Most IT teams can tell you how many laptops they bought last year. Far fewer can tell you where all of them are now.
Device lifecycle management is the discipline of tracking and governing every company device across its full life - from the purchase order through provisioning, assignment, reassignment, repair, and finally retirement and disposal. It matters because the expensive failures don't happen while a device is in service and well managed. They happen in the handoffs: the laptop that was never collected when someone left, the spare sitting in a drawer while a new one is purchased, the retired machine that was wiped but never certified.
Device lifecycle management is the end-to-end process of acquiring, deploying, maintaining, reassigning and retiring company devices, with a continuous record of where each device is, who has it, and what condition it's in.
The distinction from device management is worth being precise about, because the two get conflated constantly. Device management - the domain of MDM and UEM platforms - is about controlling a device while it's active: pushing policy, enforcing encryption, deploying apps, wiping remotely. Lifecycle management is about the device as an asset moving through states, including states where MDM has no visibility at all: sitting in a warehouse, in transit, awaiting repair, or waiting to be wiped and resold.
A device can be perfectly managed by MDM and simultaneously a lifecycle failure - enrolled, encrypted, policy-compliant, and assigned to someone who left the company four months ago.
Deciding what to buy, for whom, and when. The common failure here is buying without visibility into what's already available - purchasing new hardware while serviceable devices sit unassigned. A reliable inventory of available stock is a prerequisite for controlling spend.
Standardizing on fewer models also compounds in your favour: fewer configuration variants, fewer spare-part lines, simpler support.
Configuring the device and enrolling it in management before it reaches the user. Zero-touch enrollment is what makes this scalable - the device ships directly to the employee and configures itself on first connection.
The lifecycle-specific requirement is that enrollment should also create the asset record: serial number, assigned user, purchase date, warranty expiry, cost centre. If enrollment and asset registration are separate manual steps, one of them will be skipped.
Getting the device to a named person and recording that assignment. The record is the point. An unassigned device is untraceable, and untraceable devices are the ones that never come back.
This is also the natural moment to connect device assignment to the employee onboarding workflow, so a new hire's device, accounts and access are provisioned as one process rather than three.
Keeping devices patched, compliant and healthy in service. This is where MDM does the work - but lifecycle management adds the asset dimension: warranty status, repair history, battery and storage health, and age relative to your refresh policy.
Condition data is what lets you replace devices because they need replacing rather than because a three-year timer expired. Some devices need replacing at two years; others are fine at five.
The most frequently mishandled stage. When an employee changes role or leaves, their device typically either follows them incorrectly, gets informally handed to a colleague, or disappears into a drawer.
A controlled reassignment means: recover the device, wipe it, re-provision for the new user, update the assignment record. Skipping the wipe is a data-exposure risk; skipping the record update means you've lost the device on paper even though it's in use.
Removing the device from service means full wipe, MDM unenrollment, removal from your identity and access records, and certified disposal or resale.
Two things routinely go wrong. Devices are wiped but not unenrolled, so they occupy licences and clutter compliance reports indefinitely. And disposal happens without a certificate of data destruction - which is exactly the document an auditor will ask for.
The financial case rests on four leaks, all of which come from missing information rather than missing tooling:
The last one connects directly to SaaS and software cost optimization - device records and licence records need to agree, and in most organizations they don't.
If you fix one thing, fix this. The window between an employee's last day and their device being recovered and wiped is the single largest concentration of risk in the lifecycle.
During that window the device typically still holds cached corporate data, may still hold saved credentials and active sessions, and often remains enrolled with valid access. In distributed organizations the window is measured in weeks, because recovery depends on shipping.
Practical mitigations, in order of effectiveness:
This is also where lifecycle management stops being an IT-operations concern and becomes a security one. An unrecovered device with valid access is an identity risk as much as an asset loss - see identity risk management for how device state feeds into overall risk scoring.
The structural insight behind good lifecycle management: device state should be derived from employee state, not tracked separately.
Most organizations maintain two disconnected systems of record. HR knows who joined, moved and left. IT knows which devices exist and roughly who has them. Nothing automatically reconciles them, so reconciliation happens during audits, by hand, and reveals discrepancies every time.
When the two are connected, each employee event has a defined device consequence:
This is the same joiner-mover-leaver logic that governs application access, applied to hardware. Running them as one process rather than two is what closes the gaps — and it's why device lifecycle and device management belong in the same platform as identity and SaaS governance rather than in a separate asset tool.
Josys ties device records to employee records, so a joiner, mover or leaver event drives the corresponding device action rather than relying on a manual handoff between HR and IT. Device inventory, assignment, SaaS licences and access all sit in one place, which means the reconciliation most teams do during audits happens continuously instead.
You can see how device and identity governance connect on the identity security and risk page, or book a demo to walk through your own estate.
Device lifecycle management is the process of governing a company device across its full life - procurement, provisioning, deployment, maintenance, reassignment, and retirement or disposal - while maintaining a continuous record of location, assigned owner and condition.
Six: procurement (deciding and buying), provisioning (configuring and enrolling), deployment (assigning to a named user), maintenance (patching, compliance and health monitoring), reassignment (recovering and re-provisioning on role change or departure), and retirement (wipe, unenrollment and certified disposal).
MDM secures and configures devices that are already in service. Device lifecycle management covers the stages before and after that - purchasing, assignment records, reassignment, and retirement. A device can be fully MDM-compliant and still be a lifecycle failure if it's assigned to someone who left months ago.
Trigger the recovery task automatically from the HR departure event rather than relying on a manual handoff. Revoke access on the last working day regardless of whether the device is back. Set a recovery deadline and remote-wipe when it passes. Then track recovery rate as a metric so the gap stays visible.
Base it on condition rather than a fixed timer. Battery health, storage health, performance against current workloads and warranty status are better inputs than age alone - some devices need replacing at two years, others remain serviceable at five. A calendar-only policy retires healthy machines early and keeps failing ones too long.