A phone is often the most exposed device an employee owns and the least governed. It holds mail, chat, documents and - importantly - the MFA token protecting everything else, and it leaves the building daily.
1. Decide the model first
- Corporate-owned - fully managed, strongest control, highest cost.
- BYOD with a managed work profile - the organisation controls a container, not the device. The common compromise.
- BYOD unmanaged with app-level controls - protection applied inside specific apps only.
Be explicit about which applies to whom, because the controls below differ sharply, and enrolling a personal device without clarity about what the organisation can see or erase causes real disputes later.
2. Baseline for every device with access
- Device encryption enabled.
- Screen lock with a non-trivial passcode and a short timeout.
- Current OS version, with a defined maximum lag behind the latest release.
- Jailbreak or root detection, blocking access on failure.
- Automatic updates enabled where you can enforce it.
- Remote wipe capability - full for corporate devices, work-container only for BYOD.
3. Access and identity
- Conditional access requiring a compliant, enrolled device for corporate data.
- Consider where the MFA token lives. A phone holding both the mail client and the authenticator is a single point of compromise - phishing-resistant hardware keys for privileged users address this directly.
- Block access from devices that fail compliance rather than merely alerting.
- Session lifetimes short enough that a lost device does not stay authenticated indefinitely.
Evidence device controls against your frameworks
GRC Copilot maps device and endpoint controls to the requirements each framework imposes, with evidence per control.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
4. Data boundaries
- Prevent copy-paste and file sharing from work apps into personal apps where the platform supports it.
- Block or control backup of work data to personal cloud accounts.
- Disable automatic photo backup for anything capturing work screens.
- Control which apps can open work documents.
5. What you cannot do on a personal device
Be honest here, because overreach is what makes BYOD programmes fail:
- You generally cannot see personal apps, messages, photos or browsing.
- You generally cannot wipe the whole device, only the work container.
- You cannot enforce OS updates as strictly as on corporate hardware.
- You can require compliance as a condition of access - which is the real lever.
State these boundaries plainly in the policy and at enrolment. People accept a work container far more readily when they understand what it does not reach.
6. Offboarding and loss
- Remove work data on departure - and confirm it happened, rather than assuming.
- A reporting route for lost or stolen devices that works out of hours.
- Revoke sessions and tokens on the device, not just the passcode.
- Deregister the MFA method if the device held one.
7. Evidence auditors ask for
An enrolment and compliance report showing coverage against your user list, encryption status, OS version distribution, evidence of conditional access enforcement, and records of wipes performed on departure.
Frequently asked questions
Can we require enrolment on personal devices?
You can make it a condition of access to corporate data. Whether you can compel it varies by jurisdiction and employment terms.
Is a work container enough?
For most organisations, yes. It protects corporate data without claiming control over the personal device.
Should authenticator and mail share a device?
It is common and it is a single point of compromise. Use phishing-resistant hardware keys for privileged accounts.
What about lost devices?
Wipe the work container, revoke sessions and tokens, and deregister MFA. A passcode change alone is insufficient.
Key takeaways
- Decide the ownership model first - the controls follow from it.
- Compliance as a condition of access is the real lever on BYOD.
- Phone holding both mail and MFA is a single point of compromise.
- On loss or departure, revoke sessions and MFA - not just the passcode.