Every phone with your email on it is a copy of your company data walking out of the building.
Most UAE businesses have thought carefully about laptops and not at all about phones, even though the phone holds the same mailbox, the same documents and the same chat history, goes everywhere, and is far more likely to be lost or stolen. Managing iPhones and iPads properly is not about controlling what people do on their own devices. It is about being able to remove company data from a device you do not own, on a day you did not plan for, without touching anything personal.

- Company dataRemovable without a full wipe
- Personal privacyGenuinely preserved on BYOD
- Same dayAccess revoked when somebody leaves
- Kiosk modeiPads locked to one purpose
Eight things that matter on a phone and do not apply to a laptop.
Two genuinely different enrolment models
A company-owned phone can be supervised and fully managed, with the organisation controlling configuration, apps and what can be done on the device. A personally owned phone should use user enrolment, which manages only the work account and the work apps and leaves the rest of the device alone. Choosing the wrong model is the most common mistake, because applying company-owned controls to a personal phone is both intrusive and, in most cases, unenforceable in practice.
Removing company data without wiping the phone
This is the single most valuable capability and the reason to do any of this. When somebody leaves, or loses a personal device, you remove the work account, the work apps and the data attached to them, and their photographs, messages and personal accounts are untouched. Without management the only options are asking politely and hoping, or a full wipe you have no right to perform on a device you do not own.
Being straight about what the employer can see
On a correctly configured personal device the organisation cannot see personal photographs, personal messages, browsing history, or what applications somebody has installed for themselves. It can see the work applications it deployed and the device model and operating system version. Saying this clearly, in writing, is what actually gets staff to enrol. The organisations that struggle with BYOD adoption are almost always the ones that never explained the boundary.
Baseline security that is genuinely enforced
A passcode requirement, encryption, a current operating system version, and the ability to lock or locate a device. These sound trivial and they are the controls that fail most often, because a personally owned phone with no passcode holding a company mailbox is a data breach waiting for a taxi. Enforcement means the work account stops working if the baseline is not met, rather than a policy document saying it should be.
Apps deployed without personal Apple Accounts
Work applications installed and configured by the organisation, licensed to the organisation, and removed when the person leaves. Nobody should be asked to install a business application using their personal account, both because the licence then belongs to them and because it is a reasonable thing for an employee to refuse. Organisation-owned licensing avoids the argument entirely.
Single-app and kiosk deployments for iPads
An iPad locked to one application for point of sale, a customer sign-in desk, a warehouse process, a survey tool or a menu. The device does nothing else, cannot be exited without a code, and can be replaced by couriering another one to the site. For UAE retail, hospitality and site-based operations this is where iPad deployments create the most value, and it is straightforward to do once the account and enrolment layer exists.
Controlled access to company systems from the phone
Deciding which devices are allowed to reach your mailbox and files at all. Where you run Microsoft 365, device compliance can be connected to access, so a phone that is jailbroken, unpatched or unmanaged is refused rather than merely reported. This is the control that turns mobile management from an inventory exercise into an actual security boundary.
Lost and stolen, handled as a process rather than a panic
A phone lost in a taxi on a Thursday evening needs a defined response: locate if possible, lock, decide whether to remove company data, and revoke the sessions that phone holds. What makes this work is not the technology, which is straightforward, but having agreed in advance who authorises what, out of hours, because that is when it always happens.
Staff resist mobile management because nobody tells them the truth about it.
Almost every failed BYOD rollout we are called into failed for the same reason. The organisation announced that phones would be managed, said nothing about what that meant, and people assumed the worst. Here is the version that works.
- Tell people exactly what the organisation can see, in writing, before enrolment. Under a correctly configured personal-device enrolment: the work applications it deployed, the device model, the operating system version, and whether the device meets the security baseline. Not personal photographs, not personal messages, not browsing history, not what else is installed.
- Tell them exactly what the organisation can do. It can remove the work account and work data. It cannot wipe the whole phone, and it should not have that ability on a device you do not own. If your proposed configuration does give the employer that power on personal devices, that is worth reconsidering rather than concealing.
- Give people a real choice where you can. A company-provided phone for those who would rather keep work off their own device is the cleanest answer and removes the entire argument. Where that is not affordable for everyone, offer it at least to the roles handling the most sensitive material.
- Put it in a short policy people actually read, not a twelve-page document nobody opens. One page covering what is managed, what is visible, what happens when you leave, and who to ask. In the UAE this matters commercially as well: employees across a mix of nationalities and contract types will each have different assumptions, and only writing it down resolves that.
