IT Jargon Explained

What is Mobile Device Management (MDM)?

Mobile device management (MDM) is an automation and provisioning solution that IT admins set up once, so devices are automatically enrolled and secured, either through zero-touch enrollment or by inviting a user to enroll. From a centralized console, MDM lets organizations configure, monitor and manage smartphones, tablets, laptops and other endpoints throughout their lifecycle. It gives IT teams the ability to enforce security policies, deploy apps and track compliance across the entire device fleet.

How mobile device management works

Mobile device management works by connecting a device to a management platform, so administrators can apply settings, deploy applications, enforce security policies and monitor compliance from a central location.

Most mobile device management platforms follow the same basic process:

  1. Enroll the device.
  2. Install a management profile or management framework.
  3. Apply policies and configurations.
  4. Monitor device status and compliance.
  5. Send remote management commands when needed.

On Apple devices, MDM platforms use the Apple MDM protocol or the Declarative Device Management Framework (DDM) and Apple Push Notification services (APNs) to communicate with managed devices. Android management commonly relies on Android Enterprise and the Android Management API. Windows devices use built-in MDM capabilities and Configuration Service Providers (CSPs).

Device enrollment

Device enrollment is the process of registering a device with a mobile device management platform. Enrollment establishes the management relationship that allows IT teams to apply policies, deploy apps, enforce security settings and monitor compliance.

Common enrollment methods include:

  • Zero-touch enrollment
  • Automated device enrollment
  • User-initiated enrollment
  • QR code enrollment
  • Provisioning-based enrollment

Once enrollment is complete, the device can receive management policies and configurations from the organization.

MDM profiles and configuration

An MDM profile is a collection of settings and policies that tell a device how it should be managed. MDM profiles may include Wi-Fi settings, VPN configurations, security controls, certificates, email settings, restrictions and application policies.

When an MDM profile is removed, the organization may lose the ability to manage the device, apply policies, deploy apps or perform remote actions. The exact impact depends on the operating system, enrollment method and ownership model.

What MDM can and cannot see

Mobile device management gives administrators visibility into the information required to manage and secure devices. However, MDM platforms are generally designed to manage devices and corporate data, not monitor personal activity.

The information available to administrators may vary by platform, ownership model and organizational policy.

MDM can typically see

MDM cannot typically see

Device model and serial number

Personal text messages

Operating system version

Personal photos and videos

Device ownership status

Personal email content

Security and compliance status

Personal contacts

Encryption status

Personal passwords

Managed application inventory

Keystrokes

Device configuration settings

Content stored inside personal apps

Location information on many corporate-owned devices

Personal browsing activity in unmanaged apps

Organizations should clearly communicate what information is collected, how it is used and what privacy protections apply to managed devices.

Core capabilities of MDM software

Mobile device management software helps organizations manage, secure and monitor devices from a centralized administrative console. While capabilities vary by vendor, most MDM software includes several common functions.

Configuration management

Mobile device management software can apply and maintain settings such as Wi-Fi configurations, VPN settings, email profiles, operating system restrictions, and security controls across devices.

App management and distribution

MDM software can deploy, update, configure and remove applications on managed devices. This helps organizations maintain consistent software configurations and reduces manual administration.

Security policy and compliance

Mobile device management allows organizations to enforce passcode requirements, encryption settings, operating system update policies and other security controls. Compliance monitoring helps identify devices that fall outside policy requirements.

Certificate and identity management

Many MDM platforms support digital certificate deployment and integration with identity providers. These capabilities help organizations manage authentication and access to business resources.

Remote lock and wipe

Administrators can use MDM tools to remotely lock devices, perform selective wipes of business data or erase devices when they are lost, stolen or retired.

Inventory and reporting

MDM software provides visibility into device hardware, software, compliance status and management activity. Reporting capabilities help organizations support operational and compliance requirements.

Device ownership models and common deployment scenarios: BYOD, corporate-owned, kiosk, etc.

Mobile device management supports several ownership models, each with a different balance between organizational control and user flexibility. The deployment scenarios below can apply across multiple platforms, while Apple and Android each use their own enrollment and management approaches discussed in the following sections.

