The summary.
THE MANAGEMENT FRAMEWORK IS DELIBERATELY LIMITED
It cannot read personal data arbitrarily, which is what makes personally owned enrolment acceptable.
Communicate exactly what the organisation can and cannot see — assumptions are worse than the reality.
AUTOMATED ENROLMENT REQUIRES DEVICES BOUGHT THROUGH AUTHORISED CHANNELS
Grey-market devices cannot be added, which matters here more than in many markets.
USE ORGANISATIONAL ACCOUNTS AND VOLUME PURCHASING
Licences bought by individuals cannot be recovered when they leave, and devices tied to personal accounts become unusable.
ACTIVATION LOCK NOT CLEARED IS THE COMMONEST DEPLOYMENT FAILURE
Supervision and organisational accounts allow clearing it centrally. Verify it before any reassignment or disposal.
BE CAUTIOUS OF PROFILES FROM UNTRUSTED SOURCES
A malicious profile can install certificates permitting traffic interception. Check which profiles are installed and who issued them.
DEFER UPDATES FOR TESTING, NEVER INDEFINITELY
Set a testing period and a deadline, and plan for the major release that arrives annually regardless.
Test management configuration itself against each major version — its behaviour changes.