Four things that decide whether mobile management sticks.
We write the staff communication, not just the configuration
A one-page explanation of what is managed, what the employer can and cannot see, what happens when somebody leaves, and who to ask. This is the deliverable that determines whether people enrol willingly. We have seen technically perfect deployments stall entirely because nobody wrote it, and simple ones succeed because somebody did.
We match the model to who owns the device
Company-owned devices get full management because that is appropriate for company property. Personal devices get user enrolment that touches only work data, because anything more is both intrusive and, in practice, something people will refuse or work around. Getting this boundary right is most of the job, and it is where copied policies go wrong.
We connect compliance to access, so the control is real
A report saying a device is non-compliant achieves nothing by itself. Where you run Microsoft 365, we connect device state to whether the phone can reach your mailbox and files, so a device below the baseline is refused rather than noted. That is the difference between a mobile policy and a mobile control.
We are reachable when a phone goes missing at the weekend
Lost devices do not happen during office hours. Our tiers are P1 within 5 minutes, P2 within 10, P3 within 30, and we agree in advance who can authorise removing company data from a device so that nobody is trying to find a decision-maker at eleven at night while a phone sits in the back of a taxi.
Six UAE situations and what each one needs.
A sales or client-facing team on personal phones
Company email, client contacts and documents on devices the business does not own, with people who move between employers in a competitive market. User enrolment is the right model: work data removable on departure, personal content untouched, and a written explanation that makes people comfortable enrolling. The commercial risk here is client contact data leaving with a departing salesperson, and this is the control that addresses it.
Retail or hospitality running iPads at the point of customer contact
Point of sale, a sign-in desk, a digital menu, a feedback terminal. These should be company-owned, supervised and locked to a single application so the device cannot become anything else. Replacement then becomes a courier job rather than a site visit, which is what makes running devices across many venues practical for a small team.
A DIFC or ADGM regulated firm
Here the driver is evidence and control rather than convenience. You need to demonstrate that devices holding client information are managed, that access can be revoked, and that a lost device does not become a reportable incident by default. For the most sensitive roles we generally recommend company-owned phones outright, because it removes the ambiguity entirely.
A clinic or healthcare provider
Patient information reaching a phone, shared iPads used by clinicians across shifts, and a confidentiality obligation that does not tolerate ambiguity. Shared devices need particular thought, because a shared login destroys attribution, and attribution is exactly what a clinical governance review will ask for.
A business with high staff turnover
Hospitality, retail, logistics, construction, where people join and leave frequently and offboarding is often informal. The value here is entirely in the leaver process: being able to remove company access from a phone the same day, without needing the person to hand anything back or cooperate at all. Without it, access accumulates in a way nobody is tracking.
Executives and anyone handling the most sensitive material
The people with the most valuable information on their phones are usually the least managed, because nobody wants to impose policy upward. A company-provided, properly managed phone is the clean answer, and it is easier to introduce as a benefit than as a control. Where the exposure is genuinely elevated, hardening the device further is a separate and more specialised conversation.
Somebody resigns on Sunday and hands back nothing. What happens?
| Feature | Managed | Email account only | Unmanaged |
|---|---|---|---|
Company mailbox removed from the phone | Immediately | Eventually | Only if they cooperate |
Documents cached on the device removed | Partly | ||
Work chat history removed | |||
Work apps removed | |||
Personal content untouched | |||
App licences recovered | Not applicable | ||
You can evidence the data was removed | Partly | ||
Requires the person to cooperate | Somewhat | Entirely | |
Works if they have already left the country | Partly | ||
Time to complete | Minutes | Hours to days | Never, in practice |
Company-owned, personally owned, or nothing at all.
| Company-owned | Personal, user enrolment | Unmanaged | |
|---|---|---|---|
| Organisation controls the whole device | Yes | No | No |
| Work data removable on its own | Yes | Yes | No |
| Personal content visible to employer | Possible, be careful | No | No |
| Passcode and encryption enforced | Yes | Yes | Hoped for |
| Apps deployed and licensed by the organisation | Yes | Yes | No |
| Access blocked if device is non-compliant | Yes | Yes | No |
| Suitable for kiosk or single-app use | Yes | No | No |
| Staff generally accept it | Yes, it is company property | Yes, if explained | Not applicable |
| Leaver handled the same day | Yes | Yes | Ask and hope |
| Right for a senior person handling sensitive material | Best | Acceptable | No |
| Where most UAE staff phones sit today | Rarely | Sometimes | The default |
Five steps, and the announcement comes before the technology.
