Skip to main content

← All posts

Personal phones, company email: a sane BYOD setup for small business

Most 10 to 30 user companies are BYOD by default, not by decision. Here is how to protect company data on personal devices without managing anyone's phone.

· Jake Schaaf, Founder of Atticus Rowan

Count the personal phones with company email on them right now. In a 20-person company the number is usually 15 or more, and in most cases nobody decided that. Someone asked for email on their phone in 2019, it worked, and a policy was born by accident.

That is BYOD, bring your own device, and almost every 10 to 30 user business runs on it whether leadership has thought about it or not. The question is not whether to allow personal devices. That decision was made years ago by default. The question is whether company data on those devices has any protection at all.

What is actually at risk on a personal phone

The phone itself is not the concern. The concern is what the phone can reach:

  • Company email, including every attachment ever received
  • OneDrive and SharePoint files through the mobile apps
  • Teams messages and shared files
  • Saved passwords in mobile browsers
  • Cached copies of documents that persist after the app closes

A lost phone with no screen lock is a company data breach. So is a departed employee whose personal phone keeps syncing mail for 3 weeks because nobody thought about it during offboarding. We wrote about that failure mode in our offboarding process guide, and personal devices are consistently the loose end.

The 2 approaches, and which one fits

Mobile device management conversations go wrong when a small business is sold the heavy option first. There are 2 distinct models:

  • Full device management (MDM). The company enrolls and controls the entire phone: enforced settings, app installs, full remote wipe. Right for company-owned devices. Wrong as a default for personal phones, because employees reasonably object to their employer holding a wipe button over family photos
  • App protection policies (MAM). The company controls only the work apps and the data inside them. Outlook, Teams and OneDrive get a required PIN or biometric, copy-paste out of work apps is restricted, and the company can perform a selective wipe that removes work data and nothing else

For personal devices at a 10 to 30 user company, app protection is the right default. It protects exactly what the company owns, the data, without touching what the employee owns, the device. That distinction also makes rollout dramatically easier, because you are not asking anyone to surrender their phone.

If your company already licenses Microsoft 365 Business Premium, Intune app protection policies are included. This is one of several security capabilities sitting unused inside licensing many businesses already pay for, alongside the items in our Microsoft 365 security baselines walkthrough. Deployment for app protection is typically a 1 to 2 week project including a pilot group, not a quarter-long initiative.

The minimum requirements worth enforcing

Whether through Intune or the built-in controls in your mail platform, a sane BYOD baseline for company data access:

  • Screen lock required. A device with no PIN cannot sync company mail
  • Device encryption on. Default on modern iPhones and Android, but enforce it rather than assume it
  • Minimum OS version. A phone 3 major versions behind stops receiving security patches and should stop receiving company mail
  • Work-app PIN or biometric. The work apps lock independently of the device
  • Selective wipe capability confirmed. Tested, not assumed, before the day you need it
  • No jailbroken or rooted devices

Notice what is absent: tracking location, reading personal messages, controlling personal apps. App protection policies cannot see those, and saying so plainly in the rollout communication defuses most employee concern. In our experience the pushback on a well-explained app protection rollout is near zero, compared to real resistance when full MDM is pushed onto personal phones.

Do not forget the home computers

BYOD conversations fixate on phones, but the riskier device is often the family desktop. An employee signs into webmail from a shared home PC to check something on a Sunday, the browser offers to save the password, and now company access lives on a machine with no company visibility, teenage gaming downloads and an antivirus subscription that expired in 2023.

Two controls close most of that exposure:

  • Conditional access rules that limit what unmanaged computers can do, for example allowing web access to email but blocking file downloads to devices the company does not manage
  • A plain-language policy line: company work happens on company-issued computers, and web access from personal machines is for light use, not for downloading client files

Microsoft 365 Business Premium includes the conditional access capability to enforce the first item. The second costs a sentence in the same 1-page policy. Together they acknowledge reality, people will occasionally check email from home, while keeping bulk company data off machines nobody maintains.

The policy document, kept short

The technical controls need 1 page of paper behind them. A usable BYOD policy for a small business fits on a single page and answers:

  • Which apps and data may be accessed from personal devices
  • What the company enforces (the list above) and what it cannot see
  • What happens at departure: work data is selectively wiped, personal data untouched
  • Who to call when a device is lost, and the expectation that it is reported within hours, not days

The departure item matters most. Selective wipe turns the departed-employee phone from an open question into a 5-minute task on the offboarding checklist. Without it, the honest answer to “can former employees still read our email on their phones” is often “we do not know,” and that answer is starting to appear on cyber insurance questionnaires as a coverage-affecting gap.

Where to start

The order of operations we use at Atticus Rowan:

  • Inventory which accounts have mobile access today. The number will be higher than expected
  • Turn on app protection policies for a pilot group of 3 to 5 users, including at least 1 owner or manager
  • Roll out company-wide with a short, honest explanation of what changes and what the company cannot see
  • Add the lost-device and departure steps to your standing IT checklists
  • Revisit company-owned devices separately. Full management is appropriate there

None of this requires buying new licensing at most companies, and the whole rollout is measured in weeks. What it buys is the ability to answer “what happens if a phone with company email walks away” with a procedure instead of a shrug.

Atticus Rowan sets up app protection and BYOD baselines as part of managed IT and security for small businesses across northwest Ohio. If your company email is on 15 personal phones and nothing is enforcing anything, reach out and we will help you fix that quietly and quickly.