Telappliant
IT Guide · 7 March 2026

Mobile Device Management and BYOD done properly

How MDM and MAM secure personal devices used for work without overreaching into private data.

By the Telappliant team

Employee personal device enrolled into a corporate BYOD policy

Bring Your Own Device saves on hardware spend and keeps staff happy using phones they already know, but it puts company data on devices you do not own and cannot fully control. Mobile Device Management is what makes BYOD workable rather than a standing security risk.

Why BYOD needs its own approach, not the same policy as company devices

You cannot enforce the same level of control on a personal phone that you can on a company laptop, and users will rightly object if you try. The answer is app-level management (Mobile Application Management, or MAM) rather than full device enrolment: company data is contained inside managed apps like Outlook and Teams, encrypted separately, and wipeable without touching personal photos, messages or apps.

What MAM controls without taking over the device

  • Requires a PIN or biometric to open managed apps, independent of the phone's own lock screen
  • Blocks copy-paste of company data into unmanaged personal apps
  • Prevents saving company attachments to personal cloud storage
  • Wipes only the managed company data if the device is lost or the employee leaves, leaving personal content untouched

Where full MDM enrolment is still the right call

Company-owned phones and tablets, and any device used for privileged access such as finance approvals or admin roles, generally warrant full MDM enrolment rather than app-only management. The extra control is proportionate because the business owns the hardware or the access level justifies it.

Building a BYOD policy that survives contact with real staff

  • State plainly what the business can and cannot see on a personal device
  • Require a minimum OS version and security patch level to access company data at all
  • Make MFA and the managed app policy non-negotiable, with no exceptions for convenience
  • Set out what happens to company data on the device when someone leaves, before they leave
  • Cover reimbursement or stipend policy if devices are genuinely required for the role

The GDPR and Cyber Essentials angle

BYOD does not remove your obligations under UK GDPR; personal data processed on an employee's phone is still your responsibility as data controller. Cyber Essentials assessors expect evidence that personal devices accessing company data meet a defined security baseline, and an undocumented BYOD free-for-all is a common cause of failure.

A sensible rollout order

  • Classify roles by data sensitivity and decide MAM versus full MDM for each
  • Deploy conditional access so unmanaged, non-compliant devices are blocked automatically
  • Pilot with a willing team and gather feedback on friction before wider rollout
  • Review the policy annually as device types and threats change

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation