Device and endpoint management
All notes
Everything here, grouped by subject.
Core notes remain vendor-neutral; separate guides compare named tools. No adoption figures. Nothing here is legal advice.
What this covers
From what the platform controls to what you must never do with it
Eight sections, in the order a programme runs: what device management actually does, enrolment, policy, personal devices, the irreversible action, daily operations, and the obligations that attach when the hardware belongs to somebody else.
What it controls
Who bought the device determines what may be done to it, and everything else follows from that.
6 notes →Enrolment
Enrolment looks like a setup step. It is the decision that fixes the capability boundary for the life of the device.
7 notes →Policy on the device
For each restriction, ask what risk it addresses and what it costs the user daily. Most fail the first question.
7 notes →Personal devices
A work phone can be left in a drawer. A personal phone cannot, and that is the hidden transfer in every BYOD arrangement.
7 notes →The irreversible action
Everything else can be reversed. This cannot, which justifies treating it differently from every other capability.
6 notes →Running it
Gate access on the version rather than forcing the update. It works on any ownership model and leaves the decision where it belongs.
6 notes →Obligations
A device record is personal data about an identifiable employee, held over time.
6 notes →Reference
The end state as a description, the twelve failures, and the order to do things in.
5 notes →Before enrolling anybody
Three things that cost a day and prevent most of the trouble
Look at a device record
Open the platform and see what it actually contains. Most administrators have not, and several are surprised in both directions — more detail in some fields, less in others.
Publish what you cannot see
The list of what is not collected is worth more than the list of what you control, because it is the part people read and the part that decides whether the rest is believed.
Make full wipe unreachable
On personal hardware, use a work profile so that factory reset is unavailable by platform design rather than by rule. Restraint fails eventually; structure does not.
All 50 notes
All fifty notes, by subject
- What Device Management Actually Controls
- Managing a Thing, Affecting a Person
- Ownership Models and What Each Permits
- What You Can See, and What You Cannot
- MDM, MAM and the Distinction That Matters
- The Questions to Settle Before Enrolling Anyone
- Enrolment Models, Compared
- Zero-Touch and Why It Is Worth the Setup
- Enrolling Personal Devices Without a Fight
- What Enrolment Actually Installs
- The Consent Conversation
- Devices That Refuse to Enrol
- Unenrolment and Leaving the Programme
- Writing a Device Policy People Will Accept
- Passcodes, Biometrics and Proportionality
- Encryption and What It Does Not Do
- Restricting Features: What Is Worth It
- Application Allow and Block Lists
- Certificate and Network Configuration
- Policy Drift and Annual Review
- BYOD: the Bargain Both Sides Misunderstand
- The Work Profile and Why It Changes Everything
- What the Employer Can See on a Personal Device
- Stipends, Expectations and Unpaid Availability
- When the Employee Refuses
- Personal Devices and Out-of-Hours Contact
- Leaving: What Happens to Their Phone
- Wipe: the Irreversible Action
- Selective Wipe Versus Full Wipe
- Lost and Stolen: the First Hour
- Wiping the Wrong Device
- Backup Before Wipe, and Whose Job It Is
- Legal Hold and the Wipe You Must Not Do
- Application Distribution Without Breaking Workflows
- Operating System Updates on Devices You Do Not Hold
- Compliance Rules and What Happens When They Fail
- Kiosk and Shared Devices
- Supporting Devices You Cannot Touch
- Measuring Whether the Programme Works
The short version
Structural beats promised
An employer promising not to look is asking to be trusted. A platform that does not expose personal data is not asking for anything. Manage the data rather than the device, and publish what you cannot see.