re configured in your organisation.

For optimum performance of real time media, we strongly recommend that you configure VC media traffic to bypass proxy servers and other network security devices. Real time media is very latency sensitive and proxy servers and network security devices can significantly degrade users’ video and audio quality. Also, because VC media is already encrypted, there’s no tangible benefit from passing the traffic through a proxy server.

Mago doesn’t support authenticated proxy servers.

Mago devices don’t need to connect to an internal LAN. Consider placing Mago in a secure network segment with direct Internet access. If your internal LAN becomes compromised, the attack vector opportunities towards Mago Room will be reduced.

We strongly recommend that you connect your Mago devices to a wired network. The use of wireless networks on Mago Room devices isn’t recommended or certified. Some connectivity features, such as Wi-Fi Sense, are disabled by default.

QR code Proximity Join and other Mago features rely on TCP/UDP and Bluetooth. However, the Bluetooth implementation on Mago devices doesn’t allow for an external device connection to a Mago device. Bluetooth technology used on Mago devices is currently limited to advertising beacons and prompted proximal connections. The `ADV_NONCONN_ INT` protocol data unit (PDU) type is used in the advertising beacon. This PDU type is for non- connectable devices advertising information to the listening device. There is no Bluetooth device pairing as part of these features. Additional details on Bluetooth protocols can be found on the [Bluetooth SIG website](https://www.bluetooth.com/blog/bluetooth-low-energy-it-starts-with-advertising/).


# On-Cloud / On-Premise Deployment Security

### Mago on Cloud Security

#### Mago Server Separation of Duties and Least Privilege Security Principles

The principle of “Least Privilege” essentially means that users should not have more privileges than needed to complete their daily task. To secure data and the system in general from potential damage, it is essential to identify a comprehensive hierarchy of users and separate duties and to provide each individual with his or her own user ID and with permissions as minimal as possible to complete tasks.

#### RBAC Support and SoD

Mago Server support Role Based Access Control. Every meeting / workspace can be managed by a meeting owner who can control user permissions.

#### Microsoft Azure

Azure’s Data centres are geographically dispersed and comply to ISO/IEC 27001:2005, SOC 1 and SOC 2 and has CSA STAR certification. These Data centres are managed and operated by Microsoft who have decades-long experience building enterprise software and running some of the largest online services in the world. See the Reliability > Compliance section for more information.

#### SSL Rating

Mago Cloud has an A rating from Qualys SSL Labs, the highest ranking possible, which means it is protected from all known attacks and follows all best practices.

### Mago on premises security

Microsoft IIS, Microsoft SQL and NTFS file system are legacy components needed for to deploy internal on-prem Mago Server architecture. Layer 7 firewall are strongly suggested in order to provide high level of security and 0-Day exploit explosion.

#### Purging policy for end-users data (State-less configuration for the Mago Server)

Mago Server can be configured to schedule a daily data wipe stored into the Mago Server secured storage partition. End-users data include all user activities media content, whiteboard content, whiteboard ID, whiteboard PIN and recap files.

Notes:

* RMS supports HTTP connections (LAN only), but we strongly recommend encrypted HTTPS over TLS 1.2.
* We do not directly tunnels any service. You can access resources only passing through our dedicated API interface and after passing a double level of authentication.
* We validate client inputs, verifying the presence of security tokens inside the HTTP headers and checking the content of the client calls.
* We implemented a strong custom authentication based on a double security token. The first token is released at the first call and is mandatory to retrieve the second token. The latest is verified at the beginning of each client call.
* We added rate limits to the authentication attempts that a client can do in a time unit. After this number/time limit, the attacker client is blocked.

### Mago Data Flow

<figure><img src="/files/u7P8LOpiTKgvlTBUQsGB" alt=""><figcaption></figcaption></figure>


# Encryption

### Data Encryption at-rest and In-Transit

Mago adheres to NIST standards for encryption, utilising both at-rest and in-transit protection. AES 256 encryption for data at rest TLS 1.2 or higher for transmission, you can be assured that your data is secured by industry standards, globally.

### Key Management

The Mago key management infrastructure is designed with operational, technical, and procedural security controls with very limited direct access to keys. Encryption key generation, exchange, and storage is distributed for decentralised processing.

### File Encryption Keys

File encryption keys are created, stored, and protected by production system infrastructure security controls and security policies.

### Internal SSH keys

Access to production systems is restricted with unique SSH key pairs. Security policies and procedures require protection of SSH keys. An internal system manages the secure public key exchange process, and private keys are stored securely.

### Key Distribution

Mago automates the management and distribution of sensitive keys to only the systems that are required for operations. The key distribution system is based on Microsoft Azure Key Vault.

### Managing Secrets

All secrets such as API keys, passwords, database credentials, or certificates are stored in a centralised system for securely accessing secrets. We never store secrets on local servers or code repositories. Access to the secrets management system is authorised only for a small number IT Operations engineers.

### Network Security

Mago diligently maintains the security of our backend network. Our network security and monitoring techniques are designed to provide multiple layers of protection and defence. We employ industry-standard protection techniques, including firewalls, network vulnerability scanning, network security monitoring, and intrusion detection systems to ensure only eligible and non-malicious traffic is able to reach our infrastructure.

Our internal private network is segmented according to use and risk level. The primary networks are:

* Internet-facing DMZ
* VPN front-end DMZ
* Production network
* Corporate network

Access to the production environment is restricted to only authorised IP addresses and requires key authentication on all endpoints. IP addresses with access are associated with the corporate network or approved Re Mago personnel. Authorised IP addresses are reviewed on a quarterly basis to ensure a secure production environment. Access to modify the IP address list is restricted to authorised individuals.

Traffic from the internet destined for our production network is protected using multiple layers of firewalls and proxies.\
Mago identifies and mitigates risks via regular network security testing and auditing by both dedicated internal security teams and third-party security specialists.


# Vulnerability Management

Our security team performs automated and manual application and infrastructure security testing to identify and patch potential security vulnerabilities and bugs on a regular basis.

We also engage independent service providers to perform external penetration tests to assess the potential system security threats on an annual basis. Remediation activities against discovered vulnerabilities are performed in a timely manner to enable the pen test provider to retest and verify that the issues are fixed.

### Change Management

A formal Change Management Policy has been defined by the Mago Engineering team to ensure that all application changes have been authorised prior to implementation into the production environments. Source code changes are initiated by developers that would like to make an enhancement to the Mago application or service. All changes are stored in a version control system and are required to go through automated Quality Assurance (QA) testing procedures and manual code review to verify that security requirements are met.

Successful completion of QA procedures leads to implementation of the change. All QA-approved changes are automatically implemented in the production environment. Our software development lifecycle (SDLC) requires adherence to secure coding guidelines, as well as screening of code changes for potential security issues via our QA and manual review processes.

All changes released into production are logged and archived, and alerts are sent to the Mago Engineering team management automatically. Changes to the Mago production environment are restricted to authorised personnel only. The Mago Security team is responsible for maintaining infrastructure security and ensuring that server, firewall, and other security-related configurations are kept up-to-date with industry standards. Firewall rule sets and individuals with access to production servers are reviewed on a periodic basis.




---

[Next Page](/llms-full.txt/1)

