Endpoint management
MDM
Mobile Device Management
MDM is the practice of enrolling an entire device into a management authority. This lets the organisation apply configuration, enforce security policy, monitor compliance, and, if necessary, remotely lock or wipe the device as a whole, rather than managing only the corporate applications running on it.
Why MDM matters in a Microsoft estate
MDM matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.
How MDM shows up in practice
In the Microsoft ecosystem, MDM enrolment is handled through Microsoft Intune, using the device's native management channel: the Windows MDM stack via CSPs (Configuration Service Providers) on Windows, Apple's MDM protocol via Apple Push Notification service on iOS/iPadOS and macOS, and the Android Enterprise framework on Android. Intune acts as the cloud-based MDM authority, issuing commands and policy across all of them from one console. Once a device is MDM-enrolled, it becomes visible and controllable to a degree that Mobile Application Management alone cannot match. This includes full configuration profiles, compliance policy evaluation feeding into Conditional Access, endpoint security controls like BitLocker enforcement, remote actions such as full wipe, retire, or fresh start, and inventory data covering installed applications, OS version, and hardware detail.
That level of control is exactly why MDM is the natural fit for corporate-owned devices, where the organisation has clear ownership and legal standing to manage the whole device. It is also why MDM is a harder sell for personally owned BYOD hardware, where a full wipe destroys personal data alongside corporate data. Android Enterprise's work profile and Apple's User Enrolment modes exist specifically to give a lighter-touch MDM option for BYOD, one that partitions a managed work container from the personal side of the device without full device-wide control. MDM enrolment methods differ meaningfully in operational effort. Windows Autopilot enables zero-touch MDM enrolment straight from Windows Setup on new or reset devices, Apple Business Manager or Apple School Manager provides equivalent supervised, zero-touch enrolment for Apple hardware purchased through those programmes, and Android Enterprise's fully managed mode does the same for corporate Android devices.
Devices acquired outside those channels typically require manual, user-driven enrolment instead, which is slower to roll out and more prone to incomplete adoption across an estate. A recurring operational issue in mature MDM estates is enrolment drift: devices that were wiped and rebuilt outside the managed provisioning flow, devices that left MDM through an OS reset without a corresponding retire action in Intune, or duplicate device records left behind after a re-enrolment. All of these inflate licence counts against devices that are no longer actually receiving policy. This is why device inventory reconciliation between Intune, Entra ID, and actual active hardware is a standing housekeeping task rather than a one-off setup step.