MDM vs MAM: What's the difference, and does your business have a gap?

What's the difference between MDM and MAM

Every business now runs on a mix of devices doing company work: laptops the business issued, phones the business bought, and phones staff bought themselves that now carry the work email too. MDM and MAM are the two ways IT keeps that mix under control, and mixing up which one you need is an easy way to end up properly covered by neither.

Mobile Device Management (MDM) controls the entire device. IT can enforce a passcode, encrypt the whole thing, push updates, and remotely wipe it if it's lost or stolen. It's built for hardware the business owns outright.

Mobile Application Management (MAM) controls specific apps and their data, not the whole device. IT can wipe company email and files off a phone without touching photos, texts, or personal apps. It's built for BYOD, personal devices doing company work.

The real distinction isn't who bought the phone. It's what level IT can actually reach: the whole device, or just the slice of it that belongs to work.

Most businesses need both running side by side, not one instead of the other. The issued laptops still need MDM. The personal phone checking email at 9pm still needs MAM. Treating either as optional because the other's covered is usually where the gap in this article's title opens up.

Why this matters more since hybrid work

Hybrid work didn't create this problem, it just made it impossible to ignore. Staff have always fired off a quick reply from their own phone after hours. What's changed is how much company data now lives on personal devices as a matter of course, a work email on a personal phone, synced to a personal cloud backup, opened in whatever notes app someone happens to use, and none of that happened because a policy told it to. Most businesses have never formally decided whether any of it is covered by MDM, MAM, or nothing at all. It's one piece of the bigger picture of keeping your IT systems secure.

The fix isn't one policy for the whole business. It's sorting devices into two piles and treating each one properly.

 Company-owned devices, sort first

If a laptop or phone was bought by the business, MDM should already be switched on. Quick check:

  • Can IT remotely wipe every company-owned device if it's lost?

  • Is every company device encrypted and passcode-locked by default, not by choice?

  • Do security patches and updates roll out automatically from one place (ongoing management and support), or does someone have to remember?

If any answer is no, that's the gap to close first, it's the easier half of the job.

Personal devices / BYOD

If staff use their own phones for work email, files, or Slack, MAM is what protects the business without taking over their phone. Quick check:

  • Can IT wipe company email and files off a personal phone without touching anything else on it?

  • Is there a written BYOD policy staff have actually seen, not just a line in the handbook?

  • If someone left the business tomorrow, could IT remove company access from their personal phone within minutes?

A “no” here is common, and it's exactly the blind spot this article is about.

Governance and compliance

There's a compliance angle too, and it's not optional. Under the Privacy Act 2020, Information Privacy Principle 5 (IPP5) requires businesses to have reasonable safeguards against loss, unauthorised access, use, modification, disclosure, and other misuse of personal information. A lost phone with client details sitting in an email inbox isn't just an inconvenience, it can be a Privacy Act issue if there was no way to secure it remotely. MDM and MAM are two of the most practical safeguards a business can put in place to meet that obligation, whether the device belongs to the company or the person carrying it.

MDM locks down a whole device. MAM locks down just the work apps and data on it. Most Kiwi businesses need a bit of both, this is how to work out which.

Everyone locks the front door. Fewer people think about the window round the back that's been left on the latch for years, the one nobody remembers is even there. For most NZ businesses, that window is the mix of phones and laptops their team uses for work, some issued by the business, some just quietly adopted because a staff member's personal phone is faster to check email on than logging into a laptop.

MDM and MAM are the two locks that cover that window. Most businesses have one of them, if that, and have never actually checked which.

Frequently asked questions

Do I need MDM or MAM?

Most businesses need both. MDM covers devices the business owns outright, MAM covers personal devices staff use for work. If everyone's on issued equipment, MDM alone can be enough, but the moment BYOD is part of the picture, MAM closes the gap MDM can't reach.

Is BYOD safe for a small business?

It can be, with MAM in place. Staff using their own phones for work isn't the risk, that's not going away. The risk is company data sitting on those phones with no way to remove it if the phone is lost, stolen, or the staff member leaves.

What happens if an employee loses their phone?

It depends on whether MDM or MAM was set up beforehand. With either in place, IT can remotely wipe the company data (or the whole device, for MDM) within minutes. Without it, there's no way to act, the business just has to hope nothing sensitive was on there.

What does the Privacy Act have to do with my staff's phones?

IPP5 of the Privacy Act 2020 requires reasonable safeguards for personal information, and that includes information sitting on a phone. If a device holding client or staff details goes missing with no way to secure it remotely, that's a gap the Privacy Act expects businesses to have closed.

Where to start

You don't need to overhaul everything this week. Start by working out which of your devices are company-owned and which are personal, then run the self-check questions above against each pile. Most businesses find the gap is smaller than they feared, and narrower than a full software rollout.

If you'd rather have someone else run that check, that's exactly what a Device Security Check does: no lock-in, no jargon, just a clear picture of where MDM and MAM already cover you and where they don't.

In practice that means running through the checks above against your actual device list, with someone else doing the counting, and coming away with a plain-English list of what's sorted and what isn't, no pressure to buy anything on the spot.

It's also the kind of thing that tends to lead naturally into ongoing managed IT services, once the gap's closed, it's worth keeping closed.

Book a free device security check, talk to the Figure8 team and we'll tell you straight, no jargon, no hard sell.