Security needs visibility: The defence value of ITAM
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
- ITAM
- Governance
- Security
Enrolment, platform diversity and device security were the three things that made mobile management hard. Two of them have changed shape completely, and the third answer is no longer a separate product.
Enterprise mobile management — EMM — described the people, processes, policies and technology used to manage corporate mobile devices. When this was first written it was a discipline with its own vendors, its own consoles and its own budget line.
It is not one any more, and that turns out to be the most useful thing this post can tell you. The reason mobile management was painful was rarely the devices. It was that the devices lived in a separate system from every other asset you owned, so nobody could answer a question that spanned both.
The three challenges below were the ones worth asking a vendor about then. Two have changed shape entirely. The third has quietly become the whole point.
Enrolment was, for a long time, the single biggest obstacle to managed mobility. The reason is unglamorous: if every device has to be registered by hand, one at a time, by someone typing details into a console, then the programme’s cost scales linearly with the number of handsets and it stops being viable somewhere in the low thousands.
The fix is that enrolment should never be a per-device task performed by IT. Ask for two things:
If the answer to “how do a thousand devices get enrolled” involves a person and a spreadsheet, you have found the reason the last programme stalled.
In 2016 this section argued that you needed to manage three mobile operating systems. That is no longer true. Microsoft ended support for Windows 10 Mobile in December 2019, and the corporate mobile world settled on two: iOS and Android.
Two is easier than three, but Android remains the harder half. Manufacturers ship their own builds, on their own schedules, with their own layers on top, and the population of Android versions in any large organisation is wide and long-tailed. Devices at the back of that tail stop receiving security updates long before anyone retires them.
That has a direct consequence for BYOD. If you allow personal devices, you do not get to choose the hardware, so you cannot manage the problem by standardising your way out of it. You need a management approach that treats platform variety as normal rather than exceptional, and you need to be able to see version and patch state across the whole population rather than sampling it.
This is also the point where a separate mobile console starts costing you. “Which of our devices are running an operating system that no longer receives security updates?” is a question about every device you own, not every phone you own. Answering it in two tools and joining the results by hand is how it stops getting asked.
The original security concerns were rooted and jailbroken handsets, and expensive tablets walking off site. Both are still real. Rooted Android and jailbroken iOS devices lose the platform’s own protections, are more exposed to malware, and allow side-loaded applications to add capability the platform would otherwise refuse. Shared tablets that are meant to stay in a building have a habit of not staying in it.
If those are your risks, they are fair questions to put to any vendor:
We are not going to tell you CerteroX does all of that, because that is not what it does. What it does do is manage iOS and Android alongside everything else, and give you compliance-as-code on top: Governance Policies let you define a condition once with a reusable filter builder and have it evaluated continuously against your assets, with the policy definitions exportable as JSON so they can be reviewed and version-controlled like anything else. Where you already run Microsoft Intune, CerteroX ITAM connects to it rather than competing with it.
The threat model has moved. When this was written, the worst realistic outcome of a lost handset was the data on it. Today the handset is mostly a way of reaching things that are not on it.
A phone with a mail client, a chat client and a dozen authenticated SaaS applications is a set of live sessions and OAuth grants. Wiping the device does not revoke those. Removing someone’s Microsoft 365 licence on their last day does not revoke them either — which is why the seats and the third-party grants keep working long after the leaver has gone.
That gap is closed on the identity side, not the device side. CerteroX SaaS Management syncs from Entra ID and Okta, including MFA enrolment state, discovers OAuth grants consented to third-party applications, scores each grant from 0 to 100 on data sensitivity, scope, consent and dormancy, and revokes them in one click or as a workflow action. The offboarding checklist then shows every licence a user held and whether revocation is pending, in progress or complete.
That is the modern version of “the device left the site”, and it is not a mobile management feature.
The conclusion the original post was reaching for, without quite having the language for it, is that EMM was never really a category. It was a gap.
CerteroX ITAM inventories Windows, macOS, Linux, AIX, HP-UX and Solaris through one agent and one schema, and manages iOS and Android in the same place, through the same console, against the same asset record. Ten discovery methods land in that schema, so there is no reconciliation project between the mobile picture and everything else — because there is nothing to reconcile.
Which means the questions that used to be hard are now ordinary ones. What do we own. Who has it. What is it running. Is it still supported. What can it reach.
To see mobile devices in the same asset record as laptops, servers and licences, book a demo.
Other posts covering the same ground.
Most breaches are not exotic. They start with an old machine, forgotten software or a misconfigured endpoint nobody owned. ITAM is the layer that finds them first.
Windows 10 support ended in October 2025. If you are still finishing the migration — or paying for Extended Security Updates while you do — these are the questions to settle and a readiness check to score yourself against.
Mobile device management works properly when phones and tablets sit in the same inventory as everything else you own. Here is what CerteroX ITAM does with enrolled iOS and Android devices, and why the single record matters.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.