# What is Mobile Device Management (MDM)?

> Mobile device management (MDM) centrally enrolls devices, applies configuration and security policy, distributes managed applications or credentials, collects status, and performs remote actions.

- Canonical URL: https://yellowcube.eu/glossary/mobile-device-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It works through management services and platform-provided interfaces whose authority depends on the operating system, enrollment method, device ownership, and whether the device is fully or partly managed.

Despite its name, MDM can cover smartphones, tablets, laptops, and desktops. It supports administration and access decisions, but policies and commands are not uniform across platforms and may be restricted on personally owned devices.

### Key points

- **Enroll with assurance:** Authenticate the user and device, prefer controlled or automated enrollment for organization-owned equipment, bind records to owners, and prevent unauthorized re-enrollment or management removal.
- **Apply and observe policy:** Configure security settings, certificates, connectivity, applications, updates, encryption, and data-handling restrictions; collect inventory and compliance signals for administration and conditional access.
- **Protect the management plane:** Restrict administrator roles, require strong authentication, log changes and remote actions, secure service integrations and signing credentials, test updates, and define recovery from management-service failure.
- **Important limitation:** MDM can enforce only capabilities exposed by the device platform and enrollment mode. A command or compliant status may be delayed, incomplete, spoofed, or stale, and does not prove that the device or its user is trustworthy.

### Related terms

[Mobile security](<https://yellowcube.eu/glossary/mobile-security/>) · [Unified endpoint management (UEM)](<https://yellowcube.eu/glossary/unified-endpoint-management/>) · [Bring your own device (BYOD)](<https://yellowcube.eu/glossary/bring-your-own-device/>) · [Endpoint security](<https://yellowcube.eu/glossary/endpoint-security/>) · [Conditional access](<https://yellowcube.eu/glossary/conditional-access/>) · [Mobile application security](<https://yellowcube.eu/glossary/mobile-application-security/>)

### Sources

[NIST SP 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise](https://csrc.nist.gov/pubs/sp/800/124/r2/final) · [UK NCSC, Mobile Device Management](https://www.ncsc.gov.uk/collection/device-security-guidance/getting-ready/mobile-device-management) · [NIST SP 1800-22, Mobile Device Security: Bring Your Own Device](https://csrc.nist.gov/pubs/sp/1800/22/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

