Mobile fleet security
How a Saudi tech company locked down 900 iOS and Android devices without touching employee privacy.
Industry
Technology
Location
Riyadh, Saudi Arabia
Duration
5 weeks
900
devices secured
0
data leaks
100%
work/personal separation

A Riyadh-based technology company had a mixed device environment — some employees used corporate-issued iPhones, others used personal Android phones for work. There was no MDM in place, no app protection policies, and no way to wipe corporate data if a device was lost or an employee left the company. With sensitive client data flowing through personal devices, the risk was significant.
The challenge
The challenge
The company needed to secure corporate data on employee devices without monitoring personal activity — a distinction that matters both legally and culturally. They also needed a solution that worked across iOS and Android with consistent policies, and that could wipe only the work data when someone left, leaving personal data untouched.
- No MDM — corporate data on unmanaged personal devices
- Mixed iOS and Android fleet with no unified policy
- No remote wipe capability for lost or offboarded devices
- Risk of corporate data exposure through personal apps
What we built
What we built
Logistructure deployed Microsoft Intune with a work profile model — creating a secure, managed container for work apps and data on both iOS and Android, completely isolated from the personal side of the device. App protection policies prevented corporate data from being copied, shared, or saved outside of approved apps. Remote wipe was scoped to the work container only, leaving personal data untouched.
- 1
Device inventory and enrollment design
Catalogued all 900 devices, separated corporate-owned from BYOD, and designed distinct enrollment flows for each — corporate via Autopilot/ABM, personal via the Company Portal app.
- 2
Work profile setup on Android and iOS
Configured Android Enterprise Work Profile and iOS Managed Account settings in Intune, creating a clear boundary between corporate and personal data on every device.
- 3
App protection policies
Deployed Intune App Protection Policies (MAM) to block cut/copy/paste and file transfers from corporate apps to personal ones — preventing data leakage without restricting personal use.
- 4
Conditional access and compliance gates
Configured Conditional Access to block any unmanaged or non-compliant device from accessing Microsoft 365, email, and internal tools.
- 5
Selective wipe and offboarding process
Defined a repeatable offboarding workflow: when an employee leaves, the work profile is wiped remotely within minutes — corporate data gone, personal data intact.
The results
The results
All 900 devices — iOS and Android, corporate and personal — are now enrolled, managed, and compliant. The work/personal separation was well-received by employees: they kept full control of their personal side while the company gained the visibility and protection it needed.
900
devices enrolled
0
data leaks recorded
100%
work/personal separation
<5min
offboard wipe time
“Our employees were worried about their privacy — they thought we'd be able to see their personal photos and messages. Once they understood that only the work container is managed, they were fully on board.”
Let's build it together
Ready to transform your IT?
Tell us about your fleet and where you're stuck. We'll map the path to secure, well-managed devices your team can actually rely on.