Skip to main content

G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog

Blog

What is BYOD (bring your own device)?

BYOD lets employees use personal devices for work. Learn how to build a BYOD policy, compare security controls, and protect privacy.

BYOD (bring your own device) is a workplace policy that lets employees use personal smartphones, tablets, and laptops for work. The policy sets three things: which devices qualify, what company resources those devices can reach, and what the company is allowed to do to a device it does not own.

This guide is for enterprise IT and security leaders who are formalizing access for hybrid employees or contractors, including teams replacing unofficial personal-device use with a written program. Cloud desktops are one of four ways to deliver that access, so this guide also covers Windows Cloud, Microsoft's umbrella term for Azure Virtual Desktop and Windows 365.

How common is BYOD in the workplace?

Roughly half of employees already use a personal device for work. Forrester's 2025 Digital Workplace and Employee Technology Survey puts adoption at 55% for mobile devices and 47% for laptops. The Mobile Security Index 2024 found 59% of organizations allow work email on personal phones. The two surveys count different populations and define BYOD differently, so read them as separate signals pointing the same direction.

Working from home explains much of that. The American Time Use Survey found 35% of U.S. employees did some or all of their work at home on days they worked. When people work from home, they reach for the device in front of them. Many BYOD programs therefore start by documenting access that already exists rather than granting new access.

What are the benefits of BYOD?

BYOD lowers hardware spend, puts people on devices they already know, frees them from a fixed location, and takes hardware out of onboarding.

  • Lower hardware spend: The company buys and replaces fewer devices. A 2022 Samsung Oxford Economics study put the savings at roughly $340 per employee per year.
  • Familiar devices: People work on hardware they already know how to use, and IT stops fielding tickets about company laptops nobody likes.
  • Location flexibility: Employees can work from home, a client site, or the road without waiting on shipped equipment.
  • Faster onboarding: Hiring a contractor no longer means running a hardware purchase first, and offboarding no longer means chasing a laptop through the mail.

One caveat on the savings figure. It assumes the company pays nothing toward the employee's device or phone bill. Several jurisdictions, California among them, require some reimbursement. The legal section below covers what that does to the math.

What are the risks of BYOD?

BYOD creates four risks. IT loses sight of the devices, company data lands where IT cannot reach it, compliance gets harder to prove, and support work grows with every new device type.

  • Devices IT cannot see: Unmanaged devices were involved in 92% of successful ransomware attacks in Microsoft's Digital Defense Report 2024. In the Verizon DBIR 2025, 46% of compromised systems holding company logins were unmanaged, which Verizon attributes mostly to BYOD programs or company devices used outside policy.
  • Data in places IT cannot reach: Company files leave IT's control the moment an employee saves them to personal storage or syncs them to a personal cloud account. A lost or stolen device is the same problem with a deadline.
  • Compliance gaps: Regulated data on personal hardware makes audit trails, retention rules, and breach reporting harder to satisfy.
  • A growing support burden: A fleet of mixed operating systems, patch levels, and hardware generations takes longer to troubleshoot than a standard build.

A fifth problem sits underneath all four. IT cannot see the software either, because personal devices run apps and cloud services nobody in IT ever reviewed.

How does shadow IT relate to BYOD?

Shadow IT is any hardware or software running in an organization without IT's knowledge, and BYOD is one of its largest sources. Every personal device arrives with apps IT did not approve and cannot inventory.

The Mobile Security Index 2025 found 45% of organizations struggle to detect shadow IT because they lack the data to spot it. In the same index, 29% of security professionals named BYOD as a heightened risk and 28% named unapproved software.

The newest version of the problem is BYOAI, bring your own AI. Microsoft's Work Trend Index 2024 found that 75% of knowledge workers use AI at work, and 78% of those AI users bring their own tools, much of it in consumer apps nobody reviewed. Each unreviewed app is a decision the company never got to make, which is the argument for picking a device-ownership model on purpose instead of inheriting one by default.

What is the difference between BYOD, CYOD, COPE, and COBO?

The four models differ on one question: who buys the device, and how much control does IT get in return. Under BYOD the employee buys it and IT gets the least control. Under COBO the company buys it and IT gets the most.

