Office 365 MDM: Mobile Device Management Your team is checking Outlook on their phones at the coffee shop. Someone's pulling up a SharePoint file on a tablet during a flight. Another employee just connected to Teams over hotel Wi-Fi. This is normal work life now, and it's also a security gap many businesses never think about until something goes wrong.

A lost phone, an unsecured network, or an unvetted app can expose the same sensitive data sitting in your Office 365 environment. Verizon's 2024 Data Breach Investigations Report documented 199 lost-or-stolen-asset incidents, with 181 resulting in confirmed data disclosure — a clear signal that missing devices routinely turn into real breaches.

This guide breaks down what Office 365 MDM actually does, how it stacks up against Microsoft Intune, and how to figure out if the built-in option covers your business or if you need more.

Key Takeaways

  • Office 365 MDM (Basic Mobility and Security) is free with Microsoft 365 and covers passwords, encryption, and remote wipe
  • Built-in MDM lacks mobile application management (MAM), a gap that matters for BYOD-heavy teams
  • Setup happens through the Microsoft 365 admin center: enable the service, build policies, enroll devices
  • Regulated businesses (HIPAA, SOC 2) usually need controls beyond what built-in MDM offers
  • A managed IT partner can configure and maintain these policies so coverage stays consistent

What Is Mobile Device Management (MDM) for Office 365?

Microsoft's official name for this feature is Basic Mobility and Security, a free MDM subset built on the Intune platform and included with Microsoft 365 subscriptions. It lets admins enforce security policies on any mobile device touching company email, files, or Teams. It handles three core jobs:

  • Enforces password rules: minimum length, complexity, and expiration
  • Requires encryption on supported devices, including Android and Samsung Knox
  • Enables remote wipe so a lost or stolen device can be cleared of company data

Company-Owned and BYOD Devices

Basic Mobility and Security works for both scenarios, though personal devices require employee consent before enrollment. Supported platforms include iOS/iPadOS, Android, and Windows 10/11 PCs. Full device management typically requires enrollment. In organizations with Microsoft Entra ID P1 or P2, first-time use of new Outlook or Windows Mail apps can trigger that requirement. For small and mid-size businesses without a dedicated IT security team, the practical win is simple: it already ships inside the Microsoft 365 subscription you pay for. No extra software. No separate vendor. Lost and stolen devices remain a common breach path, so any baseline protection beats having none.

Key Features and Capabilities of Office 365 MDM

Here's what you actually get once MDM is enabled:

  • Device enrollment — users or admins register devices, giving IT visibility into what's connecting to company data
  • Policy enforcement — password complexity rules, screen lock timeouts, and basic restrictions
  • Remote wipe — removes company resources from a device, or performs a full factory reset when personal separation isn't possible
  • Conditional access — blocks noncompliant devices from reaching Exchange Online, SharePoint, and Outlook
  • Compliance monitoring — flags devices without a PIN lock or that show signs of jailbreaking/rooting
  • Data protection — required encryption on supported platforms, plus blocking of compromised devices

Office 365 MDM six core features and capabilities overview

Office 365 MDM six core features and capabilities overview

Microsoft itself describes this compliance and Conditional Access coverage as limited. That's an important word choice. It's enough to stop the most obvious risks, but it doesn't reach into how apps handle your data once a device is compliant.

Office 365 MDM vs. Microsoft Intune: Which Do You Need?

This is the question most businesses eventually hit. Basic Mobility and Security is free with a Microsoft 365 subscription. Intune is a separate paid platform with deeper controls.

The biggest gap: Intune adds mobile application management (MAM). That means app-level controls such as blocking copy/paste between managed and unmanaged apps, restricting "save as" to approved locations, and enforcing per-app data protection on personal devices where full enrollment isn't practical.

