Academy
UEM Foundations · Course F1

Lesson 2 of 5

Ownership models

8 min read
In this lesson you'll learn to
  • Distinguish fully managed, work-profile, and dedicated-device postures
  • Explain the control-versus-privacy trade each model makes
  • Match a scenario to its ownership model

Before any technical decision — enrollment method, policy depth, app strategy — comes one question that settles most of the others: who owns the device?

Three postures

Corporate-owned, fully managed. The organization bought it; the organization controls all of it. Full-device policy, mandatory management the user can't remove, complete wipe rights. This is the posture for field fleets, shared hardware, and any device whose only life is work.

Personally owned — BYOD. The employee bought it; the organization manages a work container inside it. Corporate apps, accounts, and data live in the managed side; photos, chats, and everything personal stay untouched and invisible to IT. The honest trade: control is scoped to the container, and the user can remove it — taking corporate access with it, and nothing else. (You'll also hear COPE — corporate-owned, personally enabled — the hybrid where the company buys the device but carves out personal space. Think of it as fully-managed hardware wearing a BYOD glove.)

Dedicated device — kiosk. Corporate-owned hardware locked to a single purpose: one app or a small set, no home screen wandering, often no visible OS at all. The delivery scanner, the restaurant ordering tablet, the lobby check-in screen, the digital sign. Deepest lockdown of all — because the device isn't really a computer to its user, it's an appliance.

The trade every model makes

ModelControl depthUser privacyTypical enrollment
Fully managedTotalN/A — no personal life on deviceZero-touch programs, code-based
BYODWork container onlyStructurally protectedSelf-service app/profile install
DedicatedTotal + locked to taskN/AZero-touch programs, code-based

The pattern to internalize: control and privacy aren't a dial the admin sets — they follow from ownership. Push corporate-grade control onto a personal phone and you get either legal exposure or staff revolt; give kid-gloves BYOD treatment to a corporate scanner fleet and you get theft, drift, and support tickets.

Scenario practice

A sales team's personal iPhones needing mail and CRM → BYOD. Two hundred company-issued rugged handhelds in a warehouse → fully managed. Price-checker tablets bolted to store shelves → dedicated. A company phone the exec also uses privately → COPE. Four sentences, four correct scoping calls — most deals are lost or won on getting exactly this right.

Knowledge check
1. The defining trade-off of BYOD management is…
2. A parcel scanner that runs exactly one delivery app all day is which model?
3. Why do corporate-owned devices get the deepest management?