Security needs visibility: The defence value of ITAM
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
- ITAM
- Governance
- Security
Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.
Mobile device management is usually sold as its own category, with its own console, its own agent and its own view of who owns what. That is the root of most of the trouble people have with it.
Phones and tablets are assets. They are bought, assigned, configured, secured, supported and eventually retired, exactly like laptops and servers. When they are managed in a separate tool, everything downstream of “what do we own” has to be assembled by hand from two sources that count things differently.
The alternative to a single inventory is several fragmented data sources, in different formats, that take manual work to stitch together before they mean anything. The output of that work is slower, more expensive and less trustworthy than it should be — and it goes stale immediately.
In CerteroX, mobile device management sits inside CerteroX ITAM. Enrolled iOS and Android devices land in the same schema as the Windows, macOS, Linux, AIX, HP-UX and Solaris systems discovered by the same platform. There is one asset record, one set of groups, one reporting model and one permission model across all of them.
That means the questions people actually ask get straightforward answers. Which devices does this leaver still hold, across every form factor. Which assets in this department are out of support. What is assigned to this cost centre. None of those questions respect the boundary between a phone and a laptop, so neither should the inventory.
Employees expect to use their own devices for work, and organisations largely accommodate them. That creates a real tension: IT needs enough control to protect corporate data, and employees need assurance that personal data is not being harvested along with it.
Both sides of that are configuration decisions, and they need to be explicit. CerteroX ITAM exposes privacy settings per feature — location synchronisation, for example, is a setting you deliberately enable rather than a default you discover later. Get that wrong and enrolment stalls, because people decline to enrol devices they do not trust.
The security case for enrolment is straightforward. An unmanaged device holding corporate mail and documents is exposure you cannot quantify, because you do not know it exists. An enrolled one is an asset with a known configuration, a known compliance state and a set of actions you can take when something goes wrong.
Mobile device management is the process of monitoring, securing and managing devices deployed across multiple carriers and operating systems. In practice it comes down to four things: getting devices enrolled, configuring them, watching for non-compliance, and acting when a device is lost or a user leaves.
Enrolling devices one at a time does not scale. CerteroX ITAM generates a QR code for user enrolment, so a device is brought under management by scanning it rather than by an administrator working through a wizard. Apple’s Device Enrolment Program is supported directly, with DEP devices and DEP profiles as first-class objects, and the mobile agent can be pushed to DEP devices automatically. Enrolment password policy is configurable, as is certificate pinning.
Configuration is delivered as profiles rather than instructions to the user. The profile types are Wi-Fi, VPN, email, AirPrint, certificates, bookmarks, and separate iOS and Android restrictions profiles — which cover things like disabling the camera, disabling the lock screen camera and widgets, setting a lock screen message, maximum time to lock, password quality, length, history and expiry, blocking installation from unknown sources, and disabling debugging. Configuration rules apply the right profiles to the right devices without anyone assigning them by hand.
Application management is part of the same picture. Public and enterprise applications can be published to iOS and Android, and applications can be blacklisted so their presence is treated as a compliance failure.
A device is either compliant or it is not, and the reasons are specific rather than a score. CerteroX ITAM tracks whether a device is jailbroken or rooted, whether blacklisted applications are installed, whether it has violated a geofence boundary, whether its password meets policy, whether deployed Wi-Fi networks have been removed, whether location reporting is available where it is required, and whether background processing is enabled where iOS needs it.
Geofencing is worth calling out because it is the clearest case for automation. You define geofencing sites, and location events are evaluated against them continuously with alerts attached. A person cannot watch a device cross a boundary and respond in time. A rule can.
When a device is lost, three things need to happen quickly: find it, lock it, and if necessary destroy the data on it. All three are commands you can send from the same console that holds the inventory — lock device, wipe device, clear password, unenrol, and install or remove an application. Device location history is retained against the asset record. For iOS, the activation lock bypass code can be retrieved, which is the difference between recovering a corporate iPhone and writing it off.
Because these are actions against an asset record rather than against a separate mobile console, they can be driven from a device search the same way any other bulk action is.
Administrators get dashboards for MDM devices and mobile applications, alongside the wider CerteroX ITAM reporting model — dynamic, static and custom groups built with the query builder or SQL, trend charts, KPIs and threshold alerts, and dashboards that can be personal or shared with a role. Everything is also available through the read-only Certero API, which has a documented Power BI data source, so mobile data can be reported against alongside anything else you hold.
Managing Android and iOS well is not really a mobile problem. It is an inventory problem that happens to involve phones.
Devices need to be discovered, assigned to a person, configured to policy, watched for drift and acted on when something goes wrong — and none of that works properly if mobile lives in one system and everything else lives in another. Put them in the same record and the hard part disappears.
To see Android and iOS sitting in the same asset record as everything else, book a demo.
Other posts covering the same ground.
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.
When Microsoft patched a wormable Remote Desktop flaw serious enough to warrant emergency updates for Windows XP, the hard part was not the patch. It was working out which machines you owned that needed it. That is a hardware asset management problem, and it has not gone away.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.