Capability Office 365 MDM Microsoft Intune
Cost Free with M365 subscription Plan 1: $8/user/month; Plan 2: $4/user/month add-on
Platforms iOS, Android, Windows Adds macOS support
App management (MAM) Not included Full app-level protection
Wi-Fi/VPN configuration Not included Included
Conditional access scope Exchange, SharePoint, Outlook Broader coverage
Compliance depth Limited Extensive

Office 365 MDM versus Microsoft Intune feature and cost comparison chart

Office 365 MDM versus Microsoft Intune feature and cost comparison chart

Can you run both? Yes. You can run Basic Mobility and Security alongside Intune. When a device is licensed for both, Intune enrollment takes priority.

Our take: If you run entirely on Microsoft 365, issue company devices, and have modest security needs, Basic Mobility and Security is a solid starting point. Heavy BYOD, regulated data, or app-level isolation usually means you need Intune or a comparable unified endpoint management platform.

How to Set Up MDM for Office 365: A Quick Walkthrough

Basic Mobility and Security setup follows three steps:

  1. Activate the service — Go to the Microsoft 365 admin center, find Mobile Management, and turn on Basic Mobility and Security. This requires Global Administrator or Compliance Administrator permissions.
  2. Configure security policies — In the Security & Compliance area, set password requirements, encryption rules, and access conditions. Save the policy without applying it first if you want a dry run.
  3. Enroll users and monitor status — Add users to the relevant security group. Unenrolled devices get restricted access until they complete enrollment. Watch status move from "Turning on..." to "On."

Three-step Office 365 Basic Mobility and Security setup process

Test new policies on a small group before company-wide rollout. That buffer catches a misconfigured setting before it locks out your whole sales team on a Friday afternoon.

Is Built-In MDM Enough, or Do You Need Managed Support?

Free MDM covers the basics: passwords, encryption on supported devices, and remote wipe. For a lot of small businesses, that's a solid floor. But it starts to show cracks in specific situations.

Common gaps businesses run into:

  • No centralized reporting across multiple Microsoft security tools
  • Limited or no application-level management for BYOD scenarios
  • No 24/7 monitoring to catch policy violations as they happen
  • HIPAA or SOC 2 obligations that need documented risk analysis beyond device enrollment

Neither HHS nor AICPA states that a specific MDM product automatically satisfies HIPAA or SOC 2 requirements. What they do require is documented risk analysis, administrative and technical safeguards, and evidence your controls actually work. That's a bigger lift than flipping a switch in the admin center.

This is where LME Services fits in. As a Chicagoland-based managed IT and cybersecurity provider working with law firms, financial services firms, and other regulated SMBs, LME configures Intune policies that require phones and computers to authenticate before accessing email, then keeps those devices under ongoing security policies.

Beyond initial setup, LME's managed IT approach monitors for breach indicators MDM alone won't catch:

  • Unusual login attempts
  • Newly created mailbox rules
  • Failed two-factor prompts
  • Logins from unexpected locations

Managed IT security dashboard monitoring login attempts and mailbox alerts

Rather than a one-time configuration project, it's flat-fee oversight that keeps device compliance current as your team, devices, and risks change.

Frequently Asked Questions

Is there a free MDM software?

Yes. Office 365 MDM (Basic Mobility and Security) is included free with Microsoft 365 subscriptions. It covers basic device security at no extra licensing cost; Microsoft Intune is the paid upgrade when you need more control.

What is Microsoft's MDM solution?

Microsoft offers two options: the free, built-in Basic Mobility and Security for Office 365, and the more advanced, separately licensed Microsoft Intune.

What does MDM mean in Microsoft?

It refers to the set of tools within Microsoft 365 used to secure, monitor, and manage mobile devices that access company data, including password policies and remote wipe.

Is Microsoft Intune a MDM or MAM?

Both. Intune combines device-level management (MDM) with app-level management (MAM) in a single platform, going beyond the free built-in option’s device-focused controls.

What is the difference between Microsoft MDM and Intune?

Built-in MDM is lightweight and free, covering password and encryption basics. Intune adds deeper security, application management, and advanced configuration for an additional cost.

Is SCCM being replaced by Intune?

Not officially retired, but Microsoft is consolidating endpoint management under Intune through cloud attach and co-management, making Intune the clear long-term direction for device management.