To manage cybersecurity on your company's devices, keep an inventory of every laptop and phone, enrol each in a management platform such as Microsoft Intune, Jamf or Google endpoint management, and let that console enforce the rest: a security baseline, encryption with escrowed recovery keys, updates with deadlines, no everyday admin rights, and access only from compliant devices.
This guide is for a business with anywhere from a handful to a few hundred devices and no full-time security team. It takes each job in the order to do it, with the settings that matter in Microsoft, Apple and Google tools. The wider baseline (MFA on every account, backups, email authentication, staff training) is in our small business cybersecurity checklist; if you are protecting your own phone and laptop rather than a company's, start with our guide to staying safe online and the personal device settings guide.
What device management covers
Device security in a small company usually starts as good intentions: encryption turned on for the first few laptops, a reminder to install updates. It drifts as soon as the next laptop arrives. Managing it means a system of record instead: one console that knows every device, pushes the same settings to all of them and reports the ones that fall out of line. NIST's SP 800-124 Revision 2 (May 2023) treats this as a lifecycle, from deployment through use to disposal, for company-provided and personally owned devices alike, and this guide follows the same order.
Four kinds of tool get mixed up here:
| Tool | What it controls | Where it fits |
|---|---|---|
| MDM (mobile device management) | The whole device: settings, apps, encryption, updates, lock and wipe | Every company-owned laptop, desktop and phone |
| MAM (mobile app management) | Only the work apps and the data inside them | Personal phones that open company email and files |
| EDR (endpoint detection and response) | Behaviour on each device, with alerts and remote response | Alongside MDM, reporting into the same health check |
| RMM (remote monitoring and management) | Scripts, monitoring and remote sessions for whoever provides support | Support tooling, overlapping with MDM on Windows |
Vendors also call MDM for computers and phones unified endpoint management (UEM). RMM is support tooling more than a security control; it is covered in our guide to remote IT support tools.
The yardstick used below is the CIS Controls. Version 8.1 defines Implementation Group 1 (IG1) as essential cyber hygiene: 56 safeguards for organizations that are typically small to medium-sized, with limited IT and security expertise. Most steps in this guide map to an IG1 safeguard; the few that sit in the higher groups are marked.
Start with an inventory of devices and software
You cannot secure a laptop nobody knows about. CIS safeguard 1.1 asks for an inventory of every asset that can store or process data, recording at least its hardware address, machine name, owner and department and whether it is approved to connect, reviewed bi-annually or more often; it notes that MDM tools can support this for mobile devices. Safeguard 1.2 asks for a weekly process to deal with unauthorized devices. Safeguards 2.1 and 2.2 do the same for software: a list of licensed software with its publisher, install date and business purpose, and a monthly check that everything on it is still supported by its vendor. All four are in IG1.
Build the first version from what already exists:
- Export the user list from Microsoft 365 or Google Workspace, and the devices that have signed in with those accounts.
- Add purchase records and warranty lists, and match every device to a person.
- Ask each person what else they use for work, including personal phones that receive company email.
- Mark each device as company-owned or personal, because the two are managed differently.
Once devices are enrolled, the management console becomes the inventory and keeps itself current. Jamf Pro, for example, collects hardware, software and security configuration details from Apple devices automatically. Keep a separate register only for what no console sees: purchase dates, warranties and who holds which spare.
Choose a device management platform
Pick the platform that matches the identity system you already pay for, because device health has to reach the place where people sign in.
| If your business runs on | Start with | What it gives you |
|---|---|---|
| Microsoft 365 | Microsoft Intune | Windows, macOS, iOS/iPadOS, Android and Linux; MDM and MAM; compliance for sign-in |
| Google Workspace | Google endpoint management | Basic mobile management by default; advanced management with an app; computer controls |
| Mostly Apple devices | Jamf Pro | Zero-touch deployment, inventory, declarative management, benchmark-based hardening |
Microsoft Intune runs entirely in the cloud and manages Android, iOS/iPadOS, Linux, macOS, tvOS, visionOS and Windows. It relies on Microsoft Entra ID for sign-in and groups, sends each device's compliance state to Entra ID, and needs an Intune licence for each managed user or device.
Tip
Check what you already own before buying anything. Microsoft 365 Business Premium includes Intune Plan 1, so many small businesses have paid for device management for years without switching it on.
