A fleet of scanners, tablets, and handhelds spread across distributed Canadian operations rarely fails all at once. It erodes: a device down on a loading dock here, a compliance gap in a clinical setting there, a policy no one has updated since the last operating-system migration. Learning how to manage mobile devices as a repeatable process — not a series of one-off fixes — is what keeps a fleet productive, secure, and audit-ready. This guide lays out a practical mobile device management process built for Canadian enterprises, and it pairs with our companion pillar on why your business needs mobile device management, which covers the what and the why in depth.
What is mobile device management?
Mobile device management (MDM) is the practice of configuring, securing, monitoring, and supporting the mobile devices your workforce uses — from enrollment through retirement. It is a specific technical function, not a catch-all term. Three adjacent acronyms are worth separating:
- MDM (mobile device management): control at the device level — enrollment, policy enforcement, remote lock and wipe.
- MAM (mobile application management): control at the app level, useful when you manage corporate apps and data on devices you do not own.
- EMM (enterprise mobility management) and UEM (unified endpoint management): broader frameworks that fold MDM and MAM together with identity and, for UEM, laptops and desktops under one console.
Here is the distinction that matters for how you buy. Managed mobility services (MMS) is the category — the full operational discipline of running a device fleet. MDM is one function inside that category. When you treat MDM administration as a task within a managed mobility programme, rather than as the whole programme, the process below falls into place.
Step 1 — Set your device ownership and management framework
Every mobile device management process starts with a decision you cannot skip: who owns the device, and who controls it. Three models dominate.
- Corporate-owned: the organization buys, owns, and fully manages the device. Standard for rugged fleets and regulated work.
- BYOD (bring your own device): employees use personal devices for work, typically managed through MAM containers rather than full device control.
- COPE (corporate-owned, personally enabled): the organization owns the device and permits limited personal use under policy.
For most Canadian enterprises running frontline operations — transportation and logistics, warehouse and distribution, healthcare — corporate-owned rugged devices carry the workload, because a personal smartphone does not survive a -20°C truck cab or a wet clinical environment. The framework choice also has a data-residency dimension. Where device data is stored, and under whose jurisdiction, shapes your compliance exposure before a single policy is written. Deciding this early keeps the rest of the process from drifting.
Step 2 — Define ownership, policies, and your MDM platform
With a framework set, decide who administers the fleet day to day and on which platform. Internal IT can run MDM, but it competes with every other priority on the team. Many Canadian enterprises move MDM administration to a managed mobility partner so their IT staff stay focused on strategic work while the fleet runs under defined policies and service levels. This is a co-managed model, an extension of your team — the fleet still operates under your policies, with full visibility.
Platform selection follows. PiiComm is certified on SOTI and 42Gears, and supports Microsoft Intune, across both on-premise and cloud deployments. The platform is the tool; the policy is what makes it useful.
What a mobile device management policy should cover
A mobile device management policy sets the rules the platform enforces. At minimum, it should define:
- Access and authentication: who can use a device and how they prove it.
- Configuration standards: approved apps, settings, and operating-system versions.
- Security baselines: encryption, passcode rules, and lock or wipe triggers.
- Compliance and reporting: the frameworks the fleet must satisfy and how you evidence it.
Write the policy once, enforce it fleet-wide, and review it on a set cadence. Ad hoc device rules are how gaps open.
Step 3 — Enroll, configure, and deploy devices consistently
A device is only as reliable as the day it was set up. Consistent enrollment, configuration, and deployment are where a fleet either standardizes or fragments. Zero-touch enrollment lets a device configure itself to your policies the moment it powers on, so the field worker who unboxes it never touches a setting. Staging — imaging, labelling, and quality-checking devices before they ship — makes that possible at scale.
PiiComm stages devices in its own Canadian facilities, with in-house certified technicians configuring each unit to the client’s MDM policies before it reaches the field. The result is a device that arrives ready to work, not one an operations lead has to troubleshoot on arrival. Deploying 500 devices with the same build, the same apps, and the same security posture is the difference between a fleet you govern and one you chase.
Step 4 — Secure, monitor, and enforce compliance
Security is not a one-time setup; it runs continuously. The core controls every managed fleet should enforce are:
- MFA (multi-factor authentication) on device and app access.
- Encryption of data at rest and in transit.
- Remote lock and wipe for lost or stolen devices.
- Operating-system patch management applied fleet-wide, on schedule.
For Canadian enterprises, monitoring is also a compliance obligation. Fleets handling personal data fall under PIPEDA (Personal Information Protection and Electronic Documents Act); health-sector fleets add PHIPA (Personal Health Information Protection Act); and organizations operating in Quebec must satisfy Quebec Law 25. Each requires you to demonstrate control over the data your devices hold, not simply assert it. PiiComm runs 24/7 proactive device-health and security monitoring, and its 24/7 bilingual (English and French) Canadian service desk responds when something needs escalation — the same team, in-country, that set the policies. Audit-ready reporting turns “we are compliant” into evidence you can hand a regulator.
Step 5 — Manage the full device lifecycle, from break/fix to secure decommissioning
The fifth step is the one the original version of this process guide missed entirely: what happens after deployment. Day 2 operations — break/fix, repair logistics, spare pool management, and eventual retirement — are where fleet costs and downtime actually accumulate.
Consider a transportation and logistics operator running rugged scanners across distributed Canadian sites. A scanner fails on a Sunday-night shift. With spare pool management, a pre-staged replacement ships immediately from the hot-spare pool, the failed unit routes to certified technicians for warranty assessment and repair, and the AIM (Asset Intelligence Manager) portal keeps the fleet manager’s inventory accurate throughout — down to non-assetized items like cases and styluses. The shift keeps moving; the device downtime that would have stalled it never lands.
At end-of-life, devices carry data that has to be destroyed to a verifiable standard. PiiComm’s Secure Decommissioning erases devices to NIST 800-88 and provides chain-of-custody documentation from deployment through certified erasure. This lifecycle work maps to PiiComm’s five service pillars — Strategic Sourcing, Staging & Deployment, Lifecycle Management, MDM as a Service (MDMaaS), and Secure Decommissioning — the operational capabilities behind the 500,000+ devices PiiComm manages across thousands of Canadian locations, backed by nearly two decades of managed mobility operations.
Key takeaways
Managing mobile devices well is a five-step process: set your ownership framework, define policy and platform, enroll and deploy consistently, secure and monitor continuously, and manage the full lifecycle through to certified decommissioning. Treated as a repeatable discipline rather than a run of one-off fixes, it keeps a distributed Canadian fleet productive, compliant, and audit-ready. The natural next step is deciding who runs that process for you.
Talk to a mobility expert about your device fleet.