Mobile and BYOD

BYOD policy guide for Australian businesses

Staff use personal phones for work email whether you have a policy or not. The right response is Intune App Protection Policies (MAM), which protects work data inside Outlook, Teams and OneDrive on any phone without enrolling the device. Full MDM is for company-owned devices only. A written BYOD policy, minimum OS requirements and a tested selective-wipe offboarding plan complete the picture.

See how App Protection works
Updated By Real Bytes

BYOD is already happening in your business

Nearly every Australian business has BYOD whether they have acknowledged it or not. Staff check Outlook on their own phone, access Teams on a personal laptop, download files to personal iCloud. The right response is not to ban it, it is to protect the work data without controlling the personal device.

Banning BYOD does not work. Staff find workarounds, forward work email to personal accounts, or use personal devices anyway. The practical approach is to accept BYOD, protect work data with App Protection Policies, and write a clear policy so everyone knows what is and is not acceptable.

What is and is not acceptable

Draw a clear line between reasonable BYOD and risky BYOD. Reasonable BYOD uses App Protection to keep work data safe on a personal phone. Risky BYOD treats a personal laptop as a primary work device with no compliance controls.

  • Reasonable BYOD

    Access email and Teams from a personal phone via App Protection. Occasional access from a personal laptop via browser. Multi-factor authenticator app on a personal phone. Short-term access for travelling staff.

  • Usually not acceptable

    Personal laptops as primary device for 9 to 5 work. Storing confidential or regulated data locally on personal machines. Personal devices with no compliance controls accessing sensitive SaaS. Personal email used to forward work files.

App Protection Policies (MAM)

The single best tool for BYOD is Intune App Protection Policies (APP, also called MAM). It protects work data inside Outlook, Teams, OneDrive, Word and Excel on any phone, without enrolling the device. Staff keep their personal photos, contacts and apps untouched, and IT controls only the work data.

  • Require PIN or biometric

    Require a PIN or biometric to open work apps. Personal apps on the same phone are unaffected.

  • Block copy-paste

    Block copy-paste from work apps into personal apps. Work data stays inside the work app boundary.

  • Block save to personal cloud

    Block save-as to personal iCloud or Google Drive. Work files stay in the managed OneDrive or SharePoint.

  • Block screenshots

    Block screenshot of work content on managed devices where the OS supports it.

  • Selective wipe

    Selectively wipe only work data at offboarding. Personal photos, contacts and messages are untouched.

  • Minimum OS version

    Require minimum OS version and app version so unsupported, unpatched devices cannot access work data.

  • Encryption enforced

    Enforce encryption on work data stored in managed apps.

  • Disable assistant access

    Disable Siri and Google Assistant access to work mail so voice assistants cannot read your email.

App Protection Policies work without device enrollment. Staff install the work apps, sign in with their work account, and the policy applies automatically. No company portal, no MDM enrollment, no control over the personal phone.

App Protection vs full MDM

Personal devices typically end up as Entra Registered, not Entra Joined. The difference changes how Conditional Access and Intune apply. App Protection (MAM) protects work data only and the device stays personal. Full MDM enrolls the entire device and gives IT control over the whole phone, which is only acceptable on company-owned devices.

  • App Protection (MAM)

    Protects work data only. Device stays personal. Works on any phone. Low staff resistance. Best for BYOD.

  • Full MDM

    Full device management. Device is company-controlled. Only acceptable on corporate-owned devices. Staff resist enrollment of personal devices. Use for company phones, not BYOD.

BYOD policy essentials

A written BYOD policy is not optional. Without it, staff do not know what is expected and managers make inconsistent decisions. The policy should be short, clear and acknowledged by every staff member before they access work data on a personal device.

  • Clear scope

    Clear statement of what is and is not allowed on personal devices.

  • Consent to App Protection

    Consent to App Protection Policies (or equivalent) before access is granted.

  • Minimum device requirements

    Supported OS, screen lock and recent patches required before access.

  • Lost or stolen reporting

    Lost or stolen device must be reported within 24 hours so work data can be wiped remotely.

  • Wipe on exit acknowledged

    Staff acknowledge that work data may be wiped on exit. Personal data will not be touched.

  • Reimbursement terms

    Reimbursement terms (if any) for data and voice plan use, stated up front.

Offboarding BYOD devices

Offboarding is where BYOD programs fail. Work data remains on ex-employee phones for months or years because no one ran the selective wipe. A tested offboarding plan, tied to the HR departure process, closes this gap.

  • Selective wipe via Intune

    Selective wipe of work apps and data via Intune. Personal photos, contacts, messages and apps are untouched.

