Blog Post

Last updated: October 2026 · Reviewed by the Network Right team
Mobile device management (MDM) is software that lets your IT team enroll, configure, secure and wipe company laptops, phones and tablets from one console. A new MacBook ships straight to a remote hire, enrolls itself at first boot and arrives encrypted with the right apps. For SOC 2, MDM also produces the device evidence auditors ask for.
MDM stands for mobile device management: a platform that centrally manages an organization's devices, both hardware and software, by installing a management profile or agent on each one. IT uses it to enforce encryption, passwords and updates, deploy apps, track inventory, and remotely lock or wipe lost or offboarded devices without touching them.
"Mobile" is historical. Today the same platforms manage Macs, Windows PCs, iPads, Android phones and conference-room Apple TVs. At 100+ laptops across homes and offices, MDM is the only practical way to know what you own and whether it is secure.
MDM sits inside a broader asset program. For buying, tracking and retiring hardware, see our IT asset management services.
MDM works in three steps. First, each device enrolls, ideally automatically at first boot through Apple's Automated Device Enrollment or Windows Autopilot. Second, the MDM server pushes profiles, apps and policies. Third, the device checks in regularly, reports its status and accepts remote commands such as lock, wipe or update.
Once enrolled, the device receives configuration profiles: Wi-Fi and VPN settings, password and screen-lock rules, FileVault or BitLocker encryption, firewall settings and OS update deadlines. Apps install silently.
Each device checks in with the MDM platform over an encrypted connection to confirm policies are applied and pick up changes. Admins see OS version, installed apps, encryption status and last check-in, and can send commands: lock, wipe, locate, restart or force an update.
MDM matters most when devices never pass through an office. With zero-touch enrollment, a laptop ships from the vendor to a new hire's home and configures itself over any internet connection. When someone leaves, IT locks or wipes it remotely and arranges its return, so company data stays with the company.
For remote teams, MDM replaces "bring it by the IT desk" with remote asset inventory, zero-touch deployment, fleet-wide policy enforcement, deadline-based OS and app updates, and troubleshooting that starts with device facts instead of guesses.
That lifecycle (buy, enroll, support, recover, retire) is the core of streamlining IT asset management as you scale.
MDM manages the whole device. MAM (mobile application management) manages only company apps and their data, which suits personal phones. UEM (unified endpoint management) is MDM grown up: one console for Macs, Windows PCs, phones, tablets and sometimes Linux. Most modern MDM products are marketed as UEM.
A common startup setup: MDM on company laptops, MAM on personal phones that access Slack and email. Company data stays controlled; personal phones stay personal.
The main benefits of mobile device management are faster onboarding, enforced security baselines, lost-device response in minutes, and compliance evidence you export instead of screenshot. You also get an accurate inventory of what you own, which finance and auditors both want.
The leading MDM software options for growing companies are Jamf Pro and Mosyle for Apple-only fleets, Iru (formerly Kandji) for Apple-first fleets with some Windows or Android, Microsoft Intune for Windows-heavy or Microsoft 365 companies, and Hexnode UEM for the widest platform range. Choose by your fleet mix first.
Platform support was checked against each vendor's site in September 2026.
Apple Business itself includes basic built-in MDM at no cost. It suits very small teams, but covers Apple devices only, with less policy depth and reporting than a dedicated platform. Most companies preparing for SOC 2 outgrow it.
Need MDM set up? We deploy and manage it. Network Right picks the platform, connects Apple Business and Autopilot, builds the security baseline and runs the fleet day to day.
For a Mac-heavy startup, the practical MDM setup is Apple Business plus an Apple-focused MDM (Jamf Pro, Iru or Mosyle), with Automated Device Enrollment, FileVault enforced and recovery keys escrowed in the MDM, OS updates on a deadline, and endpoint protection deployed through the MDM. Windows-heavy offices usually choose Intune.
Buy devices from Apple or an Apple Authorized Reseller linked to your Apple Business account so they appear automatically for enrollment. Laptops bought on a personal card at retail do not, and must be added by hand with Apple Configurator. Encryption deserves its own plan: here is how we handle device encryption with FileVault and BitLocker.
Is MDM overkill at 10 or 15 people? Not if customer data lives on laptops. Setup is front-loaded; after that, every device enrolls itself. For what else a small team needs, see managed IT support for small businesses.
If you would rather hand the whole fleet, and the rest of IT, to an outside team, here is what a managed service provider (MSP) does.
Growing teams such as Scribe, Origin and Clearbit run their devices and IT with Network Right; read their device and IT case studies.
