What Is MAM (Mobile Application Management)?

Related problems: Employees won't let IT manage their personal phones; Company email on personal phones with no controls; Need to remove company data when someone leaves without wiping their phone; Contractors need app access but we don't own their devices

Mobile application management (MAM) is the set of tools and practices for managing and protecting company apps on phones and tablets, and the business data inside those apps, separately from managing the device as a whole. Depending on the platform, that can include deploying, configuring, updating and inventorying work apps, and applying app-level protection such as requiring a PIN to open a work app, blocking copying company data into personal apps, and removing company data from those apps when someone leaves. Many platforms can apply app protection without enrolling the device, which makes MAM a common way to secure personal phones in a bring your own device (BYOD) program.

At a glance

  • MAM manages apps and their data; mobile device management (MDM) manages the device itself.
  • App deployment, configuration and inventory are often delivered through an enrolled device management or UEM platform.
  • App protection policies (app PIN, copy and paste limits, encryption, selective wipe) are a subset of MAM, and what works without device enrollment varies by platform.
  • Protection applies only to apps that support the platform, so check app coverage before you rely on it.
  • It is often paired with conditional access so company data is reachable from protected apps and not from unmanaged ones.

What problem it solves

Employees increasingly use their own phones for work, and many will not enroll a personal phone in device management that lets IT enforce settings or wipe the phone. Without any control, though, company email, files and chat end up on devices IT knows little about, with no reliable way to remove the data when an employee leaves or loses the phone.

MAM addresses that by putting the controls around company apps and data rather than the whole phone. On platforms that support it, the company sets rules inside its apps while the rest of the phone stays personal. That can make BYOD and contractor access acceptable to both security teams and employees, and it supports cost models such as a mobile stipend, where the company does not own the device. On company-owned devices, MAM features handle the app side of device management: getting the right apps installed, configured and updated.

How it works

App deployment and configuration. On enrolled devices, a device management or UEM platform can install required apps, push settings such as server addresses and account details, keep apps updated, and report which work apps are installed. These functions usually depend on enrollment.

App protection policies. Many platforms let administrators define rules for managed apps: require a PIN after inactivity, block screenshots, restrict copy and paste or “open in” to other managed apps, require app data to be encrypted, and block access from jailbroken or rooted devices where the platform can detect them. Some platforms apply these policies without device enrollment; others require it. Vendors often market this as app protection, which is narrower than MAM as a whole.

Supported apps. App protection is enforced by the apps themselves, so an app must support the platform. Depending on the vendor, that support comes from the app publisher’s integration through a software development kit (SDK), or from “wrapping” your own app with vendor tools. Coverage of line-of-business apps varies; check yours.

Identity and access. The user signs in with a work identity. Many deployments combine app protection with conditional access rules so company services accept connections only from protected apps, which helps close the gap of users installing unmanaged apps to reach the same data.

Selective wipe. Many platforms can remove company data from managed apps when a user leaves or reports a lost phone, and some do so automatically if an app has not checked in for a set period. Scope and behavior vary by platform and app.

These features usually come as part of unified endpoint management (UEM) platforms. Our Unified Endpoint Management solution page covers how to choose a platform that handles both device and app management.

When it matters for buyers

  • Starting or formalizing BYOD. App-level protection is a common baseline control for company data on personal phones.
  • Contractors and partners. Where the platform supports it, you can protect data in their apps without managing devices you don’t own.
  • Cyber insurance or audit questions. You may be asked how company data on mobile devices is protected and removed.
  • Data loss concerns. App protection complements data loss prevention (DLP) by limiting how data leaves managed apps on mobile devices.
  • Platform consolidation. If you already pay for a UEM or productivity suite, MAM features may be included in your license.

Questions to ask vendors

  • Which MAM functions need device enrollment, and which work without it, on each operating system we support?
  • Which apps support your app protection policies, and how do we add our own apps (SDK, wrapping or neither)?
  • How does selective wipe work, which apps does it cover, and what happens to data when a device is offline?
  • Can policies require a minimum operating system version or detect jailbroken devices?
  • How does MAM integrate with our identity provider and conditional access rules?
  • Is MAM included in our current license, or priced separately per user?
  • What will employees see on their phones, and what data about the device can IT view?

How it differs from MDM

Mobile device management (MDM) enrolls the whole device: IT can enforce a device passcode, push settings and apps, see installed apps and wipe the device entirely. MAM focuses on company apps and their data: deploying and configuring them, often through MDM or UEM on enrolled devices, and protecting the data inside them, which some platforms can do without enrollment. MDM generally suits company-owned devices where full control is expected; app protection without enrollment generally suits personal devices where employees expect privacy. Many organizations use both, applying app-level policies across personal and company devices and adding MDM where the company owns the hardware.

Frequently Asked Questions

What is the difference between MAM and MDM?
Mobile device management (MDM) manages the device itself: settings, passcode, installed apps and the ability to wipe it. MAM focuses on company apps and their data, such as deploying and configuring them, requiring a PIN to open email, or blocking copy and paste into personal apps. On some platforms MAM controls can be applied without enrolling the device, which is why MAM is often used for personal phones and MDM for company-owned ones.
Can MAM wipe an employee's phone?
MAM works at the app level, not the device level. Many platforms offer a selective wipe that removes company data from managed apps while leaving personal photos, messages and other apps alone; how it works, and which apps it covers, varies by platform. A full device wipe needs device management.
Do we need MDM as well as MAM?
It depends on who owns the devices, which platform you use and how sensitive the data is. Some organizations use app protection without enrollment for personal phones and MDM, often with app-level policies on top, for company-owned devices. Some regulated environments require device-level controls regardless of ownership.
Does MAM work with every app?
No. App-level protection policies apply only to apps that support the platform, through the publisher's integration or, on some platforms, by wrapping your own apps. Major productivity apps are commonly supported; check the apps your staff need before relying on MAM.
Is MAM part of UEM?
Usually. Most unified endpoint management platforms include app management and app protection features alongside device management, and some identity and productivity suites offer app protection policies as well. What each one can do without device enrollment differs.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.