Skip to main content
株式会社オブライト
Business DX2026-08-2210 min read

Mobile Device Management (MDM) Cost & Rollout for SMBs

Company phones and tablets bring loss, offboarding, and BYOD risks as fleets grow. This guide covers MDM costs, rollout steps, and where OS defaults suffice.


MDM (Mobile Device Management) is a system that lets a company centrally track its company-issued smartphones and tablets, remotely lock or wipe a lost device, enforce passcodes, and push business apps out in bulk. As a rough guide, monthly costs run around 300-1,000 yen per device, with initial setup typically costing 50,000-300,000 yen depending on device count and complexity. As a rule of thumb, once a company has more than about 10 devices, manual management starts falling behind and MDM becomes worth considering.

What MDM (Mobile Device Management) actually is

MDM is a cloud service that lets an administrator configure, monitor, and control multiple company devices from a single console. Typical features include tracking device location and usage, enforcing passcodes and encryption, remotely locking or wiping a lost device, bulk-installing and updating business apps, and restricting access to personal app stores. Rather than thinking of it as the company surveilling personal phones, it helps to view MDM as a tool for keeping devices that carry company data under company control.

How many devices before you need MDM

There is no hard threshold, but a few practical guidelines exist. With 5-10 devices or fewer, low staff turnover, and everyone in one department, the standard OS features described below are often enough. Once a company has more than 10 devices, distributes them across multiple locations or field staff, or has frequent hiring and departures, the cost and risk of manually configuring and recovering each device stops being negligible, and it is a reasonable time to consider MDM.

What you can handle without MDM (vs. iCloud/Google defaults)

Even without MDM, Apple's Find My iCloud, Google's Find My Device, and the built-in screen time or parental control features on iOS and Android allow remote locking and rough location checks as personal settings. However, these assume the device owner (or their personal account) is the one operating them, and a company cannot centrally monitor or enforce settings across multiple devices this way. Standard features are enough while device counts stay low, but once you need an organization-wide policy or a guaranteed wipe of a departing employee's device, that is where MDM comes in.

ComparisonStandard features (iCloud/Google account)MDM
Management unitPer device, per personal accountCentrally managed across the organization
Remote lock/wipePerformed by the individual on their own deviceAdmin can act on all devices at once
Enforcing rulesCan be undone by the user's own settingsPolicies like mandatory passcodes are enforced org-wide
App distributionInstalled individuallyBusiness apps pushed and updated in bulk
Device countPractical up to around 10 devicesMost effective above 10 devices or multiple sites
Monthly costFreeAround 300-1,000 yen per device

Typical costs

MDM pricing varies by service and contract type, but the table below gives a rough guide for small businesses evaluating the option. Some services offer free plans or trials, but these often come with feature or device-count limits, so it is a reasonable practice to budget for a paid plan for actual business use.

ItemTypical cost
Monthly fee (per device)Around 300-1,000 yen
Setup cost (in-house)0 yen (internal labor only)
Setup cost (outsourced)Around 50,000-300,000 yen
Annual total for ~10 devicesAround 40,000-120,000 yen (monthly fees only)
Annual total for ~50 devicesAround 180,000-600,000 yen (monthly fees only)
Consulting/design feesAround 100,000-500,000 yen depending on scope

Basic rollout steps

- Take inventory: list device count, OS mix (iOS/Android), users, and use cases (field sales, retail floor, factory, etc.)
- Map the risks: review past losses, gaps in device recovery at offboarding, and any BYOD usage
- Define requirements: decide must-have features (remote wipe, mandatory passcode, app distribution) plus target OS, device count, and budget
- Compare services: shortlist 2-3 MDM services that fit your scale and budget, taking advantage of free trials where offered
- Pilot it: test with a handful of devices or a single department first to work out settings and workflow
- Roll out company-wide: document usage rules, then extend to all devices in stages
- Lock in operating rules: turn periodic inventory checks, offboarding steps, and loss-response steps into an internal manual

Four steps of an MDM rollout: inventory devices, design the policy, run a pilot, then scale up and operate

BYOD (personal device use) considerations

It is common at small businesses to skip issuing company devices and instead let staff use personal phones for work email and chat. BYOD keeps hardware costs down, but it carries risks: business data may not be reliably wiped when someone leaves, and the company has little visibility if a personal device is lost. If you continue with BYOD, a practical approach is to use app-level (container-based) MDM that isolates and wipes only the business apps, or at minimum to set baseline conditions (OS version, passcode requirement) for any personal device allowed to access work data.

Initial response to a lost or stolen device

How quickly you act after a device goes missing has a big effect on how much damage occurs. Regardless of whether MDM is in place, it is worth sharing the following initial-response steps internally.

