Should Employees Use Personal Devices for Work?

lady holding phone while working on a laptop

Summary: Allow personal devices only for approved work, through approved apps, and when the device meets your security requirements. Use company-owned devices for administration, sensitive work, or jobs that require large amounts of data to be stored locally.

Employees often use personal devices for work long before the business has actually made a decision about it. They add work email to a phone, download a file to a home laptop, or sign into a company app from a computer shared with family.

Once business data is sitting on a personal device, you have far less control over updates, installed apps, backups, and who else uses that device. You also need a way to remove company data when the employee leaves, or the device gets lost โ€” which is where things get genuinely tricky.

Personal devices can absolutely be allowed. But the business should decide which devices, applications, and types of work are permitted โ€” not let it happen by default. That’s exactly the kind of policy work a good Managed IT provider should be helping you put in place.


What BYOD Includes

Bring your own device, usually shortened to BYOD, means an employee uses a personally owned phone, tablet, or computer for work.

That can include:

  • Adding work email to a personal phone
  • Signing into Microsoft 365 or Google Workspace
  • Joining online meetings
  • Opening customer or company files
  • Using a business messaging app
  • Accessing accounting, CRM, or project management software
  • Downloading documents to a personal computer

Depending on the application, business information may remain in the cloud, or be downloaded to the device as messages, attachments, cached data, or files.


What You Cannot Fully Control on a Personal Device

Your IT team can set and monitor security on company-owned devices. With personal devices, employees choose which apps to install, when to update the operating system, who else uses the device, and where files get backed up. That’s a lot of decisions happening entirely outside your visibility.

Management software can enforce some rules, but the available controls depend on the device, operating system, application, and enrolment method.

Other People May Use the Device

An employee may share a home computer or tablet with a partner, child, or another family member. Separate user accounts can reduce the risk, but many personal devices are used through one shared account, all the time.

The UK National Cyber Security Centre says BYOD access should not be permitted when an employee cannot follow the required security rules. Its example includes a device that cannot keep the employee’s work separate from other family users.

Updates May Be Missing

Your IT provider may not be able to confirm whether a personal device runs a supported operating system or has current security updates.

An employee may delay an update because the device lacks storage, an older application might stop working, or the device is rarely restarted. All perfectly ordinary reasons โ€” and all of them leave a gap.

Business Files May Enter Personal Storage

A file downloaded from work email or cloud storage may remain in the Downloads folder, a personal document folder, or a device backup.

A personal cloud backup service could then copy the file to an account the business doesn’t manage. Opening the document in a personal application may create yet another unmanaged copy. It multiplies quietly.

Other Applications May Access Business Information

Personal devices contain applications chosen by the employee. Some may have permission to read files, contacts, browser activity, or information copied to the clipboard.

The business may not know which applications are installed, or what those applications can actually access.

Repairs Can Expose Business Data

A broken personal phone or laptop may be taken to a repair shop chosen by the employee. Business email, saved sessions, or downloaded files could still be sitting on the device the whole time.

Your policy should tell employees who to contact before a device is repaired, and what to do if the device can’t be opened.

Company Data May Remain After Employment Ends

Disabling an employee’s account stops future access to many cloud services. It does not remove copies that were downloaded to personal folders, opened in unmanaged applications, or copied to personal storage.

Managed work profiles and protected applications make it easier to remove company data. They can only remove the information they actually control โ€” which is not always everything.


Decide What Work Is Allowed

Set access based on the work being performed and the information involved.

You might allow employees to read work email through an approved mobile app, while requiring a company computer for customer database exports. Staff handling financial records, health information, legal documents, or large amounts of customer data may also need company-owned devices.

Administrative work should be performed from a managed device. Anyone responsible for user accounts, security settings, backups, or business systems should not be doing that work from an unmanaged personal computer.

Apply the same rules to contractors. Their access should be limited to the applications and information required for their work โ€” no more.


Security Requirements for Personal Devices

A personal device should meet your requirements before it can access company information.

Use a supported operating system. The device should run an operating system that still receives security updates. Block access from devices that can no longer install current updates.

Install security updates. Operating system and application updates should install automatically where possible. Employees should restart their devices when an update requires it.

Require a screen lock. Require a PIN, password, fingerprint, or facial recognition to unlock the device. Configure the screen to lock automatically when the device isn’t being used.

Require device encryption. Encryption helps protect stored information if a device is lost or stolen. The Australian Cyber Security Centre recommends full-device encryption when personal devices may store business information.

Encryption must be enabled before the device is lost. It also needs to be supported by a strong device password or PIN.

Require MFA. Require MFA for work email, cloud storage, and other important systems. The NCSC recommends MFA as a minimum for BYOD access.

Block rooted or jailbroken devices. Rooting or jailbreaking removes some of the operating system’s built-in restrictions. These devices should not be allowed to access company data. Detection isn’t perfect, so it should be used alongside the other security controls in this list.

Approve the applications used for work. Tell employees which applications they may use for email, messaging, file access, and other work. Where your management service supports it, prevent business information from being saved to personal storage or copied into unmanaged applications.

Use separate accounts on shared computers. A personal computer used for work should have a separate account for the employee. Other users should have their own accounts and should not know the employee’s password.

Do not allow BYOD access when work cannot be kept separate from other users of the device.

Tell employees how to report problems. Employees need to know who to contact if a device is lost, stolen, repaired, replaced, or infected with malware. Early reporting gives the business more time to disable access, check account activity, and remove managed data.


Control Business Data With Managed Apps or Work Profiles

Device and application management services can help keep work information separate from personal information.