Model

Definition

Ownership

Typical use cases

Bring Your Own Device (BYOD)

Employee-owned devices enrolled with limited management scope, often separating personal and work data

Employee-owned

Employees accessing corporate email or apps on personal smartphones/tablets

Corporate-Owned Device Management

Company-owned devices fully managed and controlled by IT, with full policy enforcement and configuration control

Organization-owned

Company laptops and phones issued to employees, executive devices and standard office endpoints

Kiosk

Devices locked into a single app or a restricted set of apps for a dedicated function

Organization-owned

Retail checkout tablets, self-service kiosks, digital signage, restaurant ordering stations

Frontline / Shared Devices

Devices shared among multiple workers, often with per-shift or per-user check-in and check-out workflows.

Organization-owned

Warehouse scanners, hospital shared tablets, retail floor associates' handheld devices

Rugged / Field Devices

Industrial or ruggedized devices managed for durability and connectivity in harsh environments

Organization-owned

Delivery driver scanners, utility field technician tablets, logistics handheld computers

Education (1:1 or Shared)

Devices issued to students, often with content filtering and app restrictions tailored to classroom use

Organization-owned

School-issued Chromebooks or iPads, shared classroom tablet carts

As organizations move from BYOD to COBO and kiosk deployments, the management scope typically increases and privacy considerations change.

Apple enrollment options

Apple supports several enrollment methods that allow organizations to manage corporate-owned and personally owned devices. The enrollment method determines the level of management available and whether a device is supervised.

Enrollment method

Definition

Device ownership

Typical use cases

Automated Device Enrollment (ADE)

Devices purchased through Apple Business Manager/Apple School Manager auto-enroll into MDM at first setup, with supervision applied.

Organization-owned

Corporate-owned fleet deployment at scale, zero-touch provisioning

Account-Driven Device Enrollment

Newer enrollment method where a user signs in with a Managed Apple Account to enroll the device directly into MDM (no ABM/ASM required; device is not supervised).

Organization-owned or employee-owned, varies

Corporate devices not procured through ABM, or orgs wanting device-level MDM without supervision

Account-Driven User Enrollment

User signs in with a Managed Apple Account; creates a separate encrypted volume/data partition for managed data, keeping personal and work data isolated.

Employee-owned (personal device)

BYOD with strong data separation

Profile Enrollment

User manually installs an MDM configuration profile (via Safari or Settings), not tied to a Managed Apple Account or ABM/ASM.

Organization-owned or employee-owned, varies

Legacy enrollment path, ad-hoc or unmanaged-procurement devices

Shared iPad

Supervised devices (via ADE) configured to support multiple users, each signing in with a Managed Apple Account to access their own separate data.

Organization-owned

Shift workers, education, frontline/shared-use scenarios

Android Enterprise deployment models

Android Enterprise uses deployment models that determine how work and personal data are separated and how much control an organization has over a device.

Deployment model

Description

Device ownership

Typical use cases

Work Profile

Android Enterprise mode that creates a separate, encrypted container for work apps/data on a personal (BYOD) device.

Employee-owned

BYOD programs

Fully Managed Device

Android Enterprise mode where the entire device is corporate-owned and controlled by IT, typically used for corporate-issued devices.

Organization-owned

Corporate-owned devices used exclusively for work where the organization manages and controls applications, settings and security policies

Corporate-Owned Work Profile (COPE)

Android Enterprise mode combining a fully managed device with a work profile, allowing both corporate control and personal use.

Organization-owned

Corporate-owned devices with limited personal use

Corporate-Owned Business Only (COBO)

Android Enterprise mode where the organization fully manages the device and restricts it to business use only, with no expectation of personal use.

Organization-owned

Full administrative control with no personal use expected

Corporate-Owned Single-Use (COSU)

Android Enterprise deployment model designed for devices dedicated to a single business purpose or limited set of approved functions. The device is fully managed and highly restricted.

Organization-owned

Self-service kiosks, digital signage, point-of-sale systems, check-in stations, inventory scanners and other purpose-built devices

Dedicated Device

Android Enterprise mode that allows a device to be configured for a specific business purpose and restricted to one or more approved applications. Dedicated devices are commonly deployed in COSU scenarios.

Organization-owned

Retail, warehouse, logistics, healthcare, field service, and frontline scenarios

MDM vs. EMM vs. UEM vs. AEM

Mobile device management is one category of endpoint management technology. As organizations added more device types and management requirements, broader management approaches emerged.

Technology

Definition

What it added

Mobile Device Management (MDM)

Mobile device management focuses on enrolling, configuring, securing and monitoring mobile devices.

Centralized mobile device management

Enterprise Mobility Management (EMM)

Enterprise mobility management extends MDM with application and content management capabilities.

Mobile apps and content management

Unified endpoint management (UEM)

Unified endpoint management manages mobile devices, Windows Servers, PCs, Macs, Linux and other endpoints from a single solution.