- Immediate report: make it a rule that staff report a loss or theft to their manager or IT contact the moment they notice
- Remote lock and location check: lock the device and check its location via the MDM console, or the personal iCloud/Google feature
- Change passwords: promptly change passwords for any company services (email, chat, cloud storage) the device was logged into
- Remote wipe: if recovery looks unlikely, wipe the device remotely after a set waiting period
- Suspend the line/SIM: contact the carrier to temporarily suspend service
- Log the incident: record what happened, when, and where, briefly, to inform future prevention

Don't forget device recovery at offboarding

One of the areas where MDM proves its worth is handling a departing employee's device. This needs to cover not just physically returning the device but also logging out of business accounts and wiping data, as a documented procedure. For the broader set of IT account tasks to check at offboarding, see the employee offboarding IT checklist, which is worth reviewing alongside this guide.

Pairing MDM with passwords and MFA

MDM protects the device itself, but the accounts accessed from that device also need protection. This matters especially when a company device stores login credentials for work email or cloud services, since losing the device can directly lead to account takeover. For guidance on password management and setting up multi-factor authentication (MFA), see the practical guide to passwords and MFA.

Linking MDM with IT asset management

MDM handles the "in-use" management of a device, but tracking its full lifecycle from purchase to disposal is best paired with an IT asset register. As device counts grow, it becomes easy to lose track of who has been using which device since when, so it is a reasonable practice to also maintain a device ledger, as described in how to start IT asset management, alongside your MDM setup.

What to look for when choosing an MDM service

- OS coverage: choose a service that supports both iOS and Android if your fleet is mixed
- Fit with existing tools: if you already use Microsoft 365 or Google Workspace, their native MDM features (Intune, Google Endpoint Management, etc.) are often the easiest to adopt
- Pricing structure: check whether pricing is per-device usage-based or a fixed plan
- Support: if you run IT as a one-person team, prioritize the availability of support in your language and how much setup help is offered
- Room to scale gradually: confirm the contract lets you start with a few devices and add more over time

Pre-rollout checklist

- [ ] Have you inventoried device count, OS, and users?
- [ ] Are loss, theft, and offboarding response steps documented?
- [ ] Have you checked whether anyone accesses business data from a personal (BYOD) device?
- [ ] Is the goal of adopting MDM clear (cost reduction vs. risk reduction)?
- [ ] Have you set an upper limit on budget (monthly and setup costs)?
- [ ] Have you chosen a department and device count for the pilot?

Common mistakes

A common mistake when adopting MDM is choosing a service purely on feature count without deciding the operating rules first, such as who operates the admin console and who makes the call during a loss incident. MDM tools only work when paired with clear incident-response and offboarding procedures; the tool alone does not deliver the benefit. Rolling out to every device at once and then scrambling to handle issues is also common, so it is a reasonable practice to pilot with a small number of devices, lock in the operating rules, and only then roll out company-wide.

Summary

Once a company has more than about 10 smartphones and tablets, MDM becomes worth evaluating. Costs run roughly 300-1,000 yen per device per month, and risk stays manageable by moving through inventory, pilot, and company-wide rollout stages rather than deploying everywhere at once. While device counts are low, standard iCloud/Google features can cover the basics; from there, a reasonable approach is to start small while also tightening up device recovery at offboarding, password management, and an IT asset ledger.

What is the difference between MDM and MAM (Mobile Application Management)?

MDM manages the device itself, allowing device-wide controls such as mandatory passcodes and remote wipe. MAM instead manages specific business apps, letting you isolate and wipe only in-app data even on a personal (BYOD) device. Companies with heavy personal-device use often find MAM, or a container-based approach combining both, a better fit.

Does adopting MDM mean employees' personal use is monitored too?

Most MDM services can track location and some app usage on company-issued devices, but privacy needs particular attention when MDM is applied to a personal (BYOD) device. A reasonable approach is to configure container-based management that only covers the work profile, and to explain the scope of monitoring to employees in advance.

Are there any free MDM options?

Some services, such as Apple Business Manager or certain Google features, offer near-free basic management for small deployments. However, these often come with device-count limits or reduced functionality, so a paid service becomes more realistic once you pass around 10 devices or mix multiple OS platforms.

How long does an MDM rollout typically take?

It depends on device count and complexity, but a small pilot deployment typically takes a few days to two weeks, and a full company-wide rollout around one to two months as a rough guide. If you are integrating with existing tools like Microsoft 365 or Google Workspace, spending more time on the design phase tends to make the rest of the rollout go more smoothly.

Do smartphones and tablets need separate management approaches?

Most MDM services manage devices by OS, so there is generally no need to treat smartphones and tablets differently. That said, for tablets fixed in place at a store or factory (kiosk devices), it is worth considering dedicated settings such as kiosk mode, which restricts the device to a single app.

Feel free to contact us

Contact Us