On this page
Your employees are already using their personal phones to check work email. They’re logging into Microsoft 365 from their home laptops. They’re accessing Teams from tablets on the couch.
This isn’t a future scenario you need to plan for — it’s happening now. The question isn’t whether to allow BYOD (bring your own device). The question is whether you’re managing it or just hoping nothing goes wrong.
Why BYOD Keeps Growing
For small and mid-sized businesses — especially in Northern Ontario, where remote work, field work, and hybrid schedules are increasingly common — BYOD makes practical sense.
Cost savings. Not every business can afford to issue company devices to every employee. For most small businesses, the majority of employees use personal devices for at least some work functions — checking email on a personal phone, accessing files from a home laptop, or joining Teams calls from a tablet.
Employee preference. People like using the phone they already know. Carrying two phones — one personal, one work — is inconvenient and often leads to the work phone being left in a drawer.
Remote and hybrid work. The shift to flexible work means employees access company data from locations and devices outside your office network. Statistics Canada’s 2024 Labour Force Survey reported that 28% of Canadian workers worked at least some hours from home — a figure that remains significantly elevated compared to pre-pandemic levels.
The benefits are real. But so are the risks.
The Risks You’re Actually Facing
When an employee accesses company data from an unmanaged personal device, you have limited visibility into what happens to that data. Here’s what can go wrong:
Data leakage. An employee downloads a client spreadsheet to their personal phone, then backs it up to a personal iCloud or Google Drive account. That data is now outside your control. They share it through a personal messaging app. They lose their phone at a restaurant.
Unmanaged and unpatched devices. You update company-owned machines on a schedule. Personal devices? Many employees delay updates for months. The Canadian Centre for Cyber Security’s 2024 National Cyber Threat Assessment flagged unpatched personal devices used for work as a growing threat vector for Canadian organizations.
Lost and stolen devices. A personal phone with your company email, Teams, OneDrive, and SharePoint data is a significant risk if lost. Without management tools in place, you may have no way to remove company data remotely.
Shadow IT. Employees using personal devices are more likely to install unapproved apps and services — tools that may not meet your security or privacy requirements. This intersects directly with shadow AI risks as well.
Compliance exposure. If your business handles health records, financial data, or other regulated information, having that data on unmanaged personal devices can put you offside with privacy legislation like PHIPA or PIPEDA.
The Practical Controls: Securing Data Without Owning the Device
The good news is that modern tools — specifically Microsoft Intune, which is included in Microsoft 365 Business Premium — let you protect company data on personal devices without taking full control of the device itself.
This distinction matters. There are two approaches:
Mobile Device Management (MDM) — Full Device Enrollment
MDM gives your organization control over the entire device — enforcing encryption, requiring a PIN, controlling which apps can be installed, and enabling full remote wipe. This makes sense for company-owned devices, but most employees will not — and should not — fully enroll their personal phones in your MDM.
Mobile Application Management (MAM) — App-Level Protection
MAM is the BYOD-friendly approach. Instead of managing the whole device, you manage only the work apps — Outlook, Teams, OneDrive, SharePoint, and other Microsoft 365 apps. The employee’s personal photos, messages, and apps remain untouched.
With Microsoft Intune MAM, you can:
- Require a PIN or biometric to open work apps — separate from the device’s own lock
- Prevent copy/paste from work apps to personal apps — so company data can’t be pasted into a personal note or message
- Block saving work files to personal cloud storage — documents stay in OneDrive for Business, not personal Google Drive
- Require encryption for data within managed apps
- Remotely wipe only work data if the employee leaves the company or loses their device — their personal photos and apps are untouched
- Block access from jailbroken or rooted devices — which lack fundamental security protections
The employee never has to enroll their device. They download Outlook or Teams, sign in with their work account, and the MAM policy applies automatically. They may not even notice it’s there — until they try to copy a client’s email address into a personal messaging app and find it blocked.
Conditional Access: The Other Half of the Equation
MAM controls what happens inside work apps. Conditional Access — configured through Microsoft Entra ID — controls whether the device can access work data at all.
With Conditional Access, you can require:
- That the device runs a minimum OS version (blocking severely outdated and vulnerable devices)
- That the Intune MAM policy is active before granting access
- That access from certain locations or unknown devices triggers MFA
- That high-risk sign-ins (detected by Microsoft Entra ID Protection) are blocked or require additional verification
This means even if an employee’s personal laptop is compromised, Conditional Access can prevent it from accessing your Microsoft 365 environment based on risk signals — without you ever having touched the device.
For more on how these policies fit into a broader security approach, see our mobile device management service page.
Your BYOD Policy: What to Include
Technical controls are essential, but they work best alongside a clear Acceptable Use Policy (AUP). Your BYOD section should cover:
- Which devices are permitted — personal smartphones, tablets, laptops, or all three?
- Which apps and data can be accessed — email and Teams may be fine; accessing your ERP system from a personal device may not be
- Security requirements — minimum OS version, screen lock required, no jailbroken devices
- What happens when someone leaves — work data will be remotely wiped from their personal device; personal data will not be touched
- Reporting obligations — if a personal device used for work is lost or stolen, it must be reported immediately so work data can be wiped
- What the company can and cannot see — this is critical for trust (more on this below)
If you don’t have an AUP yet, our guide on IT acceptable use policies covers the full framework.
What NOT to Do: Respecting Privacy on Personal Devices
This is where many businesses get it wrong — and where trust breaks down.
Do not install full MDM on personal devices without clear consent and justification. Full MDM enrollment on a personal device gives the organization visibility into device location, installed apps, and browsing activity. Most employees will rightly object to this on a device they own.
Do not track location. Even if technically possible, tracking an employee’s personal phone location is a privacy violation that will damage trust and may violate Canadian privacy law. The Office of the Privacy Commissioner of Canada has issued guidance making clear that employee monitoring must be proportionate and the least intrusive means available.
Do not wipe entire personal devices. Use app-level wipe (removing only work data), not full device wipe. If you accidentally wipe an employee’s personal photos, contacts, and messages, you’ve created a legal and trust problem. Intune MAM’s selective wipe is designed exactly for this purpose.
Be transparent about what you can see. When an employee enrolls in MAM (not full MDM), Microsoft Intune explicitly shows them what the organization can and cannot see. Lean into this transparency — it builds trust. For more on getting this balance right, see our post on employer monitoring and workplace privacy.
How DVG Systems Approaches BYOD for Northern Ontario Clients
For our managed IT clients, BYOD policy and technical controls are part of the onboarding process. Here’s what that typically looks like:
- Assessment — we identify which roles need mobile access and what data they’ll access
- Policy development — we help draft or review the BYOD section of your AUP, making sure it’s clear and enforceable
- Intune MAM deployment — we configure app protection policies for Outlook, Teams, OneDrive, and SharePoint, tailored to your risk profile
- Conditional Access policies — we set up access controls in Microsoft Entra ID that enforce compliance without requiring full device enrollment
- Employee communication — we help you communicate the policy to staff in plain language, emphasizing what the company can and cannot see
- Ongoing management — we monitor policy compliance and adjust as your needs change
The Bottom Line
BYOD is not going away. Your employees are already using personal devices for work — the only question is whether company data on those devices is protected or exposed.
The tools exist to secure BYOD without spying on employees, without taking over their personal devices, and without creating friction that drives people to workarounds. Microsoft Intune MAM and Conditional Access, deployed thoughtfully, give you data protection and employee trust at the same time.
DVG Systems helps Northern Ontario businesses implement practical BYOD security that protects company data without overstepping. If your team is using personal devices for work and you’re not sure what’s protected, let’s talk.