← All postsHow-to

Mobile device management for small business: what you need and what you can skip

Mobile device management for small business does not require an enterprise platform. What to enforce on phones and laptops, how to handle personal devices, and what to do before someone leaves.

How-toM

Mobile device management (MDM) is the ability to enforce security settings on the phones and laptops that reach company data, and to remove that access when a device is lost or a person leaves. Enterprise deployments run to hundreds of policies; a company of fifteen people needs perhaps six of them. The risk small businesses actually carry is not a misconfigured policy — it is a former employee's personal phone that still receives company mail, and nobody knowing how many devices hold company data at all.

Mobile device management for small business: the short list

  • Screen lock with a passcode and a short auto-lock timeout.
  • Disk encryption on laptops, which is a setting rather than a product on current operating systems.
  • Remote wipe, or at least the ability to revoke the account's access to company data.
  • Operating system updates enforced rather than suggested.
  • Company accounts separated from personal ones, so removal is clean.
  • An inventory of which devices exist, who holds them, and whether they are company or personal property.

Start with what the tools you already pay for can do

Most small businesses already have basic device management inside their email and identity provider — enforcing encryption, passcodes and update policies, and revoking access per device. That covers the list above without a separate platform. A dedicated MDM product earns its cost when you need application deployment, kiosk or shared-device modes, per-app configuration, or compliance evidence for a customer contract. Buying one before those needs exist mostly adds administration.

Wiping a personal phone is legally and practically fraught. For personal devices, aim to remove company data and access rather than the whole device, and say exactly that in the policy people sign.

Personal devices need a written line

  1. Decide which company data may be reached from personal devices at all — mail and chat often yes, finance systems often no.
  2. Require the basic controls on any device that holds company data, personal or not.
  3. Write down what the company can and cannot do to a personal device, and have people acknowledge it.
  4. Use account-level removal for personal devices so leaving does not mean wiping someone's photos.
  5. Record the device against the person in your inventory, so offboarding has a checklist rather than a memory.

Ettex Records is enough for the inventory half at this size: one row per device with holder, ownership, operating system, encryption status and the date access was last verified, tied to the person rather than to a serial number nobody recognises. When someone leaves, the row is the offboarding list, which is where small companies most often lose control of their data.

Frequently asked

Do we need MDM software for five laptops?

Usually not. Enforcing encryption, passcodes and updates through your existing email or identity provider covers most of the risk. Buy a platform when application deployment or contractual compliance requires it.

Can we wipe an employee's personal phone?

Technically sometimes, legally often not, and it damages trust. Remove the company account and its data instead, and set that expectation in writing before devices are enrolled.

What is the difference between MDM and endpoint management?

MDM historically covered phones and tablets; endpoint management covers laptops and desktops as well. Current products largely merge the two, which is why vendor naming is inconsistent.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.