Broad endpoint coverage

Autonomous endpoint management (AEM)

Autonomous endpoint management adds automation and intelligent remediation capabilities to endpoint management.

Greater automation and autonomous actions

Mobile device management vs. modern device management

The acronym MDM can refer to either mobile device management or modern device management. Although the terms sound similar, they describe different concepts.

Mobile device management refers to the technology used to manage and secure devices. Modern device management refers to a cloud-first management approach that uses modern operating system frameworks, identity services and management tools.

What a mobile device management policy covers

A mobile device management policy is a document that defines how managed devices are governed within an organization. Mobile device management policies help establish security requirements, user responsibilities and privacy expectations.

A typical MDM policy may include:

  • Enrollment scope and eligibility
  • Passcode requirements
  • Encryption requirements
  • Approved and restricted apps
  • Network and VPN settings
  • Data separation requirements
  • Conditions for remote lock or wipe
  • User responsibilities
  • Privacy commitments and disclosures

A clear MDM policy helps organizations balance security requirements, compliance obligations and employee experience.

Benefits of mobile device management

Mobile device management helps organizations secure devices, improve operational efficiency and maintain visibility across distributed environments.

Consistent security posture

Mobile device management helps organizations apply security controls consistently across managed devices, regardless of location or operating system.

Stronger identity and authentication controls

Mobile device management can integrate with identity providers to enforce authentication requirements, such as Platform SSO or conditional access, helping ensure only verified users and trusted devices can access corporate resources.

Faster provisioning

Automated enrollment and configuration allow new devices to be deployed more quickly with fewer manual steps.

Reduced manual IT effort

Centralized management reduces the need for repetitive administrative tasks and helps IT teams manage larger device environments efficiently.

Audit and compliance support

Mobile device management provides visibility into policy compliance, device inventory and management activity that may support audit and reporting requirements.

Reduced device risk

Remote lock, remote wipe and policy enforcement capabilities can help reduce the risks associated with lost, stolen or compromised devices.

MDM across operating systems

iOS and iPadOS

Mobile device management on iPhone and iPad iOS devices uses Apple's management framework to deploy settings, distribute apps, enforce security policies and support corporate and personal ownership models.

Android

Mobile device management on Android devices commonly uses Android Enterprise capabilities to separate work and personal data, manage apps and enforce organizational policies.

macOS

Mobile device management on macOS supports device configuration, software deployment, compliance monitoring and security management across Apple desktop and laptop devices.

Windows

Mobile device management on Windows uses built-in management capabilities and Configuration Service Providers (CSPs) to manage settings, applications, updates and compliance policies.

XR, VR, and wearable devices

Mobile device management can also support emerging endpoint categories, including extended reality (XR) devices, virtual reality (VR) headsets, wearable technology and other specialized endpoints. As organizations expand beyond traditional smartphones and laptops, MDM helps apply security policies, manage applications, maintain compliance and support device lifecycle management across a broader range of connected devices.

Examples of managed specialty endpoints may include XR and VR headsets, wearable devices, rugged mobile computers, kiosks and other purpose-built devices used in healthcare, retail, logistics, manufacturing and field service environments.

Support for XR, VR and wearable devices varies by manufacturer, operating system and management framework. Organizations should evaluate platform-specific management capabilities when deploying these device types at scale.

Frequently asked questions

What is MDM in simple terms?

MDM, or mobile device management, is software that helps organizations manage, secure, monitor and support smartphones, tablets, laptops and other endpoint devices from a centralized platform.

Is MDM the same as UEM?

No. Mobile device management focuses primarily on managing devices, while unified endpoint management (UEM) extends management across a wider range of endpoint types, including Windows servers, Linux, PCs and other endpoints.

Can my employer see my personal data through MDM?

No. Mobile device management is commonly used in bring-your-own-device (BYOD) programs. Organizations can manage only business data and security requirements while limiting access to personal information.

What is the difference between MDM and mobile application management?

Mobile application management (MAM) focuses on managing and securing business applications and the data they contain, without necessarily managing the entire device. Organizations often use MAM to apply security policies to corporate apps, protect business data, and support bring-your-own-device (BYOD) programs. While many MDM platforms include MAM capabilities, some organizations use MAM independently of full device management.

What are some of the most popular MDM vendor examples?

Widely used MDM solutions include Ivanti Neurons for MDM, Microsoft Intune, Jamf, Omnissa Workspace ONE, and Google Workspace endpoint management.