MDM vs MTD: why you need both

"We manage our phones with Intune" and "our phones are protected" are two different claims, and most organisations have only actually made the first one.

A hand holding a smartphone with a blank screen

MDM enforces a policy. It does not watch a device

Mobile device management — Intune, Ivanti, Workspace ONE, Jamf, whichever platform is behind it — answers one kind of question: is this device configured the way we require. Encryption on. Screen lock set. Approved apps only. Operating system current. It is a policy engine, and it does that job well.

It was never built to answer a different kind of question: what is happening to this device right now. A phishing text arriving in Messages. A malicious configuration profile silently installed. A connection to a fake Wi-Fi access point at an airport lounge. None of that is a policy violation MDM can see, because none of it touches the settings MDM is watching.

What that leaves MDM structurally blind to

  • Phishing delivered outside email — SMS, messaging apps, QR codes — none of which a mobile device management platform inspects.
  • Malicious or trojanised apps, particularly ones sideloaded from outside the official app stores, which bypass the vetting Apple and Google apply to their own marketplaces entirely.
  • Network-level attacks — rogue access points, SSL stripping, man-in-the- middle interception — that happen at the network layer MDM does not monitor.
  • Device and OS-level compromise, including jailbreak or root detection evasion techniques built specifically to look clean to a management platform's own compliance check.

The mobile threat landscape, in numbers

This is not a hypothetical gap. Zimperium's 2026 Global Mobile Threat Report recorded phishing events on employee mobile devices growing 380% since January 2025, with mobile-targeted phishing succeeding at a rate 40% higher than the equivalent attack on a desktop. SMS-based phishing alone now drives 39% of all mobile threats and 70% of mobile-based phishing specifically.

The same report found spyware present on nearly one in ten devices — over four times the prior rate — and sideloaded apps, which bypass official app store vetting entirely, on 22% of Android devices and 14% of iOS devices across nearly every industry it tracked. A well-configured MDM policy does not change any of those numbers, because none of those threats are a setting MDM enforces.

What mobile threat defense actually does

Mobile threat defense — we deploy Zimperium and Lookout MTD depending on the fleet — runs on the device alongside MDM and watches behaviour rather than configuration: network traffic for interception attempts, installed apps for known and unknown malware signatures, the OS itself for tamper or compromise indicators, and phishing links across every channel a message can arrive through, not just corporate email.

The distinction that matters operationally: MTD does not just alert. Integrated with your UEM platform, a detected threat can automatically trigger a compliance action — quarantine the device, revoke access to corporate data — without waiting for someone to read an alert first.

How the two work together

Neither replaces the other. MDM without MTD leaves you managing devices you cannot see being attacked. MTD without MDM leaves you detecting threats with no automated way to act on the device. Run together, a phishing link caught by MTD becomes a device pushed out of compliance by the UEM automatically — the detection and the enforcement in the same workflow, not a finding that sits in a dashboard until someone notices it.

Questions

Do we need mobile threat defense if our devices are already enrolled in Intune?

Enrolment alone answers "is the device configured correctly," not "is something actively attacking it right now." They are complementary controls, not a substitute for each other.

Does MTD work on personal (BYO) devices?

Yes, and it is often the better-received control on BYO devices specifically — MTD inspects for threats without the visibility into personal data that a full MDM enrolment can raise concerns about.

Which is more important to deploy first, MDM or MTD?

MDM, if you are starting from nothing — you need the enforcement point before threat detection has anything useful to act on. If MDM is already deployed and mature, MTD is usually the highest-value next control, not a third device management platform.

Mobile threat statistics in this article are drawn from Zimperium's 2026 Global Mobile Threat Report. Figures reflect the report's global dataset, not an Australia-specific measurement.

Managed devices are not the same as protected devices

We run MDM/UEM and mobile threat defense together, on whichever platform you already have.