MDM manages your devices. It doesn't manage their lifecycle.
Carlos N. Escutia
· Estimated reading time: 3–5 minutes
There's a lot of MDM news right now, and it's tempting to treat your endpoint-management choice as the device-operations decision of the year. It's a real decision. It's just not the one that determines whether a laptop reaches a new hire in Manila or comes back from a departed employee in Warsaw. Here's the layer the MDM conversation keeps skipping.
MDM and device management is the policy layer for the calm middle of a device's life — it can't procure the laptop, deliver it to a new hire in another country, or recover it when they leave. Those are the expensive, risky, distributed parts of the employee hardware lifecycle, and they live in the physical world of couriers, customs, warehouses, and country-specific rules that no policy engine reaches. That's why you can switch MDM and device management vendors and still have no idea where half your hardware is. Two layers, two very different jobs — pick the MDM on its merits, then look honestly at the execution layer underneath.
The signal: endpoint management is in motion
Kandji rebranded to Iru and expanded beyond Apple. Microsoft is shifting Intune to Apple's Declarative Device Management. The Intune Suite folded into the bigger Microsoft plans with a price increase. Meanwhile Gartner is telling enterprises that PC prices are heading up roughly 17% this year — and that the alternative to growing hardware budgets 8–12% is extending the life of the devices they already own.
So IT leaders are re-evaluating the management layer at exactly the moment the lifecycle layer — the part that would let them extend device life — matters most. And in those evaluations I keep hearing MDM treated as if it's the whole of device operations. It isn't. It's one layer, and not the one that's failing.
The problem: what MDM structurally can't do
MDM does something specific and valuable: it manages a device that's enrolled, online, and in someone's hands. Configuration, policy, security posture, updates, remote lock and wipe. For the middle of a device's life, it's essential — and the products are genuinely good.
Now look at everything MDM structurally can't do:
- It can't buy the laptop in the country your new hire lives in, at a workable price and lead time.
- It can't get it there configured and ready for day one, through customs.
- It can't recover it when that employee leaves — especially the risky case, the device that's been offline and unresponsive for three weeks in a country where you have no office. A remote wipe needs the device online and enrolled. The laptop that's actually a threat is precisely the one that isn't.
- It can't store it, redeploy it to the next hire, or retire it with a chain of custody an auditor accepts.
MDM owns the middle of the device's life — the calm part. The expensive, risky, distributed parts are the beginning and the end: getting the device to a person, and getting it back. Those live in the physical world — couriers, customs, warehouses, country-specific rules — and no policy engine reaches them.
That's why you can switch MDMs and still have no idea where half your hardware is. The management layer is crowded with excellent products. The execution layer underneath is, at most companies, a spreadsheet and whoever has time.
The operator takeaway: two layers, two questions
Make the MDM decision on its merits — platform fit, security, price. Just don't mistake it for a device-operations strategy. Two layers, two questions:
- Management layer: once a device is enrolled, can I configure, secure, and update it well? (Intune, Jamf, Iru — pick well.)
- Execution layer: can I procure, deploy, recover, store, redeploy, and retire devices in every country I operate in — and always know where each one is?
When you're reviewing MDM this quarter, add the layer-2 questions to the same evaluation sheet: When a device is offboarded, what physically happens to it? Who recovers it? Can I redeploy it instead of buying new — at this year's prices? If the answer is “a person figures it out each time,” you've found the real gap. It isn't the MDM.
One GroWrk lens
To be plain about where we sit, GroWrk is not an MDM and doesn't replace yours — Intune, Jamf, and Iru are among the integrations the lifecycle runs through. GroWrk is the execution layer: procure, deliver employee-ready, recover, wipe with chain of custody, store, redeploy, retire — across 150+ countries, with one record of where every device is through global IT asset management. Your MDM manages the device while you have it. We make sure you have it, get it back, and can prove what happened to it.
MDM is the policy layer. GroWrk is the execution layer. The mistake isn't choosing the wrong MDM — it's assuming the policy layer covers the lifecycle. It never did.
One example: one device, by layer
Procurement and delivery — execution. Enrollment through daily policy — MDM (its actual job). Offboarding recovery, storage, redeployment, certified retirement — execution again. Out of a device's whole life, MDM owns the calm middle. Everything expensive happens at the two ends.
If you're re-evaluating MDM this quarter, good — the market gave you reasons to. Just put the layer-2 questions on the same sheet, because that's where distributed IT actually holds together or falls apart.
And a question I'd genuinely like answers to from this audience: when your MDM flags a device that's gone dark in another country, what happens next at your company, honestly?
If you want to see what the execution layer looks like alongside the MDM you already run, we would like to show you.
