Intune, mobile device management, and a device refresh schedule are implementation details. The decision underneath them is ownership: whether a device is company property with company control, a personal device the company partly manages, or something in between that no one has actually agreed to.
The decision to enable
Decide, role by role, whether a device is company-owned, personally owned with managed access, or unmanaged—and what that implies for support, security, and offboarding.
01
Name the ownership model before selecting a management tool
Company-owned devices, personal devices enrolled in management, and personal devices with no management at all carry different rights and different obligations. Mobile device management software enforces whichever model leadership has chosen; it does not choose the model on its own.
Which roles use company-owned devices today
Which roles use personal devices for work without any agreement
What access those personal devices currently have to company data
02
Match the lifecycle to how the device is actually used
A three-year refresh cycle that suits a standard office laptop may not suit a shared warehouse device or a field technician’s phone. Base replacement timing on real failure and support patterns for each device category, not one company-wide number chosen for simplicity.
03
Decide what happens at offboarding before day one
Removing company data from a personal device, or recovering a company-owned one, is far easier when the expectation was set at onboarding than when it is improvised during a resignation. Confirm what can technically be wiped, what cannot, and what the employee was told to expect in writing.
Whether company data can be selectively removed from a personal device
What happens to personal data on a company-owned device at exit
Who performs the removal, and how it is confirmed complete
04
Decide who pays for what, in writing
Device cost, repair, loss, and replacement responsibilities are easy to leave unspoken until a lost phone or a cracked screen forces the question. A short written policy prevents that conversation from happening for the first time during a dispute.
Decision frame
What leadership should be able to verify.
These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.
CriterionUseful signalLeadership question
OwnershipEach role’s device model—company, personal-managed, or unmanaged—is named.Which roles are using personal devices with no agreement in place?
Lifecycle fitReplacement timing matches real usage and failure patterns by category.Does the refresh schedule match how this device is actually used?
OffboardingData removal or recovery steps are defined before someone leaves.What would actually happen to company data if this person left today?
Cost and responsibilityRepair, loss, and replacement costs are assigned in writing.Who is responsible if this device is lost, damaged, or stolen?
Practical scenarios
The same discipline applied to different decisions.
Staff have been using personal phones for company email for years
Situation: No formal policy exists, but personal phones across the team already access company email and files through built-in mail apps.
Useful response: Decide explicitly whether to formalize managed access, restrict it to a safer minimum, or provide company devices instead—rather than leaving an unmanaged arrangement in place because it has not caused a visible problem yet.
Boundary: This guide does not select or configure a specific mobile device management product.
A shared field tablet outlives its expected refresh cycle
Situation: A device used by rotating field staff has been patched and repaired well past the standard replacement age used for office laptops.
Useful response: Assess this device category on its own support cost and failure risk rather than the office-equipment schedule, and decide the replacement point on that evidence.
Boundary: This guide does not estimate specific hardware costs or vendor pricing.