Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 11 of 37
Provisioning and distributing devices
Advice for IT administrators on how to provision and distribute smartphones, tablets and laptops to end users within their organisation.
Provisioning new devices and distributing them to end users efficiently is central to the running of an IT estate. How you choose to implement these processes will have a direct impact on the security of your deployment.
This guidance discusses some of the security aspects of provisioning and gives advice on ways to secure this part of the device lifecycle.
Why secure your provisioning process?
Before your corporate devices can be used by staff, they need to be set up to use the corporate services they need to do their job.
This setup can be done in one of three ways:
- Manually by end users following instructions (self enrolment)
- Manually by an administrator
- Automatically using zero-touch enrolment
Each of these has pros and cons, which you should take into account when developing your provisioning procedures.
There are plenty of opportunities for problems to occur during the provisioning process. For example, you may wish to allow users to enrol their devices into your MDM service themselves, using their corporate username and password. To do this, you will have an internet-connected service that permits single-factor authentication, leaving you vulnerable to credential stuffing and password spraying attacks.
You might also need to distribute devices to users in remote locations, sometimes using untrusted distribution channels. You should be confident that a device intercepted in transit can’t be used to access work data. This is especially important as un-enrolled devices will be particularly difficult to monitor without their enterprise configuration in place.
Preparing for secure provisioning
There are several separate steps we consider part of the provisioning process. You should consider each of these in turn.
| Topic | What to think about |
|---|---|
| Assigning devices to users | When you buy devices, how will you track who they are assigned to? If an issue is reported with a device (e.g. by protective monitoring) you need the ability to find out who its owner is. You may also have obligations to keep track of corporate assets. |
| Choosing who enrols the device into Mobile Device Management | There are essentially three approaches for enrolling devices into MDM:
|
| Applying any local configuration to the device | Some devices cannot be completely provisioned automatically and may require manual setup. For example, you may need to configure the firmware settings of your laptops manually (and also automate firmware updates using OEM tools). Your process might need to include steps where trusted administrators can apply settings locally before devices are given to users. If so, you will need to think carefully about how to manage administrative credentials here, as having one re-used password (e.g. a local admin account) across your entire fleet is a bad idea. Tools like LAPS (for Windows) can help with this. |
| Delivery of the device and credentials to users | You’ll need to get the device and some credentials (for the device itself, or for enrolment) to your users. However you do this, you should ensure that an intercepted device can’t be used to access your data. For example, posting devices with no passcode set is not a secure distribution method, nor is distributing a device and its passcode together. Send device passwords separately, out of band. Or, let users use their existing credentials (with multifactor authentication) to enrol themselves when they receive the device. If at any point, their password was transmitted or known to another person, they should be required to change it before they start using the device. |
| Enrolment into biometric authentication | Biometric authentication set up requires the end user to be present, so this cannot be done remotely. If you are going to allow biometrics, you should provide guidance on how your users can set this up once they receive and start using their device. |
| Securing the enrolment process and monitoring for issues | Because devices are not yet fully provisioned during enrolment, your protective monitoring solutions may not have full visibility of them. So, you may want to take additional steps to harden the enrolment process, including:
Review our Logging and protective monitoring guidance for further advice. |
How to provision securely

When provisioning and distributing devices to users, you should:
- Use zero-touch enrolment to automate as much of the device provisioning process as possible.
- Ensure any manual enrolment (such as your MDM service) endpoints are secure, including using multi-factor authentication.
- Ensure local accounts on devices have unique credentials per device, including BIOS and local administrator passwords.
- Use trusted channels such as internal email to distribute device or enrolment credentials to users. Ensure these credentials are changed at first use.
- Monitor for devices that should have been activated but have not, and/or time limit activation.
- Many MDMs support placeholder accounts for pre-enrolling devices you expect users to subsequently enrol. You should use these placeholder accounts to ensure that only expected devices are enrolled.


