Smartphones and tablets now give employees access to almost everything they need for work.
From one device, they may be able to open:
- Business email
- Microsoft Teams
- SharePoint
- OneDrive
- Customer records
- Finance systems
- Cloud applications
- Company documents
- Authentication tools
- Business contacts
That flexibility helps employees work from home, customer sites, trains, airports and temporary offices.
It also creates risk.
A phone may be lost. A tablet may be shared with a family member. A former employee may retain access to company email. An unsupported device may continue connecting to sensitive systems.
Without central management, the organisation may not know:
- Which devices have business access
- Whether they are encrypted
- Whether security updates are installed
- Whether screen locks are enabled
- Whether business data can be removed
- Which applications are being used
- Whether a lost device has been reported
- Whether former employees still have access
Mobile Device Management can help bring those devices under organisational control.
Stratiis helps businesses use Mobile Device Management and Microsoft Intune to protect mobile access while keeping the employee experience practical.
Secure the business data. Manage the device lifecycle. Give employees safe access wherever they work.
What is Mobile Device Management?
Mobile Device Management, often shortened to MDM, is technology used to configure, secure and manage business smartphones and tablets centrally.
It may allow an organisation to:
- Enrol devices
- Apply security policies
- Require screen locks
- Enforce encryption
- Deploy applications
- Configure email
- Configure Wi-Fi
- Control business access
- Check device compliance
- Remove company data
- Lock or wipe lost devices
- Block unsupported devices
- Maintain an asset record
- Support joiners and leavers
MDM may be used with:
- Company-owned smartphones
- Company-owned tablets
- Personally owned devices
- Shared devices
- Kiosk devices
- Field-service tablets
- Frontline-worker devices
- Meeting-room tablets
- Dedicated business applications
The controls should reflect who owns the device and how it is used.
Why do businesses need Mobile Device Management?
A mobile phone may look personal, but the information it can access may be highly sensitive.
Employees may use mobile devices to reach:
- Customer information
- Tenant records
- Financial documents
- Payroll
- Contracts
- Cloud files
- Internal messages
- Password reset tools
- Multi-factor authentication
- Business applications
If a device is lost, stolen or poorly protected, someone may gain access to more than the phone itself.
Mobile Device Management can help reduce this risk by making business access conditional on agreed security standards.
Is your mobile estate under control?
You may recognise some of these situations:
- Nobody has a complete list of mobile devices
- Employees configure email themselves
- Personal phones access business data without approval
- Former employees remain signed into applications
- Lost phones are handled informally
- Devices use weak screen locks
- Security updates are not installed
- Business documents can be copied into personal applications
- Employees share tablets
- Company applications are installed inconsistently
- Old devices remain enrolled
- SIM records and device records do not match
- The organisation cannot remove business data remotely
- Devices are used after manufacturer support ends
- Mobile access is granted without a formal onboarding process
- Nobody knows which version of Android or iOS is in use
These issues often develop gradually.
A managed approach gives the organisation clearer visibility and more consistent protection.
Our Mobile Device Management services
Stratiis can help with:
- Microsoft Intune
- Microsoft 365 mobile security
- Apple device management
- Android device management
- iPhone and iPad management
- Company-owned mobile devices
- Bring Your Own Device
- Mobile application management
- Device enrolment
- Automated device setup
- Security policies
- Compliance policies
- Conditional Access
- Application deployment
- Wi-Fi configuration
- Email configuration
- Remote lock and wipe
- Lost-device response
- Shared-device management
- Kiosk devices
- Joiner and leaver processes
- Device reporting
- Mobile asset records
- Ongoing support
Microsoft Intune
Microsoft Intune is a cloud-based service used to manage devices, applications and access.
It can work with Microsoft 365 and Microsoft Entra ID to help organisations control how employees access business information.
Intune may support:
- Device enrolment
- Compliance policies
- Security configuration
- Application deployment
- Mobile application protection
- Conditional Access
- Remote wipe
- Device inventory
- Operating-system reporting
- Password requirements
- Encryption
- Wi-Fi profiles
- Email profiles
- Shared and dedicated devices
It can manage more than mobile phones.
