Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Employee at a desk in an open-plan office with colleagues in the background

Managing devices you do not own: BYOD in practice

Almost every organisation has BYOD, whether or not it has a BYOD policy. The moment someone adds their work mailbox to their own phone, company data is sitting on a device you do not own, cannot inspect, and cannot wipe without a conversation.

5 min read Written by the ITproposal team
Short answer

Almost every organisation already has BYOD; the only question is whether the arrangement is deliberate or accidental.

Manage the data rather than the device, because application-level policy keeps your data controlled and leaves the phone alone.

The measure of the whole arrangement is what happens on someone's last day.

The two failure modes

The question is not whether to allow it. In most organisations that decision was made informally years ago. The question is whether the arrangement is deliberate or accidental.

Organisations tend to land in one of two unhappy places.

Full management on personal devices. IT enrols the phone in the same management platform used for company laptops, with the same policies. It is technically clean and it fails socially. People resent it, some refuse, and the ones who comply discover that a device wipe means their own photos too. Compliance drops, workarounds appear, and you end up with less visibility than before.

Nothing at all. Mail is added by whoever wants it, with no conditions. There is no inventory, no way to remove access when someone leaves, and no answer when a customer asks how company data is protected on mobile devices.

The workable position is between the two, and it comes from a single reframe: manage the data, not the device.

Manage the data, not the device

Modern platforms let you apply policy to the application and the data inside it rather than to the whole phone. The company mail app can require a PIN, block copy-and-paste into personal apps, prevent saving attachments to the local file system, and be wiped independently of everything else on the device.

The person keeps their phone. You keep control of your data. When they leave, you remove the company container and their photos are untouched.

This distinction matters legally as well as practically. Requiring management control over an employee's personal property raises questions about privacy and proportionality that application-level policy largely avoids. It is also a much easier conversation.

Decide what BYOD is allowed to reach

Not every system needs to be available on a personal device. Sort your systems into three groups and write the result down:

Fine on BYOD. Mail, calendar, chat, the intranet. High convenience, moderate sensitivity, well served by app-level controls.

Only with conditions. Document repositories, CRM, line-of-business applications. Available, but only through managed apps with the container policies enforced, and only on a device that meets minimum requirements.

Company devices only. Administrative consoles, finance systems, anything where a compromise would be severe. Do not make an exception for convenience here; administrative access from an unmanaged personal phone undoes a lot of other work.

Minimum conditions worth requiring

Even in the lightest arrangement, a few conditions are reasonable and enforceable through app policy rather than device control:

  • A screen lock on the device
  • An operating system version still receiving security updates
  • Not jailbroken or rooted
  • A PIN or biometric on the company app container
  • The ability for the organisation to remove the company container remotely

That last point should be stated explicitly in the policy, in plain language, so nobody is surprised by it later.

Write down what you can and cannot see

This is the part that determines whether people trust the arrangement. Most BYOD resistance comes from an accurate suspicion that the organisation can see more than it says.

Put in writing, in language a non-technical person can read: what the organisation can see (typically device model, OS version, and whether the company container is present and compliant), what it cannot see (personal apps, photos, messages, browsing, location), and what happens when someone leaves or loses the device.

A one-page document that says this clearly removes most of the objections, and it also forces you to check that your claims are actually true of the configuration you deployed.

The cost conversation

BYOD is often introduced as a saving. It partly is, and partly is not. You save on hardware. You spend on licensing for the management platform, on support for a wider range of devices and OS versions, and on the support calls that come with people using devices you did not choose.

There is also a fairness dimension. If a personal phone is genuinely required to do the job, some organisations contribute to the cost or the plan. That is a policy decision rather than a technical one, but it is worth making consciously rather than by omission.

Offboarding is the real test

The measure of a BYOD arrangement is what happens on someone's last day. If you can remove company data from their personal phone with one action, confirm it happened, and leave everything personal intact, the arrangement is working.

If the honest answer is "we ask them to delete the app", you do not have BYOD. You have data on devices you have no relationship with, and that is the situation the policy was supposed to prevent.

Starting from where you are

If BYOD in your organisation is currently informal, you do not need a project to fix it. Three steps get most of the way:

  1. Find out which personal devices currently hold company mail. Your identity provider knows.
  2. Turn on app-level protection for the company apps, and give people a deadline to comply.
  3. Write the one-page policy, including what you can and cannot see, and send it to everyone.

That is a week of work, not a quarter. What it buys is the difference between an arrangement you chose and one that simply happened.

Frequently asked

Questions we get about this

The ones that come up most often once this is on the table.

Can we require staff to use their own phone for work?

That is an employment question before it is a technical one, and the answer varies by country and by contract. Where a personal device is genuinely required to do the job, some organisations contribute to the cost. Decide it consciously rather than by omission.

Can we wipe someone's personal phone?

You should not need to. Application-level management lets you remove the company container and leave everything personal untouched, and that is the arrangement to aim for. Full device wipe on personal property is where the conflicts start.

What about people who refuse to install anything?

Give them a route that does not require it: browser-only access, or a company device for roles that genuinely need mobility. Refusal is usually about trust rather than the app, which is why writing down what you can and cannot see is worth the effort.

Does BYOD actually save money?

Partly. You save on hardware and spend on management licensing, on supporting a wider range of devices, and on the support calls that come with hardware you did not choose. It is a trade, not a saving.

Related services

Where this sits with us

The services this subject falls under.

Know which personal phones hold your company mail?

Your identity provider already knows. We turn that into a list plus a one-page policy stating what you can and cannot see. About a week of elapsed time, most of it waiting for people to comply.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.

Request a quote Call