The phones reading your company email are the least managed devices you own. Most of them are not even yours.
Indian businesses plan carefully for laptops and hardly at all for phones, yet the phone carries the same mailbox, the same files and the same chat history, travels across cities every week, and belongs to the employee more often than not. Managing iPhones and iPads properly means being able to remove company data from a device you do not own, without touching anything personal. Remote-first from Gachibowli, Hyderabad, for organisations across India.

- Work onlyCompany data removable without a full wipe
- BYOD honestPersonal content genuinely stays private
- Same dayLeaver access revoked without cooperation
- 30minManaged-client response SLA
Eight things that matter on a phone and never come up on a laptop.
Two genuinely different enrolment models
A company-owned iPhone can be supervised and fully managed: configuration, apps and restrictions all under organisational control. A personally owned phone should use account-driven User Enrolment, which manages only the work account and work apps and leaves everything else alone. Picking the wrong model is the most common mistake in Indian BYOD estates, because company-owned controls on a personal phone are intrusive and, in practice, unenforceable.
Removing company data without wiping the phone
This is the single capability that justifies the whole exercise. When somebody resigns, or a personal phone is lost, you remove the work account, the work apps and the data attached to them, and their photos, messages and personal accounts are untouched. Without management your only options are asking politely or a full wipe you have no right to run on hardware you do not own.
Being straight about what the employer can see
On a correctly configured personal device the organisation cannot see personal photos, personal messages, browsing history, or which apps the person installed for themselves. It can see the work apps it deployed, the device model and the OS version. Putting that in writing before anyone enrols is what makes BYOD adoption work; the rollouts that stall are almost always the ones that never explained the boundary.
A security baseline that is actually enforced
Passcode required, encryption on, a current iOS version, and the ability to lock or locate the device. These sound basic and they fail constantly, because a personal phone with no passcode holding a company mailbox is a breach waiting for an auto-rickshaw seat. Enforcement means the work account stops connecting when the baseline is not met, not a policy document hoping it is.
Apps deployed without personal Apple Accounts
Work applications installed and configured by the organisation, licensed to the organisation, and removed when the person leaves. Nobody should be asked to install a business app with their personal account: the licence then belongs to them, and refusing is a reasonable position for an employee to take. Organisation-owned licensing removes the argument entirely.
Single-app and kiosk iPads
An iPad locked to one application for billing counters, customer sign-in, a warehouse pick process, a survey kiosk or a clinic queue display. The device does nothing else, cannot be exited without a code, and a failed unit is replaced by couriering a configured spare to the site. For Indian retail chains and multi-city operations this is where iPads earn their keep.
Compliance connected to access
Deciding which devices may reach your mailbox and files at all. On Microsoft 365, device compliance feeds conditional access, so a jailbroken, unpatched or unmanaged phone is refused rather than merely reported. That connection is what turns mobile management from an inventory exercise into a real security boundary.
Lost and stolen as a process, not a panic
A phone left in a cab on a Friday evening needs a defined response: locate if possible, lock, decide whether to remove company data, and revoke the sessions the phone holds. The technology is straightforward. What makes it work is agreeing in advance who authorises what out of hours, because that is exactly when phones go missing.
Staff resist mobile management because nobody tells them the truth about it.
Almost every stalled BYOD rollout we see failed the same way: the company announced phones would be managed, explained nothing, and people assumed the worst. The version that works is short and honest.
- Tell people exactly what the organisation can see, in writing, before enrolment. Under a correctly configured personal-device enrolment: the work apps it deployed, the device model, the OS version, and whether the device meets the security baseline. Not personal photos, not personal messages, not browsing history, not what else is installed.
- Tell them exactly what the organisation can do. It can remove the work account and work data. It cannot wipe the whole phone, and it should not hold that power on a device it does not own. If your proposed configuration gives the employer that ability on personal devices, reconsider the configuration rather than conceal it.
- Give people a real choice where you can. A company phone for those who prefer to keep work off their own device removes the entire argument. Where that is not affordable for everyone, offer it at least to the roles handling the most sensitive material.
