Blog Post

What Is Mobile Device Management (MDM)? A Practical Guide

Last updated: October 2026 · Reviewed by the Network Right team

Mobile device management (MDM) is software that lets your IT team enroll, configure, secure and wipe company laptops, phones and tablets from one console. A new MacBook ships straight to a remote hire, enrolls itself at first boot and arrives encrypted with the right apps. For SOC 2, MDM also produces the device evidence auditors ask for.

MDM meaning

MDM stands for mobile device management: a platform that centrally manages an organization's devices, both hardware and software, by installing a management profile or agent on each one. IT uses it to enforce encryption, passwords and updates, deploy apps, track inventory, and remotely lock or wipe lost or offboarded devices without touching them.

"Mobile" is historical. Today the same platforms manage Macs, Windows PCs, iPads, Android phones and conference-room Apple TVs. At 100+ laptops across homes and offices, MDM is the only practical way to know what you own and whether it is secure.

MDM sits inside a broader asset program. For buying, tracking and retiring hardware, see our IT asset management services.

How mobile device management works

MDM works in three steps. First, each device enrolls, ideally automatically at first boot through Apple's Automated Device Enrollment or Windows Autopilot. Second, the MDM server pushes profiles, apps and policies. Third, the device checks in regularly, reports its status and accepts remote commands such as lock, wipe or update.

Step 1: Enrollment (zero-touch)

  • Apple devices: Apple Business and Automated Device Enrollment. In April 2026 Apple replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect with one free platform, Apple Business. Company-owned Macs, iPhones and iPads in Apple Business are assigned to your MDM service and, with Automated Device Enrollment, enroll during Setup Assistant on first boot. Per Apple's device management documentation for Apple Business, you can assign devices by platform, individually, in bulk or with Apple Configurator for iPhone. These devices are supervised, and a supervised device can't be unenrolled by the user.
  • Windows PCs: Windows Autopilot. Microsoft describes Windows Autopilot as "a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use." The PC joins Microsoft Entra ID and enrolls in Intune during setup. The hardware vendor or reseller registers devices to your tenant, or you upload each device's hardware hash.
  • Android: Android Enterprise. Company-owned phones use zero-touch enrollment. Personal phones use a work profile that separates company apps and data from personal ones.

Step 2: Profiles, policies and apps

Once enrolled, the device receives configuration profiles: Wi-Fi and VPN settings, password and screen-lock rules, FileVault or BitLocker encryption, firewall settings and OS update deadlines. Apps install silently.

Step 3: Check-ins and remote commands

Each device checks in with the MDM platform over an encrypted connection to confirm policies are applied and pick up changes. Admins see OS version, installed apps, encryption status and last check-in, and can send commands: lock, wipe, locate, restart or force an update.

Mobile device fleet management for remote and hybrid teams

MDM matters most when devices never pass through an office. With zero-touch enrollment, a laptop ships from the vendor to a new hire's home and configures itself over any internet connection. When someone leaves, IT locks or wipes it remotely and arranges its return, so company data stays with the company.

For remote teams, MDM replaces "bring it by the IT desk" with remote asset inventory, zero-touch deployment, fleet-wide policy enforcement, deadline-based OS and app updates, and troubleshooting that starts with device facts instead of guesses.

That lifecycle (buy, enroll, support, recover, retire) is the core of streamlining IT asset management as you scale.

MDM vs. MAM vs. UEM

MDM manages the whole device. MAM (mobile application management) manages only company apps and their data, which suits personal phones. UEM (unified endpoint management) is MDM grown up: one console for Macs, Windows PCs, phones, tablets and sometimes Linux. Most modern MDM products are marketed as UEM.

Dimension MDM MAM UEM
What it controls The entire device: settings, OS, apps, encryption Only managed apps and the data inside them All endpoints and apps from one console
Best for Company-owned laptops, phones and tablets Personal phones (BYOD) where you cannot control the device Mixed fleets across Mac, Windows, iOS, Android, Linux
Remote wipe Full device wipe Selective wipe of company app data only Both, depending on ownership
Privacy impact on user High (IT sees device inventory and settings) Low (IT sees only company apps) Varies by ownership model
Example Jamf Pro on company Macs Microsoft Intune app protection policies on personal phones Microsoft Intune or Hexnode UEM across a mixed fleet

A common startup setup: MDM on company laptops, MAM on personal phones that access Slack and email. Company data stays controlled; personal phones stay personal.

Benefits of mobile device management

The main benefits of mobile device management are faster onboarding, enforced security baselines, lost-device response in minutes, and compliance evidence you export instead of screenshot. You also get an accurate inventory of what you own, which finance and auditors both want.

