Skip to content
Sections
All notes

Device and endpoint management

All notes

Everything here, grouped by subject.

Core notes remain vendor-neutral; separate guides compare named tools. No adoption figures. Nothing here is legal advice.

What the work profile exposes
Illustrative chart showing work data visible and personal data not
Personal data visible 0
50notes
4ownership models
12common failures listed
0vendors named

What this covers

From what the platform controls to what you must never do with it

Eight sections, in the order a programme runs: what device management actually does, enrolment, policy, personal devices, the irreversible action, daily operations, and the obligations that attach when the hardware belongs to somebody else.

What it controls

Who bought the device determines what may be done to it, and everything else follows from that.

6 notes →

Enrolment

Enrolment looks like a setup step. It is the decision that fixes the capability boundary for the life of the device.

7 notes →

Policy on the device

For each restriction, ask what risk it addresses and what it costs the user daily. Most fail the first question.

7 notes →

Personal devices

A work phone can be left in a drawer. A personal phone cannot, and that is the hidden transfer in every BYOD arrangement.

7 notes →

The irreversible action

Everything else can be reversed. This cannot, which justifies treating it differently from every other capability.

6 notes →

Running it

Gate access on the version rather than forcing the update. It works on any ownership model and leaves the decision where it belongs.

6 notes →

Obligations

A device record is personal data about an identifiable employee, held over time.

6 notes →

Reference

The end state as a description, the twelve failures, and the order to do things in.

5 notes →

Before enrolling anybody

Three things that cost a day and prevent most of the trouble

Look at a device record

Open the platform and see what it actually contains. Most administrators have not, and several are surprised in both directions — more detail in some fields, less in others.

Publish what you cannot see

The list of what is not collected is worth more than the list of what you control, because it is the part people read and the part that decides whether the rest is believed.

Make full wipe unreachable

On personal hardware, use a work profile so that factory reset is unavailable by platform design rather than by rule. Restraint fails eventually; structure does not.

All 50 notes

All fifty notes, by subject

The short version

Structural beats promised

An employer promising not to look is asking to be trusted. A platform that does not expose personal data is not asking for anything. Manage the data rather than the device, and publish what you cannot see.