- Put it on one page people actually read, not a twelve-page policy nobody opens. What is managed, what is visible, what happens when you leave, who to ask. In an Indian workforce that moves between employers quickly, writing it down is also what protects the company when the relationship ends.
Four things that decide whether mobile management sticks.
We write the staff communication, not just the configuration
A one-page explanation of what is managed, what the employer can and cannot see, what happens on leaving, and who to ask. This deliverable decides whether people enrol willingly. We have seen technically perfect deployments stall because nobody wrote it, and simple ones succeed because somebody did.
We match the model to who owns the device
Company hardware gets full management because that is appropriate for company property. Personal devices get User Enrolment that touches only work data, because anything more is intrusive and will be refused or worked around. Getting this boundary right is most of the job.
We connect compliance to access, so the control is real
A report saying a device is non-compliant achieves nothing by itself. On Microsoft 365 estates we wire device state into conditional access, so a phone below the baseline is refused your mailbox rather than noted in a dashboard nobody reads. That is the difference between a mobile policy and a mobile control.
Remote-first from Hyderabad, reachable when it matters
Delivered remotely from Gachibowli, Hyderabad to organisations across India, because phone management is portal and policy work, not desk visits. Managed clients get a 30 minutes response SLA, and we agree in advance who can authorise removing company data from a lost device, so nobody is hunting for a decision-maker at midnight.
Six Indian situations and what each one needs.
A sales or field team on personal phones
Company email, client contacts and pricing sheets on devices the business does not own, carried by people who change employers often in a competitive market. User Enrolment is the right model: work data removable on departure, personal content untouched, and a written explanation that makes enrolment acceptable. The commercial risk is client data leaving with a departing salesperson, and this is the control that addresses it.
Retail or hospitality running iPads at the counter
Billing, customer sign-in, digital menus, feedback kiosks. These should be company-owned, supervised and locked to a single application so the device cannot become anything else. Replacement then becomes a courier job rather than a site visit, which is what makes running devices across dozens of outlets practical for a small IT team.
A firm handling regulated or client data
Financial services, legal, consulting and GCCs need to demonstrate that devices holding client information are managed, that access can be revoked, and that a lost phone does not become a reportable incident by default. For the most sensitive roles we generally recommend company-owned phones outright, because it removes the ambiguity entirely.
A clinic, hospital or diagnostics group
Patient information reaching phones, shared iPads passing between clinicians across shifts, and a confidentiality obligation that tolerates no ambiguity. Shared devices need particular care, because a communal login destroys attribution, and attribution is exactly what a clinical review or a DPDP breach inquiry will ask for.
A business with high staff turnover
IT services, BPO, logistics, retail, quick commerce, anywhere people join and leave monthly and offboarding is informal. The value is entirely in the leaver process: removing company access from a phone the same day, without needing the person to hand anything back or cooperate at all. Without it, access accumulates in a way nobody tracks.
Executives and founders
The people with the most valuable information on their phones are usually the least managed, because nobody imposes policy upward. A company-provided, properly managed iPhone is the clean answer, and it lands better introduced as a benefit than a control. Where the exposure is genuinely elevated, hardening beyond the baseline is a separate conversation.
Somebody resigns on Monday and hands back nothing. What happens?
| Feature | Managed | Email account only | Unmanaged |
|---|---|---|---|
Company mailbox removed from the phone | Immediately | Eventually | Only if they cooperate |
Documents cached on the device removed | Partly | ||
Work chat history removed | |||
Work apps removed | |||
Personal content untouched | |||
App licences recovered | Not applicable | ||
You can evidence the data was removed | Partly | ||
Requires the person to cooperate | Somewhat | Entirely | |
Works if they have already joined a competitor | Partly | ||
Time to complete | Minutes | Hours to days | Never, in practice |
Company-owned, personal with User Enrolment, or unmanaged.