Depending on the organisation’s licensing and design, it may also support:
- Windows computers
- macOS devices
- Tablets
- Specialist frontline devices
This page focuses mainly on smartphones and tablets.
Device management or application management?
These two approaches are related but different.
Mobile Device Management
Mobile Device Management applies controls to the device itself.
It may enforce:
- Screen-lock requirements
- Encryption
- Operating-system versions
- Approved configurations
- Device restrictions
- Remote wipe
- Device compliance
This is commonly used for company-owned devices.
Mobile Application Management
Mobile Application Management protects business applications and data, sometimes without managing the whole personal device.
It may control:
- Business email
- Teams
- OneDrive
- SharePoint
- Copy and paste
- File saving
- Application PINs
- Selective business-data removal
- Sharing between applications
This can be useful in Bring Your Own Device environments.
The right approach depends on device ownership, risk and employee expectations.
Company-owned devices
Company-owned devices normally allow the organisation to apply stronger controls.
The business may be able to:
- Configure the device automatically
- Restrict unapproved applications
- Enforce encryption
- Require strong authentication
- Block account changes
- Control software updates
- Remove all device data
- Restrict personal use
- Apply a standard home screen
- Manage Wi-Fi and VPN settings
- Maintain a clear asset record
The organisation should explain whether limited personal use is allowed.
Employees should understand that a company-owned device may be monitored and managed according to business policy.
Bring Your Own Device
Bring Your Own Device, commonly called BYOD, allows employees to use personal devices for work.
This may improve convenience and reduce hardware costs.
It also creates important questions:
- What business data can the device access?
- What security standard must it meet?
- Can the organisation inspect the whole device?
- Can business data be removed separately?
- Who supports the device?
- What happens when the employee leaves?
- What happens if the device is shared?
- Who pays for mobile data?
- Which applications are allowed?
- How is employee privacy protected?
A BYOD design should not treat a personal phone exactly like a company-owned device.
Application-level protection may provide a better balance in some cases.
Work profiles on Android
Supported Android devices may use a work profile that separates business applications and information from personal use.
This may allow:
- Business applications to appear separately
- Business data to be removed without wiping personal content
- Work applications to use different security rules
- The organisation to manage the work area
- Employees to pause work applications
This can provide a clearer separation between personal and business use.
The exact experience depends on the device, Android version and management method.
Apple device management
Apple devices can be managed using suitable enrolment and management services.
Management may include:
- iPhone and iPad enrolment
- Application deployment
- Security settings
- Wi-Fi profiles
- Email configuration
- Restrictions
- Operating-system requirements
- Lost-device actions
- Supervised company devices
- Automated setup
Organisation-owned Apple devices may be connected to Apple Business Manager to improve deployment and ownership control.
Apple Business Manager
Apple Business Manager helps organisations connect purchased Apple devices with an approved management platform.
It may support:
- Automated enrolment
- Organisation ownership
- Application licensing
- Managed Apple accounts
- Easier device deployment
- Stronger control over company devices
When configured correctly, a new iPhone or iPad can enrol into management during its initial setup.
This can reduce manual configuration.
The organisation should establish ownership and enrolment before devices are distributed where possible.
Android Enterprise
Android Enterprise provides management options for different business use cases.
These may include:
- Personally owned devices with work profiles
- Fully managed company devices
- Dedicated devices
- Company-owned devices with personal use
- Kiosk devices
The correct enrolment method affects what the organisation can control.
It should be selected before large numbers of devices are issued.
Automated device enrolment
Manual setup becomes difficult as the number of devices grows.
Automated enrolment can help configure devices when they are first switched on.
The process may apply:
- Business ownership
- Management enrolment
- Required applications
- Security policies
- Email settings
- Wi-Fi
- Device restrictions
- User authentication
This can reduce setup time and create a more consistent experience.
It also helps prevent users from bypassing required management during initial configuration.
Device compliance
A compliance policy defines the security standards a device must meet.
These may include:
- Supported operating-system version
- Encryption
- Screen lock
- Minimum password length
- Device not rooted or jailbroken
- Approved security software
- No known high-risk status
- Active management enrolment
A device may be marked non-compliant when it fails one or more checks.
The organisation then decides what happens next.
Conditional Access
Conditional Access controls whether a user can reach business services based on defined conditions.
