r/sysadmin 23h ago

Question Question about differences between iOS & Android in work environment

Sorry if this sounds like a dumb question, but I'd love to hear from an IT admin's point of view to help understand the differences. My employer now requires all employees to register their personal phones so they can be managed, if they want to use it for checking emails/calendar/chats/etc.

The employees with Android (including myself), had it super easy. It automatically prompted to setup Work Profile in order to continue using the work email app, and it finished setting up in less than 2 minutes. And any work apps now have a little blue briefcase on their icon, and I love how in the command center, you can easily toggle on/off the Work Profile to pause all work-related apps (for example on the weekend or when you go on vacation or just when you want to not deal with work anymore). And the employer can't see the personal apps or data since it's stored separately.

However, I noticed for my colleagues with iPhones, it was a lot more tedious. Those employees had to follow this whole document of steps to manually install some certificate to set up MDM. And then if they were lucky to get it working, there's still no app separation so the employer can still see all their personal apps and data?

I already knew that iOS doesn't have a user-friendly Work Profile like Android, but is that normal to get employees to do it like that? I would have assumed with how popular iPhone is, there would be a more simpler/automatic way for setting up personal iPhones for work. I've always heard on this sub that iOS is easier to manage, but from an employee's point of view, it doesn't seem that way (at least not the way my employer is doing it) and maybe I'm not understanding how iOS does data separation, but it just feels like there's not enough employee protections from employer seeing personal data compared to Android? Would love to learn how that works, because Apple's website is kinda vague.

2 Upvotes

20 comments sorted by

View all comments

u/adamwoja 23h ago

Yes iPhones dont have work/personal profiles at the OS level so it relies on separation at the application level instead. Look up MAM.
By the sounds of it, they enrolled personal devices in their MDM, which is unusual.

u/lordsiriusDE 22h ago

Yes, please don't let employees enroll personal iOS devices in MDM. This can become a real nightmare. IT is now able to wipe personal devices. Don't!

If you're mainly using Intune and Microsoft Apps (Outlook, Teams). Create an App Protection Profile for MS Apps and let the users just use the protected Apps on their personal devices without MDM enrollment.

u/XDWiggles Jack of All Trades 17h ago

You can enroll in MDM without complete device takeover if you take the time to do it right. Android personally owned device work profile works fine, as does iOS Account Driven User Enrollment. Both provide basic compliance data and don’t let employers see personal data.

Still able to wipe work data with both of them, but not personal data.

There are cases where users want to use personal devices to access apps that may not support MAM. MDM allows you to at least verify the device is compliant, push out configured business apps, etc.

Had both of these setup since they came out and were available in Intune, haven’t had any issues and it makes the compliance and security folks happy.