Mobile Device Management: What It Actually Covers
Mobile Device Management: What It Actually Covers
“Mobile device management” sounds like a big, abstract IT category, but the actual question it answers is a simple one: when someone’s phone or laptop can read your company email, open your files, or log into your systems, what stops that from becoming a problem if the device is lost, stolen, or just leaves the business along with the person carrying it?
Company-Owned Devices vs Personal Devices
There are two situations this covers, and they’re genuinely different problems. A company-owned laptop or phone is yours to manage outright, you can set whatever policies you like on it. A personal device someone uses for work, their own phone checking email on the train, is trickier: you don’t own it, but company data is still sitting on it, and you still need to protect that part without reaching into someone’s personal photos and messages.
What It Actually Does, in Practice
Properly set up, mobile device management handles a specific, practical set of things: requiring a passcode or biometric lock before company email or files can be opened, encrypting company data on the device, allowing a remote wipe of just the company data (not someone’s personal photos) if a device is lost, stolen, or an employee leaves, and checking that a device is reasonably up to date before it’s allowed to connect at all. None of this is about monitoring what someone does on their own time, it’s specifically about the boundary between personal and business data on a device that touches both.
Why This Increasingly Isn’t Optional
This has moved from “good practice” to something you’re actually assessed on. Cyber Essentials tightened its stance on personal devices significantly in the April 2026 update, if staff use their own phones or laptops to access company email, files, or cloud services, that now needs genuine, demonstrable controls in place, not just a policy document nobody’s read. We’ve covered the full detail in our guide to what changes year to year with Cyber Essentials renewal, but the short version is: if you’re relying on staff using personal phones for work email with no device management in place, that’s now a real gap, not a minor one.
You Probably Already Have the Tool for This
Most businesses already using Microsoft 365 don’t need to buy anything new here. Microsoft Intune, Microsoft’s own device management platform, is bundled into several Microsoft 365 tiers and handles exactly what’s described above: enforcing passcodes, encrypting data, remote wiping company information specifically, and checking device compliance before access is granted. The gap for most businesses isn’t the tool, it’s that it’s sitting there unconfigured, included in what they’re already paying for but never actually switched on.
Where CCSW Comes In
We set up and manage device policies as part of our Microsoft 365 support, checking what you’re already entitled to before recommending anything extra. If you’re not sure whether your team’s devices, company-owned or personal, are actually protected the way you assume they are, get in touch and we’ll take a proper look.