  • BYOD (bring your own device): The employee owns the device. Lowest hardware cost, least IT control.
  • CYOD (choose your own device): The employee picks from a list of devices the company approves and buys. IT keeps control, and the company keeps the bill.
  • COPE (corporate-owned, personal use allowed): The company owns the device and permits personal use on it. More flexible than a locked-down device, though mixing personal and company data on one device still requires careful separation.
  • COBO (corporate-owned, business-only): Company device, work use only. Most IT control, highest hardware cost.

Many organizations do not pick one. A common split is BYOD for contractors and field staff, COBO for the roles handling regulated data. Whichever mix you land on, the rules have to be written down.

What should a BYOD policy include?

A workable BYOD policy covers device requirements, data handling rules, support boundaries, and a signed user agreement. Together those four answer which devices qualify, what they may do with company data, who fixes what, and what the employee has consented to.

  • Device requirements: The minimum operating system version, screen lock, and disk encryption a device needs before it connects.
  • Data handling rules: Where company data may be opened and stored, and which apps employees may use to handle it.
  • Support boundaries: What IT will fix (work apps and access) and what stays the employee's problem (cracked screens, personal software).
  • A signed user agreement: CISA mobile guidance recommends agreements that "clearly define each device's purpose" and specify "the conditions warranting disciplinary action." The agreement is also where the employee consents to remote wipe, which matters on the day someone leaves.

Revisit the agreement and the access level together whenever someone changes roles. A promotion can change both what the person needs to reach and what they agreed to.

How should you tier BYOD access levels?

Give the least-controlled devices the fewest resources. NIST SP 800-46 recommends exactly this, "such as allowing organization-owned personal computers (PCs) to access many resources, BYOD PCs and third-party controlled client devices to access a limited set of resources, and BYOD smartphones and tablets to access only one or two lower-risk resources."

In a three-tier version, tier one gets email and calendar only. Tier two adds broader app access, on the condition that the device is encrypted and the user signs in with strong authentication. Tier three, full access, is reserved for managed devices or for virtual desktop sessions set up so data never lands on the device. Tiering also keeps the program affordable, because the strictest controls only have to cover the smallest group.

What happens when a personal device is lost or stolen?

The employee reports it, a named administrator removes company access or data, the team resets that user's credentials, then someone reviews what the account could reach while it was exposed.

Two details decide whether that sequence works. Employees need one reporting path and a stated deadline, because a phone reported three days late is a different incident. And the employee's consent to the remote action belongs in the signed user agreement rather than in a phone call during the incident.

How do you secure BYOD devices?

Four approaches secure BYOD. You can manage the whole device, manage only the work apps, wall the work apps off inside a container, or keep the apps and data in the cloud and stream a desktop to the device. Each approach draws the line between company and personal in a different place.

Approach

What it controls

Device enrollment

Effect on personal data

Mobile device management (MDM) / unified endpoint management (UEM)

The whole device

Required

Broad IT control of settings and compliance

Mobile application management (MAM)

Work apps only

Not required

Policies don't apply in personal use

Containerization

An encrypted zone for work apps and data

Container only

IT sees nothing outside the container

Virtual desktops and Cloud PCs

Apps and primary data running in the cloud

None

Settings control what can copy to the device

 

Mobile device management (MDM) and unified endpoint management (UEM)

MDM and UEM enroll the entire device, which gives IT control over its settings, its configuration, and whether it meets company security rules. That is the most control of any option, and on personal devices it is also the biggest ask.

NIST SP 1800-22 builds its reference design around this approach, layering threat detection, app review, and VPN services on top of device management. The depth suits company-owned hardware. On employee-owned hardware, the enrollment requirement is usually where the program stalls, because employees resist handing their own phone over to corporate management.

Mobile application management (MAM)

MAM manages the work apps and leaves the rest of the device alone, which is how it gets past the enrollment problem. NIST SP 800-124 notes that MAM can address employees' privacy concerns precisely because it requires no enrollment and no company profile on the device.

Microsoft Intune does this with app protection policies, which protect company data whether or not the device is enrolled. Per Microsoft: "User productivity isn't affected and policies don't apply when using the app in a personal context."

Containerization

Containerization puts work apps and data inside an encrypted, sealed-off area of the personal device. IT controls everything inside that area and sees nothing outside it. Per NIST SP 800-124, "secure containers provide software-based data isolation designed to segment enterprise applications and information from personal apps and data."

