Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
3 min read

Microsoft Mobile Device Management (MDM): central management and protection of mobile devices

Hands operating a smartphone overlaid with a digital network graphic.

Das Wichtigste in Kürze

  • MDM manages company-owned devices centrally via Microsoft Intune. Configuration, apps, updates and security policies all come from a single source
  • Full control over encryption, mandatory passwords as well as remote lock and data wipe in case of loss or theft
  • MAM is suited to BYOD, MDM to company-owned devices. Many companies combine both for a holistic security strategy

In today's modern work environment, mobile devices are a must-have; companies face the challenge of balancing security and productivity. While Mobile Application Management (MAM) focuses on protecting corporate data within apps (usually on employees' own devices), Mobile Device Management (MDM) takes it a step further: it allows for complete centralized management and security of company-owned devices. Companies that work with sensitive data or are subject to high security requirements particularly benefit from an MDM strategy.

This is the second and final part about securely managing mobile devices and applications. The first part was about Microsoft Mobile Application Management (MAM).

What is Microsoft Mobile Device Management (MDM)?

Microsoft Intune, Microsoft's cloud-based endpoint management solution, offers Mobile Device Management (MDM) to enable centralized configuration, monitoring, and security of mobile devices. IT administrators can use it to enforce security policies, manage apps, and remotely administer devices - whether they're in the office or external.

With MDM, companies can ensure that all company-owned devices are configured according to IT policies. This minimizes security risks and ensures compliance.

The benefits of Mobile Device Management (MDM) for businesses

1. Complete control over company devices

MDM allows for full control and management of company devices:

  • Enforcement of security policies such as encryption or password requirements.
  • Installation, updates, and blocking of apps on managed devices.
  • Remote wipe of data if a device is lost or stolen.

2. Uniform security standards for all devices

With MDM, IT departments can implement a uniform security strategy across all mobile devices. This includes:

  • Automatic device configurations directly at the time of setup.
  • Security mechanisms to prevent unauthorized access and data loss.
  • Integration with Microsoft Defender for additional protection against threats.

3. Protecting sensitive business data
While MAM ensures that business data is only used in approved apps, MDM controls the entire device. This allows businesses to prevent employees from using unauthorized apps or insecure networks.
4. Centralized management and increased efficiency

With Microsoft Intune, administrators can manage all MDM-managed devices from a single platform, saving time and reducing administrative overhead. New devices can be preconfigured with zero-touch deployment and made ready for use immediately.

How does MDM work in practice?

MDM is implemented using Microsoft Intune. Companies can:

  1. Register and manage devices - regardless of whether they run Windows, iOS/iPadOS, or Android.
  2. Define security, access, and app policies.
  3. Control settings and updates centrally, without users having to take any action.
  4. Remotely lock or reset devices if there is a security risk.

Sample MDM policies:

  • Mandatory device policies: passwords, biometrics, encryption requirements
  • Automatic app installation: corporate apps are specified and updated centrally
  • Device restrictions: blocking unauthorized apps or cloud services
  • Remote management: IT teams can reset or lock devices

MDM vs. MAM: When to use which solution?

  • MAM is ideal for BYOD devices, as only corporate data and apps are protected.
  • MDM is optimal for company-owned devices, as the entire device management remains under control of the IT department.

Many companies combine both approaches to develop a comprehensive security strategy.

Baggenstos' experience with MDM

If a company wants to use dedicated devices, for example in a high-security environment, MDM is the "gold standard" for mobile device security. Baggenstos has years of experience in centrally managing mobile devices and is, of course, Microsoft-certified in this area. Our customers benefit from a solution that ensures highly secure device and app management.

Bottom line: When MDM is indispensable

For companies that want to maintain full control over their mobile devices and implement a unified security concept, Mobile Device Management (MDM) is the best choice. By integrating it into Microsoft Intune, you can optimize IT processes, unify security standards, and protect your company data as effectively as possible.

You already use Microsoft 365 or Intune?
Then you should integrate MDM as a central component into your IT strategy to manage your fleet of devices efficiently and securely.

Source and further links

No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Schedule an appointment now

Ready for your digital transformation?

In a no-obligation discussion, we'll jointly clarify where your IT can have the greatest impact and how we can support you.