Business mobile services · device security

Give staff dependable access to email, Teams and business apps while keeping company information under control. Stratiis helps organisations across Scotland plan, deploy and support mobile device management for company phones, tablets and appropriate personal devices.

What is mobile device management?

Mobile device management (MDM) is a way to enrol, configure and secure smartphones and tablets centrally. It can apply device rules, deploy apps, check compliance and help remove company data when a device is lost or a person leaves. The controls available depend on the device, its owner, the enrolment method and your licences.

The business case

Why manage mobile devices?

A phone can open email, files, customer records and authentication prompts from almost anywhere. When devices are set up individually, it becomes difficult to see which ones still have access, whether they meet basic security standards or how to respond when one goes missing.

Know what has access

Keep a useful record of enrolled devices, ownership, operating system and compliance status.

Protect business data

Apply proportionate screen lock, encryption, app and access policies.

Set up users faster

Make approved apps and settings available through a repeatable joining process.

Respond to change

Act on lost devices, replacements, role changes and leavers through a defined process.

Choose the right level of control

MDM or mobile application management?

Device management and application management solve related problems. The choice should start with who owns the device and what the business needs to protect.

Approach What it controls Typical fit
Mobile device management Enrolment, device configuration, security settings, compliance, managed apps and permitted remote actions. Company-owned smartphones, tablets, shared or dedicated devices.
Mobile application management Work apps and the business data inside them, with controls such as an app PIN, sharing restrictions and selective data removal. Personal devices where full device management is unnecessary or inappropriate.
Combined approach Device compliance plus app protection and identity-based access rules. Organisations with different roles, ownership models and information risks.

Microsoft Intune can support these approaches alongside Microsoft 365 and Microsoft Entra ID, subject to licensing and configuration. Stratiis can assess whether your existing subscriptions include the capabilities you need.

Ownership and privacy

How should company-owned devices and BYOD differ?

A company-owned device can usually carry stronger configuration and lifecycle controls. A personally owned phone calls for clear boundaries: staff should know what the organisation can see, which work data it can remove and what happens when employment ends.

Company-owned phones and tablets

Depending on the platform and enrolment method, the business can standardise setup, deploy required apps, manage updates, apply restrictions and record the device as an asset. Apple Business Manager and Android Enterprise can support automated enrolment for eligible devices.

Bring your own device

Work app protection or a supported Android work profile can separate business information from personal use. The policy should explain support limits, privacy, acceptable use and whether only work data can be removed. A personal device should not be treated as if the business owns it.

What Stratiis can help manage

Practical mobile management, from enrolment to exit

We design policies around the applications people use and the level of risk each device creates, then support the day-to-day work needed to keep the estate current.

Enrolment and setup

Plan Apple, Android, shared and dedicated device enrolment; deploy approved apps, email and suitable Wi-Fi or VPN profiles.

Security and compliance

Set device standards for screen locks, encryption and supported operating systems; use compliance and Conditional Access where appropriate.

Application protection

Protect business data in supported apps, limit unwanted sharing and select the right controls for personal devices.

Lost-device response

Define who reports an incident, who checks access and which lock, selective wipe or full wipe action is available and appropriate.

Joiners, movers and leavers

Provision access consistently, update policies when roles change, then remove access and work data when someone leaves.

Reporting and support

Review enrolment, compliance, unsupported devices and exceptions while helping staff with setup and replacement devices.

Access policy

How do compliance and Conditional Access work together?

A compliance policy checks whether an enrolled device meets standards such as a supported operating system, encryption or a screen lock. Conditional Access can then use that signal, together with identity and other conditions, to decide whether a sign-in is allowed. These controls should be tested with a pilot group and include an agreed route for exceptions and recovery.

What MDM helps with

Consistent configuration, device inventory, compliance reporting, controlled application deployment and defined actions when devices are lost or retired.

What MDM cannot guarantee

It does not stop every phishing message, malicious link or identity attack. Mobile management works best alongside multi-factor authentication, user guidance and wider cybersecurity controls.

Special use cases

What about shared, field and dedicated devices?

A site tablet, front-line phone or single-purpose kiosk needs a different setup from an executive’s personal phone. We can consider shared sign-in, approved applications, network profiles, physical loss risk and how a device is reset before it moves to the next user.

Construction and field teams

Make core apps and settings consistent across mobile teams and replacements.

Shared tablets

Design sign-in, data removal and support around more than one user.

Dedicated devices

Restrict an eligible device to the business task it must perform.

Regulated information

Choose access and reporting controls that reflect your contractual and privacy obligations.

A realistic rollout

How does Stratiis introduce MDM?

