Mobile device management (MDM) is an automation and provisioning solution that IT admins set up once, so devices are automatically enrolled and secured, either through zero-touch enrollment or by inviting a user to enroll. From a centralized console, MDM lets organizations configure, monitor and manage smartphones, tablets, laptops and other endpoints throughout their lifecycle. It gives IT teams the ability to enforce security policies, deploy apps and track compliance across the entire device fleet.
IT Jargon Explained
What is Mobile Device Management (MDM)?
- How mobile device management works
- What MDM can and cannot see
- Core capabilities of MDM software
- Device ownership models and common deployment scenarios: BYOD, corporate-owned, kiosk, etc.
- Apple enrollment options
- Android Enterprise deployment models
- MDM vs. EMM vs. UEM vs. AEM
- Mobile device management vs. modern device management
- What a mobile device management policy covers
- Benefits of mobile device management
- MDM across operating systems
- Frequently asked questions
How mobile device management works
Mobile device management works by connecting a device to a management platform, so administrators can apply settings, deploy applications, enforce security policies and monitor compliance from a central location.
Most mobile device management platforms follow the same basic process:
- Enroll the device.
- Install a management profile or management framework.
- Apply policies and configurations.
- Monitor device status and compliance.
- Send remote management commands when needed.
On Apple devices, MDM platforms use the Apple MDM protocol or the Declarative Device Management Framework (DDM) and Apple Push Notification services (APNs) to communicate with managed devices. Android management commonly relies on Android Enterprise and the Android Management API. Windows devices use built-in MDM capabilities and Configuration Service Providers (CSPs).
Device enrollment
Device enrollment is the process of registering a device with a mobile device management platform. Enrollment establishes the management relationship that allows IT teams to apply policies, deploy apps, enforce security settings and monitor compliance.
Common enrollment methods include:
- Zero-touch enrollment
- Automated device enrollment
- User-initiated enrollment
- QR code enrollment
- Provisioning-based enrollment
Once enrollment is complete, the device can receive management policies and configurations from the organization.
MDM profiles and configuration
An MDM profile is a collection of settings and policies that tell a device how it should be managed. MDM profiles may include Wi-Fi settings, VPN configurations, security controls, certificates, email settings, restrictions and application policies.
When an MDM profile is removed, the organization may lose the ability to manage the device, apply policies, deploy apps or perform remote actions. The exact impact depends on the operating system, enrollment method and ownership model.
What MDM can and cannot see
Mobile device management gives administrators visibility into the information required to manage and secure devices. However, MDM platforms are generally designed to manage devices and corporate data, not monitor personal activity.
The information available to administrators may vary by platform, ownership model and organizational policy.
|
MDM can typically see |
MDM cannot typically see |
|---|---|
|
Device model and serial number |
Personal text messages |
|
Operating system version |
Personal photos and videos |
|
Device ownership status |
Personal email content |
|
Security and compliance status |
Personal contacts |
|
Encryption status |
Personal passwords |
|
Managed application inventory |
Keystrokes |
|
Device configuration settings |
Content stored inside personal apps |
|
Location information on many corporate-owned devices |
Personal browsing activity in unmanaged apps |
Organizations should clearly communicate what information is collected, how it is used and what privacy protections apply to managed devices.
Core capabilities of MDM software
Mobile device management software helps organizations manage, secure and monitor devices from a centralized administrative console. While capabilities vary by vendor, most MDM software includes several common functions.
Configuration management
Mobile device management software can apply and maintain settings such as Wi-Fi configurations, VPN settings, email profiles, operating system restrictions, and security controls across devices.
App management and distribution
MDM software can deploy, update, configure and remove applications on managed devices. This helps organizations maintain consistent software configurations and reduces manual administration.
Security policy and compliance
Mobile device management allows organizations to enforce passcode requirements, encryption settings, operating system update policies and other security controls. Compliance monitoring helps identify devices that fall outside policy requirements.
Certificate and identity management
Many MDM platforms support digital certificate deployment and integration with identity providers. These capabilities help organizations manage authentication and access to business resources.
Remote lock and wipe
Administrators can use MDM tools to remotely lock devices, perform selective wipes of business data or erase devices when they are lost, stolen or retired.
Inventory and reporting
MDM software provides visibility into device hardware, software, compliance status and management activity. Reporting capabilities help organizations support operational and compliance requirements.
Device ownership models and common deployment scenarios: BYOD, corporate-owned, kiosk, etc.
