Join our Newsletter — 33% off our NHI Course

Mobile application management: what IAM teams should actually govern

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Mobile application management software is presented as a way to secure apps on personal and corporate devices, but the article’s real value is in showing how access control, compliance enforcement, and lifecycle management shape the mobile app surface, according to Zluri. The governance lesson is broader: unmanaged app access is an identity problem, not just an endpoint problem.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 9 Mobile Application Management Software in 2026”.

Key questions

Q: How should security teams govern BYOD without losing control of access?

A: Security teams should govern BYOD by tying device posture and access policy to identity, not by relying on device ownership alone.

Q: Why do mobile app controls fail when they are managed only as endpoint settings?

A: Because endpoint settings do not fully answer who is entitled to use the app, why that access exists, or when it should end.

Q: What are the best practices for mobile app governance across employee devices?

A: The strongest practice is to keep app approval, user assignment, compliance policy, and revocation in one governed process.

Practitioner guidance

  • Align mobile app approvals with identity governance Map each approved mobile app to an entitlement owner, a business justification, and a review cadence so the approval record stays auditable across BYOD and corporate devices.
  • Tie revocation to joiner-mover-leaver events Remove mobile app access when an employee changes role, leaves a team, or exits the organisation, and verify that the revocation propagates to all assigned devices and app catalogs.
  • Separate device posture from application entitlement Use device controls to assess endpoint health, but make app access decisions from identity context, role, and policy so a compliant device does not become a proxy for unlimited access.

Bottom line: Mobile application management is best understood as a governance layer for app entitlements, not only a tool for securing phones and tablets.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Mobile application management is an identity governance problem disguised as endpoint administration. The article’s own feature set keeps returning to approval, access control, compliance, and revocation, which are all lifecycle disciplines. That means MAM belongs in the same governance conversation as app entitlement management, not in a siloed device-management queue. Practitioners should read mobile app controls as a layer of identity policy enforcement.

A few things that frame the scale:

A question worth separating out:

Q: How do IAM and mobile security teams work together on app governance?

A: They should review mobile apps as access channels, not only software artefacts. If an app carries tokens, sessions, or customer identity data, IAM and security teams need shared controls for release approval, session protection, and exception handling so identity risk is managed consistently.

👉 Read our full editorial: Mobile app management is really identity governance in disguise


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.