Skip to main content

Glossary

Application management

Application management is the part of device management that deals with the software rather than the hardware: which apps reach a device, how they're configured, how they're updated, and what happens to their data when a user leaves. For an IT team the precise term is MAM, mobile application management, and this entry exists to point the longer wording at the right concept.

How it works

Two words, one idea. Admins say "application management" when they're describing the problem and "MAM" when they're buying the tool. Vendors use both: Microsoft calls its version Intune app protection policies, Google talks about managed apps in Android Enterprise, Apple's term is managed apps on iOS and iPadOS.

Whatever the label, the mechanics rely on what the OS exposes. A managed app is installed by the management server, which owns it: it can push settings through managed app configuration, block the app from sharing data with unmanaged apps, force an update, and remove the app with its data. Public apps arrive through Managed Google Play or Apps and Books in Apple Business Manager; private ones come from your own uploads.

There's an important fork. Device-based application management assumes the device is enrolled and uses the OS controls above. Standalone application management, often called MAM without enrollment, wraps each app in an SDK or a container so it can be governed on a personal phone the company doesn't manage. The second approach needs the app vendor's cooperation and works with a shorter list of apps; Intune's app protection policies are the best-known example.

Why it matters for a fleet

Enrolling 300 devices is the easy part. The hard part is the 14 apps the warehouse team needs, two of which are built in house and updated monthly, plus the mail client that must not let a spreadsheet land in a personal cloud drive.

Application management is also the answer to the BYOD question. On a personal phone you don't want, and under GDPR shouldn't have, control over the whole device. Managing the work apps and their data, then wiping only those when the person leaves, is the proportionate option.

The catch: standalone application management without enrollment gives you no say on the OS version, the passcode or the encryption of the device around the apps. For anything that handles sensitive data, the combination of enrollment and app-level control is what most fleets end up with.

How Appaloosa handles it

Appaloosa's application management is built around an enterprise app store per fleet: public apps from Managed Google Play and Apple VPP, private apps from your own APK and IPA uploads with versioning and per-group assignment, Custom Apps through Apple Business Manager, and managed app configuration pushed at install. On personal devices it manages the work side only, through the Android work profile or a BYOD enrollment link on iOS, and removes work apps and their data without touching anything else. The full feature list sits on the Mobile Application Management page.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

Ready to try Appaloosa? Start free

Frequently asked questions

Is application management the same as MAM?
Yes. MAM is the acronym for mobile application management, and application management is how the same need is usually phrased before someone learns the acronym. Both cover app distribution, configuration, updates and data protection on mobile devices.
Can I manage apps without enrolling the device?
Partly. Standalone MAM wraps apps with an SDK so policies apply inside the app on an unenrolled phone, which works for a limited set of apps such as the Microsoft 365 suite under Intune app protection. You get no control over the device itself, so it suits low-sensitivity BYOD cases rather than regulated data.
What happens to app data when an employee leaves?
With managed apps, the MDM removes the work apps and their data in one action, a selective wipe. On Android the whole work profile is deleted; on iOS the managed apps and accounts deployed by the MDM go. Personal apps, photos and messages stay untouched on the device.