Ask a 25-person company how many laptops it owns and you usually get a confident answer that turns out to be wrong. Ask which of those laptops have encryption switched on, which are three months behind on updates, and which one belongs to the guy who left in March, and the confidence disappears. This is not incompetence. It is what happens when every machine is managed by walking over to it.
Device management is the fix, and it is the piece of business technology small companies most often assume is not for them. The assumption is that it is enterprise overhead for enterprise problems. It is not. The tooling has gotten much simpler, it is bundled into plans small businesses already buy, and the payoff shows up in the moments that hurt: a new hire’s first day, an employee’s last day, and the afternoon somebody leaves a laptop in a truck bed at a job site.
What Device Management Actually Does
Think of it as a remote control for every company computer and phone, operated from one screen in a browser. Microsoft describes its device management service as a cloud-based endpoint management service that secures and manages an organization’s devices and apps, covering enrolling devices, configuring settings, securing endpoints, deploying and protecting apps, and keeping everything up to date. Other vendors offer comparable products, and the category has carried several names, so shop for capabilities rather than a brand.
- Enforce the basics automatically. Require disk encryption so a stolen laptop is a lump of metal instead of a data breach. Require a screen lock and a real password. Set the rule once and it applies to every machine, including next week’s.
- Push updates and applications. Security updates install on a schedule you choose instead of whenever a user stops clicking “not now.” Need accounting software on every finance machine? Push it once.
- Wipe a lost or stolen device remotely. Microsoft’s documentation is blunt: if a device is lost or stolen, you can wipe it. That turns an emergency into a phone call.
- Set up a new machine without touching it. A laptop ships from the vendor to a new hire’s house. They open the box, join wi-fi, and sign in. The device recognizes itself as company-owned, applies your settings, installs your apps, and hands them a ready computer. Microsoft’s documentation lists automatic enrollment through vendor programs from Microsoft, Apple, and Google.
- See the truth about your fleet. One list of every device, who has it, whether it meets your rules, and when it last checked in. The device you forgot about appears on that list.
Why Onboarding and Offboarding Stop Hurting
Most small businesses onboard by having someone technical spend half a day unboxing, installing a dozen applications, and configuring email. With device management, onboarding becomes an account and a shipping label. Create the user, add them to the right groups, and the device configures itself at first sign-in. Ten minutes, and every device ends up identical, so troubleshooting stops being archaeology.
Offboarding is where the real value hides. Today the honest answer at most companies is that the account gets disabled and the laptop gets collected eventually, maybe. With device management you disable the account and issue a wipe or a selective removal of company data, and it happens the next time that device touches the internet. You are no longer depending on a former employee’s goodwill, or wondering whether the client list is sitting in a closet in Sanger.
That reliability is the actual product. We have made this argument elsewhere: saving time usually beats saving money, and half a day per hire adds up faster than the license cost.
The Personal Phone Problem
Your team reads company email on personal phones. That is not a policy you chose, it is reality. It creates a standoff: you need control over company data, and they reasonably do not want their employer able to erase their kid’s birthday photos.
- Full device management is where the organization manages the whole device, settings, security, and apps. Right for company-owned equipment. Wrong for someone’s personal phone, and if you try it you will get resistance, and they will be right to resist.
- App-level management is where the system controls only the work apps and the data inside them, not the rest of the device. Microsoft’s documentation describes this as typical for personal devices in bring-your-own-device scenarios, states that the user keeps control of personal apps and content while the organization protects data inside managed work apps, and states that when the user leaves you can selectively wipe organization data without touching personal content.
Lead with app-level management when you talk to your team. In practice the work email app requires its own PIN, company data cannot be copied into a personal cloud account, and on the day someone resigns the work data is removed while their photos and personal apps are untouched. A fair deal, and a much easier conversation than “we need to install management software on your phone.”
Licensing, Plainly
Device management is usually bundled into a higher subscription tier rather than sold as a line item. Microsoft includes its device management service in its top small business plan, and its published business pricing in 2026 listed that plan bundled with its AI assistant at roughly $32 per user per month on an annual commitment. Prices and bundling change regularly, and unbundled versions are priced differently, so treat that as a rough order of magnitude and confirm current licensing.
Licensing is also generally per user or per device rather than a flat company fee. Microsoft’s documentation states that each managed user or device needs a license, though administrators can manage the service without one. That matters when you have shared machines, a warehouse tablet, or a reception workstation three part-timers use, because how you count determines what you pay.
The right comparison is not license cost versus zero. It is license cost versus the cost of doing this badly: hours per onboarding, machines that never get patched, and a lost laptop being an incident of unknown scope. We have written about why cybersecurity is no longer optional for mid-sized businesses, and this is where a lot of that becomes concrete.
The Honest Part: The Work Comes First
We are not going to pretend you flip a switch and this is done. Microsoft’s own small business guidance lays out roughly half a dozen steps just to stand up full device management: deciding what can enroll, completing platform prerequisites with Apple and Google, defining what “compliant” means, writing the rules, connecting them to sign-in requirements, and enrolling the devices. App-only management for personal phones is lighter, on the order of two main steps.
There is a rollout cost too. Existing machines have to be enrolled, which sometimes means rebuilding them. Policies too strict on day one generate complaints, so you start permissive and tighten. And a mistake at scale hits every device at once, which is an argument for a pilot group first.
Our honest guidance: with fewer than about eight devices and no compliance obligations, the payback is slower and you can reasonably wait. Above that, or if you handle client financial data or health information, the setup effort pays for itself the first time you need it.
The Bottom Line
Device management is not an enterprise luxury. It is the difference between knowing the state of your equipment and hoping. It makes encryption and updates automatic, turns onboarding into a shipping label, makes offboarding final, and gives you a real answer the day a laptop goes missing.
If you are not sure what your current plan already includes, or how much of this you could turn on without buying anything new, sort that out before your next renewal. We set this up for businesses across Denton County and North Texas, including the unglamorous part where we pilot it on a few machines first. Contact us today.
Sources:
Comments are closed