Phones and personal laptops: a practical guide to BYOD security
Your staff already read work email and open client files on personal phones. Here is how to protect business data on devices you do not own, without turning IT into big brother.
Walk through almost any small Israeli business and you will find the same quiet arrangement: work email on personal phones, the occasional client document opened on a home laptop, a manager checking Teams on the train. Nobody planned it as a policy. It just happened, because it is convenient and phones are personal. The result is that some of your most sensitive business data lives on devices your company does not own, cannot see, and has no way to wipe. This is bring your own device, or BYOD, and for most SMBs the answer is not to ban it, which never sticks, but to put a light, sensible boundary around the business data on those devices.
The real risk with personal devices
It helps to be precise about what actually goes wrong, because the popular image, a hacker breaking into a phone, is rarely the problem. Far more often it is ordinary life. A phone is left in a taxi or stolen from a bag, and it has a saved, always-signed-in mailbox full of client information. An employee leaves the company and their personal phone walks out the door still holding a year of business email and files, with nobody able to remove it. A family member picks up the tablet the client contract is open on. A staff member forwards a work document to a personal account to print it at home, and it quietly sits in a personal cloud forever. The device being 'hacked' is far down the list. Access left where it should not be is the everyday risk.
Two honest options: managing the device or just the data
There are broadly two ways to bring order to this, and Microsoft's tooling, Intune, supports both. The first is mobile device management (MDM), where the device itself is enrolled and the business can enforce settings on it, push apps, require a passcode, and wipe the whole device if needed. That is a good fit for company-owned phones and laptops. The second, and usually the better fit for personal devices, is mobile application management (MAM), often called app protection policies. Here the business does not manage the whole phone at all. It only manages the business data inside the work apps, Outlook, Teams, the Office apps, and leaves everything personal untouched. For a business asking staff to use their own phones, MAM is the approach that people will actually accept, because it does not reach into their personal life.
What app protection policies actually do
App protection policies put a boundary around company data inside the apps that hold it. In practice that means a few concrete things. Business data in Outlook or Teams can be encrypted and require a separate PIN or your face to open, even if the phone itself is unlocked. Copying and pasting or saving from a work app into a personal app, like moving a client file into a personal WhatsApp or Gmail, can be blocked or limited. And if a phone is lost or an employee leaves, the business can remotely wipe only the company data from the work apps, leaving personal photos, messages, and apps completely alone. That last point matters in both directions: the business gets its data back under control, and the employee does not lose anything of their own. Most Microsoft 365 Business Premium plans already include the Intune licensing needed for this, so for many SMBs it is a configuration exercise rather than a new purchase.
Tie it to sign-in with Conditional Access
A protection policy is far stronger when the system refuses to hand over business data to a device that is not protected. That is what Conditional Access does: it sets the conditions under which someone can sign in and reach company data. A sensible baseline for BYOD is to require that mobile access to Microsoft 365 only works from apps that have an app protection policy applied. A personal phone with the managed Outlook app and the policy in place gets in; the same account added to the phone's built-in mail app, with no protection, does not. Microsoft has been consolidating these controls, recently retiring the older 'require approved client app' grant in favour of 'require app protection policy', so it is worth making sure any existing rules use the current control. Set up carefully and tested with a small group first, this is invisible to staff on a compliant device and simply blocks the risky paths.
Do not forget the laptop
Phones get the attention, but a personal Windows or Mac laptop used for work is usually the bigger exposure, because it holds more and reaches deeper. The same principles apply, with a few additions. Full-disk encryption, BitLocker on Windows or FileVault on Mac, means a stolen laptop is a lost asset rather than a data breach. Business-grade endpoint protection, EDR rather than just consumer antivirus, matters more on a machine that opens attachments and downloads files all day. And remote access from that laptop into the office network should go through a VPN with multi-factor authentication or a Zero Trust setup, not a shortcut that exposes internal systems. A personal laptop signed into your Microsoft 365 with no encryption and no endpoint protection is one of the softer targets in a typical SMB, and it is often nobody's explicit responsibility.
Company phones change the calculation
None of this means personal devices are the only option. For roles that handle a lot of sensitive data, or where you want the cleanest separation, issuing a company-owned phone or laptop is often worth it. On a company device you can use full device management, enforce settings, and wipe the whole thing on loss without any of the privacy questions that come with personal hardware, because the device belongs to the business. The trade-off is cost and the fact that many people do not want to carry two phones. A common middle ground for Israeli SMBs is company devices for a handful of key roles and app protection policies for everyone else, which keeps the business data protected across the board without buying a phone for every employee.
