Endpoints · Mobile
BYOD
Allowing personal devices to access corporate data while protecting that data without taking control of the device.
IntermediateUpdated 2026-09-01
Overview
The practical model is application level protection: corporate data is confined to managed applications with encryption, copy/paste restrictions, save as controls and selective wipe, while the device itself remains personal and unenrolled.
BYOD is as much a policy and privacy exercise as a technical one. Users must know what the organisation can and cannot see, and what happens to the device when they leave.
Security considerations
- Prefer app protection policies over full enrolment for personally owned devices.
- Require managed applications for corporate data and block unmanaged clients through access policy.