  • Security baseline on every device. Disk encryption, screen lock, firewall and OS updates are enforced, not requested. This is the foundation of endpoint security management.
  • Faster onboarding. New hires open a laptop that already has their apps and settings.
  • Clean offboarding. The device is locked or wiped the same day, then reassigned. Pair MDM with a written process for employee onboarding and offboarding IT.
  • Lost device response. Lock or wipe remotely, and prove the data was encrypted.
  • Compliance evidence. Export encryption and patch status for SOC 2 or security questionnaires.
  • Fewer tickets. Standard configurations mean fewer one-off problems.

MDM software options: Jamf, Iru (formerly Kandji), Intune, Mosyle, Hexnode

The leading MDM software options for growing companies are Jamf Pro and Mosyle for Apple-only fleets, Iru (formerly Kandji) for Apple-first fleets with some Windows or Android, Microsoft Intune for Windows-heavy or Microsoft 365 companies, and Hexnode UEM for the widest platform range. Choose by your fleet mix first.

Platform support was checked against each vendor's site in September 2026.

Tool Platforms managed Who it suits Notes
Jamf Pro macOS, iOS, iPadOS, tvOS (Apple only) Mac-heavy companies that want deep Apple control Long-standing Apple specialist with a large admin community
Iru (formerly Kandji) Apple, plus Windows and Android Apple-first startups adding a few Windows or Android devices Kandji became Iru on October 22, 2025
Microsoft Intune Windows, macOS, iOS/iPadOS, Android, Linux (Ubuntu, RHEL), ChromeOS Microsoft 365 and Windows-heavy companies; pairs with Autopilot Included in several Microsoft 365 business and enterprise plans; see Intune's supported platforms
Mosyle macOS, iOS, iPadOS (Apple only) Cost-conscious Apple fleets in business and education Mosyle Fuse bundles MDM with security and identity for businesses
Hexnode UEM iOS, iPadOS, macOS, Windows, Android, Linux, ChromeOS, tvOS, Fire OS, visionOS Mixed fleets, kiosks and frontline devices Broadest platform list here

Apple Business itself includes basic built-in MDM at no cost. It suits very small teams, but covers Apple devices only, with less policy depth and reporting than a dedicated platform. Most companies preparing for SOC 2 outgrow it.

Need MDM set up? We deploy and manage it. Network Right picks the platform, connects Apple Business and Autopilot, builds the security baseline and runs the fleet day to day.

MDM for Mac-heavy startups and small businesses

For a Mac-heavy startup, the practical MDM setup is Apple Business plus an Apple-focused MDM (Jamf Pro, Iru or Mosyle), with Automated Device Enrollment, FileVault enforced and recovery keys escrowed in the MDM, OS updates on a deadline, and endpoint protection deployed through the MDM. Windows-heavy offices usually choose Intune.

Buy devices from Apple or an Apple Authorized Reseller linked to your Apple Business account so they appear automatically for enrollment. Laptops bought on a personal card at retail do not, and must be added by hand with Apple Configurator. Encryption deserves its own plan: here is how we handle device encryption with FileVault and BitLocker.

Is MDM overkill at 10 or 15 people? Not if customer data lives on laptops. Setup is front-loaded; after that, every device enrolls itself. For what else a small team needs, see managed IT support for small businesses.

If you would rather hand the whole fleet, and the rest of IT, to an outside team, here is what a managed service provider (MSP) does.

Growing teams such as Scribe, Origin and Clearbit run their devices and IT with Network Right; read their device and IT case studies.

MDM and SOC 2: what auditors ask for

SOC 2 does not name MDM as a requirement, but auditors testing the AICPA Trust Services Criteria routinely ask for device evidence: a complete inventory, disk encryption proof, screen-lock settings, patch status, endpoint protection and offboarding records. MDM is the fastest way to produce all six from one system.

What the auditor asks Typical evidence How MDM produces it
Complete list of in-scope devices Device inventory with owner and serial Automatic inventory from check-ins
Encryption on every laptop FileVault or BitLocker status report Compliance report plus escrowed recovery keys
Screen lock and password policy Configuration profile and compliance status Enforced profile, exportable report
OS and patch status Versions by device, update deadlines Update policy and version report
Endpoint protection installed Agent presence on every device App deployment and inventory report
Offboarded devices secured Lock or wipe record with date Command history per device

The criteria most often tested this way are CC6.1 (logical access security), CC6.7 (restricting data movement, including on mobile devices) and CC6.8 (preventing unauthorized or malicious software). Your auditor decides which evidence satisfies each. For the full audit path, see our SOC 2 audit readiness support.