- 1
Find out how many phones actually hold company data
Usually from your mail platform, which knows which devices connect to it. This number is almost always higher than expected and it includes devices belonging to people who left. It is also the number that makes the case internally, because an unquantified risk gets deprioritised and a specific count does not.
- 2
Decide the ownership model per group, and write it down
Which roles get company devices, which use personal devices under user enrolment, and which need neither because web access is sufficient. This is a business decision with cost implications rather than a technical one, and it should be made by the business rather than defaulted to by IT.
- 3
Write the one-page explanation and communicate it
What is managed, what the employer can and cannot see, what happens on leaving, who to ask. Circulated and available before anybody is asked to enrol. This step is the one most often skipped and it is the one that decides whether the rest works.
- 4
Enrol in waves, starting with people who will be patient
A first group of willing colleagues surfaces the practical problems, a confusing prompt, an app that needs a setting adjusted, a device on an old iOS version, before the wider rollout meets them. Then department by department rather than everyone at once, so support is never facing the whole company in a single morning.
- 5
Connect compliance to access, then run it
Once enrolment is established, non-compliant devices are refused access rather than merely reported, which is what makes the whole exercise a control. Then the ongoing work: new starters, leavers, devices replaced, iOS versions kept current, and a defined out-of-hours process for anything lost.
“We found forty seven phones connected to our email and we own eleven of them. Six belonged to people who had left, one of them two years ago. Nobody had ever thought to check, because we were all focused on the laptops.”
What people ask, including the questions staff ask.
Fifteen questions about the phones with your data on them.
Quantify the exposure
- How many phones currently have company email on them?Most organisations cannot answer this, which is itself the answer.
- How many of those does the company own?Usually far fewer than the number holding company data.
- Could you remove company data from a personal phone today?If not, every leaver takes your mailbox with them.
- Do you know which are running an unsupported iOS version?Old phones stay in use long after they stop receiving updates.
- Has anyone left in the past year without their access being removed from their phone?Check rather than assume. Web access being revoked is not the same thing.
The controls
- Is a passcode actually enforced, or merely requested?A phone with no passcode and a company mailbox is an open door.
- Is device compliance connected to whether the phone can reach company data?Reporting non-compliance changes nothing on its own.
- Are work apps deployed by the organisation rather than installed personally?Licence ownership and removability both depend on this.
- Can a lost device be located and locked out of hours?Including at 11pm on a Friday, which is when it happens.
- Are company iPads in public-facing use locked to a single app?Otherwise they become somebody browsing device within a week.
The human and legal side
- Is there a one-page policy staff have actually read?Twelve pages nobody opens is the same as nothing.
- Have you told people in writing what the employer can and cannot see?The single biggest determinant of whether BYOD adoption succeeds.
- Is enrolment on a personal device genuinely voluntary?With a real alternative, such as a company phone or web-only access.
- Do you know your UAE data protection obligations for what you collect?Managing a device means processing data about its user.
- Is there an agreed process for a lost device out of hours?Who authorises, who acts, and how fast.
The layers around this one.
MDM solutions in Dubai
The platform-agnostic view across Apple, Android and Windows, including enrolment models, BYOD, and getting staff to accept management.
macOS management
The Mac side of the same estate, where the problems are genuinely different: FileVault key escrow, local administrator rights and the Rosetta deadline.
Microsoft Intune
What Intune covers across iPhone, iPad, Android, Mac and Windows, and how to check whether your Microsoft 365 plan already includes it.
Start by counting how many phones have your email on them.
Your mail platform already knows. The number is usually higher than expected and usually includes people who left. We will help you produce it, work out which of those devices the company owns, and give you a straight recommendation on what to do about the rest.
Related Services
Explore more solutions that work great with this service
MDM Solutions Dubai
Device management across Windows, Apple and Android
macOS Management Dubai
FileVault, admin rights, updates and the Rosetta deadline
Microsoft Intune
Device management and endpoint security
Apple Device Management
Mac and iPhone fleets, encryption, patching and the September cycle
Zero-Touch Deployment UAE
Sealed box to working device without IT touching it
Microsoft Entra
Identity and access management solutions
Endpoint Security
Defender for Endpoint and Intune managed
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations