Mobile Device Management (MDM) for Small Business
A vendor-neutral guide to MDM for small offices: MDM vs MAM, Apple Business, Android Enterprise, Intune, Jamf, Iru, and Google options, and how to choose.
Mobile device management (MDM) is software that lets a business apply security settings to phones, tablets, and laptops from a central console, and remove company data from a device that is lost or belongs to someone who has left. A small business should pick its MDM based on what it already pays for and which devices it owns: Microsoft Intune if you are on Microsoft 365 Business Premium, Apple Business or an Apple-focused tool if you are all Apple, and Google’s endpoint management if you run Google Workspace. Personal phones usually need app-level protection, not full MDM.
What Is Mobile Device Management?
An MDM tool enrolls a device and then manages it remotely. Typical capabilities:
- Require a passcode, screen lock, and encryption
- Install, update, and remove work apps
- Push Wi-Fi, VPN, and email settings
- Keep operating systems updated
- Show an inventory of devices and their health
- Lock or erase a lost device
Despite the name, most MDM products now manage laptops and desktops as well as phones. Vendors sometimes call this unified endpoint management.
MDM does not detect malware or stop phishing. It sits alongside endpoint protection and sign-in controls, not in place of them.
MDM vs MAM: What Is the Difference?
Mobile application management (MAM) protects company data inside specific apps without enrolling the device. Microsoft’s Intune overview puts it this way: with MDM the organization manages the whole device, and with MAM it manages only the work apps and the data inside them.
| MDM | MAM | |
|---|---|---|
| What is managed | The whole device | Work apps and their data only |
| Enrollment | Required | Not required |
| Typical use | Company-owned devices | Personal phones (BYOD) |
| Lost device | Can erase the entire device | Can erase work data only |
| Employee privacy | Employer sees device details and, on company devices, installed apps | Employer sees only the managed apps |
Many offices use both: MDM for equipment the company bought, MAM for staff who read work email on their own phones. The written rules for the second group belong in a BYOD policy.
The Building Blocks Apple, Google, and Microsoft Provide
Every MDM product works through management features built into the operating systems. Knowing these makes vendor conversations easier.
Apple Business (formerly Apple Business Manager)
Apple Business Manager was the free portal that linked company-purchased Apple devices to an MDM so they enrolled automatically at first power-on. On April 14, 2026, Apple replaced it with Apple Business, a free platform that combines Apple Business Manager, Apple Business Essentials, and Apple Business Connect. Apple’s user guide now opens with “Apple Business Manager is now Apple Business.”
Two things changed for small offices. Apple Business includes built-in device management, which Apple previously sold as a paid subscription in Business Essentials. It also supports Managed Apple Accounts, which Apple says keep work and personal data cryptographically separate and can be created automatically from Google Workspace or Microsoft Entra ID.
Devices need to be bought through Apple or an authorized reseller and added to your Apple Business account for automatic enrollment to work. Set the account up before your next hardware purchase.
Android Enterprise
Android Enterprise is Google’s management framework, built into modern Android. It offers a work profile (a separate, managed space for work apps on a personal phone), a fully managed mode for company-owned devices, and zero-touch enrollment, which configures company phones remotely at first startup. Any serious MDM uses Android Enterprise underneath.
Windows enrollment and Autopilot
Windows 10 and 11 include an MDM client. With Microsoft’s tools, a PC enrolls when a work account joins it to Microsoft Entra ID, and Windows Autopilot lets a new PC configure itself at first sign-in. Details are in our Microsoft Intune guide.
What Are the MDM Options for a Small Business?
Prices are vendor list prices in US dollars as of September 2026. Check the linked pages before budgeting, because vendors change them.
| Option | Platforms | Published price | Fits best when |
|---|---|---|---|
| Basic Mobility and Security | iOS, Android, Windows | Included in every Microsoft 365 business plan | You only need a PIN requirement and remote wipe on phones |
| Microsoft Intune Plan 1 | Windows, macOS, iOS, Android, Linux | Included in Business Premium ($22.00 per user per month) or $8.00 per user per month standalone | You use Microsoft 365 and have Windows PCs or mixed devices |
| Apple Business built-in management | Apple only | Free | Every device is Apple and needs are simple |
| Jamf Now | Apple only | Starting at $4 per device per month | All-Apple office wanting more than the built-in tool |
| Jamf for Mac and Jamf for Mobile | Mac, iPhone, iPad, and other mobile devices | $12.50 per Mac and $5.75 per mobile device per month, billed annually, 25-device minimum | Fleets of 25 or more devices that want management, identity, and security together |
| Iru (formerly Kandji) | Apple, now also Windows and Android | Not published here; request a quote | Apple-first offices wanting heavy automation |
| Google endpoint management | Android, iOS, plus Windows, Mac, ChromeOS, and Linux to varying degrees | Included with Google Workspace; advanced features depend on edition | You run Google Workspace |
Notes on a few of these.
