Microsoft 365

Mobile Device Management

Your team works from home, from a client site and from a train, and your data travels with them. We enrol the phones and laptops that hold business data so flexible working stays a productivity gain rather than a risk, and a lost handset stays an inconvenience instead of a reportable breach. It also makes the offer to a new hire easy: use the device you like, with the work data kept separate from the rest.

What this protects

Flexible working you can defend

Staff work from anywhere now. The real question is what happens to your data when the device it sits on walks out of the building.

Your licence to operate

A lost phone with live access to email and files is a reportable breach. Enrolment and remote wipe are the difference between an inconvenience and an incident.

A benefit that helps you hire

Letting people use the phone they like is a genuine perk, and it costs less than buying and managing a handset for every member of staff.

Working from anywhere

Enrolled devices mean people can work from a kitchen table or a client site without IT having to chase every unmanaged laptop and handset.

The gap nobody wants to talk about

Ask most businesses how many devices hold their data and you get a rough guess. It is the director's phone, the two sales laptops, a tablet the field team share, and a personal iPhone somebody set their work email up on in 2022. Few are managed, and none are wiped when they go missing.

Managing devices is not about watching staff, and we are careful to make that distinction. It is about being able to apply a policy, keep work data separate from personal, and remove the work data from a device that ends up in the back of a taxi.

What we manage

Enrolment

Company and personal devices enrolled through Microsoft Intune, across iPhone, Android, Windows and Mac.

Compliance policies

A passcode, an up-to-date operating system and device encryption as the price of getting your email on that device.

Conditional access

Work data reachable only from a compliant, trusted device, so a stolen password alone is not enough.

App protection

Work email and files kept inside managed apps, separate from the personal photos and apps alongside them.

Remote wipe

Remove company data from a lost device, or wipe it entirely if it is a company-owned handset.

BYOD, done fairly

Team members keep their own phone and their privacy. We scope what is visible to the business and what is not.

The practical rules we recommend

  • A minimum passcode and device encryption before any work email will sync
  • An operating system still receiving security updates, because a phone that has stopped patching is a phone that is not protected
  • Company data confined to managed apps, so it can be removed without touching personal content
  • A clear rule on what happens if a personal device is lost, agreed before it happens
  • Automatic enrolment for new starters, so nobody is ever the exception
  • Conditional access so signing in is judged on the device as well as the password

Company phones versus personal ones

They should be treated differently, and often are not. A company-owned handset is ours to configure fully and wipe completely if it goes missing. A personal phone should only ever have the work data removed.

Intune lets us make that distinction properly. Staff can see exactly what the business can and cannot access, and in our experience that transparency removes most of the resistance.

What this prevents

  • A lost phone with a live, unexpired session into your email and files
  • An out-of-date operating system with known flaws still signing into your tenant
  • Company data sitting in a personal cloud backup the business cannot reach
  • No answer when someone asks where all your data actually lives

Questions we get asked about Mobile Device Management

No. On a personal device we can see the work data inside managed apps, not personal messages, photos or location. We will show your team exactly what is and is not visible.

Yes, and it is usually the easier sell. Company devices should be enrolled from day one, with encryption and access rules applied automatically.

Their work data is removed from the device automatically. On a company-owned device we can wipe it fully before it is reassigned.

Yes. We manage both, along with Windows and Mac, through the same system, and policies are consistent across them.

MDM is usually included in the higher Microsoft 365 licence tiers you may already hold. Where it is not, the cost is modest against the risk of a lost, unprotected device.

Not sure whether you need mobile device management?

Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.