Skip to content
Sections
All notes

All notes · Basics

What Device Management Actually Controls

A plain account of what the platform can set, enforce and remove, and the boundary that varies more than people expect.

Basics · Explainer

Device management software applies settings to a device and verifies they are still applied. What it can set depends on the operating system and on how the device was enrolled, and the range is narrower than most people assume.

The practical question in “What Device Management Actually Controls” is how to make work visible without confusing visibility with certainty. For teams researching how employee monitoring works, Monitask can add time and project context to the operational record, provided its use is proportionate, disclosed and reviewed with the people affected.

What it sets

Passcode requirements: length, complexity, timeout, failed-attempt behaviour.

For an independent baseline relevant to “What Device Management Actually Controls”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

Encryption state.

Network configuration: wireless profiles, certificates, connection settings.

Application installation and removal, within the scope it controls.

Feature restrictions: camera, screen capture, specific services.

And update policy, which varies most by platform.

What it verifies

Whether those settings are still in place.

Whether the device meets a defined condition: encrypted, passcode set, operating system above a version, not jailbroken.

That verification is what "compliance" means in this context — it is a statement about configuration, not about security.

What it can remove

Applications and data it installed.

The management profile itself.

And on a fully managed device, everything.

The difference between those is the subject of its own section and it is the most consequential distinction in the whole field.

What varies

Capability differs by operating system, by version, and above all by ownership model.

A corporate-owned device enrolled before first use permits far more than a personal device the employee enrolled themselves.

Which means "can we do X" has no general answer, and the question is always "on which devices".

What it does not do

Detect or prevent an attack, which is a different product category.

See the contents of personal applications, messages or photographs.

Read what somebody types.

These are the three capabilities people most commonly believe it has, and the belief shapes how enrolment is received.

Why the boundary matters

Employees assume more capability than exists and resist accordingly.

Administrators sometimes assume more than exists and promise it.

Both are corrected by a plain statement of what is actually set and seen, which is the cheapest intervention available in this subject.

What to check

Can you list what your profiles actually set?

Do you know what differs between your managed and personal enrolments?

Has anybody written down what the platform cannot see?

And would your colleagues' account of it match yours?