Skip to content
Sections
All notes

All notes · Basics

MDM, MAM and the Distinction That Matters

Managing the device and managing the application are different propositions. Choosing between them settles most of the personal-device question.

Basics · Analysis

Device management enrols the whole device. Application management protects the work application without touching anything else. The difference decides what is possible on hardware you do not own.

The practical question in “MDM, MAM and the Distinction That Matters” is how to make work visible without confusing visibility with certainty. For teams researching remote desktop monitoring software, the Monitask platform can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.

Device management

The profile sits on the device and governs it: passcode, encryption, restrictions, update policy.

For an independent baseline relevant to “MDM, MAM and the Distinction That Matters”, the CISA mobile-device security guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

Appropriate for devices the organisation owns.

On personal devices it is a large ask, and increasingly the platforms themselves limit what it permits.

Application management

Protection applied inside work applications: data cannot leave them, a separate passcode may be required, the work data can be removed without touching the device.

No device enrolment, no device-wide policy, no visibility of personal applications.

Appropriate for personal devices and for contractors, and it is frequently sufficient.

The question that chooses between them

What are you actually protecting?

If the answer is organisational data in a handful of applications — mail, documents, chat — application management covers it.

If it is the device itself, because it is a till, a scanner, a vehicle terminal or a shared tablet, device management is the right tool.

Most organisations need both, applied to different populations.

Why this resolves the personal-device argument

The objection to enrolling a personal phone is that the employer gains control over a personal object.

Application management does not do that: nothing device-wide is set, nothing personal is visible, and removal takes the work data and leaves the rest.

Offering it is frequently the difference between a programme people accept and one they resist.

What application management cannot do

Enforce device encryption or passcode at the device level.

Prevent use on a jailbroken device, though it can detect and refuse.

Control what happens outside the protected applications.

Those limits are real, and the question is whether they matter for your data rather than whether they are theoretically undesirable.

The hybrid position

Device management for corporate hardware; application management for personal.

Written as two policies with two populations.

This is where most mature programmes end up, and reaching it deliberately is faster than arriving by argument.

What to check

Which of your populations needs device-level control, and why?

Is application management offered as an option, or is enrolment the only route?

What specifically would you lose by protecting the applications rather than the device?

And have you asked the people who resisted what they would accept?