Skip to content
Cloud Updated Noah Stegman

Mobile Device Management (MDM) for Small Business

A vendor-neutral guide to MDM for small offices: MDM vs MAM, Apple Business, Android Enterprise, Intune, Jamf, Iru, and Google options, and how to choose.

Mobile device management (MDM) is software that lets a business apply security settings to phones, tablets, and laptops from a central console, and remove company data from a device that is lost or belongs to someone who has left. A small business should pick its MDM based on what it already pays for and which devices it owns: Microsoft Intune if you are on Microsoft 365 Business Premium, Apple Business or an Apple-focused tool if you are all Apple, and Google’s endpoint management if you run Google Workspace. Personal phones usually need app-level protection, not full MDM.

What Is Mobile Device Management?

An MDM tool enrolls a device and then manages it remotely. Typical capabilities:

  • Require a passcode, screen lock, and encryption
  • Install, update, and remove work apps
  • Push Wi-Fi, VPN, and email settings
  • Keep operating systems updated
  • Show an inventory of devices and their health
  • Lock or erase a lost device

Despite the name, most MDM products now manage laptops and desktops as well as phones. Vendors sometimes call this unified endpoint management.

MDM does not detect malware or stop phishing. It sits alongside endpoint protection and sign-in controls, not in place of them.

MDM vs MAM: What Is the Difference?

Mobile application management (MAM) protects company data inside specific apps without enrolling the device. Microsoft’s Intune overview puts it this way: with MDM the organization manages the whole device, and with MAM it manages only the work apps and the data inside them.

MDMMAM
What is managedThe whole deviceWork apps and their data only
EnrollmentRequiredNot required
Typical useCompany-owned devicesPersonal phones (BYOD)
Lost deviceCan erase the entire deviceCan erase work data only
Employee privacyEmployer sees device details and, on company devices, installed appsEmployer sees only the managed apps

Many offices use both: MDM for equipment the company bought, MAM for staff who read work email on their own phones. The written rules for the second group belong in a BYOD policy.

The Building Blocks Apple, Google, and Microsoft Provide

Every MDM product works through management features built into the operating systems. Knowing these makes vendor conversations easier.

Apple Business (formerly Apple Business Manager)

Apple Business Manager was the free portal that linked company-purchased Apple devices to an MDM so they enrolled automatically at first power-on. On April 14, 2026, Apple replaced it with Apple Business, a free platform that combines Apple Business Manager, Apple Business Essentials, and Apple Business Connect. Apple’s user guide now opens with “Apple Business Manager is now Apple Business.”

Two things changed for small offices. Apple Business includes built-in device management, which Apple previously sold as a paid subscription in Business Essentials. It also supports Managed Apple Accounts, which Apple says keep work and personal data cryptographically separate and can be created automatically from Google Workspace or Microsoft Entra ID.

Devices need to be bought through Apple or an authorized reseller and added to your Apple Business account for automatic enrollment to work. Set the account up before your next hardware purchase.

Android Enterprise

Android Enterprise is Google’s management framework, built into modern Android. It offers a work profile (a separate, managed space for work apps on a personal phone), a fully managed mode for company-owned devices, and zero-touch enrollment, which configures company phones remotely at first startup. Any serious MDM uses Android Enterprise underneath.

Windows enrollment and Autopilot

Windows 10 and 11 include an MDM client. With Microsoft’s tools, a PC enrolls when a work account joins it to Microsoft Entra ID, and Windows Autopilot lets a new PC configure itself at first sign-in. Details are in our Microsoft Intune guide.

What Are the MDM Options for a Small Business?

Prices are vendor list prices in US dollars as of September 2026. Check the linked pages before budgeting, because vendors change them.

OptionPlatformsPublished priceFits best when
Basic Mobility and SecurityiOS, Android, WindowsIncluded in every Microsoft 365 business planYou only need a PIN requirement and remote wipe on phones
Microsoft Intune Plan 1Windows, macOS, iOS, Android, LinuxIncluded in Business Premium ($22.00 per user per month) or $8.00 per user per month standaloneYou use Microsoft 365 and have Windows PCs or mixed devices
Apple Business built-in managementApple onlyFreeEvery device is Apple and needs are simple
Jamf NowApple onlyStarting at $4 per device per monthAll-Apple office wanting more than the built-in tool
Jamf for Mac and Jamf for MobileMac, iPhone, iPad, and other mobile devices$12.50 per Mac and $5.75 per mobile device per month, billed annually, 25-device minimumFleets of 25 or more devices that want management, identity, and security together
Iru (formerly Kandji)Apple, now also Windows and AndroidNot published here; request a quoteApple-first offices wanting heavy automation
Google endpoint managementAndroid, iOS, plus Windows, Mac, ChromeOS, and Linux to varying degreesIncluded with Google Workspace; advanced features depend on editionYou run Google Workspace

Notes on a few of these.

