Chykalophia Docs
Google Workspace

Managing company devices (overview)

An overview of Google Workspace's mobile device management (MDM) tools — how to enforce security policies on phones and computers used to access company data.

Difficulty
Intermediate

When your team uses phones and computers to access company email and files, those devices become a security concern. If a device is lost or stolen, someone could access your business data. Google Workspace includes tools to manage and protect these devices.

Quick summary

Basic mobile management is on by default on every Business plan. It lets you see which devices have synced with your organization, require a screen lock, block a device, and remotely wipe the work account off a lost phone. Wiping a whole device, managing iPhone and iPad apps, and Android work profiles need advanced mobile management, which Google does not offer on Business Starter or Business Standard.

What is mobile device management?

Mobile Device Management (MDM) — Google's name for the whole set of tools is Google endpoint management — lets an admin:

  • See which devices are signed in to company accounts
  • Set passcode requirements for managed mobile devices
  • Remotely wipe the work account off a lost or stolen device
  • Block and unblock devices
  • With advanced management, wipe a whole device and require device encryption

Google Workspace's built-in level is called "basic mobile management." The stronger level is "advanced mobile management." You choose between them in the Admin console.

What's included in basic mobile management (all plans)

Basic mobile management is on by default, and Google supports it on Business Starter, Business Standard and Business Plus as well as the Enterprise editions. Nothing has to be installed on the phone. It gives you:

  • A device inventory — the phones and tablets that have synced with your organization
  • Basic passcode enforcement, so you can require a screen lock
  • Remote account wipe — removes the work account and its data from the device
  • Block and unblock devices
  • Android app management
  • Hijacking protection

What's included in advanced management (Business Plus and Enterprise)

Advanced mobile management includes everything above and adds:

  • Standard and strong passcode enforcement
  • Device approvals, so you can screen a device before it reaches work data
  • Remote device wipe — wipes the whole device, not just the account
  • iOS app management
  • Android work profiles (separate work and personal apps on Android)
  • Security policies, including "Require device encryption" and "Block compromised devices"
  • Fuller reporting on managed apps and device security

Users have to install a device policy app on their phone before you can manage it this way.

Accessing device management

Go to admin.google.com and sign in. You need the Mobile Device Management administrator privilege.

Click Menu, then Devices.

Click Mobile & endpoints, then Devices to see the list of devices that have accessed your organization.

Click on any device to see its details.

Wiping a lost device

If a device is lost or stolen:

In the Admin console, go to Menu → Devices → Mobile & endpoints → Devices and find the device. (You can also open the person's account page and click Managed devices.)

Point at the device and click More, then choose Wipe Account or Wipe Device.

Choose between:

  • Wipe Account — removes the work account from the device. On a personal phone, personal data and apps stay. Google suggests this one when it's a personal device and the person is leaving.
  • Wipe Device — removes all work data and apps. On an Android phone with no work profile, and on a device-enrolled iPhone or iPad, it also removes personal data and apps. On a company-owned device it resets the device to factory settings. This option needs advanced mobile management.

Click Wipe Account or Wipe Device to confirm.

A wipe happens at the device's next sync

The data is deleted the next time the device syncs. Google says that usually takes a few minutes, but it can take up to about three hours on some devices, and the wipe continues if the device goes offline in the meantime. While the device is offline, the Admin console still shows its status as Approved or Wiping, and only updates to Wiped or Account Wiped once the wipe finishes — so act quickly after a device is reported lost or stolen. Remember the person can still reach their work data from a computer or another authorised device.

Enrolling devices

With basic management there is nothing to install: it applies automatically, so a phone shows up once someone adds their work account to it. Advanced management is different — users have to install a device policy app, and on an Android phone that supports it they're prompted to set up a work profile during installation.

With advanced management you can also require admin approval for mobile devices, so a new device has to be approved before it can reach work data.

BYOD vs. company-owned devices

Bring Your Own Device (BYOD)Company-owned
Wipe approachWipe Account (protect personal data)Wipe Device may be appropriate
Policy enforcementLimited — employees may resist strict policies on personal phonesFull control
CostLower (no device purchase)Higher (hardware costs)

For small teams with BYOD, "Wipe Account" is usually the right option — it protects the business data without wiping the employee's personal phone.

Common questions

Do employees have to enroll their personal phones?

With basic mobile management there's nothing to enroll and no app to install — it applies automatically, and the phone appears in your device list once they add their work account. Advanced management needs a device policy app on the phone, and it lets you require admin approval before a new device can reach work data.

Will MDM let me see employees' personal messages or photos?

Google endpoint management manages the work or school account and its data. On Android, a work profile keeps the two sides apart: Google's own description is that "your organization manages your work apps and data while your personal apps, data, and usage remain private." Note that on a company-owned device, or a personal device someone sets up as work-only, a wipe removes everything on the device.

What's the difference between basic and advanced management?

Basic management covers the essentials — a device list, a screen-lock requirement, blocking a device, and wiping the work account off it. Advanced management adds stronger passcode rules, device approvals, whole-device wipe, iOS app management, Android work profiles and more detailed reporting. Most small businesses do well with basic management. Google publishes a feature-by-feature comparison, linked below.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page