Android MDM Solutions: A Practical Guide for Teams Managing Devices They May Not Own

Independent guide to Android MDM solutions in 2026. Six options on real published pricing, the three Android Enterprise enrollment modes, and why device ownership decides this more than fleet size.

Sarah Mitchell Sarah Mitchell • • 24 min read

TL;DR

  • The question that decides everything: who owns the device. Android management splits on ownership rather than on fleet size, and that is what makes it different from managing Macs.
  • Three modes, not one: work profile for personal devices, fully managed for company-owned, and dedicated for single-purpose hardware. Pick the mode before the vendor.
  • You may already own the tooling twice: Google endpoint management is included with essentially every Workspace edition, and Intune Plan 1 capability comes with Microsoft 365 E3 and E5.
  • Zero-touch is a purchasing decision: devices must be bought through a zero-touch reseller to enroll automatically. A phone bought in a shop cannot be added to it later.
  • Published prices: Scalefusion from $2 per device, Hexnode from $2.20, NinjaOne $1.50 to $3.75 depending on volume. Esper does not publish.
  • The thing nobody warns you about: Android is many vendors' hardware, so update behaviour and management depth vary by manufacturer in ways the console will not show you.

The Question That Is Not About Software

A logistics company has 400 Android devices. Roughly 250 are handheld scanners that live in warehouses and never leave. About 90 are phones issued to drivers. The remaining 60 belong to office staff who use their own phones for email and expect nobody to touch their photos.

Those are three completely different management problems and one of them is not really a fleet at all.

The scanners need to boot into a single application and resist being used for anything else. The driver phones need to be locked down, tracked and recoverable. The office phones need a boundary, not control, because the company does not own them and should not be able to wipe somebody's holiday pictures.

Any platform on this page can do all three. What varies is how much friction each one introduces, and the mistake that costs the most is treating the 400 as one problem because they appear in one console.

So the first decision is not which Android MDM. It is how many of these situations you actually have, because the answer is almost never one.

What Android Enterprise Is, and Why It Comes First

Every platform below depends on it, and it is the part most comparisons skip.

Free Weekly Briefing Stay ahead of what's changing in HR and people ops.

Join 4,200+ leaders getting practical insights every week — no fluff, just signal.

Join Free →

Android Enterprise is Google's management framework, and it plays the same structural role for Android that Apple Business plays for Apple hardware. Platforms do not invent management capability. They expose what Google provides, which is why the feature lists look so similar.

It defines three enrollment modes, and these are the vocabulary the rest of this page uses.

Work profile. The device belongs to the person. Android creates a separate, encrypted container for work applications and data, visually distinct in the launcher. You manage the container and have no visibility into or control over the personal side. You can remove the work profile and nothing personal is touched.

Fully managed. The device belongs to the company. You control the whole thing: applications, settings, restrictions, updates, wipe. The user has no expectation of privacy on it because it is not theirs.

Dedicated. A fully managed device locked to a single purpose or a small set of applications. Kiosks, scanners, point-of-sale terminals, digital signage. The user is often not an employee at all.

There is also a fully managed device with a work profile, which covers company-owned hardware where the organisation wants to allow genuine personal use with a real boundary. It is the right answer more often than it gets chosen.

The mode is not a setting you change later. It is established at enrollment, and moving between modes generally means factory resetting the device, which on a deployed fleet is the expensive kind of mistake. Decide the mode per group of devices before you choose anything else.

Zero-Touch Is a Purchasing Decision

This catches people out for exactly the same reason the equivalent Apple rule does, and it is worth stating plainly.

Zero-touch enrollment lets a company-owned Android device configure itself on first boot, with management applied before anybody can decline it. For it to work, the device must be purchased through a reseller enrolled in Google's zero-touch programme and registered to your organisation at the point of sale.

A phone bought from a high-street shop or a general online retailer cannot be added to zero-touch afterwards. You can enroll it by hand, and that enrollment is one a determined user could remove, which puts it in a weaker category than the rest of your fleet.

Audit how your organisation actually buys devices before choosing a platform, because this is procedural rather than technical and no platform can work around it. The usual culprit is the replacement purchase: a scanner breaks, a site manager buys a handset locally to keep the shift running, and that device sits permanently outside zero-touch. One is an annoyance. A pattern of them creates a second tier your enrollment numbers cannot explain.

