How Do I Manage Company Mobile Phones? A Guide for UK Businesses
Manage company mobiles through a Mobile Device Management (MDM) platform — Microsoft Intune is the standard for businesses already on Microsoft 365. MDM enforces encryption, remotely wipes lost devices, pushes security policy, and walls personal data off from corporate data.
Quick answer
Manage company mobiles through a Mobile Device Management (MDM) platform — Microsoft Intune is the standard for businesses already on Microsoft 365. MDM enforces encryption, remotely wipes lost devices, pushes security policy, and walls personal data off from corporate data. AMVIA runs this for you: one provider, security-first, Microsoft-certified.
Key Points
What you need to know.
The Short Answer
5G outdoor coverage is available from at least one operator at 97% of UK premises (Ofcom 2025).
For UK Businesses
5G now accounts for 28% of UK mobile connections, up 9 percentage points year-on-year.
Cost Considerations
Enhanced mobile connectivity could unlock £230 billion in economic value for the UK by 2035.
Next Steps
69% of UK business executives say 5G is the best investment they can make in the next 12 months.
Quick Comparison
| Feature | Option A | Option B |
|---|
A lost phone is not a lost phone. It is a lost mailbox, a lost set of files, and a lost door into your tenant. If you hand staff a handset without a way to enforce a passcode, encrypt the device, and wipe it on demand, you have handed out unmanaged access to your business. This guide explains, step by step, how to manage company mobiles properly — the controls that matter, what AMVIA actually recommends, and where mobile fits into your wider business mobile management strategy.
What does "managing company mobiles" actually mean?
Managing company mobiles means controlling the security, configuration, and data on every handset that touches your business — whether you bought it or your employee did. It covers enrolment, policy enforcement, app distribution, and the ability to remove corporate data without touching personal photos or messages.
The practical building blocks are:
- Enrolment — every device registered to a central console before it gets corporate email.
- Policy — enforced passcode, encryption, and OS-update rules applied automatically.
- App management — push approved apps; block or sandbox the rest.
- Conditional access — only compliant, enrolled devices reach Microsoft 365.
- Wipe — selective removal of corporate data on loss, theft, or a leaver.
Without these, you are trusting each employee to secure your data on a device you cannot see. The UK's National Cyber Security Centre device security guidance is blunt about this: mobile devices need the same baseline controls as laptops, because they hold the same access.
How do I manage company mobiles with Microsoft Intune?
If your business runs Microsoft 365, Microsoft Intune is the answer to managing company mobiles — it is the MDM engine built into the platform you already pay for. You enrol each handset, assign compliance and configuration policies, and Intune enforces them on iOS and Android automatically. Non-compliant devices lose access to corporate data.
Intune is included in Microsoft 365 Business Premium at £16.90 per user per month (ex VAT, annual), per Microsoft 365 UK pricing — so most managed businesses already own the licence without realising it. The set-up steps are consistent:
1. Confirm every user has a Business Premium (or equivalent) licence with Intune entitlement. 2. Define a compliance policy: encryption on, passcode required, minimum OS version, jailbreak/root blocked. 3. Define a configuration profile: Wi-Fi, email, and VPN settings pushed automatically. 4. Turn on conditional access so only compliant devices reach Exchange, Teams, and SharePoint. 5. Enrol devices — company-owned through Apple Business Manager / Android Enterprise, BYOD through the Company Portal app.
AMVIA configures Intune end to end and monitors compliance for you, rather than leaving you a console and a manual. See our Microsoft Intune mobile management service for how that day-to-day runs, and the broader Microsoft Intune deployment for laptops and desktops.
Company-owned vs BYOD: which model should I choose?
The right model depends on who owns the device and how much control you need. Company-owned gives you full management of the whole handset; Bring Your Own Device (BYOD) keeps costs down but limits you to managing only the corporate apps and data, not the personal side. Most UK SMEs run a mix.
| Factor | Company-owned (COBO/COPE) | BYOD |
|---|---|---|
| Who buys the device | The business | The employee |
| Control level | Full device management | Corporate apps/data only |
| Upfront cost | Higher (hardware + contract) | Lower (stipend only) |
| Privacy boundary | Employer-controlled | Personal data ring-fenced |
| Best for | Field staff, regulated data | Office staff, cost-sensitive teams |
| Wipe scope | Full or selective | Selective only |
Whichever you pick, the security model has to be deliberate. BYOD in particular needs a clear data boundary so you can remove corporate access without wiping someone's family photos — covered in our BYOD security guidance. For mixed fleets, get the policy written down before the first device is enrolled.
How do I secure a lost or stolen company phone?
A managed phone is recoverable; an unmanaged one is a breach. With MDM in place you can locate, lock, and wipe a lost handset from a central console in minutes — either a full wipe of a company-owned device or a selective wipe that strips corporate data and leaves personal content alone.
This matters because mobile is now a primary target, not an afterthought. Only 40% of UK businesses have two-factor authentication enabled (DSIT 2025), which means a stolen, unwiped phone is often a direct route into email and files. The controls that close that gap:
- Remote lock and locate the moment a device is reported missing.
- Selective wipe to remove corporate mail, Teams, and files without touching personal data.
- Conditional access revocation so the device cannot reconnect even if recovered by the wrong person.
- Automatic encryption so data at rest is unreadable regardless.
AMVIA's remote wipe and device security service makes this a one-call action for your team. Pair it with broader mobile security hardening so the handset is locked down before it is ever lost.
Can I manage company mobiles across different networks?
Yes — MDM is network-agnostic. Microsoft Intune manages devices regardless of whether they sit on O2, EE, Vodafone, or Three, because it controls the operating system and apps, not the SIM. You can run a multi-network fleet and enforce identical security policy on every handset.
This is useful when coverage, contract timing, or acquired businesses leave you on several networks at once. The management layer never changes — one console, one policy set, every device. AMVIA also consolidates billing across all networks under a single account, so a mixed fleet does not mean a mixed admin headache.
What happens to company data when an employee leaves?
When someone leaves, MDM lets you perform a selective wipe — removing corporate email, apps, and files from the device while leaving personal data untouched. It works on both company-owned and BYOD handsets, and it happens centrally without needing the device back in the office.
This is the offboarding control most businesses miss. Microsoft 365 has over 400 million paid commercial seats (Microsoft FY2025), and the selective-wipe capability is built into Business Premium at no extra cost — yet many firms still rely on asking a leaver to "delete the email app". Make selective wipe a step in your standard leaver checklist, triggered the moment access is revoked.
What AMVIA recommends
For most UK SMEs: standardise on Microsoft Intune, enrol every device, enforce a single compliance baseline, and turn on conditional access so only managed devices reach your data. Choose company-owned for field and regulated-data staff, BYOD with a strict data boundary for everyone else. Then make remote wipe a rehearsed, one-call action — not a thing you figure out under pressure.
The point of managing company mobiles is not control for its own sake. It is making sure that the worst day — a phone left in a taxi — is a five-minute task, not a notifiable data breach. That is the difference between a fleet you manage and devices you merely own.
Frequently Asked Questions
The most reliable way to manage company mobiles is a Mobile Device Management platform, with Microsoft Intune the default for any business on Microsoft 365. It enrols every device, enforces encryption and passcodes, controls which apps can run, and lets you wipe corporate data remotely. It turns a fleet of unknown handsets into managed, policy-compliant endpoints.
Yes. Risk scales with data, not device count. Even one unmanaged phone holding business email is a route into your tenant if it is lost or stolen. MDM enforces a passcode, encrypts the device, and lets you wipe it remotely — controls that matter just as much for five phones as for five hundred, and that Intune applies the same way at any scale.
Microsoft Intune is included in Microsoft 365 Business Premium, listed at £16.90 per user per month ex VAT on annual billing on Microsoft's UK pricing. Many businesses already hold this licence without using the mobile-management capability inside it. If your staff are on Business Premium, you can begin enrolling and securing company mobiles without buying anything new.
Yes. BYOD enrolment in Intune manages only the corporate apps and data, never the personal side of the device. You can enforce policy on work email and files, and selectively wipe them when needed, while personal photos, messages, and apps stay private and untouched. A clear, written data boundary makes this acceptable to staff and defensible for the business.
With MDM already in place, a remote lock or wipe takes minutes from a central console. You do not need the device back or the employee's cooperation — you trigger the action, and corporate data is removed or the handset is locked. This is why enrolment matters before loss happens: you cannot wipe a device that was never managed.
Related Questions
Business Mobile Management
AMVIA's managed mobile service — MDM deployment, policy management, and business mobile plans for UK businesses.
Microsoft 365 Security
Intune device management is included in Microsoft 365 Business Premium — the recommended platform for managing company mobiles.
Endpoint Security Service
Extend endpoint protection to mobile devices as part of a complete managed security stack.
Consolidate your mobile fleet → Get a Mobiles Quote