Google endpoint management comes with Google Workspace and Cloud Identity. Basic mobile management is on by default and needs no app on the phone; advanced management asks users to install one and adds device approval, remote wipe, iOS app management and Android work profiles. For computers it can block devices, sign users out remotely and apply Context-Aware Access.
Jamf Pro is Apple-only: zero-touch deployment for Mac, iPhone and iPad, settings through Apple's declarative device management, and compliance benchmarks based on industry baselines. It integrates with Microsoft Entra, Google Workspace and Okta, so an Apple-heavy team keeps the identity system it already has.
Enrol company devices without touching them
Zero-touch enrolment registers a device to your organization before it reaches the user, so it enrols itself at first sign-in instead of waiting for someone to set it up by hand. Intune supports it through Windows Autopilot, Apple Automated Device Enrollment and Android Enterprise.
- Windows. Windows Autopilot turns the Windows already installed on a new PC into a business-ready one: it applies settings and policies, installs apps and can change the edition from Pro to Enterprise, without re-imaging. Registration and the user's side of setup are covered in our guide to setting up Windows on a new computer.
- Mac, iPhone and iPad. Devices whose serial numbers are in Apple Business, the new name for Apple Business Manager, use Automated Device Enrollment. Your MDM can stop users removing management, hold the device in Setup Assistant until critical settings and apps arrive, require a minimum OS version before setup finishes and, on macOS 14 or later, turn on FileVault during setup.
- Android. Company-owned Android phones enrol through Android Enterprise in Intune, and Google endpoint management manages company-owned phones, laptops and desktops from the same Admin console.
Personal devices take a different path. Microsoft's guidance for Business Premium customers recommends MDM for every company-owned device, and blocking personal phones from full enrolment when you plan to protect them with app policies instead (see the BYOD section below).
Apply a security baseline instead of hand-picked settings
A security baseline is a published, tested set of settings: you start from expert defaults and write down only your exceptions. CIS safeguard 4.1 (IG1) asks for exactly that, a documented secure configuration process for devices and software, reviewed every year. Two sources are worth knowing:
- Microsoft security baselines. Intune ships them as templates. As of September 2026 the Security Baseline for Windows 10 and later is at version 25H2, alongside baselines for Microsoft Defender for Endpoint, Microsoft 365 Apps and Microsoft Edge. Among many other settings, its defaults turn on BitLocker for removable drives, require a password to unlock the device and disable basic authentication. Microsoft notes that the defaults are almost always the most restrictive values, so pilot them on a few devices first.
- CIS Benchmarks. The CIS Benchmarks are consensus-based configuration recommendations for more than 25 vendor product families. CIS also publishes versions written for Intune, including Microsoft Intune for Windows 11 and Intune benchmarks for macOS 26 Tahoe and for iOS and iPadOS 26. On Macs managed with Jamf, Jamf Pro's compliance benchmarks apply a similar hardening.
Add the settings a baseline leaves to you. CIS safeguard 4.3 (IG1) locks a computer's session after at most 15 minutes of inactivity and a phone's after at most 2 minutes. Safeguard 4.10 (IG2) locks a portable device after too many failed sign-ins: no more than 20 attempts on a laptop and 10 on a phone or tablet.
Patch in rings, with deadlines
Automatic updates are necessary but not enough: a laptop that postpones its restart for three weeks is automatic in name only. CIS safeguards 7.3 and 7.4 (IG1) ask for automated operating system and application patching at least monthly. The pattern that makes that true across a fleet is rings: a few devices get each update first, everyone else a few days later, and every ring has a deadline after which the update installs itself.
On Windows, the policies formerly branded Windows Update for Business are now called Windows Update client policies. Quality updates, which carry the monthly security fixes, typically ship on the second Tuesday of the month. You can defer them by up to 30 days and feature updates by up to 365, and pause either for up to 35 days when an update misbehaves. Intune's update ring settings add the part that matters most: a deadline of 2 to 30 days after which quality or feature updates install automatically, and a grace period of 0 to 7 days before the device restarts on its own.
A workable starting design for a small team:
- Test ring: two or three devices, including IT's own, with no deferral and a short deadline.
- First ring: one or two people from each team, deferred by a few days, so an app that breaks shows up in every department before it reaches all of it.
- Broad ring: everyone else, deferred a little longer, with a deadline and grace period that keep every device inside the monthly window.

Windows Autopatch can run this for you. It releases updates to Windows, Microsoft 365 Apps, Microsoft Edge and Microsoft Teams in sequential rings and aims to keep at least 95% of up-to-date devices on the latest quality update. Since April 2025 its features have been available with Microsoft 365 Business Premium, not only with enterprise licences.