SOC 2 does not name MDM as a requirement, but auditors testing the AICPA Trust Services Criteria routinely ask for device evidence: a complete inventory, disk encryption proof, screen-lock settings, patch status, endpoint protection and offboarding records. MDM is the fastest way to produce all six from one system.
The criteria most often tested this way are CC6.1 (logical access security), CC6.7 (restricting data movement, including on mobile devices) and CC6.8 (preventing unauthorized or malicious software). Your auditor decides which evidence satisfies each. For the full audit path, see our SOC 2 audit readiness support.
MDM enforces configuration; it does not watch for attacks in real time. For customers who require 24/7 endpoint detection, that is the job of an EDR tool feeding managed SOC monitoring.
MDM software is usually priced per device, billed monthly or annually, depending on platform, features and fleet size. Apple Business includes basic Apple MDM free, and Microsoft Intune comes with several Microsoft 365 plans. Dedicated platforms cost more but add policy depth, reporting and security features.
Software is often the smaller cost; setup, policy design and daily management are the larger one. Network Right includes asset management in its managed IT plans: $120 per user per month (Scale-up $170, Enterprise custom). For bundled pricing models, see how managed IT services are priced.
In IT, MDM means mobile device management: software that enrolls, configures, secures and remotely wipes company laptops, phones and tablets from one console. It is different from master data management, a data-governance discipline that shares the same acronym. If you see "MDM" in a security questionnaire, it means device management.
MDM manages the entire device, including OS settings, encryption and full remote wipe, so it suits company-owned hardware. MAM manages only company apps and their data, and can selectively wipe just that data, so it suits personal phones. Many companies use MDM on laptops and MAM on personal phones that access email and Slack.
Yes, with lighter controls. Apple offers User Enrollment for personal iPhones and Macs, and Android Enterprise uses a work profile that separates company apps from personal ones. IT can manage and wipe only the company side. For personal phones, many companies skip device enrollment and use app-level protection (MAM) instead.
Standard MDM does not show personal browsing history, texts, photos or email content. It shows device details: model, serial number, OS version, installed apps, encryption status and sometimes location when a device is reported lost. Separate tools, such as a web proxy or VPN, can log traffic, so check your company policy.
Yes. On April 14, 2026, Apple launched Apple Business, a free platform that replaced Apple Business Manager, Apple Business Essentials and Apple Business Connect. It holds your company-owned Apple devices and Managed Apple Accounts, includes basic built-in MDM, and connects to third-party MDM services for Automated Device Enrollment.
Windows Autopilot is Microsoft's zero-touch deployment service for Windows PCs. A registered device joins Microsoft Entra ID and enrolls in Microsoft Intune during first-boot setup, then installs apps and policies automatically. It replaces manual imaging, so a vendor can ship a PC straight to an employee who signs in and starts working.
IT marks it lost, sends a remote lock with a message and phone number, and, if it is not recovered, issues a remote wipe the next time it connects. Because MDM enforced FileVault or BitLocker, data on the drive stays unreadable. The command history documents it for incident reports.
Not if it was enrolled properly. Apple devices enrolled through Automated Device Enrollment are supervised, and Apple states a supervised device cannot be unenrolled by the user. Windows PCs registered with Autopilot re-enroll after a reset. Devices enrolled manually are easier to remove, which is why zero-touch enrollment matters.
SOC 2 does not name a specific tool, but auditors testing the AICPA Trust Services Criteria ask for device inventory, encryption, screen-lock, patching and offboarding evidence. Without MDM, that means manual screenshots from every laptop, every audit period. MDM is the standard way laptop fleets produce it.
For a 50 to 100 device fleet, a rollout covers platform setup, connecting Apple Business or Autopilot, building policies, piloting with a few users and enrolling the rest. Timing depends on the device mix, current enrollment and user availability. Existing devices may need re-enrollment, so include that work in the rollout schedule.
MDM works best when it is part of the device lifecycle: purchasing, enrollment, security policies, updates and recovery when someone leaves. A current inventory and clear ownership keep the fleet manageable as it grows.
Network Right chooses the platform for your fleet, connects Apple Business and Windows Autopilot, builds the security baseline and manages devices day to day, with a dedicated IT consultant, offices in San Francisco and New York, and a 4.95/5 client NPS. If your current MDM already works, we will say so and fix only the gaps.
Send us your device count, your Mac and Windows mix, and your current MDM (if any). We will send back a recommended platform, a rollout plan and a list of SOC 2 evidence gaps. Book a call with our team.