Mobile device management supports several ownership models, each with a different balance between organizational control and user flexibility. The deployment scenarios below can apply across multiple platforms, while Apple and Android each use their own enrollment and management approaches discussed in the following sections.
|
Model |
Definition |
Ownership |
Typical use cases |
|---|---|---|---|
|
Bring Your Own Device (BYOD) |
Employee-owned devices enrolled with limited management scope, often separating personal and work data |
Employee-owned |
Employees accessing corporate email or apps on personal smartphones/tablets |
|
Corporate-Owned Device Management |
Company-owned devices fully managed and controlled by IT, with full policy enforcement and configuration control |
Organization-owned |
Company laptops and phones issued to employees, executive devices and standard office endpoints |
|
Kiosk |
Devices locked into a single app or a restricted set of apps for a dedicated function |
Organization-owned |
Retail checkout tablets, self-service kiosks, digital signage, restaurant ordering stations |
|
Frontline / Shared Devices |
Devices shared among multiple workers, often with per-shift or per-user check-in and check-out workflows. |
Organization-owned |
Warehouse scanners, hospital shared tablets, retail floor associates' handheld devices |
|
Rugged / Field Devices |
Industrial or ruggedized devices managed for durability and connectivity in harsh environments |
Organization-owned |
Delivery driver scanners, utility field technician tablets, logistics handheld computers |
|
Education (1:1 or Shared) |
Devices issued to students, often with content filtering and app restrictions tailored to classroom use |
Organization-owned |
School-issued Chromebooks or iPads, shared classroom tablet carts |
As organizations move from BYOD to COBO and kiosk deployments, the management scope typically increases and privacy considerations change.
Apple enrollment options
Apple supports several enrollment methods that allow organizations to manage corporate-owned and personally owned devices. The enrollment method determines the level of management available and whether a device is supervised.
|
Enrollment method |
Definition |
Device ownership |
Typical use cases |
|---|---|---|---|
|
Automated Device Enrollment (ADE) |
Devices purchased through Apple Business Manager/Apple School Manager auto-enroll into MDM at first setup, with supervision applied. |
Organization-owned |
Corporate-owned fleet deployment at scale, zero-touch provisioning |
|
Account-Driven Device Enrollment |
Newer enrollment method where a user signs in with a Managed Apple Account to enroll the device directly into MDM (no ABM/ASM required; device is not supervised). |
Organization-owned or employee-owned, varies |
Corporate devices not procured through ABM, or orgs wanting device-level MDM without supervision |
|
Account-Driven User Enrollment |
User signs in with a Managed Apple Account; creates a separate encrypted volume/data partition for managed data, keeping personal and work data isolated. |
Employee-owned (personal device) |
BYOD with strong data separation |
|
Profile Enrollment |
User manually installs an MDM configuration profile (via Safari or Settings), not tied to a Managed Apple Account or ABM/ASM. |
Organization-owned or employee-owned, varies |
Legacy enrollment path, ad-hoc or unmanaged-procurement devices |
|
Shared iPad |
Supervised devices (via ADE) configured to support multiple users, each signing in with a Managed Apple Account to access their own separate data. |
Organization-owned |
Shift workers, education, frontline/shared-use scenarios |
Android Enterprise deployment models
Android Enterprise uses deployment models that determine how work and personal data are separated and how much control an organization has over a device.
|
Deployment model |
Description |
Device ownership |
Typical use cases |
|---|---|---|---|
|
Work Profile |
Android Enterprise mode that creates a separate, encrypted container for work apps/data on a personal (BYOD) device. |
Employee-owned |
BYOD programs |
|
Fully Managed Device |
Android Enterprise mode where the entire device is corporate-owned and controlled by IT, typically used for corporate-issued devices. |
Organization-owned |
Corporate-owned devices used exclusively for work where the organization manages and controls applications, settings and security policies |
|
Corporate-Owned Work Profile (COPE) |
Android Enterprise mode combining a fully managed device with a work profile, allowing both corporate control and personal use. |
Organization-owned |
Corporate-owned devices with limited personal use |
|
Corporate-Owned Business Only (COBO) |
Android Enterprise mode where the organization fully manages the device and restricts it to business use only, with no expectation of personal use. |
Organization-owned |
Full administrative control with no personal use expected |
|
Corporate-Owned Single-Use (COSU) |
Android Enterprise deployment model designed for devices dedicated to a single business purpose or limited set of approved functions. The device is fully managed and highly restricted. |
Organization-owned |
Self-service kiosks, digital signage, point-of-sale systems, check-in stations, inventory scanners and other purpose-built devices |
|
Dedicated Device |
Android Enterprise mode that allows a device to be configured for a specific business purpose and restricted to one or more approved applications. Dedicated devices are commonly deployed in COSU scenarios. |
Organization-owned |
Retail, warehouse, logistics, healthcare, field service, and frontline scenarios |
MDM vs. EMM vs. UEM vs. AEM
Mobile device management is one category of endpoint management technology. As organizations added more device types and management requirements, broader management approaches emerged.
|
Technology |
Definition |
What it added |
|---|---|---|
|
Mobile Device Management (MDM) |
Mobile device management focuses on enrolling, configuring, securing and monitoring mobile devices. |
Centralized mobile device management |
|
Enterprise Mobility Management (EMM) |
Enterprise mobility management extends MDM with application and content management capabilities. |
Mobile apps and content management |
|
Unified endpoint management manages mobile devices, Windows Servers, PCs, Macs, Linux and other endpoints from a single solution. |
Broad endpoint coverage |
|
|
Autonomous endpoint management adds automation and intelligent remediation capabilities to endpoint management. |
Greater automation and autonomous actions |
Mobile device management vs. modern device management
The acronym MDM can refer to either mobile device management or modern device management. Although the terms sound similar, they describe different concepts.
