Mobile device management (MDM) is a solution that enables you to centrally manage, secure and support the smartphones, tablets and laptops used across your business. It allows you to provision devices, apply security policies, manage applications and remotely wipe devices if they're lost, stolen or when an employee leaves the organisation.
With more people working across home, office and client sites than ever, mobile devices carry as much sensitive company data as any desktop. MDM is how you keep that data and your compliance position under control without slowing anyone down.
What is mobile device management?
MDM gives IT administrators a single, centralised platform to manage a fleet of mobile devices, whatever the size. As we put it on our Mobile Device Management page, whether a business has 10 devices or 500, MDM lets IT control device configurations, enforce security policies, and distribute applications and updates from one place, instead of managing every handset by hand.
Device provisioning: getting devices ready before day one
Provisioning is the process of setting a device up before it reaches the user, configuring settings, installing the right apps, and applying security policies so a new starter is productive from the first login rather than waiting on IT.
- Soft deployment: Devices are enrolled into your device management platform and configured to automatically download business applications, settings and security policies when the user signs in.
- Hard deployment: the device is fully configured before it's shipped, SIM installed, case and screen protector fitted, user details added, and every required business application installed.
Either way, provisioning through MDM turns device rollout from an IT chore into a repeatable process, which matters more the bigger your mobile estate gets.
App management: controlling what's on the device
MDM gives IT administrators control over which applications are installed on a device, the ability to track how they're used, and the means to block unauthorised or malicious apps before they become a problem. New software and updates can be pushed to the whole fleet at once, so every device stays current without a manual visit from IT.
Remote wipe and lock: your safety net when a device goes missing
Devices get lost, stolen, or need to be recovered when someone leaves the business. MDM gives administrators the ability to locate a device, remotely lock it, or wipe its data entirely protecting customer records, credentials and company information even when the hardware itself isn't in your hands. Paired with our Mobile Threat Defence, this also covers phishing, malware and network-based attacks aimed at mobile devices specifically.
Compliance: proving your data is under control
Regulators and auditors increasingly expect businesses to show exactly how mobile data is protected, not just that it is. MDM gives you the evidence: enforced security policies, encryption, access controls and an audit trail of every managed device, which supports frameworks such as GDPR, Cyber Essentials and ISO 27001.
If you're weighing up certification options, our guide to Cyber Essentials vs Cyber Essentials Plus is a useful next read. This matters most in regulated sectors such as legal, healthcare and financial services, where a lost device without MDM in place can quickly become a data breach.
Hybrid workforce security: MDM's biggest job today
Hybrid working means company data now moves between home WiFi, public networks, personal routers and client sites often on a mix of company-owned and BYOD devices. MDM is the layer that keeps that flexibility from becoming a security gap: every device, wherever it's connecting from, is subject to the same policies, the same visibility, and the same ability to lock or wipe it if something goes wrong.
For a wider look at protecting a distributed team, our blog on protecting remote workers from cyber attacks covers the network and endpoint side in more depth and our post on using Microsoft Intune to protect endpoints looks at one specific MDM platform in action.
MDM at scale
The bigger the mobile estate, the more MDM pays for itself. Our work with Costain involved managing mobile connectivity for around 3,500 users across office and field-based engineering teams, the kind of scale where centralised provisioning and device control stop being a nice-to-have and become essential.
Getting started with MDM
Our Mobile Device Management solution covers provisioning, app control, remote wipe and lock, and policy enforcement, backed by our wider business mobile solutions and cyber security services.
Browse our full range of technology solutions or talk to us about securing your mobile estate.
Frequently asked questions
What is Mobile Device Management (MDM) in simple terms?
It's software that lets a business set up, secure, monitor and if needed wipe every mobile device its staff use for work, all from one central platform.
What's the difference between MDM and mobile threat defence?
MDM manages and secures the device itself provisioning, app control, remote wipe. Mobile threat defence protects against active threats like phishing, malware and network attacks. Most businesses use both together.
Does MDM work for BYOD as well as company-owned devices?
Yes. MDM can apply policies to personal devices used for work as well as company-issued ones, though the level of control usually differs to respect personal use and privacy.
Is MDM only relevant for large businesses?
No. MDM scales from a handful of devices to several thousand the smaller the IT team, the more time it saves by replacing manual device management with automated policies.
How does MDM support compliance?
It gives you an enforceable, auditable record of device security policies, encryption and access control, which supports frameworks such as GDPR, Cyber Essentials and ISO 27001.