Bring Your Own Device (BYOD) is the practice of allowing staff to use personal smartphones, tablets, and laptops to access business systems. Most Perth businesses have some form of BYOD happening - even if they have never formally decided to allow it. Staff check work email on personal phones. Remote workers access SharePoint from home laptops. The question is not whether BYOD exists in your organisation, but whether it is managed or unmanaged.
The Case For and Against BYOD
Arguments for BYOD:
- Reduces hardware costs - staff supply their own device
- Staff prefer their own familiar devices, which can improve productivity
- Useful for casual or part-time staff who don't warrant a company device
- Practical for mobile workers (sales, trades, field staff) who already carry a personal phone
Arguments against (or for careful management of) BYOD:
- Personal devices are outside your control - you cannot enforce encryption, patching, or endpoint protection
- Company data sits on devices you cannot wipe when staff leave or are terminated
- Personal devices have a different threat profile - family members may have access, malicious apps may be installed, security is typically weaker than a managed business device
- Privacy considerations - managing a personal device creates legitimate staff privacy concerns you must navigate
- Compliance complications - industries with data protection requirements (health, legal, financial) face additional obligations when sensitive data touches personal devices
The Three BYOD Approaches
Option 1: No BYOD - company devices only
The cleanest security posture. All staff use company-issued, managed devices. No company data ever touches personal devices. Works well for roles that spend most time at a desk and for industries handling sensitive data.
The downside: hardware cost and the overhead of managing a device fleet for all staff, including part-time and casual workers.
Option 2: Managed BYOD - personal devices enrolled in MDM
Personal devices are enrolled in Mobile Device Management (Microsoft Intune or similar), giving IT some control without managing the whole device. Used widely for smartphones.
Under this model, Intune applies policies to the company data and apps on the device - requiring encryption, a PIN, and the ability to selectively wipe company data - without affecting personal apps and data.
Staff consent to this as a condition of accessing company resources from their personal device.
Option 3: Unmanaged BYOD with application controls
The most common approach in Perth SMBs, often by default rather than design. Staff access email and SharePoint via browser or standard apps on personal devices with no MDM enrollment.
This can be made more secure without full MDM by using Microsoft Entra ID Conditional Access to enforce:
- MFA required on every sign-in from an unmanaged device
- Download restrictions - users can read email and view SharePoint files in browser, but cannot download attachments to personal devices
- Session limits - require re-authentication after a short period
What a BYOD Policy Should Cover
Whether you allow BYOD formally or informally, you need a written policy. It should address:
- Which devices are permitted - minimum OS version (e.g. iOS 16+, Android 12+, Windows 11), no jailbroken or rooted devices
- What company data can be accessed - email and calendar only, or also SharePoint files, internal applications?
- Security requirements on personal devices - screen lock, PIN/biometric, device encryption (required by default on iOS, optional on Android)
- What IT will and will not do to the device - selective wipe of company data only (not personal data) vs full wipe capability
- What happens when employment ends - company data must be removed from the personal device on the last day. How this is verified and enforced.
- Staff responsibilities - keeping the OS and apps updated, reporting lost or stolen devices immediately, not sharing devices with family members when company data is accessible
- Privacy - what the company can and cannot see on a personal device (MDM visibility is limited to company apps and compliance status, not personal apps, messages, or photos)
BYOD and the Privacy Act
When personal devices hold personal information about clients or customers, the Privacy Act obligations apply to that data regardless of which device it sits on. A staff member's personal phone with client email exchanges on it is subject to the same data protection obligations as a company server.
For Perth businesses in healthcare, legal, financial services, and other regulated industries, this creates specific requirements around consent, security, and breach notification that must be addressed in your BYOD policy.
Offboarding - The Highest-Risk Moment
The most common BYOD security failure is not addressing devices when staff leave. Company email, SharePoint access, and business apps remain on a former employee's personal device until actively removed - and in contentious departures, former staff may have access to company data for weeks after leaving if IT offboarding is not immediate.
Offboarding checklist for BYOD:
- Revoke Microsoft 365 / Google Workspace access immediately - this terminates active sessions on all devices
- If enrolled in MDM, trigger selective wipe of company data from the personal device
- Revoke OAuth tokens for any third-party apps the staff member connected using company credentials
- Verify completion - confirm the former staff member can no longer access company resources
Frequently Asked Questions
Do we need a formal BYOD policy if staff are already using personal phones for email?
Yes, most businesses have some form of BYOD happening whether or not it's been formally decided, so a written policy is what turns an unmanaged risk into a managed one. Without it, you have no consistent rule for encryption, what happens when someone leaves, or what IT can and can't do to the device.
What's the difference between managed BYOD and just letting staff use their own devices?
Managed BYOD enrols personal devices in a mobile device management tool like Microsoft Intune, which applies security policies to company data and apps without touching personal photos or messages. Unmanaged BYOD relies more on controls like requiring MFA and blocking downloads through Conditional Access, which is weaker but still better than no controls at all.
What happens to company data on a personal phone when someone leaves?
This is the highest-risk moment in BYOD, so it needs to be handled immediately, not whenever it's convenient. Revoking Microsoft 365 access straight away ends active sessions, and if the device is enrolled in MDM, a selective wipe should remove company data without touching the former employee's personal files.
Does a BYOD policy raise privacy concerns for staff?
It can, and it's worth addressing directly in the policy rather than leaving it vague. Properly configured MDM only sees company apps and compliance status, not personal messages or photos, but staff should be told exactly what is and isn't visible so there's no confusion later.
We help Perth businesses implement BYOD policies and the technical controls to enforce them - Intune MAM, Conditional Access, and offboarding workflows.
Cybersecurity Services →Need a BYOD policy for your Perth business?
Call 0433 087 091 - we'll review your current setup and help you implement the right BYOD controls for your business size and risk profile.
Book a Free ConsultationFor related reading, see our guides to AI Usage Policy for Staff: Using ChatGPT and Copilot Safely, Conditional Access Policy Explained: Essential but Not Bulletproof, and The Right to Disconnect: IT Policy Implications.