Services Methodology Why Us About Us Blog Get in Touch
← Back to Device Configuration Reviews
// 07F — MOBILE DEVICE HARDENING

Mobile Device Build
Review

Configuration hardening review of corporate mobile device builds, and MDM/UEM policy sets across iOS and Android — focused on device-level security posture and enrolment policy, distinct from mobile application testing.

CIS benchmarksMDM / UEM Policy ReviewiOSAndroidIntuneJamfAndroid EnterpriseBYODContainerisation
Overview

Corporate mobile fleets carry the same sensitive data as any managed endpoint, but the security review often stops at "is MDM enrolled?". Enrolment alone does not tell you whether encryption is enforced, whether compromised devices are actually blocked from accessing corporate resources, or whether BYOD containerisation is properly isolated.

Our mobile device build reviews assess device-level configuration and MDM/UEM policy sets, across iOS/iPadOS and Android against best security practices such as CIS benchmarks and NCSC/NIST mobile device guidance — covering encryption enforcement, passcode policy, app allow/deny lists, and OS update compliance.

This is a device configuration review, not an application penetration test — we assess the platform and policy surrounding managed devices; app-level testing is covered separately under our Mobile Application Testing service.

Testing Methodology
01

Scope & Baseline Selection

Agreement on device ownership model in scope — corporate-owned, BYOD, or COPE — enrolment type, and the applicable benchmarks.

02

Policy & Configuration Extraction

Review of MDM/UEM policy sets, compliance policies, and configuration profiles exported from the management console.

03

Automated benchmark Analysis

Comparison against CIS mobile benchmarks across encryption enforcement, passcode policy, application allow/deny lists, and OS update compliance.

04

Manual Review & Contextualisation

Review of conditional access integration, jailbreak/root detection, containerisation boundary for BYOD devices, and MDM enrolment security.

05

Risk Prioritisation

Findings ranked by potential to enable data exfiltration from managed applications, bypass compliance-based conditional access, or allow persistence on a compromised device.

06

Remediation Guidance & Delivery

Custom guidance (including where appropriate, configuration profiles or policy JSON) delivered alongside a prioritised fix list.

What Makes Levantis Different

We assess whether MDM enrolment actually translates into enforced security posture — the gap between "enrolled" and "compliant" is where most mobile fleet exposure sits.

Findings are delivered with practical MDM/UEM configuration guidance and commands where applicable, so remediation can be implemented without rebuilding profiles from scratch.

// In Scope

  • iOS / iPadOS managed devices
  • Android Enterprise (Work Profile & Fully Managed)
  • MDM/UEM platforms (Intune, Jamf, Workspace ONE)
  • BYOD & COPE fleets

// Standards

  • CIS benchmarks (iOS & Android)
  • NCSC mobile device guidance
  • NIST SP 800-124
  • Vendor MDM hardening guides

// Typical Duration

  • Policy set + up to 2 device profiles: 3 days
  • 5+ device profiles: price on request

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment

Know your mobile fleet hardening gaps.

MDM enrolment isn't the same as enforced security posture. Get a clear picture of what your mobile policy actually protects against.

Get in Touch