MDM Explained: Device Management for Compliance

MDM explained: device lifecycle and security settings

MDM is how an organisation enrols, configures and secures the laptops and phones its people use for work, and removes company data from them when someone leaves.

  • Glossary
  • Endpoint

The short answer

Mobile device management enrols devices, pushes configuration and security policy to them, reports on whether they comply, and allows company data to be removed remotely. It answers the question every auditor and enterprise buyer asks: how do you know the laptop touching customer data is encrypted, patched and locked.

The name is misleading. MDM began with phones but now covers laptops, and for most startups the laptop is the device that matters, because that is where source code and customer exports live.

The device lifecycle

1. Enrol Device registered to a named person 2. Configure Encryption, lock, updates, apps 3. Monitor Continuous compliance check 4. Respond Drifted device loses access 5. Retire Company data removed Step 5 is the one auditors test, because offboarding evidence is easy to check and often missing.

What gets enforced

SettingWhy it is on every checklist
Full disk encryptionA lost laptop stops being a reportable breach if the disk is encrypted
Screen lock and passwordStops casual access in shared and public spaces
OS and patch levelUnpatched laptops are the most common route to a foothold
Endpoint protection runningProves the agent is installed and actually reporting
Removable media rulesControls whether data can be copied to a USB drive
Remote wipeRemoves company data when a device is lost or a person leaves

The questions buyers ask

Are devices encrypted?

They want a report showing the current state, not a policy stating the intention.

Are they patched?

Percentage of devices on a supported OS version, with a timeframe for the rest.

What happens at offboarding?

Evidence that access ended and company data was removed, with dates.

How Osto covers devices

Osto provides endpoint protection, device control and content filtering, with macOS agent support. The agent also underpins access: through ZTNA, internal resources stay unreachable unless that agent is installed and MFA is satisfied, so device posture becomes an access decision rather than a report nobody reads. Endpoint events land in the same platform as identity, cloud and network activity, which is what allows a device alert to be connected to what the user did next.

Free security assessment

Turn device posture into an access decision

Osto covers endpoint protection, device control and content filtering, and gates internal resources on the agent being installed and healthy.

Get a free security assessment Book a platform walkthrough

macOS agent · Access tied to device state · One platform, everything

Frequently asked questions

What does MDM stand for?

Mobile device management. It covers enrolling devices, applying configuration and security policy, monitoring compliance, and removing company data remotely. Despite the name it now covers laptops as much as phones.

What is the difference between MDM and endpoint protection?

MDM manages configuration and state: encryption on, screen lock set, OS current. Endpoint protection detects and responds to threats running on the device. They answer different questions and are usually deployed together.

Do we need MDM for SOC 2 or ISO 27001?

Neither names the technology. Both expect the outcomes: devices configured securely, kept current, and cleared at offboarding. Producing that evidence manually for more than a handful of laptops is where teams tend to give up.

Can MDM be used on personal devices?

Yes, though scope should be limited to company data and applications rather than the whole device. Most jurisdictions and most employees expect a clear boundary, and the policy should state exactly what the organisation can and cannot see.