Set expectations with your team
The technology is only half of it. BYOD works when staff understand what the business can and cannot see, because the fear that IT is reading personal messages is what makes people quietly opt out and route work through unmanaged channels instead. Be clear and put it in writing: with app protection policies, the business manages only company data in the work apps and cannot see personal photos, messages, browsing, or location. What it can do is require a PIN on the work apps and remove company data if the phone is lost or you leave. A short, plainly written BYOD policy that says which apps to use for work, what is expected of the person, and exactly what the company can and cannot do goes a long way. People follow rules they understand and trust, and route around ones they find intrusive.
Where to start
If personal devices are already in use, which they almost certainly are, the practical order is to protect the business data first and worry about the rest later. Turn on app protection policies for Outlook and Teams, require app protection for mobile access with Conditional Access, and make sure any work laptops have disk encryption and proper endpoint protection. Then write the short policy so everyone knows where they stand. NetFortress helps Israeli SMBs set this up inside their existing Microsoft 365, in a way that protects client data without treating staff as suspects. If you are not sure what is reaching your business data from personal phones and laptops today, ask us for a review and we will map it out with you.
Frequently asked questions
What is BYOD and why should a small business care?
BYOD, bring your own device, is staff using personal phones, tablets, or laptops for work, which almost every SMB already allows informally. It matters because business email and client files end up on devices the company does not own, cannot see, and cannot wipe if the device is lost or the employee leaves. A light boundary around the business data keeps it under control.
Can I secure work data on a personal phone without controlling the whole device?
Yes. Using Microsoft Intune app protection policies (mobile application management), the business manages only the company data inside work apps like Outlook and Teams, and leaves everything personal untouched. You can require a PIN on the work apps, limit copying data into personal apps, and wipe only the business data if needed, without touching personal photos or messages.
What is the difference between MDM and app protection policies?
Mobile device management (MDM) enrols and controls the whole device, which suits company-owned phones and laptops. Mobile application management (MAM), or app protection policies, controls only the business data inside specific apps and leaves the rest of the personal device alone. For staff using their own phones, MAM is usually the more workable and better-accepted option.
If someone loses their phone, can we remove the business data?
Yes. With app protection policies in place, you can remotely wipe just the company data from the work apps, leaving personal photos, messages, and apps completely alone. That also handles the departing-employee case, where a personal phone would otherwise walk out the door still holding a year of business email and files.
Will managing devices let us read employees' personal data?
Not with app protection policies. That approach manages only company data in the work apps; it cannot see personal photos, messages, browsing, or location. Being clear about this in a short written BYOD policy matters, because staff who fear IT is reading their private life tend to route work around the controls, which is exactly what you want to avoid.
What about personal laptops used for work?
They are often the bigger exposure because they hold more. Require full-disk encryption (BitLocker or FileVault), business-grade endpoint protection (EDR rather than consumer antivirus), and remote access through a VPN with MFA or a Zero Trust setup rather than exposing internal systems. A personal laptop signed into Microsoft 365 with no encryption and no endpoint protection is one of the softer targets in a typical SMB.
Related articles
Why antivirus is no longer enough: endpoint protection (EDR) for SMBs
Traditional antivirus catches yesterday's known threats; modern attacks are built to slip past it. Here is what EDR adds, why it matters for Israeli SMBs, and how to adopt it without an in-house security team.
Read articleSecuring remote and hybrid work without slowing your team down
Hybrid work is now normal for Israeli SMBs – but the old assumption that everyone sits behind the office firewall no longer holds. Here is how to secure laptops, connections, and home networks without getting in your team's way.
Read articleSmishing, fake apps, and MFA fatigue: the mobile attacks aimed at Israeli SMBs
Protecting a phone is not only about settings on the device. Most mobile incidents start with a message, a fake login page, or a well-timed prompt. Here are the attacks aimed at your team's phones and the practical ways to blunt them.
Read articleRelated services
Endpoint Protection / EDR
Endpoint detection and response for visibility across every device – so threats are caught before they spread.
Learn moreCloud Services / Microsoft 365
Microsoft 365 setup, identity security, permissions review, and secure configuration for the cloud environment your business runs on.
Learn moreReady to secure your business without building an internal IT team?
Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.