Mobile Device Management: Der umfassende MDM-Leitfaden für Unternehmen
The modern workplace is no longer limited to the office. Employees work from home, on trains, at construction sites, from delivery vehicles, or while visiting customers. Smartphones, tablets, and laptops have become essential tools for getting work done.
As early as 2022, almost 30% of employees in the EU used digital devices such as computers, tablets, or smartphones for most or all of their working time.
However, increasing workplace mobility also creates new challenges for IT departments: How can corporate devices be managed centrally? How can security policies be enforced? And how can corporate data be protected without unnecessarily restricting employees’ private use of a device?
This is where Mobile Device Management (MDM) comes in.
In this guide, you will learn what Mobile Device Management is, how an MDM works, which features modern MDM solutions offer, what businesses should consider when choosing an MDM, and what role MDM plays in data protection and IT security.
What Is Mobile Device Management?
Mobile Device Management (MDM) is software used to centrally manage, configure, and secure corporate mobile devices. These include smartphones and tablets and, depending on the solution, also laptops and other endpoints.
An MDM enables IT administrators to centrally enroll devices, configure security policies, distribute apps, manage settings, and perform certain actions remotely, such as locking or wiping a device.
The German Federal Office for Information Security (BSI) describes MDM as a combination of technical and organizational measures for centrally managing mobile devices. A key function is enforcing defined security policies and configuration parameters. (bsi.bund.de)
MDM is therefore more than simply installing software: businesses also need clear rules defining which devices are managed, which policies apply, and who has access to the MDM platform.
MDM, EMM, UEM, and RMM: What Is the Difference?
The terms MDM, EMM, UEM, and RMM are sometimes used interchangeably. Technically, however, they describe different areas of focus.
|
Solution
|
Focus
|
Typical Use Cases
|
|
|---|---|---|---|
|
MDM
|
Device management
|
Device settings, security policies, apps, remote actions
|
|
|
MAM
|
Mobile application and corporate data management
|
App protection, BYOD, separation of business and personal data
|
|
|
EMM
|
Comprehensive mobile environment management
|
Devices, apps, content, and mobile identities
|
|
|
UEM
|
Unified management of different endpoints
|
Smartphones, tablets, laptops, and other corporate devices
|
|
|
RMM
|
Remote monitoring and management
|
Servers, traditional computers, and IT infrastructure
|
|
The boundaries between these categories are not always clear-cut in practice. Modern platforms often combine several of these capabilities.
MDM
With Mobile Device Management, the device itself is at the center. Typical features include managing security settings, apps, configurations, and device access. Remote actions such as locking or wiping a device may also be available.
MAM
Mobile Application Management (MAM), on the other hand, focuses on apps and the corporate data they process. This can be particularly useful in BYOD scenarios. Instead of managing an employee’s entire personal device, for example, only business apps and data can be protected. Modern platforms can combine MDM and MAM capabilities.
EMM
Enterprise Mobility Management (EMM) expands this approach to include areas such as mobile content, applications, and identities. EMM can therefore be understood as a comprehensive approach to managing mobile work environments.
UEM
Unified Endpoint Management (UEM) goes beyond mobile devices and brings the management of different endpoint types together. Depending on the platform, this may include smartphones, tablets, macOS, Windows, or Linux devices.
RMM
Remote Monitoring and Management (RMM) is typically used to monitor and remotely manage traditional IT infrastructure and endpoints. An RMM is therefore not automatically part of an MDM and does not necessarily need to be deployed alongside one.
In short: The right approach depends on the device fleet, operating systems, security requirements, and desired scope of management.
How Does Mobile Device Management Work?
The primary purpose of an MDM is to avoid having to configure and manage mobile devices individually and manually. Instead, devices are enrolled centrally and then configured through an MDM platform. A typical MDM consists of a central management platform and the management mechanisms provided by the respective operating system. The BSI describes an MDM system accordingly as an interaction between an MDM server and an MDM client or operating-system interface. The server can distribute configurations, applications, updates, and commands to managed devices. For example, an MDM can distribute a VPN configuration to a device. However, the underlying VPN infrastructure must already have been set up and operated by the company. The MDM distributes and manages the corresponding configuration.
