Eh...all simply avoidable by resetting the device/removing it from the domain.

I've used company owned phones...they are still just normal phones. As far as I know, there is no iphone/android equivalent of giving you a windows laptop with no admin account--if you have control of the phone, you can just leave the domain. You'll lose access to any of the employer's data or services, but you don't have to do anything fancy to free the device from their limited control.