Access decisions may consider:
- User identity
- Device compliance
- Application
- Location
- Sign-in risk
- Multi-factor authentication
- Device ownership
- Operating system
For example, the organisation may require a compliant managed device before allowing access to company email or SharePoint.
Conditional Access links identity security and device management.
It can prevent business data from being accessed on unknown or insecure devices.
Multi-factor authentication
Multi-factor authentication requires more than a password.
A user may need to provide:
- A password
- An approval through an authentication application
- A security key
- A biometric check
- A temporary code
MDM does not replace multi-factor authentication.
The two controls work together.
A managed device can still be compromised by stolen credentials, and strong identity controls do not guarantee the device itself is secure.
Screen-lock policies
A mobile device should lock automatically when it is not in use.
Policies may require:
- A minimum PIN length
- A strong password
- Biometric unlock
- Automatic lock after inactivity
- Limits on repeated failed attempts
- No simple or repeated PINs
The control should be strong enough to protect business information without creating an unusable employee experience.
Biometrics may improve convenience, but they should normally work alongside an approved device passcode.
Device encryption
Encryption helps protect information stored on a device.
Modern smartphones often include encryption as part of the operating system.
Management can help verify that suitable protection is active.
Encryption is most effective when combined with:
- Strong screen locks
- Supported devices
- Secure accounts
- Remote wipe
- Prompt lost-device reporting
Rooted and jailbroken devices
Rooting or jailbreaking modifies a mobile operating system to remove manufacturer restrictions.
This may weaken security and allow untrusted changes.
A managed policy may identify or block devices that appear to be rooted or jailbroken.
Employees should not use modified devices to access business information.
Operating-system updates
Mobile operating systems receive security and reliability updates.
Problems arise when:
- Employees repeatedly delay updates
- Devices cannot run newer versions
- Manufacturers stop supporting older models
- Business applications require a newer version
- Updates are installed without testing
- Shared devices are rarely reviewed
An MDM platform can provide visibility of operating-system versions.
Policies can then encourage or require supported versions.
Unsupported mobile devices
A phone may continue functioning after security support ends.
That does not make it suitable for business use.
Unsupported devices may:
- Stop receiving security fixes
- Fail compliance checks
- Lose application compatibility
- Become unreliable
- Prevent Microsoft 365 access
- Create audit concerns
The organisation should maintain a replacement policy based on support status rather than waiting until hardware failure.
Mobile application deployment
MDM can help install approved applications centrally.
These may include:
- Microsoft Outlook
- Microsoft Teams
- OneDrive
- SharePoint
- Authenticator
- Business applications
- Security tools
- Field-service software
- Housing-management applications
- Expense systems
- VPN applications
Applications may be:
- Required
- Optional
- Available through a company portal
- Removed automatically when access ends
This creates a more consistent setup and reduces reliance on employees finding the correct application themselves.
Company application portals
A company application portal can give employees access to approved software.
They may be able to install:
- Business applications
- Security tools
- Approved productivity software
- Updates
- Specialist role-based tools
This reduces the need for broad access to unmanaged application stores.
It also helps employees identify the genuine business version of an application.
Restricting unapproved applications
On company-owned devices, the organisation may restrict applications that create security, productivity or data-protection risks.
Possible controls may include:
- Blocking unknown application stores
- Preventing sideloading
- Restricting file-sharing applications
- Disabling unapproved backup services
- Controlling social media
- Blocking high-risk applications
- Preventing changes to security settings
Restrictions should be proportionate and clearly communicated.
A business should not collect or control more personal information than it needs.
Protecting business data inside applications
Application-protection policies may control what employees can do with company information.
For example, the organisation may prevent:
- Copying business data into personal applications
- Saving files to personal cloud storage
- Opening attachments in unapproved applications
- Taking screenshots in sensitive applications
- Backing up business information to a personal service
- Sharing documents through personal messaging tools
The policy may also require:
- An application PIN
- Biometric verification
- Encryption
- Regular access checks
- Removal of company data after inactivity
Selective wipe
A selective wipe removes business data and managed application access without deleting the employee’s personal information.
