Managed IT
Guide

Mobile Device Management: How It Actually Works

Mobile device management is not one product, it is a policy layer over Intune, Jamf, or both, depending on your device mix. This guide explains how enrollment and policy actually work, when you need Jamf next to Intune, and what a real rollout involves.

Aug 31, 2026
8 min read
Mobile Device Management: How It Actually Works

"Mobile device management" sounds like a single product you buy, but in practice it is a policy layer sitting on top of one or two underlying platforms, most often Microsoft Intune for a Windows and mixed-device fleet, Jamf for an Apple-only or Apple-heavy one, or both running side by side. The tool matters less than what you actually configure it to do, and that is the part most explainer pages skip.

This guide covers how MDM actually works once it is running, how Intune and Jamf differ and when you need one, the other, or both, what a real rollout looks like week by week, and the mistakes that turn an MDM deployment into a source of help desk tickets instead of a way to prevent them.

What MDM actually does, in practice

Strip away the marketing language and MDM does four things:

  • Enrolls a device into management, so it is provisioned with the right apps, network settings and certificates before an employee ever opens it, or as they set it up themselves.
  • Enforces configuration policy: passcode and encryption requirements, which apps are allowed, whether personal apps can share data with work apps, Wi-Fi and VPN profiles pushed automatically instead of typed in by hand.
  • Reports compliance, flagging devices that are jailbroken, running an outdated OS, or missing required security settings, so those flags can feed into conditional access instead of sitting in a dashboard nobody checks.
  • Acts remotely when something goes wrong: lock a lost device, wipe the corporate data (or the whole device, depending on ownership), or push an emergency policy change to the entire fleet in minutes.

None of that requires a specific brand. What determines whether it actually works is whether the policies match how your business actually operates, and whether someone owns keeping them current as apps, employees and devices change.

Intune vs. Jamf: which one for which fleet

Microsoft Intune manages Windows, Android and iOS/iPadOS devices from one console and is usually already included in the Microsoft 365 or Entra ID licensing many Dutch SMEs are already paying for, which is why it is the default starting point for a mixed-Windows fleet. It integrates directly with Entra ID conditional access, so a device that fails a compliance check can be blocked from Outlook or SharePoint automatically, not just flagged.

Jamf is built specifically for Apple devices and goes deeper than Intune does on macOS, iPadOS and iOS: Apple-specific deployment features, tighter integration with Apple Business Manager, and configuration options for Apple hardware that Intune's more general cross-platform approach does not fully cover. If your fleet is Apple-only, Jamf alone is usually the simpler answer.

Where both show up together is the common case for a Dutch SME with a Windows-based back office and a design, marketing or leadership team on MacBooks: Intune manages the Windows majority and the Entra ID compliance signals, Jamf manages the Apple devices in more depth, and both feed device compliance status into the same conditional access policies so a non-compliant device is blocked regardless of which platform manages it. Running both is more setup work up front, but it avoids the alternative, which is either forcing Apple users onto weaker policies to keep one console, or leaving Apple devices unmanaged entirely.

BYOD vs. corporate-owned: this decision comes before the tool

Before picking a platform, decide what you are actually managing: company-owned devices, or personal devices employees use for work.

  • Corporate-owned devices can be fully managed: enrolled before they reach the employee, locked down more strictly, and wiped completely if lost, since there is no personal data on them to protect.
  • BYOD (personal devices) need a lighter touch. Both Intune and Jamf support "app protection" or "work profile" modes that manage only the work apps and their data, an employee's personal photos, messages and apps stay untouched, and a wipe only removes the work container, not the whole phone. Full device management on a personal phone is both legally awkward and a fast way to make policy adoption fail, since employees will resist enrolling a device they own into a system that can wipe their own data.

Most SMEs end up running both models at once: full management for company laptops and phones, app-level protection for personal devices used to check email. Deciding this upfront changes which policies you configure and avoids re-doing the rollout later.

