MDM projects rarely fail on technology. They fail when you ask staff to enroll personal phones the wrong way.
When one of these programs collapses, the platform is almost never the reason. Somebody pointed a corporate device policy at phones employees bought themselves, people said no, and it died in an argument that served nobody. One distinction drawn early prevents it: owning the hardware is one situation, protecting company data on hardware you will never own is a different one. Draw that line first and enrollment becomes a non-event. Blur it and no license, vendor or console repairs what follows.

- Two modelsCorporate and personal, kept separate
- Zero-touchNew devices configure themselves
- SelectiveWipe company data only on BYOD
- Often ownedIntune already in your license
Six outcomes, whichever platform you pick.
A new device configures itself
The supplier ships straight to the employee. Power-on triggers enrollment, policy, application installation and encryption before any technician has handled the machine. For a company whose people sit in several time zones and rarely visit an office, that erases the ship-to-IT-then-ship-again detour, the days a new hire spends waiting, and the entire business of maintaining golden images.
A lost device is a hardware loss, not a breach
Disk encryption with recovery keys escrowed somewhere IT can genuinely reach them, remote wipe on demand, and session revocation that ends an active sign-in immediately rather than whenever a token happens to refresh. Whether a laptop abandoned at an airport gate turns into an insurance claim or a notification obligation under a state breach law was settled by configuration choices made long before it went missing.
Company data separated from personal life
App protection policies wrap the company side of a personal phone: data stays inside approved applications, refuses to paste into personal apps, will not save to personal storage, and disappears on request without disturbing one family photograph. The handset is never enrolled, so personal apps stay invisible to you and the device itself stays beyond your reach. That boundary is what makes BYOD something American employees will actually agree to.
Compliance that actually gates access
Each device is measured against your rules, encrypted, patched, protected, not jailbroken, and Conditional Access turns that verdict into a door that opens or stays shut. Skip the link and you have built an inventory rather than a control, because the failing device still collects the mail. When an insurance questionnaire asks how device health is enforced, this connection is the thing it is really asking about.
Applications and patching that happen without asking
Software arrives from a central catalog, updates run on a schedule with deadlines that stop being optional once a grace period expires, and reporting names the machines that have fallen behind alongside the reason. Leave a fleet unmanaged and one pattern appears everywhere: restarts postponed indefinitely. A deadline is the only mechanism that reliably ends that.
Joiner and leaver that completes itself
Day one for a new hire means a configured machine, the right licenses and the right access, with nobody working down a checklist. Departure day means access gone inside the hour, company hardware wiped, personal hardware cleared of the company side alone. Any offboarding that depends on a person remembering a step will eventually skip it, and the skipped step is precisely what an auditor or an insurer goes looking for.
Never ask to fully manage an employee-owned phone.
More rollouts stall here than on any engineering problem, and a single sentence prevents it. The error is one of scope: one policy set gets aimed at every device because building two felt like extra work.
- Enroll a personal handset under a corporate profile and the employer gains the power to erase the entire device, read the full list of installed applications, and under some configurations govern the whole phone. Objecting to that on hardware you paid for and fill with family photographs is a reasonable position, and in the US it carries additional weight, since New York, Connecticut and Delaware among others oblige employers to notify staff about electronic monitoring, and heavy-handed device control invites exactly that scrutiny.
- For hardware the employee owns, protect the applications instead of the device. Work data sits behind its own PIN inside approved applications, cannot be copied or saved outward, and can be removed on its own. Personal apps stay private, the handset cannot be located, and nothing outside the work container can be erased. Explained plainly, that is a proposition most people accept without argument.
- Reserve full management for company property, where the case makes itself: our hardware, our data. Build the two as genuinely separate policy sets rather than one policy carrying a list of exceptions, because exception lists never stop growing.
- Publish the explanation before anyone enrolls, not after the first rumor circulates. Programs that move quickly are the ones where staff read a plain description of what IT can and cannot see on each device type in advance. Programs that stall are the ones where an employee found a capability nobody mentioned and told the rest of the company.
Four things that make a rollout stick.
We write the staff communication, not just the policy
When people push back on enrollment, the root cause is usually something nobody explained rather than something badly designed. We produce a plain-English note describing exactly what IT can observe and control on each category of device, circulated before the first enrollment request goes out. That single page defuses most of the objections that otherwise consume weeks, and it doubles as your disclosure record in states that expect employees to be told about monitoring.
We check what you already own first
Business Premium, E3 and E5 all include Intune, which means a sizeable share of the companies asking us about device management already pay for a platform sitting idle in their tenant. We settle that question before anyone writes a purchase order, and the recommendation is frequently to deploy the entitlement you hold rather than acquire another one.
Application packaging done properly
What separates a platform that helps from a platform that irritates is the packaging work: accurate detection rules, dependencies ordered correctly, supersedence configured so upgrades replace rather than accumulate. Detection is where this usually breaks, and a faulty rule will cheerfully report success on an install that never happened, indefinitely.
Built so the audit answer already exists
Encryption status, patch position, compliance drift and offboarding proof accumulate as a by-product of running the fleet, across Apple and Android as well as Windows. When a SOC 2 auditor, a HIPAA risk assessment or an insurance renewal asks where the fleet stands, somebody exports a report instead of opening a project. A report that quietly omits every Mac is not a fleet report at all.
The management platforms, and what sits around them.
The management platforms
Companies already standardized on Microsoft 365 usually find the answer sitting inside a subscription they pay for today. Specialist tools justify themselves at volume, or where nearly every machine carries an Apple logo.
