I actually saw this post come across Twitter as I’m setting up Apple’s MDM through OS X Lion Server. The ability to provide company access to a device (like setting up their Exchange account with one simple input of their Windows domain password), but be able to remove all of that without touching the other settings on the device is quite nice. Our BYOD settings will allow the end-user to remove the profile, but anything that came with it – Exchange, Wi-fi SSID info, web links, pushed-out volume-purchase apps, passcode/lock requirements, forcing encrypted backups, etc. automatically leave as well.