What a real rollout looks like

A properly planned MDM deployment is not "install the app on everyone's phone." A realistic sequence:

  • 1. Inventory and decide ownership. List what is actually in the field today: device types, OS versions, who owns each device. This is also when BYOD vs. corporate policy gets decided per device category.
  • 2. Draft policy before touching a device. Passcode length, encryption requirement, allowed and blocked apps, Wi-Fi and VPN profiles, what triggers a compliance failure. Getting this on paper first avoids reconfiguring live devices later.
  • 3. Pilot with a small group. Ten to twenty devices across the different roles and device types in the business, not just IT's own laptops, which are usually already clean and not representative of a real user's device.
  • 4. Fix what the pilot breaks. A policy that is too strict blocks a legitimate app or forces re-authentication constantly; one that is too loose does not actually reduce risk. This step is where most of the real tuning happens.
  • 5. Roll out in waves, not all at once, so a policy issue affects twenty people instead of two hundred.
  • 6. Wire compliance into conditional access so a non-compliant device is actually blocked from company data, not just flagged in a report that sits unread.
  • 7. Assign ongoing ownership. New starters need to be enrolled on day one, leavers need to be de-provisioned immediately, and policies need review as the app list and OS versions change. MDM is infrastructure, not a project with an end date.

Common mistakes

  • Buying the license and stopping there. Intune or Jamf sitting unconfigured with default policies provides close to none of the actual security benefit; the value is in the policy work, not the subscription.
  • Full-wiping a personal device. A single incident where someone's personal phone gets factory-reset because it was enrolled under the wrong policy will end BYOD cooperation for years.
  • No de-provisioning process. A leaver whose device is not un-enrolled keeps access to company email and files long after their last day, and nobody notices until it becomes a problem.
  • Policy that never gets revisited. A new app the team needs gets manually whitelisted once as an exception and never formalized, so the policy drifts further from reality every month.
  • Managing Apple devices as an afterthought in Intune when the business is genuinely Apple-heavy, instead of accepting the extra setup cost of adding Jamf, which usually pays for itself in fewer device-specific support tickets.

Is MDM overkill for a small team?

For a handful of employees on devices they already handle carefully, full MDM can be more overhead than the risk justifies, and a simpler set of built-in OS controls (FileVault, BitLocker, Find My) may cover the basics. The calculation changes once any of the following is true: employees access company email or files from their own phones, the business handles client or patient data with a duty of confidentiality, NIS2 or a client contract requires demonstrable device security controls, or losing a single device would mean losing data nobody can get back. Past roughly ten to fifteen devices, the manual alternative, chasing everyone individually to keep their OS and passcode settings current, usually costs more in admin time than a properly configured MDM platform does.

FAQ

What is the difference between Intune and Jamf? Intune is Microsoft's cross-platform MDM tool, managing Windows, Android and iOS/iPadOS from one console and integrating tightly with Entra ID conditional access. Jamf is built specifically for Apple devices and offers deeper macOS and iOS management than Intune's more general approach. Many SMEs with a mixed Windows and Apple fleet run both together.

Do I need MDM if I already use Microsoft 365? Intune is included in several Microsoft 365 and Entra ID licensing tiers many businesses already hold, so the platform itself may already be available. What is usually missing is the configuration: enrollment, policy and conditional access integration, which do not happen automatically just because the license exists.

Can MDM wipe an employee's personal phone? Only if the device is enrolled under full device management. For BYOD, both Intune and Jamf support app-level management that separates work data into a managed container, so a wipe removes only work apps and data, leaving personal photos, messages and apps untouched.

How long does an MDM rollout take? A pilot with a small group can be running within one to two weeks once policy is drafted. A full company-wide rollout in waves, including a properly tested pilot and policy tuning, typically takes four to eight weeks depending on fleet size and how many device types and ownership models are involved.

Get your device policy actually working

Already have Intune or Jamf licensed but not properly configured, or need Apple and Windows devices managed under one consistent policy? Our Managed IT Support team handles MDM rollout, policy design and ongoing enrollment. Pair it with Cybersecurity & Identity once device compliance needs to feed into conditional access, and see how it fits a broader security baseline in our guide to NIS2 for SMBs.

Mobile Device Management
Intune
Jamf
Managed IT
MKB

Related Articles

Managed IT

What Does Managed IT Cost for SMBs? Prices Per User (2026)

How much does managed IT support really cost for an SMB in the Netherlands? This guide breaks down price-per-user tiers, what each package includes, one-off and per-server costs, and how to compare quotes without surprises in 2026.

Read More
Managed IT

How to Choose the Right IT Partner for Your SMB (Checklist)

Choosing an IT partner is a multi-year decision that touches every part of your business. This practical checklist covers the questions to ask, the red flags to avoid, how to read an SLA, and how to compare managed service providers fairly.

Read More
Managed IT

What Does IT Workplace Management Cost in 2026?

How much should IT management per workplace actually cost? This guide breaks down 2026 price bands per tier, what a workplace really includes, and how to build the true monthly cost, not just the management fee.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.