The number of mobile devices inside organisations has grown every year since this post was first written, and the management question that came with them has not gone away. It usually gets framed as a binary: agent, or agent-less?
That framing is still worth working through, because the trade-off is genuine. But it is worth saying up front that it is no longer the most important question. The more consequential one is whether mobile devices sit in the same record as everything else you own, or in a tool of their own.
What mobile device management means
Mobile device management is the administrative management of mobile devices — smartphones and tablets, principally. It covers deploying, securing, monitoring, integrating and managing those devices at work, so that you can protect the corporate network while people get the benefit of the device.
Why it is needed
Managing mobile devices across an organisation is difficult and time-consuming without the right tooling. Access to your network and to sensitive corporate data is a balancing act: whatever manages the device has to be simple enough that the end user tolerates it, and capable enough that the organisation stays secure.
There are two legitimate interests in tension. The organisation needs to protect sensitive data on the device against misuse or theft. The individual needs their personal use of the device to stay private. That tension sharpens considerably when the device belongs to the employee, under a bring-your-own-device policy, because now you are asking to manage something you do not own.
How it works, and where the trade-off lives
The conventional approach places an agent or app on the device to monitor it and, if it is lost or stolen, control it. Plenty of employees dislike this and respond accordingly — they remove the agent, or they never enrol in the first place. The objection is not irrational. An agent gives corporate IT the ability to dictate device policy, from enforcing password rules to blocking access to particular applications in the app store, on a device the user may have paid for.
Agent-less management emerged in response, giving a degree of control back to the user. It has its own limitations, and one of them is structural rather than a matter of implementation. Without something running on the device, you cannot reliably determine whether that device has been rooted or jailbroken. A jailbroken device has had the manufacturer’s security model deliberately dismantled; it is exactly the device you would most want to identify, and it is the one an agent-less approach is least able to see. That is not a gap a vendor can close with a better integration. It follows from where the code is running.
So the trade-off is real and it does not resolve neatly. More visibility, more user resistance. Less intrusion, less assurance.
The question worth asking instead
Here is what has changed since this argument was first set out. Mobile stopped being a category that needs its own platform.
CerteroX ITAM covers mobile device management for iOS and Android, including Apple Device Enrolment Programme, alongside Windows, macOS, Linux, AIX, HP-UX and Solaris. One agent, six operating system families, ten discovery methods, and — the part that matters — one schema. A phone is not a record in a mobile system that later has to be reconciled against the record of everything else. It is a device in the inventory, next to the laptop the same person uses.
That has practical consequences for the agent-versus-agent-less argument.
You can apply different policy to different populations without running different tools. Dynamic, static and custom groups are built through a query builder or directly in SQL, so corporate-owned and personally-owned devices can carry genuinely different policies while remaining in one system of record. The BYOD distinction becomes a grouping decision rather than a procurement decision.
Device policy is enforced the same way everywhere. Governance Policies are compliance-as-code with a reusable filter builder — the same mechanism that checks whether BitLocker is enabled or Defender is running on a workstation. Mobile does not get a parallel, differently-shaped policy engine that someone has to keep in step with the main one.
If Intune is already deployed, it is an integration, not a competitor. So are Active Directory, SCCM and the rest. The point of a single inventory is not that it replaces everything you already run; it is that the answer to “what do we own and who has it” comes from one place.
The practical point
If you are choosing between agent and agent-less mobile management, understand what you are buying and what you are giving up. The agent sees more, including the conditions you most need to know about, and it is the thing users are most likely to reject. Agent-less is easier to live with and structurally blind to a rooted or jailbroken device. Pick deliberately, and be honest with yourself about which risk you are accepting.
But do not solve that question by adding another tool with another database and another interface. Mobile devices are assets. They belong in the same record as your assets.
To see mobile devices sitting in the same inventory as servers, workstations and Macs, book a demo.