Blog
What is BYOD (bring your own device)?
BYOD lets employees use personal devices for work. Learn how to build a BYOD policy, compare security controls, and protect privacy.
G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog
Blog
BYOD lets employees use personal devices for work. Learn how to build a BYOD policy, compare security controls, and protect privacy.
Table of Contents
BYOD (bring your own device) is a workplace policy that lets employees use personal smartphones, tablets, and laptops for work. The policy sets three things: which devices qualify, what company resources those devices can reach, and what the company is allowed to do to a device it does not own.
This guide is for enterprise IT and security leaders who are formalizing access for hybrid employees or contractors, including teams replacing unofficial personal-device use with a written program. Cloud desktops are one of four ways to deliver that access, so this guide also covers Windows Cloud, Microsoft's umbrella term for Azure Virtual Desktop and Windows 365.
Roughly half of employees already use a personal device for work. Forrester's 2025 Digital Workplace and Employee Technology Survey puts adoption at 55% for mobile devices and 47% for laptops. The Mobile Security Index 2024 found 59% of organizations allow work email on personal phones. The two surveys count different populations and define BYOD differently, so read them as separate signals pointing the same direction.
Working from home explains much of that. The American Time Use Survey found 35% of U.S. employees did some or all of their work at home on days they worked. When people work from home, they reach for the device in front of them. Many BYOD programs therefore start by documenting access that already exists rather than granting new access.
BYOD lowers hardware spend, puts people on devices they already know, frees them from a fixed location, and takes hardware out of onboarding.
One caveat on the savings figure. It assumes the company pays nothing toward the employee's device or phone bill. Several jurisdictions, California among them, require some reimbursement. The legal section below covers what that does to the math.
BYOD creates four risks. IT loses sight of the devices, company data lands where IT cannot reach it, compliance gets harder to prove, and support work grows with every new device type.
A fifth problem sits underneath all four. IT cannot see the software either, because personal devices run apps and cloud services nobody in IT ever reviewed.
Shadow IT is any hardware or software running in an organization without IT's knowledge, and BYOD is one of its largest sources. Every personal device arrives with apps IT did not approve and cannot inventory.
The Mobile Security Index 2025 found 45% of organizations struggle to detect shadow IT because they lack the data to spot it. In the same index, 29% of security professionals named BYOD as a heightened risk and 28% named unapproved software.
The newest version of the problem is BYOAI, bring your own AI. Microsoft's Work Trend Index 2024 found that 75% of knowledge workers use AI at work, and 78% of those AI users bring their own tools, much of it in consumer apps nobody reviewed. Each unreviewed app is a decision the company never got to make, which is the argument for picking a device-ownership model on purpose instead of inheriting one by default.
The four models differ on one question: who buys the device, and how much control does IT get in return. Under BYOD the employee buys it and IT gets the least control. Under COBO the company buys it and IT gets the most.
Many organizations do not pick one. A common split is BYOD for contractors and field staff, COBO for the roles handling regulated data. Whichever mix you land on, the rules have to be written down.
A workable BYOD policy covers device requirements, data handling rules, support boundaries, and a signed user agreement. Together those four answer which devices qualify, what they may do with company data, who fixes what, and what the employee has consented to.
Revisit the agreement and the access level together whenever someone changes roles. A promotion can change both what the person needs to reach and what they agreed to.
Give the least-controlled devices the fewest resources. NIST SP 800-46 recommends exactly this, "such as allowing organization-owned personal computers (PCs) to access many resources, BYOD PCs and third-party controlled client devices to access a limited set of resources, and BYOD smartphones and tablets to access only one or two lower-risk resources."
In a three-tier version, tier one gets email and calendar only. Tier two adds broader app access, on the condition that the device is encrypted and the user signs in with strong authentication. Tier three, full access, is reserved for managed devices or for virtual desktop sessions set up so data never lands on the device. Tiering also keeps the program affordable, because the strictest controls only have to cover the smallest group.
The employee reports it, a named administrator removes company access or data, the team resets that user's credentials, then someone reviews what the account could reach while it was exposed.
Two details decide whether that sequence works. Employees need one reporting path and a stated deadline, because a phone reported three days late is a different incident. And the employee's consent to the remote action belongs in the signed user agreement rather than in a phone call during the incident.
Four approaches secure BYOD. You can manage the whole device, manage only the work apps, wall the work apps off inside a container, or keep the apps and data in the cloud and stream a desktop to the device. Each approach draws the line between company and personal in a different place.
|
Approach |
What it controls |
Device enrollment |
Effect on personal data |
|
Mobile device management (MDM) / unified endpoint management (UEM) |
The whole device |
Required |
Broad IT control of settings and compliance |
|
Mobile application management (MAM) |
Work apps only |
Not required |
Policies don't apply in personal use |
|
Containerization |
An encrypted zone for work apps and data |
Container only |
IT sees nothing outside the container |
|
Virtual desktops and Cloud PCs |
Apps and primary data running in the cloud |
None |
Settings control what can copy to the device |
MDM and UEM enroll the entire device, which gives IT control over its settings, its configuration, and whether it meets company security rules. That is the most control of any option, and on personal devices it is also the biggest ask.
