N-Charge • Case Study

Makwa Global: Corporate & Personal Device Management Without Compromise

How a tribal enterprise federal contractor brought corporate and personal Android, iOS, and iPadOS devices under unified MDM/MAM controls through a phased rollout — closing the device exposure surface without compromising employee satisfaction.

Client Makwa Global
Industry Defense Industrial Base
Designation Tribal Enterprise Defense Contractor
Founded 2019
Platform N-Charge
At a Glance

Headline Outcomes

Four measurable results that defined the engagement — from device coverage to employee experience.

BYOD Secured Without Compromise

Personal devices brought under controls without intruding on personal data or experience.

MDM + MAM Unified Control Plane

Device management and app protection unified inside a single Microsoft control plane.

All Mobile Android, iOS, iPadOS

Universal coverage across the entire mobile device estate — no platform left unmanaged.

Phased Zero-Disruption Rollout

Controlled, wave-based deployment that improved security and employee satisfaction simultaneously.

The Situation

A Federal Contractor Operating with a Mixed Mobile Fleet — and No Unified Management

Makwa Global, founded in 2019 as a tribal enterprise defense contractor, had already established a sovereign Microsoft 365 environment, hardened the technical posture, and operationalized identity, email, endpoint EDR, and awareness disciplines. Every major technical layer was under structured management. But the mobile device estate — corporate-issued and employee-owned Android, iOS, and iPadOS devices flowing through the federal workforce — was operating outside a unified management plane.

The problem wasn’t that mobile devices were touching CUI directly — they weren’t, by design. The problem was that identity, email, calendar, and approved Microsoft 365 apps were flowing through devices that lacked enforced encryption, screen lock policies, app protection, or revocation control. For a federal contractor, that’s not a productivity issue. It’s an exposure vector — and one that compounds quickly as a workforce grows.

Two operational realities made this harder than a “lock everything down” approach. First, a meaningful portion of the device fleet was personally owned (BYOD) — and employees were rightfully unwilling to surrender personal data, photos, or private apps to a corporate management plane. Second, Makwa’s leadership saw device management as a workforce experience opportunity, not just a control imposition. The solution had to protect federal work without intruding on personal life.

The Impact

Why an Unmanaged Mobile Fleet Was a Federal Contracting Exposure

For a federal contractor, every unmanaged endpoint that touches corporate identity, email, or M365 apps is a quiet but compounding risk. Without the N-Charge engagement, Makwa faced four concrete consequences:

📱

Identity and Data Drift to Unmanaged Devices

Identity, mailbox content, and M365 app data flowing through devices without enforced encryption, screen locks, or app protection created an exposure surface no email gateway or EDR could close.

🚫

No Revocation Path on Lost or Departing Devices

When a device was lost, stolen, or an employee transitioned, there was no clean way to remotely revoke access, wipe corporate data, or prove the action was taken — a federal audit risk waiting to happen.

⚠️

BYOD as a Privacy and Compliance Tension

Without a thoughtful BYOD model, the choice would have collapsed into “manage the whole device or manage nothing” — neither outcome respects employees nor protects federal work.

📊

Audit Posture Gap on Mobile

Federal supply chain reviews and CMMC expectations increasingly look at how mobile devices touching corporate identity are managed — and an unmanaged fleet leaves that question dangerously unanswered.

The Resolution

An N-Charge-Led Unified MDM + MAM Deployment Across Corporate and Personal Devices

Jadex Strategic Group delivered the engagement through its N-Charge platform — a structured endpoint and device control model built on Microsoft Intune, designed to bring corporate and personal devices under unified management without compromising employee experience or privacy.

01

Device Estate Discovery and Policy Design

Inventoried the corporate and BYOD device fleet across Android, iOS, and iPadOS — and designed differentiated policy paths: full MDM enrollment for corporate-issued devices and app-protection MAM (without device enrollment) for personally owned devices.

02

Corporate Device MDM Enrollment

Brought corporate-issued Android, iOS, and iPadOS devices under full Intune MDM enrollment — enforcing encryption, screen lock, compliance baselines, conditional access, and remote wipe capability across the corporate-owned estate.

03

BYOD App Protection Policies (MAM Without Enrollment)

Deployed app protection policies on personal devices that secured only the corporate Microsoft 365 apps — encrypting corporate data, blocking save-out to personal locations, and enabling selective wipe of corporate content — without touching personal photos, apps, or data.

04

Conditional Access Integration

Tied device compliance and app protection posture into Conditional Access — ensuring only managed, compliant, app-protected devices could reach corporate identity, mailboxes, and Microsoft 365 workloads.

05

Phased Rollout, Workforce Communication, and Handoff

Rolled the program out in controlled enrollment waves with clear workforce communication on what was being managed and what wasn’t — building trust, improving employee satisfaction, and transitioning ongoing operations to Makwa’s internal team.

The Outcomes

Universal Device Management — Without the BYOD Privacy Tradeoff

The N-Charge engagement closed the mobile exposure surface across Makwa’s federal workforce — unifying corporate and BYOD devices under a single, intelligently differentiated control plane that improved both security posture and employee experience.

Universal Mobile Coverage

Android, iOS, and iPadOS devices across both corporate-owned and BYOD are now under unified management — no platform left unmanaged, no device class left as a gap.

BYOD Without Privacy Tradeoff

Personal devices are secured at the app layer, not the device layer — corporate Microsoft 365 data is protected, encrypted, and selectively wipeable, while personal photos, apps, and data remain untouched.

Remote Wipe and Revocation in Place

When a device is lost, stolen, or an employee transitions, Makwa can now remotely revoke corporate access and wipe corporate data on demand — and prove it was done.

Conditional Access as the Gatekeeper

Only compliant, app-protected devices can reach corporate identity and Microsoft 365 workloads — turning device posture into an actively enforced gate, not a static configuration.

Improved Employee Satisfaction

The phased rollout, transparent communication, and BYOD privacy model improved employee satisfaction — proving that strong device discipline and respect for personal space aren’t a tradeoff.

A Stronger Federal Audit Posture

Mobile device management is now a defensible answer in federal supply chain reviews and CMMC conversations — no longer the quiet “we’ll get to that” gap in the audit story.

We wanted to protect federal work without intruding on personal life. N-Charge gave us exactly that — managed corporate devices, app-protected BYOD, and a workforce that trusted the rollout because it respected the line between the two.
Makwa Global Leadership Tribal Enterprise • Defense Industrial Base
Is Your Mobile Fleet the Quiet Gap in Your Audit Story?

Unify Device Management Without the BYOD Tradeoff.

Like Makwa, your business may already have identity, email, and endpoint discipline in place — while the mobile fleet stays the quiet gap. N-Charge brings corporate and personal devices under unified management without intruding on personal life — and closes the federal audit conversation you don’t want to be having later.