If your only mobile device management (MDM) admin just resigned, the next two weeks matter more than the hiring decision. Most of what keeps a fleet running lives in that person’s head, their accounts, and their calendar of renewals.
Nothing breaks on the day they leave. Things break quietly over the following weeks, when a certificate expires, an update goes out unchecked, or a new device won’t enrol.
This post covers what tends to break first, what to secure before their last day, and how to decide between rehiring, upskilling, and getting outside help.
What breaks first when nobody owns the MDM console
An MDM platform keeps running without an admin, but it stops being managed. The software enforces whatever policy was last set. Nobody is watching whether that policy still fits.
The first failures are usually tied to renewals. Apple push certificates and Apple Business Manager tokens renew on a yearly cycle, and Android Enterprise is bound to a Google account. If any of those sit under the departing admin’s personal login, a missed renewal can stop new enrolments or cut devices off from management.
Next comes drift. Operating system updates go out without testing, apps fall behind, and compliance alerts land in an inbox nobody reads. The slow slide of MDM policy drift is how a well-built environment turns into a liability without anyone changing a setting.
Then the requests pile up. New hires need devices, lost phones need locking, and a site manager needs a kiosk app changed. Each one waits for someone who knows where to click.
The lost-device requests carry the most risk. Under PIPEDA you remain accountable for personal information on company devices, so a phone that can’t be locked or wiped promptly is a privacy problem, not just an IT backlog item.
Your first two weeks: a handover checklist
Use the notice period to move knowledge out of one person and into your systems. If they’ve already left, work through the same list with whatever access you have.
- Transfer account ownership. Move the MDM vendor portal, Apple Business Manager, Android Enterprise binding, and certificate accounts to a shared, role-based login.
- List every renewal date. Push certificates, tokens, licences, and support contracts, with a named owner for each.
- Export the configuration. Policies, profiles, app lists, and device groups, saved somewhere the team can find them.
- Document enrolment. How a new device gets from the box to managed, step by step, for each platform.
- Map integrations. Identity, email, Wi-Fi certificates, and any business apps that depend on MDM.
- Redirect alerts. Make sure compliance and error notifications go to a shared mailbox, not a personal one.
- Freeze non-urgent changes. Hold major policy or OS changes until someone owns the environment again.
What to tell leadership this week
Leadership doesn’t need the technical detail. They need to know the risk, the interim plan, and when a permanent decision will be made.
Describe the risk in business terms. New devices may not enrol, lost devices may not be locked quickly, and updates may go out untested until someone owns the platform again. Then give the interim plan, such as a named internal owner for urgent requests and outside help on standby for anything beyond their reach.
Close with a decision date. A two-week stabilization period followed by a clear recommendation (rehire, upskill, or outside administration) shows you’re managing the gap, not waiting for a résumé to fix it.
Why replacing the admin takes longer than you think
Finding a replacement is the slow part, and the market isn’t on your side. A Robert Half survey of 1,500 Canadian hiring managers, published in February 2026, found that only 5% of technology managers say they have the skills and headcount to complete high-priority projects. Robert Half is a staffing firm, but the finding matches what most IT leaders already feel.
Hiring is only half of it. Just know that a new admin won’t inherit undocumented configuration, so plan for a period where they rebuild understanding of why things were set up the way they were.
The workload isn’t standing still either. Fleets keep adding device types, apps, and sites, while IT headcount rarely grows at the same pace. Replacing one person to manage a growing fleet is a short-term fix for a long-term trend.
Rehire, upskill, or bring in outside administration
There are four realistic paths, and the right one depends on fleet size, complexity, and how much MDM expertise you want to keep in-house.
| Option | Fits best when | Trade-off |
|---|---|---|
| Rehire a specialist | Mobility is strategic and you want deep expertise on staff | Slow to fill, and you’re back to one person holding the knowledge |
| Upskill a generalist | The fleet is small and stable, and someone on the team has capacity | Learning curve, and MDM competes with everything else on their plate |
| Co-managed MDM | You want to keep policy decisions in-house and hand off the day-to-day work | Needs clear lines on who approves changes and who makes them |
| Fully managed MDM | The fleet is large or complex and you’d rather your team work on other projects | Less hands-on control, so reporting and governance need to be agreed up front |
Whatever you choose, read the limits of what your MDM licence covers first. A licence gives you the platform. It doesn’t give you anyone to run it.
The co-managed and fully managed options are the work we do. Our certified MDM technicians administer the client’s existing platform as a managed service, inside your policies, under our MDM as a Service (MDMaaS) model.
It’s a strong fit for organizations running hundreds or thousands of frontline devices with a small IT team. For a fleet of a few dozen phones, upskilling someone internally may be all you need.
How to stop this happening again
The real problem wasn’t the resignation. It was that one person was the system. Whichever path you take, build the environment so the next departure is an inconvenience, not an incident.
That means shared accounts, written runbooks, a renewal calendar the whole team can see, and at least two people (internal or external) who can make a change safely. The IT leader’s guide to MDM as a Service covers how organizations split that ownership between their own team and a partner.
Questions we hear when an MDM admin leaves
What happens to our devices if nobody manages our MDM?
Devices keep working under the last policies applied, but management slowly erodes. Certificates and tokens can expire, which stops new enrolments or disconnects devices, while updates go out untested, apps fall behind, and lost devices may not get locked in time. The risk builds over weeks rather than all at once.
How do I take over MDM accounts the admin set up personally?
Start with the MDM vendor, Apple, and Google, since each has an account recovery or ownership transfer process for organizational accounts. Move every account to a shared, role-based login tied to a company domain. If the admin is still serving notice, do the transfer together before their last day.
Is managed MDM the same as buying an MDM licence?
No. An MDM licence is the software, while managed MDM is people who run that software for you, including policy changes, updates, enrolment, compliance monitoring, and support. Many organizations keep their existing platform and licences and hand the administration to a managed service provider.
Where to start
Before anything else, find out which accounts and certificates sit under the departing admin’s name, and move them. Then capture the configuration and renewal dates while someone still knows what they mean. With that done, the choice between rehiring and outside help becomes a decision about the future instead of an emergency.
References
- Robert Half Canada, Only five per cent of organizations have the skills and headcount needed for priority projects in 2026 (February 2026). Survey of 1,500 Canadian hiring managers.