This may be useful when:
- An employee leaves
- A personal device is no longer approved
- A device is replaced
- Business access is withdrawn
- A management profile is removed
Selective wipe is particularly important in BYOD environments.
The exact data removed depends on the management and application design.
Full device wipe
A full wipe restores the device to its factory condition and removes all data.
It may be appropriate when:
- A company-owned device is lost
- A company-owned device is stolen
- The device is being reassigned
- A serious security incident occurs
- The device is being disposed of
- Ownership remains with the organisation
A full wipe should be used carefully.
On a personal device, it could delete personal photographs, messages and applications.
The management model should make the available actions clear.
Remote lock
Remote lock can help secure a device that has been lost or left unattended.
It may:
- Lock the screen
- Require the approved passcode
- Display a recovery message
- Restrict access until the device is found
It should be combined with:
- SIM suspension
- Account review
- Risk assessment
- Remote wipe where necessary
- Incident logging
Lost or stolen devices
A lost mobile device should be treated as a security incident.
The response may include:
- Confirm which device is missing
- Identify the user and business access
- Lock the device
- Suspend the SIM
- Revoke business sessions
- Reset relevant credentials
- Remove or wipe company data
- Review unusual account activity
- Report the incident internally
- Provide a replacement
- Update the asset register
- Assess any data-protection implications
Employees should know how to report a loss immediately.
Waiting until the next working day may increase risk.
Mobile phishing and malicious applications
MDM can improve control of devices and applications.
It does not prevent every mobile threat.
Employees may still receive:
- Phishing emails
- Fraudulent text messages
- Fake authentication prompts
- Malicious QR codes
- Unsafe application links
- Impersonation messages
- Account-recovery scams
Mobile security should also include:
- User awareness
- Email security
- Identity protection
- DNS filtering
- Safe application policies
- Prompt incident reporting
- Account monitoring
Mobile security and SMS authentication
Many business services use SMS codes for authentication.
This can be better than relying on a password alone.
It may still be vulnerable to:
- SIM-swap fraud
- Stolen phones
- Message interception
- Social engineering
- Number reassignment
Where appropriate, organisations may prefer:
- Authentication applications
- Passkeys
- Security keys
- Certificate-based access
- Managed-device authentication
The choice should reflect the service, user and risk.
Wi-Fi configuration
MDM can deploy approved Wi-Fi settings to business devices.
This may help employees connect automatically to:
- Head-office Wi-Fi
- Branch-office Wi-Fi
- Secure employee networks
- Certificate-based wireless services
It can reduce the need to share Wi-Fi passwords manually.
When a wireless profile changes, the new settings may be deployed centrally.
VPN configuration
Some mobile users may need a Virtual Private Network to reach business systems.
MDM can help deploy:
- VPN applications
- Server settings
- Certificates
- Connection profiles
- Application-specific VPNs
A VPN should not be added automatically when cloud applications can be accessed more securely through identity and application controls.
The design should reflect where the business system is hosted.
Email configuration
MDM can help configure business email consistently.
This may include:
- Outlook deployment
- Approved account setup
- Authentication requirements
- Application-protection policies
- Restrictions on native mail applications
- Removal of old accounts
The organisation can reduce the risk of employees configuring company email in unapproved applications.
Managing business contacts
Mobile devices may contain customer, employee and supplier contact details.
The organisation should consider:
- Whether contacts synchronise to personal accounts
- Whether they remain after an employee leaves
- Whether personal and business contacts are mixed
- Whether contact export is allowed
- How shared-role contacts are managed
- Whether customer details are stored locally
Application and device policies can help reduce uncontrolled copying.
Shared mobile devices
Some teams use shared smartphones or tablets.
Examples include:
- Reception devices
- Duty phones
- Warehouse tablets
- Site tablets
- Care or support devices
- Meeting-room controllers
- Shared inspection devices
- Frontline-worker phones
Shared devices need a clear process for:
- User sign-in
- Access removal
- Application access
- Cleaning and charging
- Data separation
- Lost-device reporting
- Shift handover
- Asset ownership
A shared device should not remain permanently signed into one employee’s personal account.
Kiosk and dedicated devices
A kiosk device is configured for a limited task.
It may run:
- A visitor application
- A check-in system
- Digital signage
- A customer survey
- A stock application
- A room-booking application
- A field-service tool
Management may restrict the device to one or several approved applications.
This can improve reliability and reduce misuse.
Frontline-worker devices
Frontline employees may use mobile devices for:
- Job information
- Repairs
- Inspections
- Customer records
- Forms
- Photographs
- Signatures
- Navigation
- Safety applications
- Communication
Their devices may need:
- Rugged protection
- Mobile data
- High battery capacity
- Remote support
- Automated setup
- Application restrictions
- Offline functionality
- Rapid replacement
The mobile service, device and management platform should be designed together.
Mobile Device Management and business SIMs
Mobile Device Management controls the device and access.
The SIM provides mobile connectivity.
Together, they can support:
- Device ownership records
- User and number assignments
- Lost-device response
- Data usage
- Mobile working
- Remote support
- Joiners and leavers
- Business continuity
A suspended SIM does not remove business data already stored on the device.
A remote wipe does not automatically cancel the mobile contract.
Both processes are required.
Joiner processes
A new employee’s mobile access should be prepared before their start date.
The onboarding process may include:
- Approving the device
- Assigning a business number
- Enrolling into management
- Applying security policies
- Installing applications
- Configuring email
- Configuring Wi-Fi
- Configuring authentication
- Recording the asset
- Providing user guidance
- Testing access
This creates a more professional first-day experience.
Role changes
When an employee changes role, their mobile access may also need to change.
The organisation may need to:
- Add applications
- Remove applications
- Change data access
- Adjust mobile permissions
- Remove administrative tools
- Change the assigned device
- Update the mobile plan
- Update the asset register
Mobile permissions should follow job responsibilities.
Leaver processes
When an employee leaves, the organisation should:
- Block sign-in
- Revoke active sessions
- Remove business data
- Retain or reassign the mobile number
- Recover company-owned devices
- Suspend or cancel the SIM
- Remove applications
- Remove management records
- Reset shared-device access
- Update the asset register
- Review customer communication
- Securely prepare the device for reuse
This process should happen promptly and consistently.
Device reassignment
A company-owned phone or tablet may be reassigned to another employee.
Before reassignment, the organisation should:
- Back up required business information
- Remove the previous user
- Perform an approved wipe
- Confirm activation locks are removed
- Update ownership records
- Check hardware condition
- Install updates
- Re-enrol the device
- Apply the new role’s applications
- Test the service
A device should not be handed to a new employee with the previous user’s information still present.
Secure device disposal
When a device reaches the end of its life, the organisation should:
- Remove business accounts
- Wipe the device
- Remove the management record
- Remove SIMs
- Remove activation locks
- Update the asset register
- Confirm data destruction
- Use an approved recycling or disposal route
- Retain evidence where required
A broken screen does not mean the stored information is inaccessible.
Asset management
A mobile-device register may include:
- Device owner
- User
- Manufacturer
- Model
- Serial number
- IMEI
- Mobile number
- SIM details
- Operating system
- Enrolment status
- Compliance status
- Purchase date
- Warranty
- Support end date
- Replacement date
- Current location
MDM reporting can support the asset register.
It should not be the only record of ownership, cost and lifecycle.
Reporting and visibility
Mobile Device Management reporting may show:
- Enrolled devices
- Device owners
- Operating-system versions
- Compliance status
- Encryption
- Applications
- Last check-in
- Device model
- Security state
- Policy failures
- Unsupported devices
- Lost-device actions
Useful reporting can help answer:
- Which devices are not compliant?
- Which devices are no longer active?
- Which users have not enrolled?
- Which models need replacement?
- Which operating-system versions create risk?
- Which applications are missing?
- Are personal devices accessing business data?
Privacy and employee communication
Mobile management can raise understandable employee privacy concerns.
The organisation should explain:
- Which devices are managed
- What information the organisation can see
- What it cannot see
- Which actions it can take
- When a device may be wiped
- Whether location is collected
- How personal information is treated
- What happens when employment ends
- Which support is provided
The level of management should be proportionate.
A personal device should not be monitored as if it were fully owned by the organisation unless there is a clear, lawful and agreed reason.
Location tracking
Some management and mobile platforms may provide location-related features.
The organisation should not enable tracking simply because it is available.
Before using location information, consider:
- The business purpose
- Employee expectations
- Accuracy
- Working hours
- Device ownership
- Access controls
- Retention
- Data protection
- Employment policies
- Alternatives
Device location may be appropriate for recovering a lost company-owned device.
Continuous employee tracking creates wider privacy and employment concerns.
Mobile Device Management for accountancy firms
Accountancy firms may use mobile devices to access:
- Client email
- Tax documents
- Payroll information
- Cloud accounting systems
- Microsoft Teams
- OneDrive
- SharePoint
- Authentication applications
MDM can help protect client confidentiality by requiring compliant devices and controlling where company information can be stored or shared.
Company data should not remain on a personal phone after an employee leaves.
Mobile Device Management for housing associations
Housing associations may provide mobile devices to:
- Housing officers
- Repairs teams
- Property employees
- Customer-service managers
- Executives
- Lone workers
- Community teams
These devices may access:
- Tenant information
- Repairs records
- Property photographs
- Case notes
- Microsoft Teams
- Housing-management systems
MDM can help apply consistent security across employees working away from the office.
The organisation should pay particular attention to sensitive tenant information and photographs stored on devices.
Mobile Device Management for charities
Charities may use a mixture of:
- Company-owned devices
- Employee-owned phones
- Volunteer devices
- Temporary project tablets
- Shared devices
- Outreach equipment
This can create complex ownership and access questions.
A managed approach can help separate business information, remove access at the end of projects and avoid leaving service-user data on personal devices.
Mobile Device Management for professional services firms
Professional services organisations may need to protect:
- Client correspondence
- Documents
- Case information
- Financial information
- Microsoft 365 access
- Video meetings
- Authentication tools
MDM can help create a consistent mobile security standard without preventing flexible client work.
Mobile Device Management for construction and field teams
Construction, engineering and field-service teams may use devices for:
- Job scheduling
- Risk assessments
- Drawings
- Photographs
- Customer records
- Forms
- Signatures
- Navigation
- Communication
Devices may be exposed to:
- Damage
- Loss
- Theft
- Poor connectivity
- Shared use
- Rapid employee turnover
The management design should support quick replacement, offline work and clear asset ownership.
Benefits of Mobile Device Management
Better visibility
You can see which devices access business services.
Stronger security
Encryption, screen locks and supported operating systems can be required.
Faster deployment
Applications and settings can be applied automatically.
Improved lost-device response
Devices can be locked, wiped or removed from business access.
Better joiner and leaver control
Access can be added and removed through a consistent process.
Safer BYOD
Business applications can be protected without always managing the entire personal device.
Consistent applications
Employees receive approved versions of the tools they need.
Better compliance reporting
The organisation can identify devices that do not meet policy.
Improved lifecycle management
Unsupported and inactive devices can be identified.
Easier remote support
Some configuration problems can be resolved centrally.
What are the disadvantages of Mobile Device Management?
It requires planning
Poorly designed policies may disrupt employee access.
Employees may have privacy concerns
The organisation must explain what is managed and visible.
Some older devices may become unusable
Unsupported devices may fail compliance requirements.
Licensing may be required
Microsoft or third-party management services may involve additional subscriptions.
Enrolment creates user work
Employees may need to complete setup and authentication.
Application restrictions can frustrate users
Controls should be proportionate and tested.
Not every device supports every feature
Capabilities vary by platform, manufacturer and ownership model.
MDM does not prevent every threat
Identity, email, endpoint and user-awareness controls are still needed.
Common Mobile Device Management mistakes
Deploying technology without a mobile policy
Employees need clear rules and expectations.
Applying the same controls to every device
Company-owned, personal and shared devices require different approaches.
Enrolling devices without Conditional Access
Unmanaged devices may still retain alternative access routes.
Blocking users without testing policies
A small configuration mistake can interrupt access across the organisation.
Ignoring employee privacy
This creates mistrust and may result in disproportionate monitoring.
Managing devices but not applications
Business data may still move into personal services.
Allowing unsupported operating systems
Old devices create security and application risks.
Failing to remove leavers
Access and company data may remain active.
Wiping personal devices incorrectly
A full wipe can remove personal information unnecessarily.