NIST SP 1800-22 builds its reference design around this approach, layering threat detection, app review, and VPN services on top of device management. The depth suits company-owned hardware. On employee-owned hardware, the enrollment requirement is usually where the program stalls, because employees resist handing their own phone over to corporate management.
MAM manages the work apps and leaves the rest of the device alone, which is how it gets past the enrollment problem. NIST SP 800-124 notes that MAM can address employees' privacy concerns precisely because it requires no enrollment and no company profile on the device.
Microsoft Intune does this with app protection policies, which protect company data whether or not the device is enrolled. Per Microsoft: "User productivity isn't affected and policies don't apply when using the app in a personal context."
Containerization puts work apps and data inside an encrypted, sealed-off area of the personal device. IT controls everything inside that area and sees nothing outside it. Per NIST SP 800-124, "secure containers provide software-based data isolation designed to segment enterprise applications and information from personal apps and data."
Virtual desktops move the line furthest of the four. The apps and the data run in the cloud, and the personal device acts as a screen, keyboard, and mouse. NIST SP 800-46 (previously cited) states: "VDI is particularly helpful for safeguarding telework on BYOD and third-party-controlled devices, which are more likely than organization-issued devices to not meet the organization's security requirements." It is the same isolation idea behind virtual desktop infrastructure (VDI), the older on-premises version.
Both Windows Cloud services support this pattern, and many enterprises run both for different groups of workers. With a Windows 365 Cloud PC, the virtual disk and content sit in the Azure region where administrators create the Cloud PC. With Azure Virtual Desktop, app-related data resides in the Azure region you pick.
Choosing the region keeps the main copy of the data in the cloud, but it does not stop data from moving to the device. Four routes stay open until an administrator closes them: copy and paste, mapped local drives, browser downloads, and printing.
Device support decides whether this is practical. The Windows 365 web client runs on Windows, Mac, iOS, Android, ChromeOS, Linux, and LG webOS 23, so almost anything an employee already owns can reach a company desktop under those controls.
Zero Trust assumes no device is safe because of who owns it or what network it is on, which is the assumption BYOD requires. Every request gets checked against identity and device condition, and the check repeats during the session instead of happening once at login.
NIST SP 800-207 names this use case directly, covering "bring-your-own-device (BYOD) policies that allow enterprise subjects to use nonenterprise-owned devices to access enterprise resources." A valid password is no longer enough to open a company resource.
Microsoft's Intune Zero Trust guidance gives an order to work in. Start with app protection policies, which need no device management at all. Then work with the identity team to add Conditional Access policies that require an approved app or a compliant device before a resource opens.
Identity carries more of the load here than it does with company hardware. CISA's Zero Trust Maturity Model v2.0 notes that agencies "employing BYOD policies will likely have fewer options to maintain visibility and control of such devices." Fewer options on the device means the checks move to sign-in and to the session itself. Employees, reasonably, want to know how far those checks reach.
Less than employees usually assume. On a personal device enrolled in Microsoft Intune, the organization cannot see calling or web browsing history, email and text messages, contacts, calendar, passwords, photos, or documents the employee created. Under MAM, where the device is never enrolled, IT sees only the managed work apps.
NIST SP 1800-22 (previously cited) lists five privacy risks in BYOD programs, including wipe actions that delete personal data by accident and data collection broad enough to count as employee surveillance. Its reference design routes personal app traffic outside the company VPN so personal browsing stays invisible to IT. Enrollment choices, agreement wording, and VPN setup all need to line up with the same boundary.
Regulators expect similar restraint. The UK ICO warns that "excessive monitoring is likely to intrude into workers' private lives and undermine their privacy and mental wellbeing," and requires a data protection impact assessment before any monitoring likely to pose a high risk to workers. Writing the boundaries into the BYOD agreement is what turns a privacy promise into something an employee can check.
Two questions fall outside the security team's control. Does the company have to pay employees for using their own hardware, and which roles are allowed in the program at all? Both need answers before enrollment opens.
It depends on where the employee works. California Labor Code §2802 requires employers to reimburse necessary work expenses, and using a personal phone for work generally calls for reasonable reimbursement.
