Mobile Device Management (MDM)

Central tooling that enrols phones, tablets and laptops and enforces configuration, encryption, passcode, app and remote-wipe policy on the devices that hold organisational data.

Mobile Device Management (MDM) is the practice, and the tooling, for managing mobile devices centrally. A device is enrolled with the management service, which then pushes configuration profiles and enforces policy: passcode rules, storage encryption, approved apps, update levels, and the ability to lock or wipe a lost or stolen device remotely. NIST SP 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise, covers this area, including the centralised management technologies that MDM products provide.

MDM supports access control by reporting whether a device meets policy. Many organisations feed that compliance state into access decisions, so a phone that is unencrypted or out of date can be refused access to email or applications, a pattern used in zero trust architectures. Personally owned devices raise a privacy trade-off, so organisations commonly separate work data into a managed container or work profile, which allows a selective wipe of company data without erasing the owner’s personal content. MDM is one form of endpoint security, aimed at devices the organisation may not physically control.

Exam relevance: a scenario is likely to describe a lost phone holding company data, or a bring-your-own-device policy. Candidates are expected to recognise MDM, remote wipe and device compliance checks as the fitting controls, and to weigh the privacy of personally owned devices.