On Macs, iPhones and iPads, Apple's declarative device management does the same job. Supervised devices can defer an update by 1 to 90 days after Apple releases it, and a Mac can defer OS updates, major upgrades and other updates separately. An enforcement date then sets the deadline, in each device's local time. Users get increasingly frequent reminders; at the deadline, a Mac force-quits open apps, including ones with unsaved documents, and restarts to install. Tell people before the first enforced update. What updating looks like on each individual device is covered in how to update your computer or phone.
Encrypt every disk and escrow the recovery keys
Encryption turns a stolen laptop from a data breach into a hardware loss. CIS safeguard 3.6 (IG1) asks for encryption on end-user devices that hold sensitive data, and names BitLocker, FileVault and dm-crypt as examples. What goes wrong in practice is the recovery key: if nobody saved it, the next recovery prompt locks the business out of its own data.
- Windows (BitLocker). Intune can turn BitLocker on silently, with no prompts and no admin rights needed on the device, on Entra-joined PCs with a TPM, UEFI firmware and Secure Boot. Recovery keys are stored in Microsoft Entra ID and shown per device in the Intune admin center, and each time someone reveals one, an audit log entry is written. Microsoft also suggests turning on automatic recovery password rotation.
- macOS (FileVault). Intune escrows the recovery key first and only then starts encryption. The user sees a personal recovery key once and can retrieve the current one later from the Company Portal website.
- iPhone and iPad. In Intune's compliance rules, the encryption requirement on iOS is met by setting a passcode, so the passcode policy is the encryption policy.
Take away everyday admin rights
An everyday account with administrator rights lets anything its user opens change the whole system. That is why CIS safeguard 5.4 (IG1) keeps administrator privileges in dedicated admin accounts and daily work in standard ones. On Windows this needs a deliberate change, because by default Microsoft Entra join adds the person who joins the PC to its local Administrators group. Two settings prevent it: the Entra device registration setting that controls whether joining users become local administrators, and a Windows Autopilot profile that stops the primary user from becoming one.
IT still needs a way in. Windows LAPS, built into Windows 11 23H2 and later (and into earlier versions with the April 11, 2023 update), manages the password of each device's local administrator account: it rotates the password regularly, backs it up to Microsoft Entra ID or Active Directory, and lets authorized admins retrieve it. It closes a common gap: Microsoft notes that local administrator accounts often share one password across many devices, which attackers use to move from machine to machine.
For people who genuinely need elevation, such as developers, grant it through an Entra group assigned as local administrators on specific devices, rather than making them administrators everywhere.
Let only compliant devices reach company data
Everything above is configuration. A compliance policy checks that it worked: platform-specific rules such as a minimum OS version, encryption turned on, a device that is not jailbroken or rooted, or a threat level reported by your security software. A device that fails is marked noncompliant, and you can add actions: email the user, lock the device remotely after some time, or mark it for retirement.
Compliance becomes enforcement when Conditional Access requires a compliant device. Intune reports each device's state to Microsoft Entra ID, and a sign-in to email, files or any other protected app from a device that is not marked compliant is refused until the device is fixed.

Three details decide whether this works:
- Change the tenant default. Out of the box, Intune treats a device with no compliance policy assigned as compliant. When you rely on Conditional Access, set Mark devices with no compliance policy assigned as to Not compliant.
- Mind the check-in window. A device that has not reported its compliance within the validity period (30 days by default, configurable from 1 to 120) is treated as noncompliant.
- Start in report-only mode, and exclude your emergency access accounts, so one misconfigured policy cannot lock every administrator out. Create the compliance policy before the Conditional Access policy, or the second one will not work as intended.
For Windows, Microsoft's Business Premium guidance suggests requiring BitLocker, Secure Boot, code integrity, the firewall, a TPM, antivirus and Microsoft Defender real-time protection with current security intelligence, and giving users one day before a failing device is marked noncompliant.
Endpoint security belongs in the same check. CIS safeguard 10.1 (IG1) requires anti-malware on every enterprise asset. Microsoft Defender for Business, built on Defender for Endpoint for organizations of up to 300 users, adds endpoint detection and response (EDR) and is included in Business Premium, and the compliance policy above can require its antimalware and real-time protection to be running. Whether the protection built into Windows is enough, and when EDR earns its cost, is covered in how to choose antivirus software.
