Mobile application management (MAM) is the set of tools and practices for managing and protecting company apps on phones and tablets, and the business data inside those apps, separately from managing the device as a whole. Depending on the platform, that can include deploying, configuring, updating and inventorying work apps, and applying app-level protection such as requiring a PIN to open a work app, blocking copying company data into personal apps, and removing company data from those apps when someone leaves. Many platforms can apply app protection without enrolling the device, which makes MAM a common way to secure personal phones in a bring your own device (BYOD) program.
At a glance
- MAM manages apps and their data; mobile device management (MDM) manages the device itself.
- App deployment, configuration and inventory are often delivered through an enrolled device management or UEM platform.
- App protection policies (app PIN, copy and paste limits, encryption, selective wipe) are a subset of MAM, and what works without device enrollment varies by platform.
- Protection applies only to apps that support the platform, so check app coverage before you rely on it.
- It is often paired with conditional access so company data is reachable from protected apps and not from unmanaged ones.
What problem it solves
Employees increasingly use their own phones for work, and many will not enroll a personal phone in device management that lets IT enforce settings or wipe the phone. Without any control, though, company email, files and chat end up on devices IT knows little about, with no reliable way to remove the data when an employee leaves or loses the phone.
MAM addresses that by putting the controls around company apps and data rather than the whole phone. On platforms that support it, the company sets rules inside its apps while the rest of the phone stays personal. That can make BYOD and contractor access acceptable to both security teams and employees, and it supports cost models such as a mobile stipend, where the company does not own the device. On company-owned devices, MAM features handle the app side of device management: getting the right apps installed, configured and updated.
How it works
App deployment and configuration. On enrolled devices, a device management or UEM platform can install required apps, push settings such as server addresses and account details, keep apps updated, and report which work apps are installed. These functions usually depend on enrollment.
App protection policies. Many platforms let administrators define rules for managed apps: require a PIN after inactivity, block screenshots, restrict copy and paste or “open in” to other managed apps, require app data to be encrypted, and block access from jailbroken or rooted devices where the platform can detect them. Some platforms apply these policies without device enrollment; others require it. Vendors often market this as app protection, which is narrower than MAM as a whole.
Supported apps. App protection is enforced by the apps themselves, so an app must support the platform. Depending on the vendor, that support comes from the app publisher’s integration through a software development kit (SDK), or from “wrapping” your own app with vendor tools. Coverage of line-of-business apps varies; check yours.
Identity and access. The user signs in with a work identity. Many deployments combine app protection with conditional access rules so company services accept connections only from protected apps, which helps close the gap of users installing unmanaged apps to reach the same data.
Selective wipe. Many platforms can remove company data from managed apps when a user leaves or reports a lost phone, and some do so automatically if an app has not checked in for a set period. Scope and behavior vary by platform and app.
These features usually come as part of unified endpoint management (UEM) platforms. Our Unified Endpoint Management solution page covers how to choose a platform that handles both device and app management.
When it matters for buyers
- Starting or formalizing BYOD. App-level protection is a common baseline control for company data on personal phones.
- Contractors and partners. Where the platform supports it, you can protect data in their apps without managing devices you don’t own.
- Cyber insurance or audit questions. You may be asked how company data on mobile devices is protected and removed.
- Data loss concerns. App protection complements data loss prevention (DLP) by limiting how data leaves managed apps on mobile devices.
- Platform consolidation. If you already pay for a UEM or productivity suite, MAM features may be included in your license.
Questions to ask vendors
- Which MAM functions need device enrollment, and which work without it, on each operating system we support?
- Which apps support your app protection policies, and how do we add our own apps (SDK, wrapping or neither)?
- How does selective wipe work, which apps does it cover, and what happens to data when a device is offline?
- Can policies require a minimum operating system version or detect jailbroken devices?
- How does MAM integrate with our identity provider and conditional access rules?
- Is MAM included in our current license, or priced separately per user?
- What will employees see on their phones, and what data about the device can IT view?
How it differs from MDM
Mobile device management (MDM) enrolls the whole device: IT can enforce a device passcode, push settings and apps, see installed apps and wipe the device entirely. MAM focuses on company apps and their data: deploying and configuring them, often through MDM or UEM on enrolled devices, and protecting the data inside them, which some platforms can do without enrollment. MDM generally suits company-owned devices where full control is expected; app protection without enrollment generally suits personal devices where employees expect privacy. Many organizations use both, applying app-level policies across personal and company devices and adding MDM where the company owns the hardware.