  • Revoke at identity layer

    Revoke mail and SaaS access at the identity layer so the device cannot re-authenticate even if the wipe is delayed.

  • Confirm wipe completed

    Confirm wipe completed. Status is visible in the Intune admin console.

  • Document in checklist

    Document the wipe in the offboarding checklist so HR and IT both confirm it happened.

Selective wipe removes only the work data managed by Intune. It does not factory-reset the phone. Staff keep their personal data. This is the key difference between App Protection and full MDM, and it is why staff accept App Protection without resistance.

Common BYOD mistakes

The same mistakes repeat across BYOD programs. Pretending it is not happening, forcing full MDM on personal phones, no written policy, no wipe plan and no minimum OS requirements.

  • Pretending BYOD does not exist

    Staff use personal phones anyway. Without protection, work data leaks. Accept BYOD, protect it, write the policy.

  • Forcing full MDM on personal phones

    Staff resist enrollment. They find workarounds or refuse to use corporate apps. Use App Protection instead.

  • No written BYOD policy

    Staff do not know what is expected. Managers make inconsistent decisions. Write a short, clear policy and have everyone acknowledge it.

  • No wipe plan at offboarding

    Work data remains on ex-employee phones for months or years. Tie the selective wipe to the HR departure process.

  • No minimum OS requirement

    Years-old iOS and Android missing security patches. App Protection allows OS minimums. Set them.

How we deploy BYOD protection

We deploy Intune App Protection Policies and BYOD governance as a fixed-scope engagement. You receive configured policies, a written BYOD policy template and a tested offboarding procedure.

  1. Step 1

    Assess current BYOD state

    We review who is accessing work data from personal devices and what protection exists today. You receive a gap report.

  2. Step 2

    Configure App Protection Policies

    We configure Intune App Protection for Outlook, Teams, OneDrive and Office apps. Staff get a PIN prompt on work apps, not device enrollment.

  3. Step 3

    Write the BYOD policy

    We write a short BYOD policy template covering scope, consent, minimum requirements, lost device reporting and offboarding. You publish it to staff.

  4. Step 4

    Test offboarding wipe

    We test the selective wipe on a sample device so you can confirm personal data is untouched and work data is removed.

Common questions

What is the difference between BYOD and company-provided devices?

BYOD (Bring Your Own Device) means staff use their personal phone or laptop for work. Company-provided devices are owned and managed by the business. BYOD should use Intune App Protection Policies (MAM) to protect work data without controlling the personal device. Company-provided devices should use full MDM for complete management and compliance control.

Can my employer see my personal data on a BYOD phone?

With Intune App Protection Policies, no. The policy protects work data inside work apps only. Your personal photos, contacts, messages and personal apps are untouched. IT cannot see your personal data, wipe your personal apps, or track your location. The selective wipe at offboarding removes only the work data managed by Intune.

Do I need Intune for BYOD?

Intune App Protection Policies are the standard for protecting work data on personal devices in a Microsoft 365 environment. If you use Microsoft 365, Intune is included in Business Premium and is the right tool. Alternatives exist in other ecosystems but Intune is the most common choice for Australian SMBs because it integrates with Entra ID and Conditional Access.

What happens to my work data if I lose my BYOD phone?

You report the lost device to your IT team within 24 hours (or whatever your policy states). IT issues a selective wipe from the Intune console, which removes work data from the device the next time it connects to the internet. Your personal data is not affected. IT should also revoke your mail and SaaS access at the identity layer so the device cannot re-authenticate.

Is BYOD secure enough for regulated industries?

Yes, with the right controls. App Protection Policies enforce encryption, block data exfiltration to personal apps, require PIN or biometric access, and allow selective wipe. Combined with Conditional Access (which blocks non-compliant devices), MFA and a written policy, BYOD meets the device security expectations of most Australian regulators and cyber insurers. The key is enforcing the controls, not just having the policy.

Should I use MDM or MAM for BYOD?

Use MAM (Intune App Protection Policies) for BYOD. MAM protects work data inside work apps without enrolling the personal device. Use MDM (full mobile device management) for company-owned phones and tablets only. Forcing MDM on personal phones causes staff resistance, workarounds and refusal to use corporate apps. MAM gives you the data protection you need without the privacy conflict.

Secure BYOD without taking over personal devices

We deploy Intune App Protection Policies and BYOD governance so staff can use personal devices safely and work data stays protected. You receive configured policies, a written BYOD policy template and a tested offboarding procedure. Tell us your device landscape and we will scope the deployment.