Security

BYOD Policy: Should Staff Use Personal Devices?

employee mobile device

The Short Answer on BYOD

Personal devices can work for some tasks — but only when the device meets your security requirements, employees use approved apps, and the work involved is appropriate for an unmanaged device. Sensitive work, admin access, and roles that store large volumes of data locally should use company-owned equipment. Full stop.

The problem is that most businesses don’t make this decision before it’s already happened. Someone adds their work email to a personal phone, downloads a file to a home laptop, or signs into a company app from a shared family computer. Once business data lands on a personal device, you’ve lost visibility over updates, installed apps, backups, and who else touches that device.

What BYOD Actually Covers

Bring your own device (BYOD) means an employee uses a personally owned phone, tablet, or computer for work. In practice, that includes:

  • Adding work email to a personal phone
  • Signing into M365 apps
  • Joining video meetings
  • Opening customer or company files
  • Using business messaging, CRM, or project management tools
  • Downloading documents to a personal computer

Depending on the application, business information may stay in the cloud — or it may be cached, downloaded, or saved locally without the employee realising it.

What You Can’t Fully Control on a Personal Device

Shared devices and other users

A home computer or tablet shared with family is one of the biggest BYOD risks. Separate user accounts help, but many personal devices run through a single shared account. The ACSC recommends treating shared devices as high-risk for any business data.

Missing updates

Your IT team can’t always confirm whether a personal device is running a supported operating system or has current security patches installed. Employees delay updates for all sorts of reasons — low storage, an older app that breaks, or simply never restarting the device.

Files ending up in personal storage

A file downloaded from work email or SharePoint might sit in the Downloads folder, a personal document library, or a device backup that syncs to an unmanaged personal cloud account. Once it’s there, you have little control over it.

Personal apps accessing business data

Personal devices carry apps chosen by the employee — some of which may have permission to read files, contacts, clipboard content, or browser activity. The business often has no visibility into what’s installed or what those apps can access.

Data that outlasts employment

Disabling an account cuts off future access to cloud services, but it doesn’t remove files already downloaded to personal folders or copied into unmanaged apps. Without managed work profiles or protected applications, offboarding becomes a data governance problem.

Security Requirements for Personal Devices

Before any personal device touches company information, it should meet these baseline requirements — consistent with ACSC guidance and the Essential Eight:

  • Supported OS — the device must run an operating system that still receives security updates
  • Automatic updates — OS and app updates should install automatically where possible
  • Screen lock — PIN, password, fingerprint, or facial recognition, with auto-lock enabled
  • Full-device encryption — required before a device is lost, not after
  • MFA — mandatory for work email, cloud storage, and any critical system
  • No rooted or jailbroken devices — these bypass built-in OS protections and should be blocked outright
  • Approved apps only — tell employees exactly which apps may be used for work

Controlling Business Data with Microsoft Intune

Microsoft Intune supports two approaches depending on how much control you need:

Mobile Device Management (MDM) enrolls the device and applies settings across it — useful for company-owned hardware.

Mobile Application Management (MAM) applies controls only to managed work apps and their data. For employee-owned devices, this is usually the right approach. Intune can restrict copy-paste between work and personal apps, block saving to personal storage, and selectively remove company data from managed apps when an employee leaves — without touching their personal files.

Selective removal only affects data Intune manages. It can’t delete a file that was copied into an unmanaged app or personal backup. That’s why approved app lists and download restrictions matter from day one.

What Your BYOD Policy Must Address

A clear written policy should cover:

  • Which employees and contractors may use personal devices
  • Which device types and operating systems are permitted
  • What work is allowed — and what isn’t
  • Which apps must be used
  • Whether company files can be downloaded locally
  • What the business can see, control, and remotely remove
  • What happens when a device is lost, repaired, sold, or the employee leaves
  • Who covers costs for mobile data or repairs

Under the Privacy Act 1988 and Notifiable Data Breaches scheme, businesses are responsible for protecting personal information regardless of which device it sits on. Have your policy reviewed for the locations where you employ people, and make sure employees acknowledge it before any company access is added to their devices.

When to Skip BYOD Entirely and Provide a Company Device

Some roles simply aren’t suited to BYOD:

  • The employee handles sensitive or health-related information
  • The role involves administrator access to systems or user accounts
  • Large volumes of company data need to be stored locally
  • The device is shared with other users
  • The OS is no longer supported or encryption can’t be enabled

Company-owned devices managed through Intune are easier to support, audit, and secure — because your IT team knows exactly what’s on them.


If your staff are already using personal devices for work, the first step is understanding what they can access and whether the right controls are in place. Get in touch with the IT TechNinjas team and we’ll help you assess your current exposure and put a practical BYOD policy in place.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.