The MDM Management Lifecycle
A managed device typically goes through four stages during its lifecycle:
Enroll the Device:
Before a device can be managed centrally, it must first be enrolled in the MDM environment.
For Android devices, various Android Enterprise enrollment methods are available, including QR code enrollment, work profiles, and zero-touch enrollment. With Android zero-touch enrollment, compatible devices purchased through authorized resellers can be preconfigured for corporate management. During the initial setup, the assigned corporate configuration is automatically applied.
Apple also offers automated enrollment methods. Through Apple Business, corporate iPhone, iPad, and Mac devices can be assigned to a device management service and enrolled automatically. This allows companies to ship devices directly to employees without requiring the IT department to physically configure each device beforehand.
Different enrollment models are available for personally owned devices, depending on the platform. These include work profiles and User Enrollment, which can help separate business and personal data.
Automated enrollment: Particularly for corporate-owned devices, automated provisioning can significantly reduce manual setup effort.
Manual enrollment: For BYOD scenarios or certain devices, platforms may support methods such as QR codes, enrollment codes, or other enrollment processes.Manage Devices:
Once a device has been enrolled, IT administrators can centrally distribute configurations and policies. These may include:
– security and passcode policies
– Wi-Fi and VPN configurations
– app assignments
– restrictions on certain device functions
– email and account settings
– software and operating system updatesFor example, Apple provides options for centrally managing settings and software through device management, monitoring compliance, and remotely locking or wiping devices.
Monitor Compliance:
An MDM can regularly receive information on the status of a managed device and check whether specified security requirements are being met.
If, for example, it is determined that a device does not meet a specific security requirement, the MDM platform can, depending on the solution, generate an alert or trigger a defined action. Find out more about alerts and breaches on the IOTIQ blog: Warnings in MobiVisor.
It is important to note that whilst an MDM can technically enforce security policies or monitor compliance with them, it cannot guarantee under all circumstances that a device will be online or fully compliant at all times.Trigger Security Measures:
Companies can define responses to specific events. Depending on the platform and configuration, these may include locking a device, restricting certain functions, or remotely deleting corporate data. If a device is lost or stolen, a Remote Lock or Remote Wipe can help prevent unauthorized access to corporate data. For more information about lost devices, see the IOTIQ article: What to do if your company phone is lost?
Key Features of an MDM Platform
Modern MDM solutions can combine a wide range of management and security functions. The features available depend on the provider, operating system, and selected plan.
Over-the-Air Installation:
Over-the-Air (OTA) technology allows configurations, apps, updates, and commands to be transmitted to managed devices over a network.
This means that a device does not need to be physically accessible to the IT department for many management tasks. However, the device must be able to establish an appropriate network connection, and the platform must support the respective function.
App and Data Management:
MDM solutions can centrally distribute, configure, update, or remove apps. Depending on the operating system, companies can also control which apps may be installed or used.
The management of corporate data can also be part of a broader mobility management strategy. For example, app protection mechanisms or container solutions can be used to separate corporate data from personal data.
MobiVisor can also be used for secure file transfers through MobiVisor Files.
Secure Separation of Personal and Business Data:
Separating personal and corporate data is particularly important in BYOD and other mixed-use scenarios. Android Enterprise, for example, supports work profiles on both personally owned and corporate-owned devices. This allows business apps, data, and management policies to be restricted to the work profile. Apple also offers management models such as Account-driven User Enrollment and Device Enrollment, which can help separate business and personal data.
Learn more:
Data separation on Apple devices
COPE vs. COWP on Android devices
Depending on the operating system and enrollment model, specific restrictions can be configured for features such as screenshots, cameras, or apps.
Identity and Access Management:
MDM platforms can integrate with existing identity and access management systems. This allows companies to connect users, devices, and security policies.
Single Sign-On (SSO) and Multi-Factor Authentication (MFA) can form part of an overarching Identity and Access Management strategy. The available integrations depend on the respective MDM and IAM platforms.