Microsoft describes Basic Mobility and Security as a limited subset of Intune. It does not offer MAM or Mac management.

Kandji renamed itself Iru and states that its Apple device management continues under the new name, with Windows and Android support added.

Google says endpoint management is included with Google Workspace, with certain advanced features limited to Business and Enterprise licenses. Its basic, agentless mode can enforce passcodes and wipe a work account from a phone without installing anything.

How Do You Choose?

Work through these in order.

  1. What do you already pay for? If you have Business Premium, you own Intune. If you have Google Workspace, you own Google’s tool. Start there before buying anything.
  2. What devices do you have? All Apple points toward Apple Business, Jamf, or Iru. Any Windows PCs point toward Intune. A mix usually means Intune, because it covers every platform under one license.
  3. Who owns the devices? Company-owned devices get MDM. Personal devices usually get MAM or a work profile.
  4. What must you prove? If you handle patient data under HIPAA or financial data under the FTC Safeguards Rule, confirm the tool can report encryption status and device inventory, since an assessor will ask.
  5. Who will run it? Every MDM needs someone to renew certificates, review reports, and handle new and departing devices. A simpler tool that gets looked after beats a powerful one nobody opens.

Questions to ask an MDM vendor

  • Is there a minimum device count or contract length?
  • Is pricing per device or per user, and do shared devices cost extra?
  • Does it support app protection without enrollment for personal phones?
  • Does it connect to our sign-in system (Microsoft Entra ID or Google) so a noncompliant device can be blocked?
  • What exactly can an administrator see on a personal device?
  • How do we export our device list and leave if we change tools?

When You Do Not Need MDM

A two or three person business with company data only in cloud apps, multi-factor authentication on every account, encrypted and auto-updating devices, and no regulatory requirements can reasonably manage devices by hand. Write down the settings you expect (encryption on, screen lock on, updates automatic, Find My or Find My Device on) and check them twice a year.

MDM starts paying for itself when checking by hand stops being realistic, when personal phones carry company email, when staff work remotely, or when someone outside the business (an insurer, an auditor, a customer’s security questionnaire) asks how you know your devices are secure.

Common Mistakes

  • Assuming a Microsoft 365 or Google Workspace subscription manages devices automatically. Nothing is managed until someone configures and enrolls it.
  • Fully enrolling personal phones when app-level protection would meet the need.
  • Buying Apple devices outside your Apple Business account, which means they do not enroll automatically at first power-on.
  • Setting up the Apple push certificate with one employee’s Apple account.
  • Rolling out restrictions with no notice to staff. A short explanation of what is and is not visible prevents most objections.
  • Never testing a remote wipe on a spare device before it is needed.

Common Questions

Is MDM the same as Microsoft Intune?

No. MDM is the category and Intune is one product in it. Jamf, Iru, Apple Business, and Google endpoint management are others. Intune is the common choice for offices on Microsoft 365 because Business Premium includes it and it covers Windows, Mac, iPhone, and Android together.

Can MDM see what employees do on their personal phones?

It depends on the mode. With app-level protection or an Android work profile, the employer sees only the managed work apps. Even with full enrollment, Microsoft states that Intune can never see browsing history, messages, photos, contacts, or passwords, and cannot locate a personal device.

What happened to Apple Business Manager?

Apple folded it into Apple Business on April 14, 2026, along with Apple Business Essentials and Apple Business Connect. Apple made the new platform available to existing users of all three. Apple Business is free and adds built-in device management, so a small all-Apple office can now manage devices without buying a separate MDM.

Do we need MDM for laptops too?

If you want consistent encryption, updates, and the ability to erase a lost machine, yes. Laptops hold far more company data than phones. Most current MDM products manage computers as well as phones, and for Windows PCs that generally means Intune.

How Coastal Growth Co. Can Help

We help small businesses in Orange County choose and set up device management: inventory what you have, check what your current subscriptions already include, configure enrollment and app protection, and document how to add and remove devices. If the honest answer is that you do not need MDM yet, we will say so. Scope and price are agreed before paid work begins. See our managed IT services or contact us.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.