Secure devices, practical mobile working

Give your people secure access wherever work takes them

Stratiis helps Scottish organisations manage laptops, tablets and phones from a consistent set of policies. We connect device setup, applications, identity and security so employees can work across offices, sites and home without leaving business data on unmanaged equipment.

What is Mobile Device Management?

Mobile Device Management (MDM) is the central administration of the devices people use to access business systems. It can enrol company equipment, apply settings, deploy approved applications, check whether a device meets security requirements and remove business access when a device is lost or a user leaves. The right design depends on device ownership, operating system and the information each role needs.

Business outcomes

Keep control of devices without slowing people down

A managed device estate makes secure working easier to support and gives leaders a clearer view of risk and replacement needs.

Consistent setup

Prepare devices with the right applications, access and settings for each role.

Safer access

Use encryption, screen locks, compliance checks and identity controls together.

Faster response

Identify affected devices and take appropriate action when equipment is lost or compromised.

Clearer lifecycle

Track ownership, support status and replacement priorities across locations.

What the service can cover

Device management designed around your workforce

Stratiis can plan and operate the controls your organisation needs, then align them with Microsoft 365, cybersecurity and day-to-day IT support.

Enrolment and deployment

Bring approved Windows, macOS, iOS and Android devices into management, with setup suited to company-owned, shared and personal equipment.

Configuration and updates

Apply device settings, approved applications, Wi-Fi and security policies, then identify devices that fall behind required versions.

Compliance and access

Check device health and use Microsoft Entra ID Conditional Access where appropriate to limit access from unknown or non-compliant devices.

Application protection

Protect business information inside approved applications, including on personal devices where whole-device management would be excessive.

Lost-device response

Define how to revoke sessions, remove company information, lock or wipe devices and replace equipment after loss or theft.

Ongoing support and reporting

Support enrolment, new starters, leavers, policy exceptions and useful reporting on compliance, ownership and ageing devices.

Choose the right level of control

Company-owned, personal and shared devices need different policies

A useful management design begins with ownership and the way each device is used.

Device model Typical approach Decision to make
Company-owned laptop or phone Full enrolment, standard configuration, compliance checks and controlled replacement. Which applications and settings should every device receive?
Personal phone or tablet Protect approved business applications and data with a proportionate privacy boundary. Can company data be removed without affecting personal content?
Shared or dedicated device Limit the device to the required roles or applications and define handover responsibility. Who signs in, supports the device and reports a loss?
Site or field device Plan for mobility, intermittent connectivity, physical wear and rapid replacement. Which work must remain available when a connection drops?

For a deeper look at smartphones, tablets and personal-device policies, see our mobile device management services guide.

Device and application protection

Protect the device, the business data, or both

Some organisations need strong control over company equipment. Others need a safer way for staff to use approved work apps on personal phones.

Device management

Full enrolment can apply configuration, encryption, update, application and compliance policies to the device. It is usually appropriate for equipment owned by the organisation.

Application management

Application-level policies can restrict how company data is opened, copied and saved, and can remove business data without managing the entire personal device.

Microsoft Intune can provide device and application management alongside Microsoft 365. Its capabilities depend on the licences, device platform and enrolment method in use. Stratiis can review what is already available and design a staged deployment.

Security and privacy

Connect device compliance to identity and incident response

MDM helps manage a device, but it works best alongside multi-factor authentication, endpoint protection, monitored alerts, backup and clear user processes.

When a device is lost

Confirm ownership and the information it could access, then take the agreed action: revoke sessions, lock or wipe the device, review account activity and prepare a replacement. The response should be documented before an incident.

When a device is personal

Explain what the organisation can see and what actions it can take. A selective removal of company data may be more suitable than a full wipe. Policies should respect employee privacy and be tested with real users.

Encryption and screen-lock standards
Supported operating-system versions
Approved applications and safe sharing
Conditional Access and MFA
Lost-device and leaver processes
Documented exceptions and reporting

How we work

A practical route from device sprawl to managed access

Policies should be introduced in stages so that security improvements do not unexpectedly block the work people need to do.

1

Discover

Review devices, ownership, users, applications, Microsoft licensing and current access.

2

Design

Set standards by role and ownership model, including privacy and lost-device actions.

3

Pilot

Test enrolment, policies and support with representative devices and users.

4

Deploy

Roll out management and approved applications with clear employee guidance.

5

Support

Help staff with access, replacements, new starters, role changes and leavers.

6

Improve

Review compliance, policy failures, unsupported devices and changing business needs.

Connected Stratiis services

Device management works across the wider IT environment

Managed devices are most valuable when support, identity, security and connectivity have clear ownership.

Microsoft 365

Connect Intune, Entra ID, applications and device access with your Microsoft 365 environment.

Explore Microsoft 365 →

Cybersecurity

Combine device compliance with identity, endpoint, email and incident-response controls.

Explore cybersecurity →

Frequently asked questions

Mobile Device Management explained

Can MDM cover laptops as well as phones?

Yes. Modern management platforms can support laptops, tablets and smartphones, although available controls vary by operating system, licence and enrolment method.

Do employees have to give up privacy on personal phones?

No. A personal-device approach should state what the business manages and can see. Application protection may allow the organisation to secure and remove its own data without managing the entire phone.

Can a lost device be wiped remotely?

Depending on the device and enrolment method, a company device may be locked or fully wiped, while business data on a personal device may be removed selectively. The correct action should be agreed in advance.

Does MDM replace cybersecurity or backup?

No. Device management supports security, but identity protection, threat detection, employee awareness, backup and response planning are still needed.

How much does Mobile Device Management cost?

Cost depends on the number and type of devices, existing Microsoft licences, required controls, deployment work and ongoing support. A review should separate platform licensing from setup and management.

Manage devices with confidence

Review your device estate and mobile access

Talk to Stratiis about laptops, tablets, phones, Microsoft Intune, company-owned devices and personal-device access. We can identify the gaps and plan a practical rollout for your organisation.

Book a Mobile Device Management reviewExplore managed IT services

Call 0141 348 7960 or email hello@stratiis.com.