August 24, 2026
Radmila
Cybersecurity Awareness & Human Risk Management
Listen
The Device Is Personal. The Risk Isn't
Employees no longer work only from company-issued laptops inside company offices.
They check emails from personal phones, open documents on tablets, join Teams meetings from home computers, and access cloud applications from devices IT may have never seen.
For employees, this flexibility is convenient. For organizations, it creates a much bigger question:
What happens to corporate data when the device accessing it is outside your control?
A personal device may belong to the employee. But the emails, documents, credentials, customer information, and business systems it can access belong to the organization.
The device is personal. The risk isn’t.
A company-managed laptop usually comes with security controls already in place. IT can enforce encryption, deploy updates, configure antivirus protection, monitor compliance, and respond when something goes wrong.
With an unmanaged device, many of those guarantees disappear.
The device could be running an outdated operating system. Encryption may be disabled. Security updates may be months behind. Malware protection may be missing. Corporate documents may be downloaded into locations the organization cannot monitor or control.
And yet, if the employee can successfully sign in, that device may still be able to access Outlook, Teams, SharePoint, OneDrive, and other business applications.
That's the real problem with unmanaged devices:
The organization may trust the user without knowing whether it can trust the device.
Imagine an employee opens a confidential document from Outlook on their personal phone.
Where does that document go next?
Can it be copied into a personal application? Saved to personal cloud storage? Shared through another messaging platform? What happens if the phone is lost or the employee leaves the company?
The organization may still be responsible for protecting that information, even though it has little control over the device storing it.
Simply allowing personal devices without defining how corporate data can be accessed, stored, and shared creates a blind spot.
Fortunately, securing BYOD doesn’t necessarily mean taking complete control of employees’ personal devices.
Mobile Device Management (MDM) allows organizations to manage devices and enforce minimum security requirements.
Using a platform such as Microsoft Intune, IT teams can require encryption, supported operating system versions, passwords or PINs, security configurations, and other compliance settings.
That compliance status can then become part of the access decision.
Instead of asking only:
“Does this user have the correct credentials?”
The organization can also ask:
“Does this device meet our security requirements?”
If it doesn’t, access to sensitive corporate resources can be restricted until the problem is resolved.
Full device management isn’t always appropriate. Especially when the device belongs to the employee.
That’s where Mobile Application Management (MAM) provides another layer of control.
With Microsoft Intune App Protection Policies, organizations can protect corporate information inside supported applications without fully enrolling or managing the personal device.
For example, work data can be prevented from being copied into personal applications. Organizations can restrict where corporate files are saved, require additional authentication to access protected apps, and selectively remove company data when an employee leaves.
The organization protects what actually matters - its application and data - while the employee keeps control of their personal device.
MDM and MAM become even more effective when combined with Microsoft Entra Conditional Access.
A managed and compliant corporate laptop might receive full access.
A personal phone could be allowed to use Outlook and Teams with App Protection Policies applied.
An unmanaged home computer could be restricted to browser-only access, preventing corporate documents from being downloaded locally.
And a device that presents unacceptable risk can be blocked altogether.
This creates a much stronger model than simply trusting anything that successfully signs in.
Access should reflect how much the organization knows - and controls - about the device requesting it.
Personal devices aren’t going away. Neither is remote and hybrid work.
The answer isn’t necessarily to block every device the organization doesn’t own. It’s to make sure unmanaged access doesn’t also mean unmanaged data.
At Hopp Solutions, we help organizations use technologies such as Microsoft Intune, MDM, MAM, App Protection Policies, device compliance, and Entra Conditional Access to create secure access models for both corporate and personal devices.
The goal is simple: give employees the flexibility to work from different devices while keeping corporate information under organizational control.
Because a phone, tablet, or laptop may belong to the employee.
The data - and the risk that comes with it - still belongs to the business.
Designing and developing digital experiences that move businesses forward.
Contact
hello@hoppsolutions.com
+49 155 1027 5723
+389 77 540 743
Office
Bul. Turisticka 21
6000 Ohrid, North Macedonia
Made with love by Hopp Solutions | 2026