← All controls

20 Basic mobile device management

draft

The free floor of device control: every phone that syncs work data is enrolled, must carry a screen lock, refuses to sync when rooted or jailbroken, and can have its work account wiped from the console the day its owner leaves. All of it ships in every edition — basic management needs no agent on iOS and only the Device Policy app on Android. Device-trust CAA (29 Device-trust CAA via MDM) builds posture gating on top of the same screens; this control is the layer beneath it that every tenant can afford, and it is what makes the wipe step of the leaver runbook (21 Leaver offboarding runbook) possible.

Caveats

Setup steps

  1. Screenshot pending capture — follow the steps below.

    Devices › Mobile & endpoints › Settings › Universal

    Mobile management
    Basic (Advanced for company-owned devices)
  2. Devices › Mobile & endpoints › Settings › Universal

    Security > Compromised devices: Block rooted/jailbroken devices from syncing = On

  3. Devices › Mobile & endpoints › Settings › Universal

    Security > Device approvals
    Require admin approval

Ongoing maintenance

How to verify

  1. Enrol a test phone with no screen lock — sync must be refused until a passcode is set. The refusal is the control working; observe it on the device, not in the console.

  2. Export the inventory and confirm every syncing device is managed and approved.

    gam print mobile fields deviceid,email,model,status,lastsync

draft v0.1.0 Prevent policy #25 · #7 ↗