Microsoft describes Basic Mobility and Security as a limited subset of Intune. It does not offer MAM or Mac management.
Kandji renamed itself Iru and states that its Apple device management continues under the new name, with Windows and Android support added.
Google says endpoint management is included with Google Workspace, with certain advanced features limited to Business and Enterprise licenses. Its basic, agentless mode can enforce passcodes and wipe a work account from a phone without installing anything.
How Do You Choose?
Work through these in order.
- What do you already pay for? If you have Business Premium, you own Intune. If you have Google Workspace, you own Google’s tool. Start there before buying anything.
- What devices do you have? All Apple points toward Apple Business, Jamf, or Iru. Any Windows PCs point toward Intune. A mix usually means Intune, because it covers every platform under one license.
- Who owns the devices? Company-owned devices get MDM. Personal devices usually get MAM or a work profile.
- What must you prove? If you handle patient data under HIPAA or financial data under the FTC Safeguards Rule, confirm the tool can report encryption status and device inventory, since an assessor will ask.
- Who will run it? Every MDM needs someone to renew certificates, review reports, and handle new and departing devices. A simpler tool that gets looked after beats a powerful one nobody opens.
Questions to ask an MDM vendor
- Is there a minimum device count or contract length?
- Is pricing per device or per user, and do shared devices cost extra?
- Does it support app protection without enrollment for personal phones?
- Does it connect to our sign-in system (Microsoft Entra ID or Google) so a noncompliant device can be blocked?
- What exactly can an administrator see on a personal device?
- How do we export our device list and leave if we change tools?
When You Do Not Need MDM
A two or three person business with company data only in cloud apps, multi-factor authentication on every account, encrypted and auto-updating devices, and no regulatory requirements can reasonably manage devices by hand. Write down the settings you expect (encryption on, screen lock on, updates automatic, Find My or Find My Device on) and check them twice a year.
MDM starts paying for itself when checking by hand stops being realistic, when personal phones carry company email, when staff work remotely, or when someone outside the business (an insurer, an auditor, a customer’s security questionnaire) asks how you know your devices are secure.
Common Mistakes
- Assuming a Microsoft 365 or Google Workspace subscription manages devices automatically. Nothing is managed until someone configures and enrolls it.
- Fully enrolling personal phones when app-level protection would meet the need.
- Buying Apple devices outside your Apple Business account, which means they do not enroll automatically at first power-on.
- Setting up the Apple push certificate with one employee’s Apple account.
- Rolling out restrictions with no notice to staff. A short explanation of what is and is not visible prevents most objections.
- Never testing a remote wipe on a spare device before it is needed.
Common Questions
Is MDM the same as Microsoft Intune?
No. MDM is the category and Intune is one product in it. Jamf, Iru, Apple Business, and Google endpoint management are others. Intune is the common choice for offices on Microsoft 365 because Business Premium includes it and it covers Windows, Mac, iPhone, and Android together.
Can MDM see what employees do on their personal phones?
It depends on the mode. With app-level protection or an Android work profile, the employer sees only the managed work apps. Even with full enrollment, Microsoft states that Intune can never see browsing history, messages, photos, contacts, or passwords, and cannot locate a personal device.
What happened to Apple Business Manager?
Apple folded it into Apple Business on April 14, 2026, along with Apple Business Essentials and Apple Business Connect. Apple made the new platform available to existing users of all three. Apple Business is free and adds built-in device management, so a small all-Apple office can now manage devices without buying a separate MDM.
Do we need MDM for laptops too?
If you want consistent encryption, updates, and the ability to erase a lost machine, yes. Laptops hold far more company data than phones. Most current MDM products manage computers as well as phones, and for Windows PCs that generally means Intune.
How Coastal Growth Co. Can Help
We help small businesses in Orange County choose and set up device management: inventory what you have, check what your current subscriptions already include, configure enrollment and app protection, and document how to add and remove devices. If the honest answer is that you do not need MDM yet, we will say so. Scope and price are agreed before paid work begins. See our managed IT services or contact us.
- mobile device management
- MDM
- Apple Business
- Android Enterprise
- small business
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward