Accessibility settings

Text size

100%

IoT & Devices 4 min read

MDM

Mobile device management Also known as: mobile device management

Definition

Mobile device management (MDM) is software that lets an organization enroll, configure, monitor, lock and wipe phones, tablets and other devices from a central console, by sending policies to an agent or to the management interface of each device's operating system.

Cite this entry

Text

"MDM". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/mdm/

HTML

<a href="https://ordergroup.co/glossary/mdm/">MDM</a> - Order Group

How MDM works

MDM has three parts: a console with a server, an agent or management profile on each device, and the management interface of the device's operating system. NIST SP 800-124 Rev. 2 (May 2023) describes enterprise mobility management (EMM), also called unified endpoint management (UEM), as a solution to deploy, configure and actively manage mobile devices. An EMM suite may include MDM, mobile application management (MAM) and mobile threat defense. In everyday use, MDM is the name for the whole category.

The operating system decides what an MDM can do. Major mobile platforms expose management APIs that ordinary apps cannot call: controlling app behavior, configuring device and security settings and reading sensitive device information. Access to these APIs may be limited to developers vetted by the platform owner, has to be accepted by the user or the IT staff, and most platforms allow only one MDM to control them. On Android the on-device part is the device policy controller (DPC), which Google describes as the bridge between the EMM console and the device.

A device is enrolled, receives policies, checks in with the server at intervals, reports its state and executes commands. NIST lists the typical controls:

  • manage wireless interfaces such as Wi-Fi, Bluetooth and NFC;
  • restrict access to hardware (for example the camera) and to features (for example copy and paste);
  • detect changes to the approved security configuration and block access from rooted devices or outdated OS versions;
  • disable developer mode;
  • require a passcode, lock the device remotely, and wipe it after too many failed unlock attempts or after a set time without checking in;
  • restrict app stores and apps by allowlist or blocklist, and keep an inventory of installed apps.

The ownership model sets the limits. NIST describes fully managed organization devices, corporate-owned personally enabled devices (COPE), and bring your own device (BYOD), where MAM instead of full MDM can address the owner's privacy concerns. On Android, a work profile keeps work apps and data separate from personal ones. When the profile owner calls wipeData, the profile and its data are removed and the personal side stays. A full factory reset with wipeDevice is reserved for the device owner or the profile owner of an organization-owned device.

What MDM means for your software

For a company that buys MDM for standard phones, the question is which product covers its ownership model. For a company that builds its own device or operating system, management is part of the product, and these requirements apply:

  • The ownership model is explicit per device: company-owned, personally enabled or personal. It decides what an administrator may see, restrict and wipe, and the panel shows it next to every device.
  • Policy is versioned data per organization and group, as described under deep packet inspection, and the console shows devices that drift from it.
  • The device enforces policy offline. A check-in interval, a warning threshold and an automatic wipe threshold run on the device itself, because a stolen phone will not talk to the server. The server computes the same status for the console.
  • Every remote command is confirmed and logged: who sent it, when the device received it and what happened. If a wipe fails silently, the operator believes the data is gone when it is not.
  • The console is the most valuable target in the system. NIST lists theft of EMM administrator credentials and malicious insiders among the threats, so the panel needs strong authentication, roles and an audit trail.
  • Device integrity is checked. SIM card changes, USB modes, debugging and modified system files are signals the device reports and the policy acts on.
  • Management and updates belong together. Agent and OS changes reach devices through the OTA channel; policy syncs from the server. Devices on old versions are visible in the console.
  • Building on stock Android has a limit: Android Enterprise no longer accepts new registrations of custom DPCs to the Google Play EMM API. A product that controls its own OS build can place management inside the system instead.
Device ownership models and what MDM controls
ModelWho owns the deviceWhat the administrator controlsWhat a remote wipe removes
Fully managed (company-owned, business use)OrganizationThe whole device, app allowlist, network and hardware settingsThe whole device (factory reset)
COPE (company-owned, personally enabled)OrganizationWork profile and selected device settings, personal apps limited by a blocklistWork profile, or the whole device if needed
BYOD with work profileEmployeeWork profile onlyWork profile and its data, personal data stays
BYOD with MAM onlyEmployeeSelected work apps and their dataWork app data
Dedicated or own-OS deviceOrganization or manufacturerEverything the system exposes, defined by the device makerDefined by the product, often the whole device

From our projects

From 2019 to 2021 we built Raw Control's hardened Android-based OS, with management built into the operating system and an administration panel for companies and groups.

Offline protection was configured per company or group with three times: how often the device reports to the backend, when the user gets a warning about lost communication, and when the device wipes itself. With the example values of 5, 60 and 120 minutes, the console shows OK while the device reports at least every 5 minutes, WARNING after 5 minutes of silence, CRITICAL after 60 minutes and WIPED after 120, together with the time of the planned wipe. Later fixes covered the warning shown before the wipe and a case where a failed account sync prevented the wipe.

The panel and API managed Bluetooth allowlists and blocklists by MAC address and device class. The phone synced them, blocked connections to untrusted devices and removed already paired ones. When a locked phone lost its SIM card, a 10-minute countdown to reset started; it stopped when the user unlocked the phone with two-factor authentication or put the same SIM back. Other controls covered access to the camera, microphone, location and other sensors at system level, data quotas per app with blocking at the limit, device attestation checks (integrity reports that the phone sent and the backend stored and verified), and the USB modes an administrator allows.

Sources

  1. NIST SP 800-124 Rev. 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise - NIST
  2. DevicePolicyManager (Android API reference) - Android Developers
  3. Build a device policy controller - Android Developers

FAQ

Maciej Sułek
Maciej Sułek
Co-founder & CTO
Talk to an engineer
  • MDM manages the device itself. NIST describes EMM, also called UEM, as the wider suite that may add mobile application management and mobile threat defense. Vendors use the names loosely, so compare the feature lists.

  • It depends on enrollment. With an Android work profile on a personal phone, a wipe from the profile owner removes the work profile and its data and leaves personal data alone. A full factory reset needs device owner rights, which apply to company-owned devices.

  • Policy that the device must enforce, such as locking or wiping after a set time without check-in, has to run on the device itself. NIST lists wiping after a predetermined interval without checking in as a standard control.

  • For standard phones and tablets, a commercial MDM usually covers the needs. If you build your own device or operating system, no third-party agent can reach what you add to the system, so management becomes part of your product and your update channel.

Building a system that depends on MDM?

See how we build software for this domain, with case studies and the stack we use.

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.

Your checklist is empty. Use the plus next to a term to add it.

    Order Group sp. z o.o. (Warsaw) uses your e-mail to send the checklist (Art. 6(1)(b) GDPR) and keeps a record of the request (Art. 6(1)(f) GDPR). Marketing consent is optional and can be withdrawn at any time. Read the Privacy Policy