Skip to content
Cyber Risk Calculator

Business mobile buying guide

Business mobiles and device management

Choose the ownership and enrolment model before choosing handsets. Device, network tariff, identity, business apps and management policy are connected decisions, but they are not the same product.

Choose company-owned or BYOD first

Company-owned devices can support broader organisational control and a consistent build. Bring your own device can reduce the number of handsets people carry, but it needs a clear privacy boundary and a supported enrolment method. A mixed model is common where most roles receive managed company equipment and a smaller group uses a work profile on a personal phone.

Available controls differ by ownership and enrolment method. Apple User Enrolment is designed for user-owned BYOD and separates organisation-provisioned accounts, settings and information from the personal account. Android Enterprise likewise distinguishes employee-owned work profiles from company-owned management. Write the intended boundary into policy before buying devices.

Sources for this section: Apple Platform Deployment — User Enrolment, Google Workspace Admin Help — device policy distinctions, Android Enterprise — Work Profile

Match devices to jobs, not status

Group users by work: standard communication, field photography, navigation, scanning, accessibility, rugged environments, long shifts or specialist apps. For each group, set a minimum rather than defaulting every user to a flagship model.

Check required apps, operating-system support policy, storage, battery routine, screen and input needs, accessibility features, repair process and protective equipment. Pilot representative devices with the real apps and accessories before approving a fleet.

Assess coverage, tariff and management separately

Test network coverage at the sites, travel routes and indoor locations that matter to each role. Then size calls, data and roaming from actual working patterns. A suitable tariff does not enrol, secure or administer the phone, and a management profile does not improve radio coverage.

Keep the device record, SIM or eSIM, telephone number, assigned user and management status connected in the asset register. That makes replacements and leaver actions less dependent on one person remembering which service belongs to which handset.

Pilot enrolment, identity and business apps

Pilot each ownership model on representative devices. Confirm enrolment, sign-in, required apps, updates, email, VPN, certificates, data sharing between work and personal areas, backup expectations and the help route for a locked-out user.

Explain what the organisation can and cannot see or remove. On Android, removing a work profile removes its local work apps and data; a factory reset is a different action. The approval process for a lost device should distinguish selective removal of business data from a whole-device reset.

Sources for this section: Google Workspace Admin Help — Android work profiles, Android Enterprise — Work Profile

Write joiner, leaver and lost-device playbooks

A joiner process should assign the device and number, apply the chosen enrolment, provide approved apps and record acceptance. A leaver process should disable identity access, remove organisational data according to the ownership model, recover company equipment and update the asset record.

For a lost or stolen device, record who can approve a lock, work-profile removal or whole-device action; how the user contacts support; and how the SIM or eSIM is handled. Test the support chain before an urgent incident. Do not write one universal “remote wipe” instruction for both personal and company-owned devices.

Sources for this section: Google Workspace Admin Help — Android work profiles, Google Workspace Admin Help — device policy distinctions

Choose the ownership and enrolment model

Start with responsibility and privacy, then confirm the controls supported by the actual platform and enrolment method.

Business mobile ownership and enrolment decision table
Estate approachGood starting fitManagement boundary to confirm
Company-owned and managedRoles needing a consistent business build, shared policy and equipment recoveryPermitted device controls, personal-use policy, enrolment method and whole-device actions
Employee-owned with work enrolmentApproved BYOD where work and personal information need a clear separationSupported devices, work-profile or User Enrolment controls, privacy notice and selective work-data removal
Mixed estateDifferent roles require different ownership while using one documented operating modelWhich roles use each route, exceptions, support boundary and separate leaver or lost-device actions

Mobile estate rollout checklist

Use a representative pilot before committing the wider estate.

  • Assign each role to company-owned, BYOD or an approved exception with a written privacy boundary.
  • Confirm required apps, minimum operating-system support, storage, battery routine, accessibility and physical protection.
  • Test network coverage at real sites and travel locations; size tariff and roaming separately from management.
  • Pilot enrolment, identity, apps, updates, VPN, certificates and data-sharing rules on representative devices.
  • Record device, SIM or eSIM, telephone number, user, ownership and management status in the asset register.
  • Write and test joiner, leaver, lost-device, replacement and support processes.
  • Name who approves selective work-data removal or whole-device action for each ownership model.
  • Review supported platforms and the estate policy before each refresh rather than assuming prior controls are unchanged.

Related services and next steps

Business mobiles and device management — common questions

Does a business SIM manage the phone?

No. The network service and the device-management enrolment are separate. A business SIM or tariff does not by itself apply apps, identity settings, security policy or a leaver process.

Can IT wipe a personal BYOD phone?

Do not assume that every enrolment method provides the same action. User-owned work enrolment is designed around separation of organisational and personal data. Confirm the precise platform controls and make the privacy and approval boundary clear in policy.

Should every employee receive the same handset?

Usually it is better to define a small range by role. Standard users, field workers and specialist or accessibility needs may justify different minimums while still keeping procurement and support manageable.

What should happen when somebody leaves?

Disable organisational identity access, remove work data using the action appropriate to that ownership model, recover company equipment, handle the SIM or eSIM and update the asset register. The steps and approver should be written before a leaver event.

Plan devices and management together

Tell SCG Solutions how many users you have, where they work, the apps they need and whether the estate is company-owned, BYOD or mixed. We can help shape a supportable shortlist and quote.

Discuss business mobiles

What do you need?

It's easy to talk to us