Blog · Bring Your Own Chaos
The Phones Nobody’s Watching
In Part 1 of this series, we looked at what managed and unmanaged devices mean, and how most small businesses often end up with a mix of both without ever deciding to. Phones tend to be where the unmanaged/managed divide shows up the most, and tends to be the hardest to fix too.
Work PCs normally get bought as a business expense, so there’s a moment where someone could have made a decision about them, but mobiles rarely get that moment.
How a Phone Ends Up With Company Access
The process is normally quite simple. Often, someone simply asks if they can get work email on their personal phone, an admin says yes and sets it up in five minutes, and that’s it. There’s no discussion about policy, no passcode requirement, and no real thought given to what happens if that phone is lost, stolen, or still in someone’s pocket eighteen months after they’ve left the company.
Multiply that by every employee who’s ever asked the same question, and most small businesses end up with a genuinely unknown number of personal phones holding a live copy of the company inbox, calendar, and often a good chunk of SharePoint or OneDrive too.
When Things Go Wrong
The above may seem like a minor issue, but there’s plenty of simple ways it can cause a data governance nightmare. Say, for instance, an employee leaves the company on good terms, hands back their laptop, and IT blocks their account so they can’t sign in anywhere. Their personal phone, though, had the Outlook app installed for the last three years, and every email, attachment, and file it ever synced is still sitting on that device.
Blocking the account stops anything new. It doesn’t reach into a phone the business doesn’t own and remove what’s already there. Nobody had a record of that phone in the first place, so nobody’s in a position to do anything about it.
Even a simple mistake can become a big data security issue. Say a phone gets left in a taxi or stolen. Without a managed device, there’s no remote wipe option and no way to know what it can access. The business finds out only if something goes missing or becomes a problem, and by then it may well be too late.
The Two Realistic Options
There are two different tools for two different situations, and mixing them up is where most of the confusion comes from.
Full device management (MDM) makes sense for phones the business owns. Through Intune, a company-owned phone can be fully enrolled: passcode enforced, encryption required, and the entire device wiped remotely if it’s lost. This gives complete control, which is appropriate because the business owns the hardware.
App protection policies (MAM) are the answer for personal phones, and they solve a different problem. Rather than managing the whole device, this approach protects company data inside specific apps like Outlook, Teams, and OneDrive, without touching anything else on the phone. In practice, this looks like:
- A PIN required to open Outlook or Teams, separate from the phone’s own lock screen.
- Copying text or files out of a managed app into a personal app (like pasting an email into WhatsApp) gets blocked.
- Company data can be wiped from just those apps if someone leaves or the phone is lost, without touching personal photos, messages, or anything else on the device.
This second option is usually the right one for BYOD, because it solves the actual risk (company data sitting unprotected) without asking anyone to hand over control of a phone they own and paid for. Most employee pushback around mobile management disappears once it’s clear the business isn’t asking to wipe their holiday photos.
Tying It to Sign-In
This connects directly to Conditional Access, which we touched on in an earlier post about the shift toward passkeys. Once app protection policies exist, Conditional Access can require a device to meet that standard before it’s allowed to access company email or files at all. A phone with no protection policy simply doesn’t get in, regardless of whether the password is correct.
This is where the pieces of this series start fitting together. A managed policy isn’t useful if there’s no way to enforce it at the point of sign-in.
What Managed Mobiles Configured by Outlaw Behave Like
Going back to the leaver scenario: with an app protection policy in place, offboarding a personal phone takes one action rather than a manual chase. We trigger what’s called a selective wipe, and within minutes the company email, attachments, and any synced files disappear from that phone. Nothing else on that device changes, so photos, texts, banking apps, and everything else on the phone stays exactly as it was, because a selective wipe only touches data inside the protected work apps, not the device itself.
The lost phone in a taxi becomes far less stressful too. Even if someone picks it up while it’s unlocked, opening Outlook or Teams still asks for a separate PIN, one that has nothing to do with the phone’s own passcode. Whoever’s holding the phone can’t get into company email without it, and the moment it’s reported missing, that data can be wiped from the apps directly, without anyone needing to physically get hold of the device.
Coming Up Next
Part 3 of this series looks at what a tool like Intune delivers once policies like these are properly set up, beyond just the idea of “managing devices,” and what that’s worth to a business day to day.
Where Does Your Business Stand on This?
If you’re not sure how many personal phones currently have access to company email, or whether any policy exists to protect that data if one goes missing, that’s worth finding out before it becomes a problem rather than after.
This is exactly what we check as part of our Free M365 Assessment, alongside a wider look at how your Microsoft 365 environment is set up.