Choosing the Enrollment Mode, Concretely

This page tells you several times to decide the mode before anything else, so here is how. Work through it per group of devices rather than for the fleet as a whole, because most organisations need more than one answer.

Start with one question: who bought the device? If the employee bought it, you are in work profile territory and the rest of the decision is largely made for you. If the company bought it, continue.

Then ask whether the person is expected to use it personally. A company phone that somebody carries everywhere and uses for their own messaging is better served by a fully managed device with a work profile than by locking the whole thing down. You keep control of the company side and they keep a genuine boundary, which removes an entire category of complaint.

Then ask whether the device has one job. If it exists to run a single application, and the person holding it is often not an employee, that is a dedicated device regardless of how it was bought. A scanner is infrastructure, not a tool somebody was issued.

If the device is And personal use is The mode is Changing it later means
Employee-owned The whole point Work profile Removing the profile, nothing personal lost
Company-owned, general purpose Expected and reasonable Fully managed with work profile Factory reset
Company-owned, general purpose Not expected Fully managed Factory reset
Company-owned, single application Not applicable Dedicated Factory reset

The fourth column is the reason this decision comes first. Only one row is cheap to change, and it is the row where you have the least control anyway. Everything else means collecting hardware that is currently doing a job, wiping it and redeploying it.

Write the decision down somewhere the next person will find it. The common failure is not a bad decision, it is an undocumented one, where somebody enrolling a later batch picks a different mode because nothing told them otherwise, and the fleet quietly splits into two management realities.

When You Don't Need a Dedicated Android MDM

When what you already pay for covers it

Check this before anything else, because two of the largest software vendors in the world may already have handed you Android management.

Google endpoint management is included across essentially every Google Workspace edition, including Business Starter, Standard and Plus, Enterprise Standard and Plus, Frontline, Essentials and Cloud Identity. Basic mobile management is applied automatically with no user setup, covering foundational protections. Advanced mobile management asks users to install a management app and adds remote wipe, stronger password enforcement, Android work profiles and more.

Separately, Intune Plan 1 capability is included with Microsoft 365 E3 and E5, and it manages Android alongside Windows, macOS and iOS.

If you hold either suite, establish exactly what the entitlement covers before buying anything. Teams regularly purchase Android management they were already paying for.

When it is genuinely BYOD and small

Under about twenty personal phones used for email and calendar, a work profile managed through whichever suite you already own is usually sufficient. The requirement is a boundary rather than control, and the boundary is the part Android provides rather than the part a vendor adds.

When friction starts showing

The signal is usually application deployment. When getting a new version of an internal app onto 200 devices involves somebody walking around with a cable, or asking users to sideload something, the gap has become a recurring cost.

The second signal is devices that come back wiped or locked and nobody can recover them, which on company-owned hardware is a direct loss.

The edge case that forces it

Dedicated devices. Kiosks, scanners and single-purpose terminals are where general-purpose tooling struggles most, and where specialists earn their place. If a device needs to boot into one application, survive being handed to the public, and recover itself without a visit, that requirement alone justifies looking past whatever you already own.

Five Questions Teams Ask at 11pm

"Can I wipe this phone?" Only the work profile, if the device is personally owned. That is the design rather than a limitation, and it is the thing to explain to leadership before somebody promises an auditor otherwise.

"Why will this device not update?" Because Android update behaviour is set by the hardware manufacturer, not by Google and not by your MDM. Two devices on the same platform from different vendors will have different update windows and different support lifespans, and your console will show you compliance without explaining the cause.

"Why can I not enroll this one automatically?" Because of where it was bought. Zero-touch is decided at purchase and cannot be applied retrospectively.

"What happens when somebody leaves?" On a work profile, you remove the profile and the work data goes with it, leaving the personal device intact. On a fully managed device you wipe it, and then you need the device back, which is a logistics problem rather than a management one.

"Who is going to run this?" The same question that decides every device management purchase. Dedicated-device fleets in particular tend to need somebody who will maintain application configurations rather than somebody who sets it up once.

The Three Kinds of Android MDM

Suites you may already own

Microsoft Intune and Google endpoint management. Both manage Android as one platform among several, both are already paid for by a large share of organisations, and both are the correct starting point if the entitlement exists.

Right when: Android is one platform among several, and the requirements are mainstream.

Fails when: dedicated devices, rugged hardware, or anything where a single-purpose configuration is the point.

Cross-platform suites you buy

Hexnode, Scalefusion, NinjaOne, ManageEngine. One console for Android alongside Windows, Apple and sometimes more, bought on their own merits rather than bundled.

Right when: you do not hold Microsoft 365 or Workspace at the relevant tier, or the bundled option has a specific gap.

Fails when: the entitlement you already hold would have done the job, which is the most common and most avoidable outcome.

Dedicated-device specialists

Esper and the kiosk-focused capabilities inside Scalefusion. Built for fleets where devices run one application, are often not held by employees, and must recover without a human.

Right when: scanners, kiosks, signage, point-of-sale, or anything where the device is infrastructure rather than a personal tool.

Fails when: the fleet is mostly ordinary phones, where you are paying for provisioning depth you will not use.

Kind Options Right when
Already owned Microsoft Intune, Google endpoint management Mainstream phones, entitlement exists
Bought cross-platform Hexnode, Scalefusion, NinjaOne, ManageEngine No entitlement, or a specific gap
Dedicated specialists Esper, Scalefusion kiosk capability Scanners, kiosks, single-purpose hardware

How to Choose: Five Questions Before You Talk to Any Vendor

Split the fleet by ownership and purpose first. How many personal, how many company-owned general purpose, how many dedicated. Three numbers. Everything else follows from them, and almost nobody writes them down.

Check both entitlements. Google Workspace edition and Microsoft 365 licence. Establish exactly what each already includes for Android before evaluating anything you would pay for.

Decide the enrollment mode per group. Before procurement, because changing mode later means factory resets across deployed hardware.

Audit how devices are actually bought. Including the emergency replacements nobody logs, because zero-touch depends entirely on the purchase channel.

List your hardware manufacturers. Then ask each candidate platform what it supports specifically on those. Android management depth is not uniform across OEMs, and a generic answer is not an answer.

Six Options Worth Knowing

Pricing is what each vendor published on its own site, checked on 3 October 2026. Where a vendor does not publish a figure that can be attributed to a plan, this says so rather than estimating.

Google endpoint management

Best for: organisations already on Google Workspace with mainstream Android phones.

Why teams choose it: it is included rather than bought. Basic mobile management applies automatically with no user setup across essentially every Workspace edition, and advanced mobile management adds remote wipe, stronger password policy and work profile support once users install the management app.

Where it struggles: it is device management as a feature of a productivity suite rather than a dedicated platform, so dedicated-device and kiosk scenarios are not its ground. Advanced capabilities vary by edition, so confirm against your own before planning around them.

Pricing: included with Workspace editions. Basic mobile management carries no additional cost.

Microsoft Intune

Best for: organisations holding Microsoft 365 E3 or E5 with a mixed estate.

Why teams choose it: the capability is already paid for, it covers Android alongside Windows, macOS and iOS in one console, and device compliance ties natively into conditional access through Entra ID so a non-compliant Android device can be blocked from resources without an integration in between.

Where it struggles: dedicated and rugged devices, where specialists are meaningfully better. The administrative surface is also demanding, which is a fair complaint at any scale.

Pricing: Plan 1 capability included with Microsoft 365 E3 and E5. Plan 2 available separately.

Scalefusion

Best for: mixed fleets that include dedicated, kiosk or rugged Android devices.

Why teams choose it: genuinely broad device-type coverage, which is the thing general-purpose suites handle most awkwardly. For a fleet that is half phones and half scanners, it covers both without a second tool, and it publishes its rate card.

Where it struggles: enterprise identity integration is less native than Microsoft's, so conditional access comes through configuration rather than by default.

Pricing: published per-device, starting at $2 per device per month on annual billing, with higher tiers published on the same page.

Hexnode

Best for: teams wanting Android, Apple and Windows from one console with readable pricing.

Why teams choose it: a published rate card makes budgeting possible without a sales cycle, and the cross-platform coverage is real rather than nominal. For an evenly mixed estate, one adequate tool often beats two excellent ones and a reconciliation problem between them.

Where it struggles: it is a generalist, so the deepest Android-specific provisioning scenarios are not where it is strongest.

Pricing: on annual billing, $2.20 per device per month for Pro, $3.20 for Enterprise, $4.70 for Ultimate and $5.40 for Ultra. Monthly billing is $2.40, $3.60, $5.20 and $6.00.

NinjaOne

Best for: large endpoint counts where management and monitoring belong in one tool.

Why teams choose it: it combines device management with monitoring and patching, which suits teams operating reactively as well as administratively, and it states its pricing shape openly.

Where it struggles: its pricing curve runs against the usual assumption, which catches small teams out, and dedicated Android hardware is not its focus.

Pricing: per-device, and it gets cheaper with scale in the opposite direction to most expectations. NinjaOne states it starts as low as $1.50 per device per month at 10,000 endpoints, rising to $3.75 at 50 or fewer endpoints. A small team pays the higher end.

Esper

Best for: dedicated-device fleets at scale, particularly where the device is a product rather than a tool.

Why teams choose it: built specifically for single-purpose Android hardware, with provisioning and application release management aimed at teams shipping software to devices rather than managing employees. For kiosks, scanners and point-of-sale estates it addresses problems general suites treat as edge cases.

Where it struggles: it is the wrong shape for ordinary employee phones, and it does not publish pricing, so budgeting requires a conversation.

Pricing: not published.

What Each One Published

Platform Published price Dedicated devices Already owned by many Conditional access
Google endpoint management Included with Workspace No Yes, via Workspace Through Google identity
Microsoft Intune Included with E3 and E5 Weak Yes, via Microsoft 365 Native via Entra ID
NinjaOne $1.50 to $3.75 per device No No Through integration
Scalefusion From $2.00 per device Strong No Through configuration
Hexnode $2.20 to $5.40 per device Moderate No Through integration
Esper Not published Strongest No Not its focus

Read the fourth column first. Two of these six may already be paid for, and that reframes every price in the second column. The question for those rows is not whether something cheaper exists, but whether anything is better by enough to justify a line item you do not currently have.

The Decision Table

Situation Scale Setup Primary Pain Recommended Starting Point
Personal phones, email and calendar only Under 50 BYOD Boundary, not control Work profile via Workspace or Intune
Company phones, mainstream hardware 50 to 500 Fully managed App deployment and recovery Intune if you hold E3 or E5
Scanners or kiosks, single application 100 plus Dedicated Devices that must self-recover Scalefusion or Esper
Mixed phones and rugged devices 100 to 500 Both Two tools for one fleet Scalefusion
Android alongside Apple and Windows Any Mixed One console, readable price Hexnode
Very large endpoint count 1,000 plus Any Management and monitoring split NinjaOne
Devices not coming back from leavers Any Company-owned Physical recovery, not configuration Not an MDM problem

The first two rows cover most organisations, and both of them start with checking an entitlement rather than buying something. The third row is where the money genuinely has to be spent, because it is the scenario the bundled options were not built for.

Where Teams Get Android Management Wrong

Treating one console as one problem. Personal phones, company phones and scanners are three management problems. Choosing a platform for the largest group and applying it to all three produces friction in two of them.

Buying what you already own. Google endpoint management is included with essentially every Workspace edition and Intune capability comes with E3 and E5. Purchasing Android management without checking both is a real recurring cost paid for nothing, and it takes ten minutes to rule out.

Choosing the enrollment mode by default. Enrolling personally owned devices as fully managed because it was easier at the time creates a privacy problem and an industrial relations one, and unwinding it means factory resets. Decide the mode deliberately, per group.

Promising control over devices you do not own. On a work profile you can manage the container and nothing else. If somebody has told an auditor the company can wipe every phone, that statement is wrong for the BYOD portion and it is better corrected early.

Assuming update behaviour is uniform. It is set by the hardware manufacturer. A fleet spanning three OEMs has three update realities and three support lifespans, and this is invisible in a feature comparison while being very visible in a compliance report.

Forgetting the purchase channel. Zero-touch depends entirely on buying through an enrolled reseller. The emergency local purchase is the usual cause of a permanent second tier in the fleet.

Budgeting from the lowest published figure. Most per-device pricing improves with scale. At least one vendor here publishes the opposite shape. Model your own count against each vendor's own curve.

What None of Them Will Tell You

Every platform here knows about devices it manages, which sounds complete until you need the other list.

None can tell you about a device that was never enrolled, because none has seen it. None can tell you where a handset physically is, only where it last checked in from. None can tell you whether the phone issued to a driver who left in March came back, only that it stopped reporting. And none can tell you what you own, which is the question an auditor actually asks.

This bites harder on Android than on Apple, for a simple reason. Android fleets tend to be larger, cheaper per unit and more widely distributed, which means devices go missing more often and each loss is individually too small to chase. A hundred unaccounted scanners is a real number on a balance sheet assembled from a hundred decisions nobody escalated.

That is an asset management gap rather than a shortcoming of any product here. The fix is a register alongside the MDM rather than a different MDM. Platforms built for that side of the problem, such as RemoAsset, handle procurement, delivery and physical retrieval, with enrollment happening on delivery. RemoAsset is not an MDM and does not replace anything on this list.

The diagnostic is one question. Ask what went wrong last quarter. A device that was misconfigured, unpatched or running the wrong application version is an MDM problem and this comparison is the right one. A device nobody can account for is not.

What to Establish Before You Commit

Three numbers: personal, company-owned general purpose, dedicated. The split that determines everything, and the one least often written down.

Both entitlements, confirmed. Your Google Workspace edition and your Microsoft 365 licence, and precisely what each includes for Android.

The enrollment mode for each group. Decided before procurement, because changing it later means factory resets.

Your list of hardware manufacturers. Then each candidate platform's specific support on those, not a general claim.

How devices are actually purchased. Including emergency replacements, because zero-touch lives or dies on the channel.

What you will tell people about privacy on their own devices. Written down before enrollment, not after the first complaint.

Your device count on each vendor's own volume curve. Particularly where that curve runs the unusual way.

None of those seven requires a vendor conversation. They are answerable inside your own organisation in about a day, and together they eliminate most of this page before anybody books a call.

What Getting This Wrong Costs

The first cost is paying for what you already hold. A new Android management licence alongside a Workspace or Microsoft 365 entitlement that already covered it, running quietly until somebody notices at renewal.

The second is the enrollment mode mistake, and it is the most expensive one specific to Android. Devices enrolled in the wrong mode must be factory reset to change, which on deployed hardware means collecting it, wiping it and redeploying it. On 300 scanners across eleven sites that is not a configuration change, it is a programme, and it is entirely avoidable by deciding the mode before procurement rather than during rollout.

The third is a privacy dispute, which costs trust rather than money. Enrolling personally owned phones as fully managed, then having to explain what the company can and cannot see, damages something that is slow to rebuild. Work profiles exist precisely to avoid this, and the explanation is far easier before enrollment than after.

The fourth lands at the audit. Android fleets accumulate exceptions faster than Apple fleets because the devices are cheaper and the purchases are more distributed, so enrollment coverage drifts quietly. A year later the compliance evidence has a hole in it, found by somebody who is not on your side. Track coverage to a number rather than to an impression.

When You Are Ready to Decide

Split the fleet into three numbers first: personal, company-owned general purpose, dedicated. If one of those is zero, the comparison gets considerably simpler. If none of them is, you are probably looking at two tools and should decide that deliberately.

Then check both entitlements. Google endpoint management comes with essentially every Workspace edition and Intune capability comes with Microsoft 365 E3 and E5, so for mainstream phones the answer may already be installed. Establishing what each covers costs a conversation rather than a budget.

Then decide the enrollment mode per group, before procurement, because this is the one decision on this page that is expensive to reverse.

Then trial on real devices in the real environment. A scanner in a warehouse with poor connectivity behaves differently from the same device on an office network, and dedicated-device platforms are precisely where that difference shows. Push an application update, lock a device to one app, and try to recover one that has been left in a bad state without sending somebody to it.

And give the trial to whoever will maintain it, not to whoever is most curious. On dedicated fleets that person is maintaining application configurations continuously rather than setting something up once, which is a different job from the one most evaluations test for.

One last point that applies to Android more than to any other platform. The hardware is not one thing, and neither is the fleet. An organisation managing Apple devices is dealing with one manufacturer, one update schedule and one set of management capabilities. An organisation managing Android is dealing with however many manufacturers it has bought from, each with its own update behaviour and support lifespan, and with devices that may be phones, tablets, scanners or terminals. That variety is the actual difficulty of Android management, and no console removes it. What a good platform does is make the variety visible, so the exceptions are things you decided rather than things you discover.


Frequently Asked Questions

What is the best Android MDM solution?

It depends on who owns the devices and what they are for, which is the split that matters more on Android than fleet size does. For mainstream company phones, start by checking whether you already hold the capability, because Intune Plan 1 comes with Microsoft 365 E3 and E5 and Google endpoint management is included across essentially every Workspace edition. For personally owned phones, a work profile managed through whichever suite you already own is usually sufficient, since the requirement is a boundary rather than control. For scanners, kiosks and single-purpose hardware, the bundled options are weakest and a specialist like Esper or the kiosk capability in Scalefusion earns its cost. Split the fleet by ownership and purpose before shortlisting anything.

