Every iPhone, iPad and Mac has a device management client built into the operating system, so there is no agent app to install. An MDM server sends a silent push through Apple Push Notification service, the device checks in over a secure connection and applies whatever the server has queued: configuration profiles for Wi-Fi, passcodes and restrictions, app installs, questions about its state, and commands such as lock or erase. On recent iOS, iPadOS and macOS versions, declarative device management lets devices apply settings and report changes on their own, which keeps dashboards current with less polling.
How much control an organisation gets depends on how a device was enrolled. Devices the organisation owns and sets up through Automated Device Enrollment are supervised, which unlocks stricter restrictions and, on iPhone and iPad, Single App Mode and Managed Lost Mode. Personal devices use User Enrollment, where the organisation manages only its own apps, accounts and data.
Running your own MDM server is a real commitment. The Account Holder of your Apple Developer Program or Apple Developer Enterprise Program membership has to contact Apple to request an MDM vendor CSR signing certificate, the MDM push certificate is renewed every year, and each OS release needs testing. That is worth it when device management is part of your product; otherwise we usually extend an existing MDM service.