Skip to content

Employer device versus personal device at home.

Work device: employer manages, patches, can wipe. Personal device (BYOD): employee owns, employer has limited rights. For SMB we recommend work-device-only, BYOD is a legal and security minefield.

Try this first

  1. 1Policy: work device mandatory for production data, personal device only for webmail.
  2. 2Work device gets MDM (Intune, Jamf, Kandji), patches, EDR, encryption, lock policy.
  3. 3Personal device: only via MAM (mobile app management) or a ZTNA portal, no full device access.
  4. 4On exit: work device returned within 5 business days, personal device only work-data wiped via remote-wipe app.

When to bring us in

A key person refuses a work device (consultant, temp): either sign a strong BYOD agreement with audit rights, or supply a laptop on loan for the duration anyway.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.