Having no lost-device process
Technology is less useful when nobody knows how to trigger it.
Treating MDM as complete mobile security
Phishing, identity attacks and malicious messages still need attention.
What should you look for in an MDM provider?
Microsoft and mobile expertise
The provider should understand Intune, Microsoft 365, Apple and Android management.
Clear ownership models
They should distinguish company-owned, personal, shared and dedicated devices.
Identity knowledge
MDM should work with multi-factor authentication and Conditional Access.
Application protection
The provider should explain how business data is controlled inside applications.
Practical policy design
Security should not make mobile working unnecessarily difficult.
Privacy awareness
The solution should respect personal-device boundaries.
Deployment planning
Enrolment should be staged, tested and communicated.
Joiner and leaver processes
Device access should follow the employee lifecycle.
Reporting
You should receive meaningful information about compliance and unsupported devices.
Ongoing support
Employees need help with enrolment, replacement devices and access problems.
Questions to ask before introducing Mobile Device Management
- Which mobile devices access business data?
- Who owns each device?
- Are personal devices allowed?
- Which applications need protection?
- Which information is most sensitive?
- Do devices need full management?
- Would application-only protection be enough?
- Which operating systems are supported?
- How old are the devices?
- Is Microsoft Intune already licensed?
- Will Conditional Access be used?
- How will employees enrol?
- What will the organisation be able to see?
- How will privacy be explained?
- What happens when a device is lost?
- What happens when an employee leaves?
- Can business data be removed selectively?
- Which applications should be blocked?
- How will shared devices work?
- How will unsupported devices be replaced?
- Who provides user support?
Our Mobile Device Management process
1
Discovery
We begin by understanding:
- Number of mobile users
- Device types
- Device ownership
- Microsoft 365 environment
- Current mobile access
- Business applications
- Sensitive information
- BYOD
- Shared devices
- Mobile workforce
- Existing policies
- Security requirements
- User-support needs
2
Mobile estate audit
We review:
- Known devices
- Operating systems
- Device age
- Ownership
- Existing management
- Mobile applications
- Email access
- Authentication
- Business SIMs
- Unsupported devices
- Lost-device process
- Joiner and leaver process
- Existing Microsoft licensing
3
Risk and use-case review
We assess:
- Information accessed
- User roles
- Device loss risk
- Personal-device use
- Field work
- Shared-device requirements
- Regulatory or contractual needs
- Privacy
- Business impact of access loss
4
Management design
We define the appropriate model for:
- Company-owned devices
- Personally owned devices
- Shared devices
- Kiosk devices
- Frontline workers
- Executives
- Temporary employees
- Contractors
5
Policy design
Policies may cover:
- Enrolment
- Screen locks
- Encryption
- Operating-system versions
- Rooted or jailbroken devices
- Application controls
- Data sharing
- Remote wipe
- Wi-Fi
- VPN
- Compliance
- Conditional Access
- Privacy
- Device replacement
6
Pilot deployment
We normally test the design with a smaller pilot group.
The pilot may include:
- Different device models
- Different operating systems
- Company-owned devices
- Personal devices
- Office and field users
- Different applications
This helps identify problems before wider deployment.
7
Enrolment and configuration
We configure:
- Management platform
- Device enrolment
- Compliance policies
- Application protection
- Conditional Access
- Required applications
- Wi-Fi profiles
- Security settings
- Administrator access
- Reporting
8
User communication and training
Employees may receive guidance covering:
- Why management is being introduced
- What the organisation can see
- What it cannot see
- How to enrol
- Required security settings
- Approved applications
- Lost-device reporting
- BYOD expectations
- Support
- Leaver processes
9
Wider deployment
Devices are enrolled according to an agreed schedule.
We track:
- Successful enrolment
- Compliance
- Access problems
- Unsupported devices
- Application deployment
- User support
- Exceptions
10
Ongoing management and support
Stratiis can continue to support:
- New starters
- Leavers
- Replacement devices
- Lost devices
- Enrolment
- Compliance
- Application deployment
- Policy changes
- Operating-system updates
- Conditional Access
- Reporting
- Licensing
- Device lifecycle
- User support
Frequently asked questions
What does MDM stand for?
