How devices are configured centrally.
WHAT MOBILE DEVICE MANAGEMENT IS
A protocol allowing a server to configure, monitor and control enrolled devices.
WHAT IT CAN DO
Apply configuration settings Install and remove applications Enforce passcode and encryption policy Restrict features Wipe or lock a device remotely Collect inventory information
WHAT IT CANNOT DO
Read the user's personal data arbitrarily.
WHY THAT MATTERS
The framework is deliberately limited, which is what makes personally owned device enrolment acceptable.
WHAT ENROLMENT TYPES EXIST
Device enrolment, for organisation-owned devices, applied automatically at setup User enrolment, for personally owned devices, with limited scope Manual enrolment
WHAT DEVICE ENROLMENT PROVIDES
Automatic, supervised configuration that the user cannot remove.
WHAT SUPERVISION ENABLES
Additional restrictions and capabilities available only to organisation-owned devices.
WHAT USER ENROLMENT PROTECTS
The user's personal data, which the organisation cannot reach or erase.
WHAT TO ESTABLISH
Which model fits how devices are actually owned.
WHAT TO DOCUMENT
What the organisation can and cannot see.