On User Enrolled (BYOD) devices, can MDM take over management of an application that was installed manually by the user?

No. On devices that are enrolled using Device Enrollment (Enrollment by Link) or Automated Enrollment (DEP), MDM can request and take over management of applications that were installed manually on devices, allowing the MDM to update and delete those applications.

However, when using User Enrollment (BYOD), a separate partition is created on the device during enrollment, leaving a user/personal partition and a managed partition. This is a privacy mechanism to ensure that user's personal apps and data cannot be accessed or modified by a management tool. As a result, if the user has already installed an application on their device manually through the App Store, an MDM cannot take over management of that application unless it is uninstalled manually by the user and then re-installed by the MDM.

Was this article helpful?
Still have a question or want to share what you have learned? Visit our Community Discord to get help and collaborate with others.