Protect personal phones with app policies, not full enrolment
Full enrolment of an employee's own phone gives the company control over a device it does not own. For bring your own device (BYOD), protecting the work apps is usually the better trade. Intune app protection policies apply only when an app is used with a work account, and work without enrolling the device at all. Typical rules:
- a PIN or fingerprint to open work apps such as Outlook and Teams;
- no copying company data into personal apps, and no saving it to personal storage;
- per Microsoft's Business Premium recommendations, company data kept out of iCloud and iTunes backups, and saved only to OneDrive and SharePoint;
- a Conditional Access rule that requires an approved app or an app protection policy, so company data cannot be opened in an unprotected app.
On Android, the Intune Company Portal app must be installed to receive these policies, even though the phone is not enrolled.
The selective wipe is the point of the design. When someone leaves, or loses the phone, IT removes company data from the managed apps and leaves photos, messages and personal apps alone, which is also what makes the policy easy to accept.

Apple and Google offer the same split in the operating system. Apple's account-driven User Enrollment is designed for personally owned devices: IT can manage only the organization's accounts, settings and data, never the user's personal account. Google endpoint management's advanced mode uses Android work profiles, which CIS safeguard 4.12 (IG3) describes as separating enterprise apps and data from personal ones.
What to do when a device is lost or stolen
Write the procedure down before you need it. Microsoft's guidance on revoking access explains why speed matters: access tokens normally last about an hour, a wipe only happens once the device is online, and a device kept offline still has whatever is stored on it. That is also why encryption has to be in place first. CIS safeguard 4.11 (IG2) asks for remote wipe on company-owned portable devices; this is the order to use it:
- Lock it. Intune's remote lock works on iPhone, iPad, Mac and company-owned Android devices, and only if a passcode was already set. On supervised iPhones and iPads, Lost Mode locks the device, shows a message and phone number on the lock screen, and lets you locate it.
- Cut off the account. Block the user's sign-in and select Revoke sessions in Microsoft Entra ID, or sign the user out remotely in Google Workspace. Let them back in on a replacement device.
- Wipe it once recovery is unlikely. A wipe is a factory reset that removes all personal and company data, apps and settings. On Apple devices, erasing destroys the encryption keys and leaves the data cryptographically inaccessible. For a personal phone, wipe only the company data.
- Record it. Update the inventory entry, and note what data was on the device in case it triggers a breach notification duty.
Onboarding and offboarding without loose ends
Most device risk sits in two moments: a new starter's first day and a leaver's last.
Onboarding should need no IT visit. With zero-touch enrolment the new laptop is registered to your organization before it ships. The user signs in, and the device joins your directory, enrols in management, receives its baseline, encryption and update ring, and installs its apps. A checklist per role decides which groups the new account joins, and therefore which policies and apps follow.
Offboarding should be one documented sequence, done the same way every time:
- Disable the account and revoke its sessions, then remove it from groups, shared mailboxes and admin roles.
- Collect company-owned devices, then wipe them, or reset them for the next person.
- Run a selective wipe of company data on any personal phone.
- Reclaim licences and close or update each inventory record.
Warning
Retire and wipe are not the same action. Retire unenrolls a device and removes company apps and settings but keeps user content; wipe resets it. Retiring or deleting an Entra-joined Windows PC protected by BitLocker also removes its key protectors and suspends BitLocker on the system drive, so back up the recovery key and the local administrator password first.
Prove it with compliance reports
A console nobody reads is just an expensive inventory. Intune's reports answer the questions an auditor, insurer or customer questionnaire will ask: which devices are noncompliant and on which setting, which devices have no compliance policy at all, and how compliance has trended over the last 30 days. Export them, and keep a copy each month as evidence.
A short monthly review:
- noncompliant devices, and who owns fixing each one;
- devices that have not checked in for weeks (lost, stored or broken);
- devices on an operating system version that no longer gets security updates;
- Intune's encryption report, for any laptop that never finished encrypting;
- admin role assignments, and whether each one is still needed;
- the inventory compared with purchases and leavers.
If you would rather not build and run this yourself, our IT support service covers device management with Microsoft Intune or Jamf: laptops and phones enrolled, configured and kept compliant from one console, disk encryption and compliance policies, remote lock and wipe, patching for operating systems and apps, local admin rights removed, and offboarding in one documented sequence. Device management covers what your people carry. The websites, servers and cloud accounts you expose to the internet need a different check, which our security scanning service runs on a schedule. More guides on the subject are under security.


