It's done on a per device basis.
If you want do be able to manage them you need the Universal Server with it. Then you can issue tokens to reset passwords, gain administrator access for things like patching and many many other benefits.
Depending on the number, if you get to more than 20 laptops I'd strongly suggest getting the Universal Server to manage them, otherwise it will be a big headache. You will need to have written down the token for each install, and many other things to consider.
You also cant prevent the user from interacting with the software in standalone, but you can in managed