What is a mobile-device-management log?¶
An MDM log records selected enrolment, policy, command and status events for managed endpoints. It does not provide a complete user history or prove who physically held a device.
Management status has several stages¶
Records may show device IDs, assigned user, compliance, applications, certificates, check-ins and lock or wipe commands. “Sent”, “acknowledged” and “completed” can mean different things, and an assigned user is an administrative relationship. Devices may be shared, reassigned, lost or remotely accessed.
Trace device and command lifecycle¶
Identify provider, tenant, endpoint and policy, enrolment method and stable identifiers. Preserve inventory, assignment history, compliance, commands and administrator audit.
For lock or wipe, establish request, connectivity, delivery and returned confirmation. Correlate identity, endpoint, network and forensic evidence.
The point to remember
MDM records establish management events and status, not physical possession or the full effect of a command without corroboration.