Good deployment starts with the device estate and the people using it. We agree ownership, access needs, licences and privacy expectations before configuring policies.

1

Discover

Map devices, users, apps, ownership and existing access.

2

Design

Choose enrolment, app protection and compliance policies.

3

Pilot

Test with representative devices and user roles.

4

Explain

Tell staff what changes, what can be seen and how to get help.

5

Deploy

Enrol in stages and resolve access or app issues.

6

Maintain

Support changes, compliance, replacements and leavers.

Planning and cost

What affects the cost of mobile device management?

Cost depends on the number of users and devices, existing Microsoft licensing, platform choices, enrolment work, app protection needs and ongoing support. A small estate with existing licences differs from a mixed fleet of shared, personal and company devices. We review what you already own before proposing new subscriptions or a rollout.

Ask any provider to spell out licence costs, initial setup, user communication, support, lost-device actions and reporting. A clear scope makes it easier to compare proposals.

Related services

Keep mobile access connected to the wider service

Mobile management works best when it fits your connectivity, mobile contracts and employee support.

Business Mobile Services

Plan devices, connections and mobile support together.

Explore Business Mobile Services →

Business SIM-Only Plans

Align business SIM records with the devices and people using them.

Explore Business SIM-Only Plans →

Managed Wi-Fi

Give managed devices suitable network access at your sites.

Explore Managed Wi-Fi →

Mobile device management FAQs

Frequently asked questions

Clear answers to the questions businesses and employees raise before an MDM rollout.

Does MDM mean the business can see personal photos and messages?

That depends on the device and enrolment model, but access to personal content should never be assumed. The organisation should explain exactly what its chosen platform can see and manage before enrolment, especially for personal phones.

Can business data be removed without wiping a personal phone?

Supported app protection or work-profile approaches can remove managed work data selectively. The exact result depends on the platform, apps and configuration; it should be tested and explained in the BYOD policy.

Can a lost phone be locked or wiped remotely?

Eligible enrolled devices may support remote lock, selective wipe or full wipe. The available action depends on ownership and enrolment. If the phone is offline, a command may wait until it reconnects, so account access also needs prompt review.

Can MDM track an employee’s location?

Location capabilities vary by platform and enrolment type. They should be assessed against a legitimate business purpose and explained clearly to staff. MDM should not be introduced as a blanket employee tracking tool.

Do employees need to hand over personal phones?

Usually not. Many BYOD approaches let employees enrol or protect work apps themselves using guided steps. The organisation should provide support and explain what changes before requiring personal-device access.

Is Microsoft Intune included with Microsoft 365?

It is included in some Microsoft subscriptions and available separately for others. The right answer depends on your exact licences and the features you need; Stratiis can check this during discovery.

Can Intune manage iPhones, iPads and Android devices?

Yes, Intune supports management options for Apple and Android devices. Available features differ by operating system, ownership, enrolment method and licence.

What is a compliant device?

It is a device that meets the security conditions your organisation defines, such as an approved operating-system version, encryption or a screen lock. Compliance can be used as one signal in access decisions.

Can unmanaged devices be blocked from Microsoft 365?

Conditional Access can restrict access based on policies and signals such as device compliance or protected apps. It needs careful design and testing so legitimate users retain a workable route to the tools they need.

Does MDM prevent phishing?

No. It can reduce some device and data risks, but phishing also calls for identity protection, sensible email controls, user awareness and an incident response process.

Can apps and Wi-Fi settings be deployed automatically?

On supported managed devices, approved apps and network profiles can often be deployed centrally. The exact capabilities depend on the device and enrolment method.

Can shared tablets or kiosk devices be managed?

Yes, suitable Apple and Android enrolment models can support shared or dedicated use. The design should cover sign-in, data separation, app restrictions and how each device is reassigned.

What happens when an employee leaves?

Access should be removed promptly, company-owned devices recovered where appropriate, and managed business data removed from personal devices using the agreed method. A documented leaver process prevents devices and accounts being overlooked.

How long does an MDM rollout take?

It depends on device numbers, ownership, licensing, application compatibility and the amount of user communication needed. A pilot helps expose issues before wider deployment.

How much does MDM cost?

There may be platform licences, initial configuration and ongoing management charges. Existing subscriptions may cover some features. A useful quote states what is included per user or device and what support costs extra.

Can Stratiis help with mobile contracts too?

Yes. Our Business Mobile Services can help align connectivity, devices and support with your management plan.

Make mobile working easier to manage

Tell us how your team uses phones and tablets. We’ll review devices, ownership, Microsoft licensing and access needs, then recommend a practical management approach.

Book a Mobile Device Management ReviewCall 0141 348 7960

Email sales@stratiis.com