Skip to content
Business Services

Device Management (MDM)

Your office has a lock on the door. Your information does not. It goes home every night on laptops and phones, and it stays behind on them when people leave. Device management puts the company back in control of company data, wherever it happens to be sitting, without surveilling the people carrying it.

The perimeter went home years ago

Business security used to mean securing the office: the server in the rack, the firewall at the edge, the machines at the desks. That perimeter is gone. Today the company's information lives in mailboxes on personal phones, files synced to laptops on kitchen tables, and Teams chats on whatever device was nearest, and every one of those devices can be lost on a train, left in a ute, or walked out the door by someone whose last day is Friday.

Ask three questions of your business as it stands: If a phone with company email on it were lost today, could you remove that data, or would you be hoping? When someone leaves, does company information leave their personal devices, or does it stay there indefinitely? And do you actually know which devices can reach your files right now? For most small businesses the honest answers are hoping, it stays, and no. None of those answers survives contact with a cyber incident, an insurer's questionnaire, or a privacy complaint.

What managed devices change

  • Lost is an inconvenience rather than a breach. Company data wiped remotely within minutes, so the phone left in the taxi is a hardware cost rather than a notifiable incident.
  • Leaving means leaving. When someone moves on, the work profile comes off their devices as part of offboarding. Access removed is only half the job; information retrieved is the other half, and it is the half most businesses skip.
  • Every device encrypted and patched. Enforced rather than requested. Two Essential Eight behaviours, delivered automatically instead of by nagging.
  • Only healthy devices get in. Paired with conditional access, sign-in can require a known, up-to-date device: a stolen password on a random computer no longer opens your files.
  • New machines arrive ready. Enrolment means a new laptop sets itself up to company standard out of the box, rather than being hand-built at a desk for an afternoon.
  • Answers on paper. When the insurer or an auditor asks how company data on mobile devices is controlled, the answer is a policy and a console rather than a shrug.

What we can't see, and won't

This is the part staff reasonably want answered before anything is enrolled, so here it is plainly. On a personal phone, management applies to a separate work profile only. We can see that the work apps are present, protected and up to date. We cannot read messages, view photos, see browsing history or watch location. If the phone is wiped, the work profile goes and everything personal stays. The whole point is controlling the company's information rather than watching the person carrying it, and a rollout only works when staff understand that distinction, which is why explaining it to your team is part of how we deploy.

Theirs

Photos, messages, banking, browsing. We cannot see this side, by architecture rather than as a courtesy. A wipe never touches it.

PERSONALWORK PROFILEPhotosMessagesBankingBrowserOutlookTeamsFilesOneDriveinvisible to usencrypted · updatedwipeable in minutesthe line Intune draws

The company’s

Mail, Teams and files: encrypted, kept updated, and removable the moment a phone is lost or a person leaves. This side is ours to look after.

Lose the phone, and the work side is wiped remotely. The personal side never even notices.

You may already own the licence

Intune, Microsoft's device management platform, is included in Microsoft 365 Business Premium, which plenty of businesses already pay for without ever switching it on. It is the same story as identity and access: the protection is frequently sitting in licensing you already own, waiting to be configured. We check that first, before anything new goes on a bill.

What's included

  • Licence check: use what you own
  • Windows, Mac, iPhone, iPad, Android
  • Encryption and update policy, enforced
  • Work-profile separation on personal phones
  • Remote wipe for lost devices
  • Device offboarding when staff leave
  • Staff briefing: what we can and can't see
FAQ

Frequently asked questions

Is this spying on our staff?

No, and it would not survive in a workplace if it were. On a company machine we manage the machine: encryption, updates, what can be installed. On a personal phone, only a separate work profile is managed. We can see that the work apps are present, up to date and protected, and we cannot see messages, photos, browsing or anything else on the personal side. We manage the company's information, not the person.

What happens when a phone or laptop is lost?

The work data (mail, files, Teams, the lot) is wiped remotely, usually within minutes of the call. On a personal phone the wipe takes the work profile and nothing else; the family photos are untouched. A lost device becomes an inconvenience and a replacement, rather than a data breach you may have obligations to report.

We pay for Microsoft 365 Business Premium. Do we already own this?

Very likely yes. Intune is included in Business Premium, and it is one of the most commonly paid-for-but-never-switched-on protections we find. The first step of any engagement is checking what your licensing already covers before anything new is bought.

What about staff using their own computers for work?

That is the quiet risk most businesses have without deciding to: company files synced to a personal laptop with no encryption, no updates policy and no way to remove them when the person moves on. The fix is policy plus tooling: either the device is enrolled, or company data stays out of it. We will help you draw that line somewhere staff can live with.

Does it cover Apple and Android as well as Windows?

Yes. Windows and Mac computers, iPhones, iPads and Android, managed from the one place. Mixed fleets are normal and not a problem.

What does it cost?

Often less than expected, because the licensing is frequently already in your Microsoft 365 plan. Setup is quoted to your fleet, and ongoing management is part of a managed support contract. Call 03 5280 8088 and we will check what you already own first.

Device management for the data that goes home at night

Most businesses honestly don't know where their data slept last night. A device audit is a quick, quiet way to find out, and the licence you need is probably already paid for.