Practice lags the law. The 2025 SHRM Employee Benefits Survey found 55% of employers offer a home equipment subsidy, averaging a maximum of $888 a year, and 62% of those programs cover cellphone service. A 2024 academic review found 61.8% of BYOD employees get no stipend at all. Check the rules in every state and country where your people work, then subtract whatever you owe them from the hardware savings.
The usual exclusions are roles that handle regulated data and roles whose business communications must be recorded. Healthcare, financial services, and government teams are the common examples, and a company-issued device is the answer where the risk is too high.
Keep participation voluntary for everyone else. A mandatory program penalizes employees who do not own a suitable phone or laptop, so publish the costs, the eligibility rules, and the company-device alternative before anyone enrolls.
Onboarding takes four steps. The employee confirms the device meets requirements, signs the user agreement, enrolls the device or installs the protected apps, and gets an access level. Offboarding takes two. Remove company data and access, then close the account. Remote hires can finish onboarding the same day, which is a large part of why BYOD suits hybrid teams.
Offboarding is where the privacy promises get tested, so define it before the program starts. Microsoft Intune offers two actions with very different outcomes. The Intune Retire action removes company data and leaves personal data in place, which Microsoft calls "ideal for personally owned devices." Wipe resets the whole device to factory condition. For apps managed through MAM, selective wipe clears company data out of those apps and touches nothing else, though it can take up to 30 minutes to run.
Consent decides which of those you may use. The Canadian Centre for Cyber Security states that a full wipe "should not be performed unless the user consents, as it would erase the personal data of the owner." Deleting data is also only half the job. Revoke network access and close the account, because a wiped device with a valid sign-in token can still connect.
Eight controls make a BYOD program defensible, and they work as a set because no single one covers every risk above.
Run together, these eight turn BYOD security into ongoing operational work across identity, devices, and cloud desktops. That is the part somebody has to do every day.
Nerdio Manager for Enterprise puts the daily work of running cloud desktops for BYOD into one console: Cloud PCs, Intune policies, and Azure Virtual Desktop session hosts in the same place. That covers Windows 365, Microsoft Intune, and Azure Virtual Desktop, which simplifies the work for enterprises running both Windows Cloud services side by side.
Nerdio Manager extends Intune app delivery through Unified Application Management, so admins install applications on Cloud PCs and update them in bulk rather than device by device. It also backs up and restores Intune policies, which native Intune cannot do once a policy has been deleted. In a BYOD program where app protection policies carry much of the security load, that restore path is the difference between a fast fix and a rebuild.
Oversized Cloud PCs are easy to miss, and so are licenses that three shift workers could share. Nerdio Advisor flags Cloud PCs sized larger than their usage warrants and recommends Windows 365 Flex (previously called Frontline) license conversions where users never work at the same time. Windows 365 pricing is predictable by design, and Advisor is how teams keep that predictable spend matched to who is working as the BYOD population changes.
An idle Azure Virtual Desktop session host keeps billing for compute until something powers it down and deallocates it, and deallocation is the step that stops the compute charge. Nerdio Manager's auto-scaling does both outside working hours. Penn State reported a 71% reduction in Azure Virtual Desktop spend while supporting 1,000+ users.
Role-based access control limits which admins can act on which Cloud PCs and host pools, so the person who can wipe an employee's device is the person the policy names. The audit log records who changed what and when.
A workable BYOD program sets access levels, protects employee privacy, and matches controls to the risk of each device and role. Nerdio Manager supports the enterprise teams running Windows 365, Microsoft Intune, and Azure Virtual Desktop as part of that operating model. If cloud desktops are the delivery route you are weighing, read next on how to manage Windows 365 with Intune.
Get a demo or try it free to see how Nerdio Manager handles cloud desktop and endpoint management for BYOD.
BYOD stands for bring your own device. A BYOD policy lets employees use personal devices for work and sets the rules for device requirements, data handling, and security controls.
On a personal device enrolled in Microsoft Intune, your employer cannot see your calling or web browsing history, email and text messages, contacts, calendar, passwords, photos, or the documents you created. Under MAM, where the device is never enrolled, IT sees only the managed work apps.
A well-run program removes company data and access and leaves your personal data alone. Microsoft Intune's Retire action and MAM selective wipe both work this way, and a full factory reset should only happen with the device owner's consent.
No. Under BYOD the employee owns the device. Under CYOD the company buys a device the employee picks from an approved list. Under COPE the company owns the device but allows personal use. The three differ on who pays for the hardware and how much control IT keeps.
BYOD can be voluntary, and reimbursement depends on where the employee works. California Labor Code §2802 requires reimbursement of necessary work expenses, including reasonable personal-phone costs, yet a 2024 academic review found 61.8% of BYOD employees receive no stipend. A company-device option keeps the program open to people who do not own suitable hardware, and some regulated roles should be excluded from BYOD altogether.
Learn more about Nerdio Manager