The lost phone test
Someone on your team leaves their phone at a cafe in the Valley this afternoon. Right now, today: can you say with confidence that it has a passcode, that the data on it is encrypted, and that you can wipe company data off it remotely within the hour? If any answer is "not sure", then whoever picks up that phone potentially picks up your email, client files and payment approvals with it.
What MDM actually does
Mobile device management enrols each work phone and tablet so sensible rules are enforced automatically rather than politely requested. A passcode and encryption are mandatory, not optional. Work apps and email are kept in a managed bubble, separate from personal apps. Lost or stolen devices can be located, locked, or wiped remotely. And when someone leaves the raft, company data comes off their device in one click, without touching their personal photos.
That last distinction matters for BYOD (bring your own device). MDM done properly protects the company's slice of a personal phone while leaving the rest alone, which is both more respectful and, for most 20 to 200 person teams, far cheaper than buying everyone a handset.
MDM and your Microsoft 365 tier
If your users are on Business Premium, Intune (Microsoft's device management) is already in the licence, and our tier guide explains that overlap. The MDM add-on covers the rafts that aren't there yet, or the devices outside that world, so nobody has to jump a licence tier just to make phones safe.
What it costs
Mobile device management (MDM) is an optional add-on at $15 per device per month: company phones and tablets enrolled, secured and remotely wipeable if one goes for a swim. Tick it in the calculator against however many phones and tablets carry company data. Hint: it's more than you think. Count the boss's iPad.