Kiosk Mode:
In Kiosk Mode, a device can be restricted so that users can access only selected apps or, in Single-App Mode, a single application. This can be useful for:
- digital menus
- check-in terminals
- ordering terminals
- mobile point-of-sale solutions
- form collection
- information and signage systems
Mobile Threat Defense:
An MDM is not an MTD system in the traditional sense, as an MDM cannot actively detect and ward off threats to mobile devices. However, an MDM acts preventively by fundamentally raising the security level of mobile devices.
Cloud vs. On-Premises: Where Is Your Data Hosted?
When selecting an MDM solution, companies should also consider how the platform will be operated. In general, organizations can choose between cloud-based solutions and on-premises models.
Hosting-Model
Cloud-based (SaaS)
On-Premises
Advantages
- No investment in physical servers.
- Easy scaling without building an internal server infrastructure.
- The provider typically handles maintenance of the underlying platform.
- Can be used without a large internal IT team.
- Greater direct control over infrastructure and data storage.
- Suitable for companies with specific requirements regarding data sovereignty and infrastructure control.
- Can be suitable for particularly protected or isolated environments.
Technical Limits
- A network connection is generally required for centralized management and the delivery of new policies and commands.
- Companies need to assess the provider’s data location, data processing, contractual arrangements, and security concept.
- Higher investments in servers, backups, and potentially licenses.
- The company is responsible for updates, patches, backups, and infrastructure.
- Appropriate technical expertise and resources must be available internally.
A cloud solution does not automatically mean that fewer data protection requirements apply. Companies should assess, among other things, where data is processed, which service providers are involved, and which contractual and technical safeguards are in place.
Mobile Device Management Across Different Industries
The requirements for mobile devices vary depending on the industry and use case.
Logistics and Delivery Services:
In logistics and field service, devices are often used under demanding conditions. Rugged devices and durable handheld scanners can therefore be suitable for these environments.
An MDM can centrally configure devices and, for example, determine which apps are available. If a device is lost, it can – depending on the platform and configuration – be locked or remotely wiped.
Healthcare and Medical Services:
Healthcare organizations process particularly sensitive personal data. Accordingly, they face high requirements regarding data protection and information security.
An MDM is not generally required by law. However, it can be a technical tool that helps organizations implement security policies on mobile devices.
- secure passcode requirements
- restricting screenshots
- app management
- controlling certain network connections
- separating business and personal data
The applicable requirements depend on the specific organization, the data being processed, and the relevant legal framework.
Retail and Service:
In retail, tablets and smartphones can be used in Kiosk Mode for various purposes, including digital signage, check-in stations, or mobile POS scenarios. Learn more in the MobiVisor customer case study: MDM in practice: Retail use case
Banking and Financial Services:
Financial organizations have high requirements for protecting data and access credentials.
MDM can help enforce security policies on managed devices. Depending on the platform, screenshots can be restricted, apps managed, or certain interfaces controlled.
For particularly sensitive applications, additional app protection or container solutions can be used.
Mobile Device Management and Data Protection: What Does the GDPR Say?
The GDPR does not generally require companies to use MDM. However, it requires controllers and processors to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Article 32 GDPR refers, among other things, to encryption, confidentiality, integrity, availability, and regular testing of security measures. An MDM can be one component of these technical measures, particularly when a company needs to centrally manage mobile devices and enforce security policies.
Is an MDM Automatically GDPR-Compliant?
No. An MDM is not automatically GDPR-compliant. However, it can be used in a GDPR-compliant way. Relevant factors include:
- which personal data is processed,
- the purpose of the processing,
- the applicable legal basis,
- access permissions,
- retention periods,
- and the technical configuration of the MDM platform.
The ability to locate devices or access certain device information may also be relevant from a data protection perspective. Companies should therefore assess which data is actually processed before introducing an MDM and whether the selected settings are necessary and appropriate for the intended purpose.
Data Breaches: When Must They Be Reported?
A data breach does not automatically have to be reported to a data protection authority.
Under Article 33 GDPR, a personal data breach generally has to be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours if it is likely to result in a risk to the rights and freedoms of natural persons. If such a risk is unlikely, notification is not required. If a breach is likely to result in a high risk to affected individuals, they may also need to be informed. For businesses, this means that mobile security is not only about protecting devices. Processes for detecting, assessing, and responding to security and data protection incidents are also part of a comprehensive security strategy.