Virtual desktops and Cloud PCs

Virtual desktops move the line furthest of the four. The apps and the data run in the cloud, and the personal device acts as a screen, keyboard, and mouse. NIST SP 800-46 (previously cited) states: "VDI is particularly helpful for safeguarding telework on BYOD and third-party-controlled devices, which are more likely than organization-issued devices to not meet the organization's security requirements." It is the same isolation idea behind virtual desktop infrastructure (VDI), the older on-premises version.

Both Windows Cloud services support this pattern, and many enterprises run both for different groups of workers. With a Windows 365 Cloud PC, the virtual disk and content sit in the Azure region where administrators create the Cloud PC. With Azure Virtual Desktop, app-related data resides in the Azure region you pick.

Choosing the region keeps the main copy of the data in the cloud, but it does not stop data from moving to the device. Four routes stay open until an administrator closes them: copy and paste, mapped local drives, browser downloads, and printing.

Device support decides whether this is practical. The Windows 365 web client runs on Windows, Mac, iOS, Android, ChromeOS, Linux, and LG webOS 23, so almost anything an employee already owns can reach a company desktop under those controls.

How does Zero Trust apply to BYOD?

Zero Trust assumes no device is safe because of who owns it or what network it is on, which is the assumption BYOD requires. Every request gets checked against identity and device condition, and the check repeats during the session instead of happening once at login.

NIST SP 800-207 names this use case directly, covering "bring-your-own-device (BYOD) policies that allow enterprise subjects to use nonenterprise-owned devices to access enterprise resources." A valid password is no longer enough to open a company resource.

Microsoft's Intune Zero Trust guidance gives an order to work in. Start with app protection policies, which need no device management at all. Then work with the identity team to add Conditional Access policies that require an approved app or a compliant device before a resource opens.

Identity carries more of the load here than it does with company hardware. CISA's Zero Trust Maturity Model v2.0 notes that agencies "employing BYOD policies will likely have fewer options to maintain visibility and control of such devices." Fewer options on the device means the checks move to sign-in and to the session itself. Employees, reasonably, want to know how far those checks reach.

What can an employer see on a personal device?

Less than employees usually assume. On a personal device enrolled in Microsoft Intune, the organization cannot see calling or web browsing history, email and text messages, contacts, calendar, passwords, photos, or documents the employee created. Under MAM, where the device is never enrolled, IT sees only the managed work apps.

NIST SP 1800-22 (previously cited) lists five privacy risks in BYOD programs, including wipe actions that delete personal data by accident and data collection broad enough to count as employee surveillance. Its reference design routes personal app traffic outside the company VPN so personal browsing stays invisible to IT. Enrollment choices, agreement wording, and VPN setup all need to line up with the same boundary.

Regulators expect similar restraint. The UK ICO warns that "excessive monitoring is likely to intrude into workers' private lives and undermine their privacy and mental wellbeing," and requires a data protection impact assessment before any monitoring likely to pose a high risk to workers. Writing the boundaries into the BYOD agreement is what turns a privacy promise into something an employee can check.

What are the legal and HR requirements for BYOD?

Two questions fall outside the security team's control. Does the company have to pay employees for using their own hardware, and which roles are allowed in the program at all? Both need answers before enrollment opens.

Does an employer have to reimburse BYOD costs?

It depends on where the employee works. California Labor Code §2802 requires employers to reimburse necessary work expenses, and using a personal phone for work generally calls for reasonable reimbursement.

Practice lags the law. The 2025 SHRM Employee Benefits Survey found 55% of employers offer a home equipment subsidy, averaging a maximum of $888 a year, and 62% of those programs cover cellphone service. A 2024 academic review found 61.8% of BYOD employees get no stipend at all. Check the rules in every state and country where your people work, then subtract whatever you owe them from the hardware savings.

Which roles should be excluded from BYOD?

The usual exclusions are roles that handle regulated data and roles whose business communications must be recorded. Healthcare, financial services, and government teams are the common examples, and a company-issued device is the answer where the risk is too high.

Keep participation voluntary for everyone else. A mandatory program penalizes employees who do not own a suitable phone or laptop, so publish the costs, the eligibility rules, and the company-device alternative before anyone enrolls.

How do you onboard and offboard BYOD devices?

Onboarding takes four steps. The employee confirms the device meets requirements, signs the user agreement, enrolls the device or installs the protected apps, and gets an access level. Offboarding takes two. Remove company data and access, then close the account. Remote hires can finish onboarding the same day, which is a large part of why BYOD suits hybrid teams.

