Skip to content

MDM: agent or agent-less management for your mobile devices?

Agent-based mobile device management sees more and annoys users. Agent-less sees less and stays out of the way. The trade-off is real — but the more useful question in 2026 is why mobile is being managed in a separate tool at all.

The number of mobile devices inside organisations has grown every year since this post was first written, and the management question that came with them has not gone away. It usually gets framed as a binary: agent, or agent-less?

That framing is still worth working through, because the trade-off is genuine. But it is worth saying up front that it is no longer the most important question. The more consequential one is whether mobile devices sit in the same record as everything else you own, or in a tool of their own.

What mobile device management means

Mobile device management is the administrative management of mobile devices — smartphones and tablets, principally. It covers deploying, securing, monitoring, integrating and managing those devices at work, so that you can protect the corporate network while people get the benefit of the device.

Why it is needed

Managing mobile devices across an organisation is difficult and time-consuming without the right tooling. Access to your network and to sensitive corporate data is a balancing act: whatever manages the device has to be simple enough that the end user tolerates it, and capable enough that the organisation stays secure.

There are two legitimate interests in tension. The organisation needs to protect sensitive data on the device against misuse or theft. The individual needs their personal use of the device to stay private. That tension sharpens considerably when the device belongs to the employee, under a bring-your-own-device policy, because now you are asking to manage something you do not own.

How it works, and where the trade-off lives

The conventional approach places an agent or app on the device to monitor it and, if it is lost or stolen, control it. Plenty of employees dislike this and respond accordingly — they remove the agent, or they never enrol in the first place. The objection is not irrational. An agent gives corporate IT the ability to dictate device policy, from enforcing password rules to blocking access to particular applications in the app store, on a device the user may have paid for.

Agent-less management emerged in response, giving a degree of control back to the user. It has its own limitations, and one of them is structural rather than a matter of implementation. Without something running on the device, you cannot reliably determine whether that device has been rooted or jailbroken. A jailbroken device has had the manufacturer’s security model deliberately dismantled; it is exactly the device you would most want to identify, and it is the one an agent-less approach is least able to see. That is not a gap a vendor can close with a better integration. It follows from where the code is running.

So the trade-off is real and it does not resolve neatly. More visibility, more user resistance. Less intrusion, less assurance.

The question worth asking instead

Here is what has changed since this argument was first set out. Mobile stopped being a category that needs its own platform.

CerteroX ITAM covers mobile device management for iOS and Android, including Apple Device Enrolment Programme, alongside Windows, macOS, Linux, AIX, HP-UX and Solaris. One agent, six operating system families, ten discovery methods, and — the part that matters — one schema. A phone is not a record in a mobile system that later has to be reconciled against the record of everything else. It is a device in the inventory, next to the laptop the same person uses.

That has practical consequences for the agent-versus-agent-less argument.

You can apply different policy to different populations without running different tools. Dynamic, static and custom groups are built through a query builder or directly in SQL, so corporate-owned and personally-owned devices can carry genuinely different policies while remaining in one system of record. The BYOD distinction becomes a grouping decision rather than a procurement decision.

Device policy is enforced the same way everywhere. Governance Policies are compliance-as-code with a reusable filter builder — the same mechanism that checks whether BitLocker is enabled or Defender is running on a workstation. Mobile does not get a parallel, differently-shaped policy engine that someone has to keep in step with the main one.

If Intune is already deployed, it is an integration, not a competitor. So are Active Directory, SCCM and the rest. The point of a single inventory is not that it replaces everything you already run; it is that the answer to “what do we own and who has it” comes from one place.

The practical point

If you are choosing between agent and agent-less mobile management, understand what you are buying and what you are giving up. The agent sees more, including the conditions you most need to know about, and it is the thing users are most likely to reject. Agent-less is easier to live with and structurally blind to a rooted or jailbroken device. Pick deliberately, and be honest with yourself about which risk you are accepting.

But do not solve that question by adding another tool with another database and another interface. Mobile devices are assets. They belong in the same record as your assets.

To see mobile devices sitting in the same inventory as servers, workstations and Macs, book a demo.

Related reading

Other posts covering the same ground.

  • The hidden cost of a software-only mindset

    Cloud and SaaS dominate the budget conversation, but every workload still lands on a physical machine. When hardware visibility drifts, security, finance and IT all start working from numbers nobody trusts.

    • ITAM
    • Security
    6 min
  • Is Apple Set to Dominate the Enterprise?

    Written in 2016, when IBM had just started replacing Windows PCs with Macs at scale and Android fragmentation was making broad mobile support expensive. The argument holds up better than the prediction.

    • ITAM
    • Security
    5 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.