Does Google Workspace include mobile device management?

Yes, and a surprising number of organisations do not realise it. Google endpoint management is included across essentially every Workspace edition, including Business Starter, Standard and Plus, Enterprise Standard and Plus, Frontline, Essentials and Cloud Identity. Basic mobile management is applied automatically with no user setup and covers foundational protections, while advanced mobile management asks users to install a management app and adds capabilities including remote wipe, stronger password enforcement and Android work profiles. Specific feature availability varies by edition, so confirm against the one you hold rather than planning from a general description, but the starting point is that you may already have what you were about to buy.

What is the difference between work profile and fully managed?

Ownership, and it determines what you are permitted to do rather than merely what you are able to do. A work profile is for a device the person owns: Android creates a separate encrypted container for work applications and data, you manage only that container, and you have no visibility into or control over the personal side, so removing the work profile leaves everything personal untouched. Fully managed is for company-owned hardware, where you control applications, settings, restrictions, updates and wipe across the whole device. There is also a fully managed device with a work profile, for company hardware where you want to permit genuine personal use with a real boundary, and it is the right answer more often than it gets chosen.

Can I switch a device from work profile to fully managed later?

Generally not without a factory reset, and this is the most expensive mistake specific to Android management. The enrollment mode is established when the device is enrolled rather than configured afterwards, so changing it means wiping the device and starting again. On a handful of phones that is an afternoon. On several hundred deployed scanners across multiple sites it means collecting, wiping and redeploying hardware that is currently doing a job, which is a programme rather than a change. Decide the mode for each group of devices before procurement rather than during rollout, and write the decision down so the next person enrolling a batch does not quietly pick something different.

What is Android zero-touch enrollment?

It is the mechanism that lets a company-owned Android device configure itself on first boot, with management applied before anybody has a chance to decline it, and it is the Android equivalent of the automated enrollment Apple provides. The catch is that it is decided at purchase: the device must be bought through a reseller enrolled in Google's zero-touch programme and registered to your organisation at the point of sale. A handset bought from a high-street shop or a general online retailer cannot be added afterwards, so you are left enrolling it by hand into a weaker state a determined user could undo. Audit how your organisation actually buys devices before choosing a platform, because no software can work around the purchase channel.

Why do some Android devices not get updates?

Because update behaviour is determined by the hardware manufacturer rather than by Google or by your management platform, and this is the most consequential difference between managing Android and managing Apple hardware. Two devices enrolled in the same platform, running the same policies, from different manufacturers, will have different update windows and different support lifespans. Your console will report the resulting compliance gap accurately without explaining the cause, which leads teams to look for a configuration fault that does not exist. The practical response is to treat the manufacturer list as part of the specification, ask each candidate platform what it supports specifically on your hardware, and factor OEM support lifespans into refresh planning rather than discovering them at an audit.

Do I need a separate tool for kiosks and scanners?

Often yes, and this is the clearest case on this page for spending money rather than using what you already hold. Dedicated devices are the scenario the bundled suites were not built for: a device that must boot into a single application, survive being handed to members of the public, and recover itself without somebody travelling to it. Microsoft Intune and Google endpoint management both handle mainstream phones well and treat dedicated hardware as an edge case, while Esper and the kiosk capability in Scalefusion are built around it. If dedicated devices are a small minority of your fleet, living with the compromise is reasonable. If they are most of it, a specialist is the cheaper answer once you count the support visits you stop making.

Will an MDM tell me where our Android devices are?

No, and this matters more on Android than elsewhere because of how these fleets are shaped. Every platform here reports where a device last checked in from, which is not the same as knowing where it physically is, whether the handset issued to a driver who left in March came back, or what hardware you own but never enrolled. Android fleets tend to be larger, cheaper per unit and more widely distributed than Apple ones, so devices go missing more often and each individual loss is too small for anybody to chase. That is an asset management gap rather than a shortcoming of any platform, and the fix is a register alongside the MDM rather than a different MDM. Ask what actually went wrong last quarter: a misconfigured device is an MDM problem, and a device nobody can account for is not.

Share on X Share on LinkedIn

What to do next?

Explore More Articles

Dig deeper into HR Ops strategy, tools, and workflows built for real teams.

Browse the blog →
Join the HROpsLab Community

Connect with People Ops practitioners sharing real workflows, tools, and challenges.

Join now →