Spotsaas Blog

What Is Mobile Device Management (MDM)? How It Works, Uses and Costs

The short answer: mobile device management (MDM) is software that lets an organisation enroll, configure, secure and track the phones, tablets and laptops its people use for work. Once a device is enrolled, IT can push Wi-Fi, email and VPN settings, install apps, require a passcode and encryption, update the operating system, and lock or wipe the device if it is lost. It works through management frameworks built into Apple, Android and Windows devices.

This guide explains how MDM works step by step, the difference between company-owned and personal (BYOD) devices, how MDM compares with MAM and UEM, what it is used for in security and compliance, and what it costs in 2026. Vendor facts are vendor-published, checked September 2026.

What does mobile device management do?

An MDM gives IT one console to manage every enrolled device. The core jobs are the same across vendors:

Job What it means in practice
Enrollment Bringing a device under management, ideally automatically when it is first switched on
Configuration Pushing Wi-Fi, email, VPN, certificates and restrictions without touching the device
App management Installing, updating and removing work apps, and blocking unapproved ones
Security policy Enforcing passcodes, encryption and OS versions, and reporting devices that fall out of compliance
OS updates Scheduling or forcing operating system updates
Inventory Tracking model, serial number, OS version, owner and installed managed apps
Lost-device response Locking, locating (on company-owned devices) and remotely wiping lost or stolen devices

How does MDM work?

Modern MDM relies on management protocols that Apple, Google and Microsoft build into their operating systems. The MDM vendor runs the server and console; the device’s own OS does the enforcing. The process has four parts.

1. Enrollment

A device has to be enrolled before it can be managed. There are two broad routes:

  • Automated (zero-touch) enrollment for company-owned devices. The organisation registers device serial numbers with the platform owner: Apple Business (which replaced Apple Business Manager in April 2026) for Apple devices, Android zero-touch enrollment for Android, and Windows Autopilot for Windows. When the device is first switched on, it finds its assigned MDM and configures itself. Apple’s deployment guide calls this Automated Device Enrollment.
  • User-initiated enrollment, where the employee installs a profile or app, or signs in with a work account. This is common for personal devices.

2. Profiles and policies

After enrollment, the MDM sends configuration profiles (Apple’s term) or policies (Android and Windows). A profile is a bundle of settings, such as “require a six-digit passcode”, “connect to the office Wi-Fi with this certificate” or “block the camera”. The device applies them and reports back whether it is compliant.

3. Push notifications

MDM servers do not hold a constant connection to each device. Instead they use the platform’s push service to wake the device and tell it to check in. Apple devices use the Apple Push Notification service (APNs), which is why every Apple MDM needs a push certificate from Apple. Android devices are managed through Android Enterprise, and Windows has its own built-in MDM protocol. When the device checks in, it collects any new commands, such as “install this app” or “lock now”.

4. Supervision and ownership level

How much control IT gets depends on how the device was enrolled. On Apple devices, Automated Device Enrollment makes a device supervised, which unlocks extra restrictions and lets the organisation prevent the user from removing management. Apple says a supervised device “can’t be unenrolled by the user.” Personal devices enrolled through User Enrollment get far fewer controls, by design.

BYOD vs corporate-owned devices

The same MDM behaves very differently on a personal phone and a company phone.

Corporate-owned Personal (BYOD)
Typical enrollment Automated (Apple Business, Android zero-touch, Windows Autopilot) User-initiated (Apple User Enrollment, Android work profile)
What IT controls The whole device A separate work container or work apps only
Remote wipe Full device wipe Removes work data and apps only
Location Can locate a lost device Generally not visible
Can the user remove MDM? Often blocked on supervised devices Yes, which also removes work access

Microsoft’s Intune documentation is a useful reference for what an employer can and cannot see: it lists call and browsing history, email and texts, contacts, calendar, passwords, photos and personal documents as things the organisation “can never see”, while device model, serial number, OS version and IMEI are always visible. On personal devices IT sees only the last four digits of the phone number and cannot view the device’s location.

Android has a middle option for company-owned phones that staff may also use personally: a work profile on a company-owned device, which Scalefusion lists as “WPCO enrollment” in its Growth plan.

MDM vs MAM vs UEM: what’s the difference?

Term Manages Best for
MDM (mobile device management) The whole device: settings, apps, security, OS Company-owned phones, tablets and laptops
MAM (mobile application management) Only work apps and the data inside them Personal devices where the user will not enroll the whole device
EMM (enterprise mobility management) MDM plus MAM and content management An older umbrella term, still used by some vendors
UEM (unified endpoint management) Every endpoint (mobile, desktop, rugged, IoT) from one console, often with patching Organisations managing Windows, macOS, iOS and Android together

Microsoft’s documentation puts the MDM and MAM split simply: with MAM, “you can’t factory reset a device… but you can remove company resources from the device,” which is why MAM suits BYOD and MDM suits company-owned devices. In 2026 most vendors sell UEM under the MDM label: Hexnode, Scalefusion, Omnissa Workspace ONE, Iru (formerly Kandji) and Intune all manage desktops as well as mobiles.

What is MDM used for in security and compliance?