| Company-owned | Personal, User Enrolment | Unmanaged | |
|---|---|---|---|
| Organisation controls the whole device | Yes | No | No |
| Work data removable on its own | Yes | Yes | No |
| Personal content visible to the employer | Possible, be careful | No | No |
| Passcode and encryption enforced | Yes | Yes | Hoped for |
| Apps deployed and licensed by the organisation | Yes | Yes | No |
| Access blocked if the device is non-compliant | Yes | Yes | No |
| Suitable for kiosk or single-app use | Yes | No | No |
| Staff generally accept it | Yes, company property | Yes, if explained | Not applicable |
| Leaver handled the same day | Yes | Yes | Ask and hope |
| Right for senior people with sensitive material | Best | Acceptable | No |
| Where most Indian staff phones sit today | Rarely | Sometimes | The default |
Five steps, and the announcement comes before the technology.
- 1
Count the phones that actually hold company data
Week 1
Your mail platform already knows which devices connect to it. The number is almost always higher than expected and includes people who left. It is also the number that makes the internal case, because an unquantified risk gets deprioritised and a specific count does not.
- 2
Decide the ownership model per group, in writing
Week 1-2
Which roles get company devices, which use personal phones under User Enrolment, and which need only web access on a computer. This is a business decision with cost implications, and it should be made by the business rather than defaulted to by IT.
- 3
Write the one-page explanation and circulate it
Week 2
What is managed, what the employer can and cannot see, what happens on leaving, who to ask. Available before anybody is asked to enrol. This is the step most often skipped and the one that decides whether the rest works.
- 4
Enrol in waves, starting with patient volunteers
Week 3-5
A first group of willing colleagues surfaces the practical snags: a confusing prompt, an app needing a setting, a phone on an old iOS version. Then department by department rather than the whole company in one morning, so support never faces everyone at once.
- 5
Connect compliance to access, then run it
Continuous
Once enrolment is established, non-compliant devices are refused access rather than reported, which is what makes the exercise a control. Then the ongoing rhythm: joiners, leavers, replaced devices, iOS versions kept current, and a defined out-of-hours process for anything lost. Managed clients get a 30 minutes response SLA for all of it.
What people ask, including the questions your staff will ask.
Fifteen questions about the phones with your data on them.
Quantify the exposure
- How many phones currently have company email on them?Most organisations cannot answer this, which is itself the answer.
- How many of those does the company own?Usually far fewer than the number holding company data.
- Could you remove company data from a personal phone today?If not, every leaver takes your mailbox with them.
- Do you know which are running an unsupported iOS version?Old phones stay in circulation long after updates stop.
- Has anyone left in the past year with access still on their phone?Check rather than assume. Disabling web login is not the same thing.
The controls
- Is a passcode actually enforced, or merely requested?A phone with no passcode and a company mailbox is an open door.
- Is device compliance connected to access?A non-compliance report changes nothing on its own.
- Are work apps deployed by the organisation, not installed personally?Licence ownership and removability both depend on this.
- Can a lost device be located and locked out of hours?Including late on a Friday, which is when it happens.
- Are customer-facing iPads locked to a single app?Otherwise they become a browsing device within a week.
The human and legal side
- Is there a one-page policy staff have actually read?Twelve pages nobody opens is the same as nothing.
- Have you told people in writing what the employer can and cannot see?The single biggest determinant of BYOD adoption.
- Is enrolment on a personal device genuinely voluntary?With a real alternative such as a company phone or web-only access.
- Do you know your DPDP Act obligations for what you collect?Managing a device means processing personal data about its user.
- Is there an agreed out-of-hours process for a lost device?Who authorises, who acts, and how fast.
The pages around this one.
Apple device management India
The hub: how iPhone, iPad and Mac management fits together for an Indian organisation, and where to start.
Learn moreZero-touch Apple deployment
Getting company-owned devices supervised and configured before anyone touches them, starting at the purchase order.
Learn moreMicrosoft Intune
What Intune covers across iPhone, iPad, Android, Mac and Windows, and how to check whether your Microsoft 365 plan already includes it.
Learn moreStart by counting how many phones have your email on them.
Your mail platform already knows. The number is usually higher than expected and usually includes people who left. We will help you produce it, work out which of those devices the company owns, and give you a straight recommendation on what to do about the rest. Initial reply within 4 business hours.