BYOD Full MDM Consent Form


Document Number: ISMS-FORM-BYOD-01

Version: 0.1.0

Parent Policy: BYOD Security Policy (ISMS-POL-BYOD-01) §3.2

Parent Procedure: Device Lifecycle Procedure (ISMS-PROC-BYOD-01) §2.4

Author: Lucas Shin — Security Director

Effective Date: February 20, 2026


BYOD Full MDM Consent Form

Windows Desktop App Access — Opt-in Agreement

This form must be completed and signed by any employee requesting Office desktop app access on a personal Windows device under the BYOD Full MDM Exception Path (BYOD Security Policy §3.2).

ℹ️
This agreement elevates your device's management level, not ownership. Your device remains personally owned. The company gains additional management jurisdiction in exchange for granting desktop app access.

Employee Information

Name
Position
Date
Device Make / Model
Device Serial Number
Windows Version

1. Entra Join + Full MDM Enrolment

By signing this form, I acknowledge and consent that my personal Windows device will be:


2. BitLocker Full-Disk Encryption

I consent to the following:


3. Full Wipe Acknowledgment

⚠️
This is the most critical section. Please read carefully.

I understand and accept that:


4. Standard User Enforcement

I accept that:


5. OneDrive Known Folder Move (KFM)

I understand that:


6. Personal Use

I understand that:


7. Privacy Boundary — Differences from Standard BYOD

I understand that the Full MDM exception path changes the company's visibility and control compared to standard BYOD:

AreaStandard BYODFull MDM (this agreement)
Device management scopeEdge browser only (MAM)Entire device (Full MDM)
Data wipe capabilitySelective Wipe only (work data)Selective Wipe first; Full Wipe if needed
Disk encryptionNot enforcedBitLocker enforced; key escrowed to company
Admin rightsUser retains adminStandard User enforced
Folder redirectionNoneDesktop / Documents / Pictures → corporate OneDrive
Desktop app accessBlockedEnabled (Teams, Outlook, Word, Excel, etc.)

8. Opt-out Right

I may revoke this consent at any time by submitting a written request to the Security Director. Upon opt-out:


Declaration and Signatures

Employee Declaration:

I have read and understood all sections of this consent form. I voluntarily agree to the terms described above. I understand that this consent is separate from and in addition to the standard BYOD User Consent Form.

Employee Signature
Date

Security Director Approval:

Approved By
Date
Exception Register Reference

Document Retention: This signed form must be retained in SharePoint (HR folder) for the duration of the employee's employment plus 12 months, per Device Lifecycle Procedure §6.

[End of Consent Form]