Mobile Device Management and BYOD done properly
How MDM and MAM secure personal devices used for work without overreaching into private data.
By the Telappliant team

Bring Your Own Device saves on hardware spend and keeps staff happy using phones they already know, but it puts company data on devices you do not own and cannot fully control. Mobile Device Management is what makes BYOD workable rather than a standing security risk.
Why BYOD needs its own approach, not the same policy as company devices
You cannot enforce the same level of control on a personal phone that you can on a company laptop, and users will rightly object if you try. The answer is app-level management (Mobile Application Management, or MAM) rather than full device enrolment: company data is contained inside managed apps like Outlook and Teams, encrypted separately, and wipeable without touching personal photos, messages or apps.
What MAM controls without taking over the device
- Requires a PIN or biometric to open managed apps, independent of the phone's own lock screen
- Blocks copy-paste of company data into unmanaged personal apps
- Prevents saving company attachments to personal cloud storage
- Wipes only the managed company data if the device is lost or the employee leaves, leaving personal content untouched
Where full MDM enrolment is still the right call
Company-owned phones and tablets, and any device used for privileged access such as finance approvals or admin roles, generally warrant full MDM enrolment rather than app-only management. The extra control is proportionate because the business owns the hardware or the access level justifies it.
Building a BYOD policy that survives contact with real staff
- State plainly what the business can and cannot see on a personal device
- Require a minimum OS version and security patch level to access company data at all
- Make MFA and the managed app policy non-negotiable, with no exceptions for convenience
- Set out what happens to company data on the device when someone leaves, before they leave
- Cover reimbursement or stipend policy if devices are genuinely required for the role
The GDPR and Cyber Essentials angle
BYOD does not remove your obligations under UK GDPR; personal data processed on an employee's phone is still your responsibility as data controller. Cyber Essentials assessors expect evidence that personal devices accessing company data meet a defined security baseline, and an undocumented BYOD free-for-all is a common cause of failure.
A sensible rollout order
- Classify roles by data sensitivity and decide MAM versus full MDM for each
- Deploy conditional access so unmanaged, non-compliant devices are blocked automatically
- Pilot with a willing team and gather feedback on friction before wider rollout
- Review the policy annually as device types and threats change