- Microsoft IntuneOne console spanning Windows, Apple and Android, and an entitlement that ships inside Business Premium, E3 and E5.
- Apple Business ManagerCosts nothing, and without it zero-touch on Apple hardware is impossible whichever MDM you run.
- Jamf ProDeep Apple tooling for Mac-heavy shops, with a straight answer on when Intune already covers you.
- Android EnterpriseEvery Android enrollment route, and the wipe-or-no-wipe question that belongs before the purchase order.
What turns management into security
Enrollment on its own produces a list of devices. These are the components that turn that list into something capable of refusing access.
- Microsoft EntraConditional Access, which converts a failed compliance check into a closed door rather than a line in a report.
- Microsoft DefenderThreat signal from the endpoint feeding straight into whether a device still counts as healthy.
- Endpoint securityThe broader endpoint program across platforms and vendors.
- MFA solutionsStrong authentication paired with device health, which together leave a stolen token worth very little.
The decisions inside the discipline
Nobody buys device management in isolation, and the expensive errors concentrate in a handful of choices. Each has a page of its own.
- Device enrollment designWhich route each group of devices takes, and which of those routes begin by erasing the machine.
- Kiosk and shared devicesDisplays, terminals and handhelds passed between shifts, pinned to a single purpose.
- Cybersecurity audit and complianceEncryption coverage, patch currency and offboarding proof are perennial findings in these reviews.
- Managed IT servicesDevices handled inside a complete outsourced IT function instead of as a one-off deployment.
Six US environments and what drives the device requirement.
Distributed and remote-first teams
People spread across several states, or working entirely from home, whose laptops may never once reach a corporate network. Self-configuring enrollment and cloud-delivered patching stop being conveniences here and become the only mechanism available, because there is no office to bring the machine into.
Retail and hospitality
Tablets shared at the counter, pinned to the application they exist to run, cleared between shifts, and recoverable on the day one leaves a store in somebody's bag.
Clinics and healthcare
Any device touching protected health information needs encryption, controlled software installation, and records proving both. Those controls and the evidence they generate line up directly with the HIPAA Security Rule safeguards a risk assessment puts under a microscope.
Warehousing and field operations
Ruggedized handhelds passed between crews, where the real difficulty is switching users quickly without everybody sharing one login and destroying the ability to attribute anything to anyone.
Regulated financial firms
GLBA and the FTC Safeguards Rule, plus NYDFS Part 500 where it applies, all expect device controls that are written down and evidenced, and expect the evidence to span the whole fleet rather than the Windows portion of it.
Schools and training providers
Tablets moving between classes, filtering obligations to satisfy, and a device population that turns over with every new intake.
Four ways a device gets managed, and when each applies.
Model
Corporate, fully managed
- Who owns the device
- Company
- What IT can do
- Full policy, app deployment, full wipe, restrictions
- What IT cannot do
- Little is off limits, since the hardware belongs to the company
- Typical use
- Standard-issue laptops and phones
Model
Corporate, shared or kiosk
- Who owns the device
- Company
- What IT can do
- Pin to one app, clear between users, retain no personal data
- What IT cannot do
- Serve as somebody's personal device in any form
- Typical use
- Retail point of sale, warehouse handhelds, clinic tablets
Model
Personal, app protection only
- Who owns the device
- Employee
- What IT can do
- Protect and selectively remove company data inside approved apps
- What IT cannot do
- View personal apps, locate the handset, or erase it
- Typical use
- BYOD phones, contractor laptops
Model
Personal, user enrollment
- Who owns the device
- Employee
- What IT can do
- Administer a walled-off work area on the device
- What IT cannot do
- Reach anything living in the personal area
- Typical use
- Employee-owned iPhones needing a little more control
Five steps, and the pilot is the one not to compress.
- 1
Fleet discovery and model decision
Week 1
An inventory of what exists, who owns each machine, which operating systems are in play, and which management model each population belongs in. The corporate versus personal boundary gets drawn here, and HR needs a seat at that table alongside IT.
- 2
Design and staff communication
Weeks 1-2
Compliance rules, configuration profiles, the Conditional Access connection and a catalog of applications to package. Running beside it, the plain-English note telling employees what IT can and cannot see on each device type, signed off before a single enrollment request is sent.
- 3
Application packaging
Weeks 2-5
Your software prepared with detection rules that work, dependencies sequenced and supersedence configured. Fifteen to thirty titles is the usual count worth doing properly at mid-market scale, and the payoff is a recurring support burden that disappears permanently.
- 4
Pilot with real users
Weeks 4-6
Fifteen to twenty colleagues from different roles doing genuine work, deliberately including somebody whose workflow nobody quite understands, because that is where the surprises live. Printing and line-of-business software are where a pilot earns its keep every time.
- 5
Rollout and steady state
Weeks 6-10
Department by department, with new hardware arriving pre-configured and existing hardware brought in by wave. Then it becomes routine: patch cycles, compliance monitoring, application updates, and joiner and leaver handling that runs itself.
What US businesses ask about device management.
Where to go next.
Microsoft Intune
The platform sitting unused in a great many tenants already: compliance rules, app protection, configuration and patching.
Device enrollment design
The enrollment choice examined properly, including which routes begin by erasing the machine and which do not.
Microsoft Entra
Conditional Access, the component that converts a compliance verdict into an actual access decision.
Check whether the platform you were about to buy is already in your subscription.
We take stock of the hardware, read what your Microsoft subscriptions already entitle you to, and set out which management model belongs to which population. You get that in writing, and for a fair number of US businesses it concludes that the license has been paid for all along and what remains is deployment rather than procurement.
Related Services
Explore more solutions that work great with this service