Mobile Device Management | System Administration

COBO: Maximum Security at a Cost

12. August 2026, Avatar of Franz BraunFranz Braun

A quick message to a colleague via a private messenger. Intended for business purposes? Technically, it is still a security incident. These are precisely the everyday situations that Company Owned, Business Only (COBO) aims to prevent. With this model, companies provide mobile devices in full and strictly limit their use to business purposes. The high level of control increases security, but at the same time presents IT teams with organizational and cultural challenges.

Company Owned, Business Only – At a Glance

  • COBO means that companies provide mobile devices in full, manage them centrally, and authorize them exclusively for business purposes. Private use is prohibited organizationally and restricted as far as possible through technical means.
  • The approach maximizes control, IT security, and compliance, but reduces flexibility and can noticeably impair the Digital Employee Experience.
  • COBO is particularly suitable for regulated industries and security-critical areas where data protection, auditability, and risk minimization are more important than a high degree of freedom in device use.

The deal is simple: The more control IT has over a device, the less freedom employees have — and the greater the temptation to look for workarounds. Company Owned, Business Only (COBO) is therefore not merely a security feature. Choosing COBO has advantages and side effects, which is why it is worth taking a look at how it works in practice first.

Use Case: COBO in hospital operations

The typical day of an IT admin in a hospital shows how many balls COBO has to keep in the air at the same time. If, for example, the admin has 800 COBO smartphones in circulation, they must ensure that the devices are configured identically, have the necessary specialist applications preinstalled, and that camera and cloud functions are disabled in sensitive areas. Updates run at night during fixed maintenance windows so that hospital operations do not grind to a halt — technically clean and fully documented.

And yet, that is still not quite enough. Alongside the 800 managed devices, an unknown number of private smartphones are also in use, through which someone may quickly send a message between two shifts or share a photo for internal coordination. From the perspective of nursing staff, this is simply the fastest way to communicate during a stressful shift. From IT’s perspective, it is precisely the shadow IT that COBO was supposed to prevent: unencrypted communication, unclear storage locations, and no traceability.

For the admin, this means that a well-managed device fleet is only half the battle. Without employee acceptance, COBO remains purely theoretical.

Company Owned, Business Only – explained simply

Company Owned, Business Only (COBO) describes a device model in which companies provide their own smartphones, tablets, or laptops for employees and consistently restrict their use to professional purposes. The IT department centrally controls configurations, apps, network settings, and security policies. Private use is prohibited by policy and prevented through technical measures such as restrictive profiles or app whitelisting.

How COBO is implemented technically

COBO stands or falls with three components: standardized hardware, end-to-end lifecycle management, and a UEM platform that is consistently enforced.

  • Device procurement: One or a few corporate device models go through the complete lifecycle: provisioning (ideally via Zero-Touch Enrollment), deployment, patch management, and defined exit processes when devices are replaced or decommissioned. Fewer variants mean less support effort and a smaller attack surface caused by inconsistent patch levels.
  • MDM/UEM as the backbone: Mobile Device Management, ideally embedded in a Unified Endpoint Management solution, handles automated policy rollout, password and encryption requirements, and remote wipe in the event of loss or theft. Whether operations are cloud-based or on-premises depends on compliance requirements: on-premises for strict data residency requirements, and cloud-based when scalability and time-to-deploy are the priority.
  • Policy layer: On top of this comes granular control, such as app whitelisting instead of pure blacklists, controlled access to cameras, microphones, and cloud storage, and network segmentation based on sensitivity levels. This keeps the software environment on every device under close control.

In most COBO environments, this is not an isolated solution but part of a Zero Trust model that also includes Enterprise Mobility Management, with continuous access verification and complete logging.

Disadvantages of COBO and impacts on the Digital Employee Experience

What gives IT security takes flexibility away from employees, and this trade-off does not always pay off. Because private communication is not possible via COBO devices, many employees also carry their own smartphone: a multi-device problem that can quickly be perceived as impractical and outdated in everyday work. In addition, restrictive policies put a strain on the Digital Employee Experience (DEX) as soon as simple tasks can no longer be completed in the way employees are accustomed to from their private digital environment.

The greater this discrepancy, the more likely workarounds become — and with them shadow IT: private messengers, cloud storage, or note-taking apps used as informal workarounds. The price is paradoxical: The very risks that COBO was intended to eliminate return through the back door. Without clear communication, training, and a genuine understanding of how people work, COBO will fail.

COBO is just one model – the right strategy makes the difference

Company Owned, Business Only provides maximum control, but it is not the best choice for every scenario.

The Best Practice Guide “Mobile Device Management (MDM) and Remote Access” helps with the assessment: When is COBO worthwhile, and when are COPE or BYOD the better options? And how can you combine device models with remote support to create a practical overall strategy?

Download the Best Practice Guide now

Why COBO is still worthwhile

However much friction COBO creates in everyday work, its advantages are significant enough that the model is virtually non-negotiable in certain environments. Organizations that work with sensitive data, strict regulations, or a high risk of attack gain three things from COBO:

  • A smaller attack surface: No uncontrolled applications, clearly defined communication channels, and no corporate data stored in consumer clouds. Centralized MDM/UEM solutions consistently enforce encryption, compliance requirements, and role-based permissions.
  • Greater standardization: Fewer device models, predefined configuration profiles, and bundled updates. This reduces support effort, shortens response times during security incidents, and lowers the risk of errors in day-to-day operations.
  • Complete traceability: At any time, it is documented which devices are in use, how they are configured, and which protective measures are in effect — a decisive advantage during audits in healthcare, financial services, or critical infrastructure.

And yes, COBO is more expensive to purchase because the company finances every device. But this additional cost almost always pays off when weighed against reduced support, troubleshooting, and incident-related effort, as well as the consequential costs of a data breach or failed audit. This is also the strongest argument for IT admins when dealing with the CIO, CISO, or executive management: In regulated industries, complete documentation is more important than the savings promised by BYOD.

COBO vs. BYOD vs. COPE: Which model is the right fit?

Ultimately, choosing between COBO vs. BYOD vs. COPE is about analyzing and weighing priorities and framework conditions.

  • COBO stands for maximum control: corporate devices, no private use, and consistently enforced policies. The focus is on data protection, compliance, and a minimal attack surface — ideal for critical infrastructure, public authorities, and highly regulated industries.
  • COPE (Corporate Owned, Personally Enabled) is the hybrid approach: corporate devices with clearly defined private use, usually separated technically through containerization. IT controls the corporate area without managing the private section — resulting in higher acceptance and a better DEX, but only with carefully designed policies and a mature UEM concept.
  • BYOD (Bring Your Own Device) relies on private devices with a work area secured by IT. High flexibility and lower hardware costs are offset by more complex data protection issues and greater coordination effort.

The following applies when making a decision:

  • High regulation, clear compliance requirements, low risk tolerance → COBO
  • A balance between control and employee satisfaction → COPE
  • A focus on flexibility and lower hardware costs → BYOD

Conclusion: Use COBO selectively, not reflexively

Company Owned, Business Only (COBO) gives companies a high degree of control, security, and compliance. In security-critical or highly regulated environments, this approach remains an important component of the device strategy. At the same time, a purely technical perspective quickly leads to acceptance problems, shadow IT, and friction in everyday work.

A future-ready IT organization evaluates COBO in conjunction with BYOD, COPE, and the Digital Employee Experience. Organizations that establish clear priorities regarding risk and regulation, understand actual workflows, and involve employees at an early stage can use COBO where it plays to its strengths. Where flexibility and user experience take priority, other alternatives should be chosen.

Read more

Entries 1 to 3 of 3