MDM stands for Mobile Device Management.
It is used to configure, secure and manage smartphones, tablets and other devices centrally.
What is Microsoft Intune?
Microsoft Intune is a cloud-based Microsoft service used to manage devices, applications and access.
Is Intune included with Microsoft 365?
It is included in some Microsoft 365 and security licences but not all.
Your current licensing should be reviewed before deployment.
Can Intune manage iPhones and iPads?
Yes.
Intune can manage supported Apple devices using appropriate enrolment and Apple services.
Can Intune manage Android devices?
Yes.
It supports several Android management models, including work profiles and fully managed devices.
Can Mobile Device Management manage personal phones?
Yes, but the level of control should reflect personal ownership.
Application-level protection or work profiles may be more appropriate than full-device management.
Can my employer see personal photographs and messages?
This depends on the management model.
A properly designed BYOD approach should limit the organisation to the business applications and security information it genuinely needs.
The organisation should explain clearly what is visible.
Can MDM track an employee’s location?
Some systems may provide location-related features for certain managed devices.
Continuous tracking should not be enabled without a clear purpose, appropriate policy and data-protection consideration.
Can business data be removed without wiping personal data?
Yes, in suitable application-management or work-profile designs.
This is commonly called selective wipe.
Can a lost phone be wiped remotely?
Yes, when it is enrolled and remains able to receive the command.
A full or selective wipe may be used depending on device ownership.
What happens when the phone is offline?
The management action may remain pending until the device reconnects.
Account access and the SIM may also need to be suspended.
Does MDM protect against phishing?
It can reduce risk by controlling applications and access.
It does not stop every phishing email, text message or fraudulent sign-in.
Does MDM replace mobile antivirus?
No.
The appropriate security controls depend on the mobile platform, applications and risk.
MDM is one part of mobile security.
What is Conditional Access?
Conditional Access uses conditions such as device compliance, user identity and sign-in risk to decide whether access should be allowed.
Can unmanaged devices be blocked from Microsoft 365?
Yes.
Conditional Access can be configured to require approved or compliant devices for selected services.
What is a compliant device?
A compliant device meets the security standards defined by the organisation, such as encryption, supported software and an approved screen lock.
Can MDM install applications automatically?
Yes.
Required business applications can be assigned to users or devices.
Can applications be removed when an employee leaves?
Yes.
Managed business applications and data can be removed as part of the leaver process.
Can Wi-Fi settings be deployed automatically?
Yes.
Approved wireless profiles and certificates may be deployed to managed devices.
Can mobile devices be configured before employees receive them?
Yes.
Automated enrolment can apply management and settings during initial setup.
Do employees need to hand over their personal phones?
Not necessarily.
BYOD enrolment is normally completed by the user through a guided process.
Can shared tablets be managed?
Yes.
Shared and kiosk devices can be configured for limited users, applications or purposes.
How long does an MDM deployment take?
The timescale depends on:
- Number of devices
- Device ownership
- Microsoft licensing
- Applications
- Current policies
- Conditional Access
- Apple and Android setup
- User communication
- Pilot testing
A phased deployment is normally safer than changing every user at once.
How much does Mobile Device Management cost?
The cost depends on:
- Microsoft or third-party licensing
- Number of users and devices
- Company-owned or personal devices
- Application management
- Conditional Access
- Automated enrolment
- Policy complexity
- Deployment
- User support
- Ongoing management
Existing Microsoft licences may already include some required capabilities.
Can Stratiis manage our mobile contracts as well?
Yes.
Stratiis can help with SIM-only plans, mobile numbers, devices, Mobile Device Management, mobile security and wider Microsoft services.
Give employees mobile access without giving up control of business data
Mobile working is no longer optional for many organisations.
Employees need access to email, Teams, documents and business applications wherever their work takes them.
The answer is not to block mobile access.
It is to provide it through devices and applications the organisation can recognise, secure and remove when necessary.
Stratiis can help you introduce Mobile Device Management in a way that protects business information without creating unnecessary frustration for employees.
We will review your devices, Microsoft licensing, applications, ownership models and security requirements before recommending the right management approach.
Let’s make mobile working safer, easier to support and more consistent across your organisation.


