TL;DR:
- If your staff access company data on phones or laptops, you need some form of device management — unmanaged endpoints are one of the biggest risk gaps for UK SMBs
- Microsoft Intune is the default choice for Microsoft 365 subscribers and included in Business Premium — many small businesses are already paying for it without using it
- For Apple-heavy environments or mixed fleets, Jamf (for Macs/iPhones) and simpler tools like Hexnode or JumpCloud are worth evaluating
Here’s a question worth asking: if one of your staff members lost their phone today, could you remotely wipe your company data from it? And if their laptop was stolen, do you know whether it had full-disk encryption enabled? If the answer to either is “no” or “I don’t know”, you have a mobile device management gap — and it’s one that UK cyber insurers are increasingly asking about.
What MDM Actually Does
Mobile Device Management (MDM) software lets you centrally manage and secure the devices your staff use for work. That covers smartphones, tablets, and laptops — whether they’re company-owned or personal devices used for work (bring your own device, or BYOD).
The core capabilities most UK small businesses need are fairly modest. You want to be able to remotely wipe a lost or stolen device, enforce basic security policies (screen lock PINs, disk encryption, automatic OS updates), deploy and remove apps centrally, and have an inventory of what devices are connected to your systems.
The more advanced features — application containerisation, zero-trust network access integration, compliance reporting for auditors — matter for organisations with stricter requirements, like those handling financial data, healthcare records, or working towards ISO 27001 certification.
Microsoft Intune: You’re Probably Already Paying for It
If your business uses Microsoft 365 Business Premium (currently around £20 per user per month), Microsoft Intune is included. Intune is Microsoft’s MDM and mobile application management (MAM) platform, and for a Microsoft-centric environment it’s the path of least resistance.
Setting it up takes some time — you’ll need to configure enrolment policies, create compliance rules, and connect your devices — but once configured it’s genuinely useful. Intune can manage Windows PCs, Android phones, iPhones, and Macs from a single admin console. You can enforce BitLocker encryption on Windows machines, require device PIN or biometric lock, prevent corporate email from being opened in personal apps, and remotely wipe corporate data when a device is lost or an employee leaves.
The NCSC’s Cyber Essentials scheme has technical requirements that map well to what Intune can enforce — boundary firewalls, secure configuration, software updates, malware protection, and access controls. If you’re working towards Cyber Essentials certification, Intune can help you demonstrate compliance with the device management aspects.
To be honest, the Intune admin interface has a reputation for being complex. If you don’t have IT support or someone comfortable with Microsoft admin portals, you may want help getting it configured initially. Your IT provider should be able to do this as a one-off setup engagement.
Jamf: The Apple-First Option
If your business runs primarily on Macs, iPhones, and iPads, Jamf is worth a serious look. Jamf Now (the SMB-targeted product) starts at around £2.50 per device per month with a free tier for up to three devices, and it’s significantly easier to use than Intune for Apple-only fleets.
Jamf integrates directly with Apple Business Manager, Apple’s enterprise deployment programme, which lets you configure new Macs and iPhones before they’re even unboxed. You enrol devices in Apple Business Manager, connect it to Jamf, and new devices can be set up with corporate configuration, pre-installed apps, and security policies automatically when they’re first powered on. For a business that regularly onboards new staff, this is genuinely convenient.
Jamf also handles Mac-specific compliance tasks well — FileVault encryption status, Gatekeeper settings, automatic software updates, and local firewall configuration. If you’re a creative agency, architecture practice, or any business running a Mac-centric environment, Jamf Now is often a cleaner fit than Intune.
Simpler Alternatives for Very Small Teams
For businesses with fewer than ten staff and fairly simple requirements, the enterprise MDM options can feel like overkill. A few lighter-weight alternatives are worth knowing about.
Hexnode is a solid mid-market MDM with competitive pricing (around £1.50 per device per month) and a cleaner interface than Intune. It supports Android, iOS, Windows, and Mac, making it a reasonable cross-platform choice without the Microsoft dependency.
JumpCloud combines MDM with identity management — it can replace both your MDM and your Active Directory or Azure AD for a flat per-user fee (around £9 per user per month for the full platform). For very small businesses that don’t want to run Microsoft 365 at all, JumpCloud provides directory services, single sign-on, and device management in one tool.
If you’re purely on Android and need something simple, Google Workspace with Android Enterprise provides basic MDM for Android devices without additional cost if you’re already paying for Google Workspace.
BYOD Considerations
Many small businesses operate with staff using their personal phones to access work email and files. This is a legitimate approach — requiring staff to carry a separate work phone is often impractical — but it does create security considerations.
The modern approach to BYOD is mobile application management (MAM) rather than full device management. Instead of managing the entire personal device, you manage only the corporate apps and data on it. Intune and Jamf both support this model. Corporate email opens in a managed Outlook or Mail app, corporate files live in a managed OneDrive container, and if someone leaves or loses their phone you can wipe just the corporate data without touching personal photos and messages.
From a UK GDPR perspective, this approach is cleaner than full device management for personal phones, because you’re not accessing or holding data about the device owner’s personal use.
Getting Started
The practical starting point for most small businesses: check whether you’re already licensed for Intune through your Microsoft 365 subscription before spending money on alternatives. If you’re on Business Basic (without Intune), the step up to Business Premium may be worth it for the MDM capability alone, particularly if you’d otherwise pay for a separate MDM tool.
If you’re Apple-first and want simplicity, try Jamf Now’s free tier on your first three devices to evaluate the interface before committing.
Either way, getting device management in place doesn’t require a project of months. A basic configuration covering device enrolment, disk encryption enforcement, screen lock requirements, and remote wipe capability can be done in an afternoon by someone comfortable with IT admin consoles, or in a day if you’re getting professional help.
The risk you’re managing is clear: lost and stolen devices are a common route for data breaches affecting small businesses, and an unmanaged fleet makes incident response significantly harder. It’s one of the more straightforward risk areas to address once you know which tool to reach for.