Mobile device management (MDM) can apply settings to an enrolled device and report whether it meets company requirements. The amount of control depends on the platform and enrolment method.

Mobile application management (MAM) applies controls to supported work applications and their data. Depending on the product, it may restrict copying, block saving to personal storage, require another PIN, or remove company information from managed apps.

For example, Microsoft Intune can remove company data from protected applications when a device is lost or an employee leaves โ€” while personal information stays untouched.

Selective removal only affects data managed by the service. It cannot delete a file copied into an unmanaged application, personal backup, or unsupported storage location. A factory reset removes personal and business data together, and Microsoft warns administrators about the risk of applying full device management to computers and phones the business doesn’t own. Configure selective removal where possible, and tell employees exactly what your management service can see and do.


What Your BYOD Policy Should Cover

Your policy should answer these questions:

  • Which employees and contractors may use personal devices?
  • Which types of devices are permitted?
  • What work can be performed on them?
  • Which applications must be used?
  • Can company files be downloaded?
  • Can the device be shared with other people?
  • Which security settings are required?
  • What information can the business or IT provider see?
  • What settings can the business control?
  • Can company information be removed remotely?
  • What happens if the device is lost or stolen?
  • What must happen before the device is repaired or sold?
  • What happens when the employee leaves?
  • Who pays for mobile data, repairs, or replacement?

Privacy, employment, and data protection requirements vary between countries. Have the policy reviewed for each location where you employ people.

Employees should read and accept the policy before company access is added to their devices โ€” no exceptions, even for the trusted ones.


What to Do When a Personal Device Is Lost or Stolen

The employee should contact the business or IT Support provider as soon as possible.

Your response may include:

  • Disabling access if the device cannot be accounted for
  • Revoking active sign-in sessions
  • Removing company data from managed applications
  • Removing the device from approved-device lists
  • Checking account activity for unexpected sign-ins
  • Resetting credentials if they may have been exposed
  • Recording which company files may have been stored on the device

Remote locking and removal commands only work after the device connects to the management service. A device that remains switched off or offline may never receive the command โ€” which is exactly why encryption and account controls are still required regardless.


What to Do When an Employee Leaves

Disable the employee’s account and revoke active sessions at the agreed time. Remove company data from managed applications or work profiles.

Check whether business files were downloaded to the device, and confirm how those copies will be returned or deleted.

Remove the device from your approved-device records. Where your management service supports it, remove business applications, certificates, email profiles, and VPN settings.


When Personal Devices Should Not Be Allowed

Provide a company-owned device when:

  • The employee handles sensitive information
  • The role requires administrator access
  • Large amounts of company data must be stored locally
  • The device is shared with other people
  • The operating system is no longer supported
  • Encryption cannot be enabled
  • The business cannot separate or remove its data
  • The employee does not accept the required security controls
  • The device has been rooted or jailbroken

Company-owned devices are easier for your Managed Services provider to support because their settings and installed software are already known โ€” no surprises to manage.


Frequently Asked Questions

Can Employees Use a Web Browser Without Enrolling Their Personal Device?

You can allow browser access, but information may still remain in the browser cache, Downloads folder, saved passwords, screenshots, or active sessions. Access policies can limit the devices and browsers that are permitted. Sensitive work may still require a managed device.

Is MFA Enough to Secure a Personal Device?

MFA helps protect the employee’s account. Device encryption protects stored files, while managed applications control how company information is used and copied. You still need updates, screen locks, approved applications, and a process for lost devices.

Can the Business See an Employee’s Personal Information?

It depends on the management method. App management focuses on business applications and their data. Device enrolment can show device details and allow broader control. Give employees a written explanation of what your IT team can see, change, lock, or remove before they enrol.

Can the Business Erase a Personal Phone?

Some enrolment methods support a full factory reset, while app-only management does not. A factory reset deletes personal information as well as company data. Use selective removal for employee-owned devices where it’s available.

Is BYOD Cheaper Than Providing Company Devices?

BYOD may reduce hardware purchases, but it can add costs for management, support, security, and administration. Whether it saves money depends on the devices, applications, and work you allow.


Sources and Further Reading

NCSC: Bring your own device guidance โ€” UK guidance on BYOD security requirements.

NCSC: BYOD costs and security requirements โ€” further BYOD planning guidance.

Australian Cyber Security Centre: Risk management of enterprise mobility and BYOD โ€” ACSC guidance on managing BYOD risk.

Microsoft Learn: Protect data and devices with Intune โ€” how Intune manages devices and applications.

Microsoft Learn: Remove company data from protected applications โ€” selective removal of business data from BYOD.


Whether you’re managing a small team in Mackay or a growing workforce across Brisbane, BYOD isn’t something to ban outright โ€” it’s something to structure properly, with clear rules everyone actually understands.

If employees are already using personal devices for work, check out our cybersecurity services, or get in touch with us and we’ll help you check what they can access and whether the right controls are in place.

—

Featured Image Credit

Related Post

Hi there,

We would love to hear from you!

Send us an email

Give us a call

Headquarters

Unit 4 / 789 Kingsford Smith Drive

Eagle Farm, QLD, 4009

The Elevate Difference 3D animated woman in yellow top and blue pants, waving,

GET A QUOTE

Hi there,

We would love to hear from you!

Send us an email

Give us a call

Headquarters

Unit 4 / 789 Kingsford Smith Drive

Eagle Farm, QLD, 4009

The Elevate Difference 3D animated woman in yellow top and blue pants, waving,

GET A QUOTE

Elevate Technology Logo

Give us a call

1300 463 538

Send us an email