How Much Does an MDM Cost?
Pricing for MDM solutions can vary significantly.
Many providers offer several pricing tiers. A basic plan may include core features, while functions such as Kiosk Mode, Remote Support, or advanced security features may only be available in higher-tier plans. Other providers bundle a broader range of features into a single package. Pricing models also differ and may include:
- per-device licensing
- per-user licensing
- volume-based pricing
- different billing periods
- additional fees for specific features or support services
Companies should therefore not compare license prices alone, but instead consider the total scope of the required functionality. An inexpensive MDM can become more expensive if important requirements require additional modules.
What Should Companies Consider When Choosing an MDM?
Before selecting an MDM solution, IT teams should define:
- Which operating systems need to be managed?
- How many devices need to be managed?
- Will BYOD devices be used?
- Which security policies are required?
- Is Kiosk Mode needed?
- Is Remote Support required?
- Which integrations with IAM, Apple Business, or Android Enterprise are needed?
- Where should data be processed and stored?
- Which support services are required?
- What are the total costs over the contract period?
Price should therefore not be the only selection criterion.
Tip: All MobiVisor features and support are included in the license price.
Mobile Device Management Best Practices
An MDM can support the technical security of mobile devices. However, a successful implementation also requires clear processes and responsibilities.
Define Actions for Security Violations:
An MDM can check the status of managed devices and identify whether certain security requirements are not being met.
Depending on the solution, violations can be displayed in the MDM console or reported to administrators via notifications. Companies can also define which actions should be triggered by specific events. Learn more about device alerts and violations:
Warning messages in the MDM– IOTIQ BlogDefine How Devices May Be Used:
Before introducing an MDM, companies should determine whether devices are:
– used exclusively for business,
– used for both business and personal purposes
– or privately owned BYOD devices.This determines which management and security measures are appropriate.
Define Roles and Access Rights:
Not every administrator needs the same permissions.
Companies should therefore define in advance:
– Who can enroll devices?
– Who can change policies?
– Who can distribute apps?
– Who can wipe or lock devices?
– Who has read-only access?End users should also be assigned to appropriate groups so that policies and apps can be assigned efficiently.
Keep the MDM Structure Simple:
When it comes to MDM, the principle is: As much as necessary, as little as possible.
Too many groups, policies, and individual exceptions can make device management unnecessarily complicated. Instead of configuring every employee individually, companies should work with clearly defined roles and use cases.Inform Employees:
Introducing an MDM affects how employees use their devices. Companies should therefore explain: which functions the MDM provides, which data is processed, which restrictions apply, how Remote Support works, and what to do if a device is lost or stolen. Especially in BYOD scenarios, companies should clearly communicate which personal data remains outside the scope of management and which corporate data is protected.
Establish Clear BYOD Policies:
Private devices should not be used for corporate purposes without clear rules.
Companies should define whether BYOD is permitted, which devices and operating systems are supported, and which security requirements apply.
Depending on the platform, a work profile or app protection solution can be used instead of managing the entire personal device to the same extent.
3 MDM Myths Businesses Should Know
Myth #1: All MDM Solutions Are the Same
False.
MDM solutions differ in terms of supported operating systems, features, integrations, hosting models, support, and pricing. Even when providers use similar terms such as App Management, Kiosk Mode, or Remote Support, the actual functionality can differ significantly.
Myth #2: MDM Only Makes Sense for Large Device Fleets
False.
An MDM can also be useful for smaller device fleets. If, for example, 10, 20, or 50 devices have to be configured and maintained individually, the administrative effort can quickly add up. There is also a security benefit: an MDM can help companies centrally implement security policies and monitor the status of managed devices.
Myth #3: MDM Automatically Means an Invasion of Privacy
Not necessarily.
Depending on the platform and configuration, an MDM can process certain device and usage information. However, this does not automatically mean that administrators can access personal messages, photos, or other private content.
Especially in BYOD scenarios, platforms such as Android Enterprise and Apple offer management models that can separate business and personal data.
