UEM Foundations · Course F1Lesson 2 of 5
Ownership models
8 min read- Distinguish fully managed, work-profile, and dedicated-device postures
- Explain the control-versus-privacy trade each model makes
- Match a scenario to its ownership model
Before any technical decision — enrollment method, policy depth, app strategy — comes one question that settles most of the others: who owns the device?
Three postures
Corporate-owned, fully managed. The organization bought it; the organization controls all of it. Full-device policy, mandatory management the user can't remove, complete wipe rights. This is the posture for field fleets, shared hardware, and any device whose only life is work.
Personally owned — BYOD. The employee bought it; the organization manages a work container inside it. Corporate apps, accounts, and data live in the managed side; photos, chats, and everything personal stay untouched and invisible to IT. The honest trade: control is scoped to the container, and the user can remove it — taking corporate access with it, and nothing else. (You'll also hear COPE — corporate-owned, personally enabled — the hybrid where the company buys the device but carves out personal space. Think of it as fully-managed hardware wearing a BYOD glove.)
Dedicated device — kiosk. Corporate-owned hardware locked to a single purpose: one app or a small set, no home screen wandering, often no visible OS at all. The delivery scanner, the restaurant ordering tablet, the lobby check-in screen, the digital sign. Deepest lockdown of all — because the device isn't really a computer to its user, it's an appliance.
The trade every model makes
| Model | Control depth | User privacy | Typical enrollment |
|---|---|---|---|
| Fully managed | Total | N/A — no personal life on device | Zero-touch programs, code-based |
| BYOD | Work container only | Structurally protected | Self-service app/profile install |
| Dedicated | Total + locked to task | N/A | Zero-touch programs, code-based |
The pattern to internalize: control and privacy aren't a dial the admin sets — they follow from ownership. Push corporate-grade control onto a personal phone and you get either legal exposure or staff revolt; give kid-gloves BYOD treatment to a corporate scanner fleet and you get theft, drift, and support tickets.
Scenario practice
A sales team's personal iPhones needing mail and CRM → BYOD. Two hundred company-issued rugged handhelds in a warehouse → fully managed. Price-checker tablets bolted to store shelves → dedicated. A company phone the exec also uses privately → COPE. Four sentences, four correct scoping calls — most deals are lost or won on getting exactly this right.