Offboarding is where the privacy promises get tested, so define it before the program starts. Microsoft Intune offers two actions with very different outcomes. The Intune Retire action removes company data and leaves personal data in place, which Microsoft calls "ideal for personally owned devices." Wipe resets the whole device to factory condition. For apps managed through MAM, selective wipe clears company data out of those apps and touches nothing else, though it can take up to 30 minutes to run.

Consent decides which of those you may use. The Canadian Centre for Cyber Security states that a full wipe "should not be performed unless the user consents, as it would erase the personal data of the owner." Deleting data is also only half the job. Revoke network access and close the account, because a wiped device with a valid sign-in token can still connect.

BYOD security best practices

Eight controls make a BYOD program defensible, and they work as a set because no single one covers every risk above.

  1. Require multifactor authentication (MFA) everywhere: Microsoft's Digital Defense Report 2025 reports that MFA blocks over 99% of identity-based attacks. CISA's mobile communications guidance goes further and recommends phishing-resistant options like FIDO hardware keys or passkeys.
  2. Encrypt company data in transit and at rest: On the device, inside containers, and in the cloud services behind them.
  3. Match access to risk: A personal phone never reaches as far as a managed workstation. For teams outside the office, the top access level can run through a virtual desktop session and keep company data off the device entirely.
  4. Treat remote wipe as one layer, not the plan: NIST's 2013 mobile device guidelines call remote wipe "a fundamentally unreliable security control" and tell organizations to treat it as one layer among several.
  5. Require timely updates: CISA's mobile guidance recommends weekly or automatic software updates on mobile devices.
  6. Train employees: The human element shows up in roughly 60% of breaches in Verizon's 2025 Data Breach Investigations Report (previously cited), and BYOD puts more of the attack surface in employees' hands.
  7. Review the policy on a schedule: Device platforms, threats, and employment rules all change faster than an annual review assumes.
  8. Audit access periodically. Check which personal devices still hold company access and remove the ones that no longer qualify. CISA's Zero Trust Maturity Model v2.0 (previously cited) sets the goal as continuous verification across the full life of every device.

Run together, these eight turn BYOD security into ongoing operational work across identity, devices, and cloud desktops. That is the part somebody has to do every day.

How Nerdio helps with BYOD

Nerdio Manager for Enterprise puts the daily work of running cloud desktops for BYOD into one console: Cloud PCs, Intune policies, and Azure Virtual Desktop session hosts in the same place. That covers Windows 365, Microsoft Intune, and Azure Virtual Desktop, which simplifies the work for enterprises running both Windows Cloud services side by side.

Application delivery and policy recovery

Nerdio Manager extends Intune app delivery through Unified Application Management, so admins install applications on Cloud PCs and update them in bulk rather than device by device. It also backs up and restores Intune policies, which native Intune cannot do once a policy has been deleted. In a BYOD program where app protection policies carry much of the security load, that restore path is the difference between a fast fix and a rebuild.

License and Cloud PC right-sizing

Oversized Cloud PCs are easy to miss, and so are licenses that three shift workers could share. Nerdio Advisor flags Cloud PCs sized larger than their usage warrants and recommends Windows 365 Flex (previously called Frontline) license conversions where users never work at the same time. Windows 365 pricing is predictable by design, and Advisor is how teams keep that predictable spend matched to who is working as the BYOD population changes.

Cost control for Azure Virtual Desktop

An idle Azure Virtual Desktop session host keeps billing for compute until something powers it down and deallocates it, and deallocation is the step that stops the compute charge. Nerdio Manager's auto-scaling does both outside working hours. Penn State reported a 71% reduction in Azure Virtual Desktop spend while supporting 1,000+ users.

Scoped administration and change tracking

Role-based access control limits which admins can act on which Cloud PCs and host pools, so the person who can wipe an employee's device is the person the policy names. The audit log records who changed what and when.

Build a controlled BYOD program

A workable BYOD program sets access levels, protects employee privacy, and matches controls to the risk of each device and role. Nerdio Manager supports the enterprise teams running Windows 365, Microsoft Intune, and Azure Virtual Desktop as part of that operating model. If cloud desktops are the delivery route you are weighing, read next on how to manage Windows 365 with Intune.

Get a demo or try it free to see how Nerdio Manager handles cloud desktop and endpoint management for BYOD.

Frequently asked questions about BYOD

Ready to get started?