TL;DR: Legacy MDM tools struggle to manage today’s BYOD, multi-OS environments, where 34% of devices are personally owned and 85% of IT admins want a single platform for device, identity, and access management, according to JumpCloud. The security problem is no longer endpoint sprawl alone, but inconsistent identity-aware control across diverse device ownership models.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “How to Manage Every Device Type in a BYOD World”.
By the numbers:
- 34% of devices are personally owned, increasing the likelihood of inconsistent controls and limited IT oversight.
- 85% of IT admins want a single platform that unifies device, identity, and access management.
Key questions
Q: How should security teams govern BYOD without losing control of access?
A: Security teams should govern BYOD by tying device posture and access policy to identity, not by relying on device ownership alone.
Q: Why do legacy MDM tools fail in multi-OS environments?
A: They were built for a simpler estate with company-owned hardware and limited operating system variation.
Q: What are the signs that device management is too fragmented?
A: Look for separate consoles per OS, uneven patch coverage, exceptions for BYOD or contractors, and inconsistent enforcement of security policy.
Practitioner guidance
- Define ownership-based device classes Separate corporate-owned, personally owned, shared, and contractor-used endpoints into distinct governance classes so policy, monitoring, and response can differ where trust differs.
- Tie device enrollment to identity records Require directory-backed identity attributes to drive enrollment, access assignment, and lifecycle state so a device is managed in context, not in isolation.
- Reduce tool fragmentation across OSs Consolidate Windows, macOS, Linux, mobile, and virtual machine management where possible so policy enforcement and patch visibility do not depend on the endpoint type.
Bottom line: Device management is no longer just about endpoint inventory because ownership, OS diversity, and remote work change the trust model.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity, not inventory, is now the organising principle for device control: device management breaks when teams treat endpoints as static assets instead of access-bearing entities. BYOD, contractor access, and mixed ownership mean the same physical device can move between trust states, so policy must follow the identity and context attached to the session. The practitioner conclusion is straightforward: device governance has to align with who is using the device and under what authority.
A question worth separating out:
Q: When does device management become an IAM problem rather than an endpoint problem?
A: It becomes an IAM problem when device state determines whether a user can access applications or networks. At that point, enrollment, trust checks, and offboarding affect authorization, not just hardware administration. Treating devices as separate from identity leaves revocation gaps and inconsistent policy enforcement.
👉 Read our full editorial: Modern device management now depends on identity-aware control