MDM enforces configuration; it does not watch for attacks in real time. For customers who require 24/7 endpoint detection, that is the job of an EDR tool feeding managed SOC monitoring.

How much does MDM software cost?

MDM software is usually priced per device, billed monthly or annually, depending on platform, features and fleet size. Apple Business includes basic Apple MDM free, and Microsoft Intune comes with several Microsoft 365 plans. Dedicated platforms cost more but add policy depth, reporting and security features.

Software is often the smaller cost; setup, policy design and daily management are the larger one. Network Right includes asset management in its managed IT plans: $120 per user per month (Scale-up $170, Enterprise custom). For bundled pricing models, see how managed IT services are priced.

Frequently asked questions

What does MDM mean in IT?

In IT, MDM means mobile device management: software that enrolls, configures, secures and remotely wipes company laptops, phones and tablets from one console. It is different from master data management, a data-governance discipline that shares the same acronym. If you see "MDM" in a security questionnaire, it means device management.

What is the difference between MDM and MAM?

MDM manages the entire device, including OS settings, encryption and full remote wipe, so it suits company-owned hardware. MAM manages only company apps and their data, and can selectively wipe just that data, so it suits personal phones. Many companies use MDM on laptops and MAM on personal phones that access email and Slack.

Does MDM work on personal (BYOD) devices?

Yes, with lighter controls. Apple offers User Enrollment for personal iPhones and Macs, and Android Enterprise uses a work profile that separates company apps from personal ones. IT can manage and wipe only the company side. For personal phones, many companies skip device enrollment and use app-level protection (MAM) instead.

Can my employer see my browsing history through MDM?

Standard MDM does not show personal browsing history, texts, photos or email content. It shows device details: model, serial number, OS version, installed apps, encryption status and sometimes location when a device is reported lost. Separate tools, such as a web proxy or VPN, can log traffic, so check your company policy.

What is Apple Business, and did it replace Apple Business Manager?

Yes. On April 14, 2026, Apple launched Apple Business, a free platform that replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect. It holds your company-owned Apple devices and Managed Apple Accounts, includes basic built-in MDM, and connects to third-party MDM services for Automated Device Enrollment.

What is Windows Autopilot?

Windows Autopilot is Microsoft's zero-touch deployment service for Windows PCs. A registered device joins Microsoft Entra ID and enrolls in Microsoft Intune during first-boot setup, then installs apps and policies automatically. It replaces manual imaging, so a vendor can ship a PC straight to an employee who signs in and starts working.

What happens to a lost laptop enrolled in MDM?

IT marks it lost, sends a remote lock with a message and phone number, and, if it is not recovered, issues a remote wipe the next time it connects. Because MDM enforced FileVault or BitLocker, data on the drive stays unreadable. The command history documents it for incident reports.

Can an employee remove MDM from a company laptop?

Not if it was enrolled properly. Apple devices enrolled through Automated Device Enrollment are supervised, and Apple states a supervised device cannot be unenrolled by the user. Windows PCs registered with Autopilot re-enroll after a reset. Devices enrolled manually are easier to remove, which is why zero-touch enrollment matters.

Is MDM required for SOC 2?

SOC 2 does not name a specific tool, but auditors testing the AICPA Trust Services Criteria ask for device inventory, encryption, screen-lock, patching and offboarding evidence. Without MDM, that means manual screenshots from every laptop, every audit period. MDM is the standard way laptop fleets produce it.

How long does an MDM rollout take?

For a 50 to 100 device fleet, a rollout covers platform setup, connecting Apple Business or Autopilot, building policies, piloting with a few users and enrolling the rest. Timing depends on the device mix, current enrollment and user availability. Existing devices may need re-enrollment, so include that work in the rollout schedule.

Get MDM deployed and managed by Network Right

MDM works best when it is part of the device lifecycle: purchasing, enrollment, security policies, updates and recovery when someone leaves. A current inventory and clear ownership keep the fleet manageable as it grows.

Network Right chooses the platform for your fleet, connects Apple Business and Windows Autopilot, builds the security baseline and manages devices day to day, with a dedicated IT consultant, offices in San Francisco and New York, and a 4.95/5 client NPS. If your current MDM already works, we will say so and fix only the gaps.

Send us your device count, your Mac and Windows mix, and your current MDM (if any). We will send back a recommended platform, a rollout plan and a list of SOC 2 evidence gaps. Book a call with our team.

‍