Mobile device management refers to the technology used to manage and secure devices. Modern device management refers to a cloud-first management approach that uses modern operating system frameworks, identity services and management tools.
What a mobile device management policy covers
A mobile device management policy is a document that defines how managed devices are governed within an organization. Mobile device management policies help establish security requirements, user responsibilities and privacy expectations.
A typical MDM policy may include:
- Enrollment scope and eligibility
- Passcode requirements
- Encryption requirements
- Approved and restricted apps
- Network and VPN settings
- Data separation requirements
- Conditions for remote lock or wipe
- User responsibilities
- Privacy commitments and disclosures
A clear MDM policy helps organizations balance security requirements, compliance obligations and employee experience.
Benefits of mobile device management
Mobile device management helps organizations secure devices, improve operational efficiency and maintain visibility across distributed environments.
Consistent security posture
Mobile device management helps organizations apply security controls consistently across managed devices, regardless of location or operating system.
Stronger identity and authentication controls
Mobile device management can integrate with identity providers to enforce authentication requirements, such as Platform SSO or conditional access, helping ensure only verified users and trusted devices can access corporate resources.
Faster provisioning
Automated enrollment and configuration allow new devices to be deployed more quickly with fewer manual steps.
Reduced manual IT effort
Centralized management reduces the need for repetitive administrative tasks and helps IT teams manage larger device environments efficiently.
Audit and compliance support
Mobile device management provides visibility into policy compliance, device inventory and management activity that may support audit and reporting requirements.
Reduced device risk
Remote lock, remote wipe and policy enforcement capabilities can help reduce the risks associated with lost, stolen or compromised devices.
MDM across operating systems
iOS and iPadOS
Mobile device management on iPhone and iPad iOS devices uses Apple's management framework to deploy settings, distribute apps, enforce security policies and support corporate and personal ownership models.
Android
Mobile device management on Android devices commonly uses Android Enterprise capabilities to separate work and personal data, manage apps and enforce organizational policies.
macOS
Mobile device management on macOS supports device configuration, software deployment, compliance monitoring and security management across Apple desktop and laptop devices.
Windows
Mobile device management on Windows uses built-in management capabilities and Configuration Service Providers (CSPs) to manage settings, applications, updates and compliance policies.
XR, VR, and wearable devices
Mobile device management can also support emerging endpoint categories, including extended reality (XR) devices, virtual reality (VR) headsets, wearable technology and other specialized endpoints. As organizations expand beyond traditional smartphones and laptops, MDM helps apply security policies, manage applications, maintain compliance and support device lifecycle management across a broader range of connected devices.
Examples of managed specialty endpoints may include XR and VR headsets, wearable devices, rugged mobile computers, kiosks and other purpose-built devices used in healthcare, retail, logistics, manufacturing and field service environments.
Support for XR, VR and wearable devices varies by manufacturer, operating system and management framework. Organizations should evaluate platform-specific management capabilities when deploying these device types at scale.
Frequently asked questions
What is MDM in simple terms?
MDM, or mobile device management, is software that helps organizations manage, secure, monitor and support smartphones, tablets, laptops and other endpoint devices from a centralized platform.
Is MDM the same as UEM?
No. Mobile device management focuses primarily on managing devices, while unified endpoint management (UEM) extends management across a wider range of endpoint types, including Windows servers, Linux, PCs and other endpoints.
Can my employer see my personal data through MDM?
No. Mobile device management is commonly used in bring-your-own-device (BYOD) programs. Organizations can manage only business data and security requirements while limiting access to personal information.
What is the difference between MDM and mobile application management?
Mobile application management (MAM) focuses on managing and securing business applications and the data they contain, without necessarily managing the entire device. Organizations often use MAM to apply security policies to corporate apps, protect business data, and support bring-your-own-device (BYOD) programs. While many MDM platforms include MAM capabilities, some organizations use MAM independently of full device management.
What are some of the most popular MDM vendor examples?
Widely used MDM solutions include Ivanti Neurons for MDM, Microsoft Intune, Jamf, Omnissa Workspace ONE, and Google Workspace endpoint management.