All case studies
MDM

Mobile fleet security

How a Saudi tech company locked down 900 iOS and Android devices without touching employee privacy.

Industry

Technology

Location

Riyadh, Saudi Arabia

Duration

5 weeks

900

devices secured

0

data leaks

100%

work/personal separation

Mobile fleet security

A Riyadh-based technology company had a mixed device environment — some employees used corporate-issued iPhones, others used personal Android phones for work. There was no MDM in place, no app protection policies, and no way to wipe corporate data if a device was lost or an employee left the company. With sensitive client data flowing through personal devices, the risk was significant.

The challenge

The challenge

The company needed to secure corporate data on employee devices without monitoring personal activity — a distinction that matters both legally and culturally. They also needed a solution that worked across iOS and Android with consistent policies, and that could wipe only the work data when someone left, leaving personal data untouched.

  • No MDM — corporate data on unmanaged personal devices
  • Mixed iOS and Android fleet with no unified policy
  • No remote wipe capability for lost or offboarded devices
  • Risk of corporate data exposure through personal apps

What we built

What we built

Logistructure deployed Microsoft Intune with a work profile model — creating a secure, managed container for work apps and data on both iOS and Android, completely isolated from the personal side of the device. App protection policies prevented corporate data from being copied, shared, or saved outside of approved apps. Remote wipe was scoped to the work container only, leaving personal data untouched.

  1. 1

    Device inventory and enrollment design

    Catalogued all 900 devices, separated corporate-owned from BYOD, and designed distinct enrollment flows for each — corporate via Autopilot/ABM, personal via the Company Portal app.

  2. 2

    Work profile setup on Android and iOS

    Configured Android Enterprise Work Profile and iOS Managed Account settings in Intune, creating a clear boundary between corporate and personal data on every device.

  3. 3

    App protection policies

    Deployed Intune App Protection Policies (MAM) to block cut/copy/paste and file transfers from corporate apps to personal ones — preventing data leakage without restricting personal use.

  4. 4

    Conditional access and compliance gates

    Configured Conditional Access to block any unmanaged or non-compliant device from accessing Microsoft 365, email, and internal tools.

  5. 5

    Selective wipe and offboarding process

    Defined a repeatable offboarding workflow: when an employee leaves, the work profile is wiped remotely within minutes — corporate data gone, personal data intact.

The results

The results

All 900 devices — iOS and Android, corporate and personal — are now enrolled, managed, and compliant. The work/personal separation was well-received by employees: they kept full control of their personal side while the company gained the visibility and protection it needed.

900

devices enrolled

0

data leaks recorded

100%

work/personal separation

<5min

offboard wipe time

Our employees were worried about their privacy — they thought we'd be able to see their personal photos and messages. Once they understood that only the work container is managed, they were fully on board.

Faisal Al-Mutairi

Head of IT, Technology Company, Riyadh

Let's build it together

Ready to transform your IT?

Tell us about your fleet and where you're stuck. We'll map the path to secure, well-managed devices your team can actually rely on.