Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Mobile device management (MDM) is the centralized administration of phones, tablets, computers, and other devices used for work. An organization enrolls devices in a management service, then uses it to apply settings and security policies, check compliance, and carry out supported remote actions. The exact controls depend on the device platform and how it is enrolled.

What does mobile device management mean?

NIST defines mobile device management as the administration of mobile devices, usually through a third-party product with management features for particular device vendors. In practice, an organization uses MDM to manage supported devices centrally rather than configuring each one independently. The category covers smartphones and tablets, as well as computers and laptops.

MDM is a software and administration approach, not a special type of phone or a physical accessory. Its capabilities are platform-specific: Apple describes MDM for iOS, iPadOS, macOS, and tvOS, while Microsoft documents enrollment and management components for Windows. A single console or feature set should not be assumed to work identically across operating systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does MDM do?

After a device is enrolled, it can receive settings and policies from the organization’s management service and report information used to assess compliance. Depending on platform and setup, administrators may use MDM to:

  • Configure device settings and distribute profiles.
  • Apply security requirements and check whether devices meet them.
  • Distribute supported apps or software updates.
  • Respond to a lost device or a change in its work status with available remote actions, such as locking or erasing it.

These are common functions, not a guarantee that every MDM product or enrollment supports every action. For example, Apple documents remotely delivered profiles and commands, compliance monitoring, settings and software updates, and remote lock or erase capabilities. Microsoft’s Windows management documentation describes a separate platform-specific implementation.

How does MDM work?

  1. Enroll the device. A user or administrator connects the device to the organization’s management service using an available enrollment method. Enrollment enables the device to receive management settings and communicate with that service.
  2. Apply policies and settings. Administrators configure requirements or profiles, and the service delivers supported settings, apps, or commands to enrolled devices.
  3. Check compliance. The organization reviews whether devices meet its requirements and can respond when a device no longer complies.
  4. Take action when needed. If a device is lost, retired, or otherwise needs attention, the administrator may be able to lock, erase, reset, or unenroll it. Available actions depend on platform and ownership model.

NIST’s guidance treats device security as a lifecycle matter spanning deployment, use, and disposal. Enrollment and remote controls are therefore part of a broader administration process, not just a way to install work apps.

MDM vs. MAM: what is the difference?

Mobile device management (MDM) manages the device as a whole. Mobile application management (MAM) focuses on selected work apps and the work data within them. Microsoft describes MDM as common for organization-owned hardware and MAM as common for bring-your-own-device (BYOD) situations; an organization can also combine the approaches.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach What it manages Typical fit
MDM Device-level settings, apps, and security policies, subject to platform and enrollment capabilities. Often organization-owned devices; can also be used for personally owned devices.
MAM Selected work apps and the data in them, rather than the entire device. Often BYOD when the organization wants to protect work data within managed apps.
MDM and MAM together Device-level controls alongside app-level controls. Deployments that need both kinds of management.

For someone using a personal phone, the distinction matters: device enrollment can place more of the device under organizational policies, while app-level management can limit controls to selected work apps and their data. The precise privacy boundary depends on the organization’s configuration and the platform. Check the enrollment terms and applicable device documentation rather than assuming that “personal device” means the organization can see nothing or control nothing.

Can an employer manage a personal phone?

Yes. MDM can be used for personally owned as well as organization-owned devices, but the enrollment arrangement and available controls vary. Apple documents both user-approved enrollment and automated enrollment for organization-owned devices. The precise experience differs by platform, and enrollment does not imply that every administrative action is available on every device.

Before enrolling a personal device, ask your organization what enrollment method it uses, which settings and apps it can manage, what information it can view, and what remote actions it may take. Also find out how work data is removed when you leave or stop using the device for work. Those details are determined by the organization’s configuration and the platform, not by the MDM label alone.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an organization consider when choosing an approach?

Start with the devices and work scenario, then compare the management requirements that follow from them:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Platform and device support: Confirm support for the operating systems and device models in use; management capabilities are vendor- and platform-specific.
  • Ownership and enrollment: Check enrollment options for both organization-owned and personally owned devices, and understand what each option permits.
  • Scope: Decide whether the requirement calls for whole-device MDM, app-level MAM, or a combination.
  • Controls and compliance: Identify the settings, security policies, app distribution, and compliance checks the organization actually needs.
  • Remote actions: Verify which actions are supported for each platform and ownership model, especially for a lost or retired device.
  • Work-data separation: For BYOD, examine how work apps and data are separated from personal use and what happens to work data at unenrollment.

NIST’s mobile device management glossary defines the term. Its SP 800-124 Rev. 2, published May 17, 2023, discusses mobile-device security across deployment, use, and disposal, including organization-provided and personally owned deployments. Platform details are available in Apple’s MDM deployment guidance, Microsoft’s Windows MDM documentation, and the NIST NCCoE enterprise mobility management reference.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.