Your office manager checks Outlook on her own iPhone at the ballgame. A bookkeeper opens a client spreadsheet on his home laptop. A nurse texts a coworker a question about a patient. None of those devices belong to the business, and every one of them is part of your bring your own device (BYOD) program, whether you wrote a BYOD policy or not.
We write BYOD policies for our clients, and the right answer differs from one organization to the next. Some protect company data inside the work apps only. Some fully enroll personal devices. Some decide personal devices aren’t allowed for work and issue company phones. All three are reasonable. The point is to choose on purpose and write it down.
Key takeaways
- If staff read work email on personal phones, you already have a BYOD program, and it needs written rules.
- Microsoft Intune app protection can secure company data inside Outlook, Teams and OneDrive without managing the whole phone.
- Tell staff plainly what the business can and can’t see. Privacy is the biggest source of pushback.
- Plan the last day before the first: how company data and accounts come off a personal device when someone leaves.
What a BYOD policy must cover
- Who is eligible, and which roles must use a company-owned device instead, such as anyone handling large volumes of patient or financial records.
- Supported devices and minimum versions, limited to current iPhone, Android, Windows and Mac versions that still get security updates.
- Required controls: screen lock, current updates, the approved work apps, and multi-factor authentication.
- Where company data may and may not go: no saving to personal cloud storage, no forwarding to personal email, no texting client information.
- Business calls and texts through your business phone system’s mobile app, so clients reach a company number, not a personal one.
- What the business can see, what it can’t, and what it will remove.
- How to report a lost or stolen device, the same day.
- Reimbursement, if any. A California appeals court ruled in 2014 that employers there must reimburse a reasonable share of personal cell phone bills used for work.
- What happens to company data and accounts on the last day.
BYOD security: three ways to protect company data
You no longer have to choose between ignoring personal phones and taking full control of them. With Microsoft 365, there are three practical approaches, and they match the choices we see clients make.

| Approach | What IT controls | Good fit |
|---|---|---|
| App protection, no enrollment | Company data inside Outlook, Teams, OneDrive, Word and Excel | Most personal phones in most offices |
| Work profile or user enrollment | A separate work container, plus settings like Wi-Fi, VPN or certificates | Staff who need more than email and files |
| Company devices only | The whole device | Roles handling large volumes of regulated data |
Microsoft documents that Intune app protection policies can require a PIN or biometric to open company data, block copy and paste into personal apps, stop saving company files to personal storage, encrypt company data at rest, and wipe only company data when a device is lost or someone leaves. Android’s work profile and Apple’s account-driven user enrollment keep work and personal data apart without wiping the phone to set up.
Then make the rules stick. A Microsoft Entra Conditional Access policy can require app protection before an iPhone or Android device reaches company email and files, which blocks sign-in through the phone’s built-in mail app or an unknown third-party app. Pair it with multi-factor authentication on every account. Our Microsoft 365 services cover the setup.
A template outline for your BYOD policy
- Purpose and scope: which devices, apps and data the policy covers.
- Approach: app protection, enrollment, or company devices only, and which roles fall under each.
- Eligible devices and minimum operating system versions.
- Required security settings and approved apps.
- Data handling rules: where company data can be stored, shared and sent.
- Business calls and texts.
- Privacy: what the business can and can’t see, in plain language.
- Lost or stolen devices: who to tell, how fast, and what IT will do.
- Reimbursement.
- Leaving the company: removal of company data and accounts on the last day.
- Signed acknowledgment and the date of the next yearly review.
Keep it to two or three pages. A policy that still mentions BlackBerry tells employees nobody reads it, and they will treat the rest the same way.
Tell people what you can and can’t see
The most common objection to BYOD is employees asking, “Can my boss see my texts?” Microsoft publishes what an organization can see on an enrolled device. Intune doesn’t show the business personal email, text messages, call or browsing history, contacts, calendar, passwords or photos, and on a personal device the business can’t view its location. Share that page with staff, and put the same promises in your policy. Be just as clear about what you can do: removing company data from the work apps is fair, and a full factory reset of someone’s personal phone usually isn’t.
BYOD for healthcare, financial and legal firms
- Healthcare. The HIPAA Security Rule requires a risk analysis that covers electronic protected health information wherever it lives, plus device and media controls, so a personal phone with patient data belongs in that analysis. HHS has proposed requiring encryption and multi-factor authentication with limited exceptions. As of this writing that proposal is not final.
- Accounting, tax and financial firms. The FTC Safeguards Rule already requires covered firms to encrypt customer information, use multi-factor authentication for anyone accessing it, and keep an inventory of the systems and devices that hold it, personal devices included.
- Law firms. Client confidentiality duties apply on a personal phone too. App-level protection and fast removal of firm data are the practical way to meet them.
If you’re not sure how personal devices fit your risk assessment, raise it at your next compliance review.
Rollout tips
- Start with app protection for everyone who reads email on a phone, then add enrollment only for the people who need it.
- Train staff with real examples, such as a phone left in an Uber with Outlook open, and skip the signature-page-only approach.
- Have staff report a missing phone right away. Our guide to lost or stolen devices covers the first hour.
- Write down the last-day steps: disable the Microsoft 365 sign-in and revoke sessions, selectively wipe company data, remove the device from Intune and Entra ID, move the business phone extension, and record that it was done. For our clients, access is disabled the same day the client asks. Our offboarding checklist has the full list.
- Review the policy at least once a year.
If your team already uses personal phones for work and you can’t say what is protected, start there. Book a 20-minute call and we’ll help you pick the approach that fits, as part of our cybersecurity services.
FAQ
Frequently asked questions
What is the difference between MDM and MAM?
Mobile device management (MDM) enrolls and manages the whole device. Mobile application management (MAM) protects company data inside specific apps, which is usually the better fit for personal phones.
Should employees use personal laptops for work?
It is riskier than phones because laptops can store and sync far more data. If you allow it, limit access to the browser or a virtual desktop with app protection, or provide company laptops for anyone handling regulated data.
Sources: Microsoft Learn: App protection policies overview; Microsoft Learn: Protect data and devices with Microsoft Intune; Microsoft Learn: MAM and personally owned work profiles on Android Enterprise; Microsoft Learn: Set up account driven Apple User Enrollment; Microsoft Learn: Require approved client apps or app protection policy; Microsoft Learn: What information can my organization see when I enroll my device?; NIST SP 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise, 2023; HHS: Summary of the HIPAA Security Rule; HHS: HIPAA Security Rule NPRM fact sheet, 2024; FTC: Safeguards Rule, what your business needs to know; Winston & Strawn: Cochran v. Schwan’s Home Service (Cal. Ct. App. 2014).