Companies should review which personal data is actually processed before introducing an MDM and communicate this transparently to employees.
MobiVisor MDM: Simple and Reliable Mobile Device Management
When selecting an MDM, many factors matter. One of the most important is usability: A platform should enable companies to manage devices centrally without making administration unnecessarily complex.
MobiVisor MDM is designed to support businesses of different sizes in managing and securing mobile devices.
No Hidden Costs
Apple and Android enrollment, app distribution, security policies, Remote Support, and Kiosk Mode are included in the MobiVisor license. MobiVisor does not use a premium-tier model.
Hosting in Germany
The MobiVisor infrastructure is operated on servers in Germany.
Multi-Platform Support
MobiVisor supports several operating systems and platforms, including Android Enterprise, iOS, iPadOS, macOS, and Linux. We also offer integrations with Android Zero-Touch, Apple Business, Apple School Manager, and Samsung Knox.
Location-Based Policies
MobiVisor offers features that allow policies to be configured based on a device’s location. Location-dependent Wi-Fi configurations are also supported. Which location data is processed and exactly how these features are technically implemented can be assessed based on the specific product configuration and applicable privacy documentation.
Software as a Service
MobiVisor is offered as a SaaS solution. This means customers do not have to operate the underlying server infrastructure themselves. This service also includes onboarding, assistance with setting up MobiVisor, and ongoing support. Learn more about our Mobile Device Service on the IOTIQ website.
Conclusion: Mobile Device Management as Part of a Comprehensive IT Security Strategy
Mobile devices have become an essential part of modern workplaces. At the same time, distributed devices, remote work, BYOD, and multiple operating systems increase the demands placed on IT management. Mobile Device Management provides a central layer through which companies can enroll, configure, manage, and secure devices. An MDM does not replace a comprehensive cybersecurity strategy. However, it can be an important part of one – particularly when mobile devices access corporate data and systems. When choosing an MDM, companies should therefore look beyond price. The key factors include required functionality, supported platforms, integrations, data protection requirements, hosting, support, and ease of day-to-day management.
FAQ
What Is MDM?
Mobile Device Management (MDM) is software used to centrally manage and secure corporate mobile devices. It can include device and app management, security policies, and remote actions such as locking or wiping devices.
Does My Company Need an MDM?
Not every company is legally required to use an MDM. However, an MDM can be useful if a company wants to centrally manage and secure mobile devices – particularly in larger device fleets, field service, remote work, or BYOD scenarios.
The GDPR does not require a specific technology such as MDM, EMM, or UEM. Instead, it requires appropriate technical and organizational measures based on the risks involved.
Which Companies Should Use an MDM?
An MDM can be useful for any company that wants to centrally manage and secure mobile devices. It is particularly relevant for businesses with large numbers of mobile devices, field employees, remote workplaces, or BYOD environments.
Additional security and data protection requirements may apply to highly regulated industries. Whether a company is classified as a critical infrastructure operator depends on the applicable legal requirements and thresholds.
Is an MDM GDPR-Compliant?
An MDM is not automatically GDPR-compliant, but it can be used in a GDPR-compliant way.
Relevant factors include the type of personal data processed, the purpose and legal basis of processing, access rights, retention periods, and the configuration of the MDM solution.
What Can an MDM Do?
Depending on the platform and provider, an MDM can:
- enroll devices,
- enforce security policies,
- distribute apps,
- manage Wi-Fi and VPN configurations,
- lock or wipe devices,
- provide compliance information,
- enable Kiosk Mode scenarios,
- and centralize the management of corporate devices.
Available features depend on the operating system and specific MDM solution.
Can an MDM Read Employees' Private Data?
Depending on the platform, an MDM can process certain device information and personal data, but it does not automatically have access to all private content on a device. For BYOD environments, platforms such as Android Enterprise and Apple offer management models that can separate business and personal data.
Cloud or On-Premises: Which Is Better?
It depends on the company’s requirements.
Cloud MDM typically reduces the need for internal infrastructure and makes scaling easier. On-premises solutions can provide more direct control over infrastructure and data storage, but require internal technical resources.