  • Enforcing baseline controls: passcodes, disk encryption (FileVault, BitLocker, mobile storage encryption), screen lock and minimum OS versions.
  • Conditional access: only compliant, managed devices can reach email and business apps. Intune does this through Microsoft Entra ID; other MDMs integrate with Okta and Google.
  • Lost and stolen devices: lock, locate (company-owned) and wipe, so a lost laptop is an inconvenience, not a data breach.
  • Patching: pushing OS updates and, on UEM tiers, third-party app patches.
  • Audit evidence: device inventories and compliance reports that support frameworks such as HIPAA, SOC 2, ISO 27001 and GDPR. HIPAA, for example, does not name MDM but requires safeguards for devices holding patient data, and MDM is the usual way to enforce and show them.

MDM is one layer of endpoint security, not all of it. Most organisations pair it with endpoint protection, identity and a password manager; see our 1Password vs Bitwarden for Business comparison for the last of those.

How much does MDM cost?

MDM ranges from free to about $15 per device per month in 2026, based on vendor-published prices:

  • Free: Apple Business (Apple devices, free since April 14, 2026), Miradore (up to 50 devices), Mosyle (up to 30 Apple devices), ManageEngine Mobile Device Manager Plus (up to 25 devices). See the best free MDM software.
  • $1 to $6 per device per month: most paid plans, including Mosyle ($1), Scalefusion ($2 to $6), Hexnode ($2.20 to $4.70) and Miradore ($2.75 to $3.95 annual).
  • Per user: Microsoft Intune Plan 1 is $8 per user and is included in Microsoft 365 Business Premium, E3 and E5 (see Intune pricing).
  • Premium Apple bundles: Jamf for Mac is $12.50 per Mac with security included (see Jamf pricing).

Every vendor’s tiers and minimums are compared in our MDM pricing guide.

How do I know if my phone has mobile device management?

On an iPhone or iPad, go to Settings > General > VPN & Device Management. Apple’s support documentation says installed configuration profiles and any device management appear there. If you see a management profile from your employer or school, the device is enrolled.

On Android, look for a separate “Work” tab or work profile in the app drawer, or check the device administrator and work profile entries in the Security or Accounts section of Settings (menu names vary by manufacturer). A fully managed company phone usually shows a notice on the lock screen or in Settings that the device is managed by your organisation.

Can MDM be permanently removed?

It depends on how the device was enrolled.

  • Personal devices: yes. On an iPhone you can remove the management profile in VPN & Device Management, and on Android you can remove the work profile. Doing so also removes your employer’s apps, data and access.
  • Company-owned, supervised devices: usually not. Apple lets organisations prevent unenrollment on devices set up through Automated Device Enrollment, and those devices are tied to the organisation by serial number in Apple Business, so they are directed back to the company’s MDM when set up again. Android zero-touch and Windows Autopilot work in a similar way.

The legitimate way to remove MDM from a company device is to ask IT to release it from the organisation’s account, for example when you buy a device from a former employer.

Can a factory reset remove MDM?

A factory reset removes MDM from a personally enrolled device, along with everything else on it. It does not free a company-owned device registered for automated enrollment: after the reset, the device finds its assigned MDM again during setup. Only the organisation can release it.

Does an MDM lock mean a device is stolen?

Not necessarily. A remote-management screen during setup means the device is still registered to an organisation, often because a company sold or recycled it without releasing it. It can also mean the device was lost or stolen. Ask the seller for proof that the organisation has released the device, and be cautious about buying any device that shows remote management at setup.

How to choose an MDM

  1. List devices by platform and ownership (company-owned, BYOD, shared or kiosk).
  2. Start from your identity provider. Microsoft Entra ID points to Intune; Okta and Google keep every option open.
  3. Confirm zero-touch support for Apple Business, Android zero-touch and Windows Autopilot.
  4. Decide how much you need beyond MDM: patching, remote support, endpoint security.
  5. Pilot with real devices, including a test wipe, before you commit.

Our guide to the best MDM software in 2026 compares Intune, Jamf, Iru, Hexnode, Scalefusion and more. For remote support alongside MDM, see AnyDesk vs TeamViewer, and for the wider picture, browse the unified endpoint management category.

Frequently asked questions about mobile device management

What is an example of mobile device management?

A company ships new iPhones straight to employees. Each phone enrolls itself in the company’s MDM at first power-on, installs email, Wi-Fi and work apps, and requires a passcode. If one is lost, IT wipes it remotely.

What does MDM stand for?

Mobile device management. In data teams, MDM can also mean master data management, which is an unrelated discipline.

Can my employer see my texts with MDM?

No. Microsoft’s Intune documentation, for example, lists email and text messages, browsing history, photos and passwords as things your organisation can never see. A company VPN or web filter is a separate tool and can log traffic that passes through it.

Is MDM the same as UEM?

Not quite. MDM started with phones and tablets; UEM manages every endpoint, including desktops and laptops, from one console. Most modern MDM products are really UEM.

Do small businesses need MDM?

Any business with company data on phones or laptops benefits, and free tiers make it low-risk. Apple Business, Miradore, Mosyle and ManageEngine all offer free options for small fleets.

Does MDM work without internet?

Policies already applied keep working offline, such as passcode and encryption rules. New commands, like a remote wipe, take effect the next time the device connects and checks in.

Can MDM track my location?

On company-owned devices, usually yes, often only in lost mode. On personal devices enrolled in Intune, Microsoft says your organisation cannot view the device’s location. For other tools, check your employer’s device policy.

Translate »