BYOD Quick Reference — Platform User Guide

Audience: All staff (BYOD users)

Purpose: A quick reference for what you can and cannot do on your personal device

Document type: Operational reference (not an ISMS artefact)

Last updated: 2026-02-25


ℹ️
This document is a user-facing summary of the BYOD Security Policy (SEC-POL-BYOD-002). Refer to the source policy for full details.

What the Company Can and Cannot See

What the company CAN seeWhat the company CANNOT see
Work app versions, compliance statusPersonal app list
OS versionPersonal photos, messages, files
Device compliance state (Compliant / Non-compliant)Personal browsing history
Work data (inside Managed Volume / Managed Edge)Location / GPS
Phone calls / texts
This boundary is enforced at the OS level by Apple User Enrollment and Android Work Profile. The company cannot technically cross this boundary.

macOS BYOD

Enrolment method: ADUE (Account-Driven User Enrollment) — Managed Volume created automatically

✅ What You Can Do

❌ What You Cannot Do

⚠️ Things to Know


Windows BYOD — Default Path (Edge Only)

Enrolment method: Entra Registered (no MDM enrolment) — web app access via Managed Edge

✅ What You Can Do

❌ What You Cannot Do

⚠️ Things to Know


Windows BYOD — Full MDM Exception Path

Enrolment method: Entra Join + Intune Full MDM — opt-in path for desktop app access

⚠️
This path is not applied automatically. You must request it, receive Security Director approval, and sign the Consent Form before it takes effect.

✅ What You Can Do

❌ What You Cannot Do

⚠️ Things to Know


Mobile — iOS / Android

Enrolment method: iOS = ADUE (Managed Volume) / Android = Work Profile (container separation)

✅ What You Can Do

❌ What You Cannot Do

⚠️ Things to Know


Platform Comparison

macOSWindows (Default)Windows (Full MDM)Mobile
M365 accessNative appsEdge web apps onlyNative appsNative apps
Desktop apps
Copy/paste blockedPolicy-prohibitedAllowed✅ Technically blocked
File download blockedVolume isolation✅ Technically blocked✅ Technically blocked
Screenshot blocked✅ Technically blocked
On offboardingManaged Volume deletedEdge org data removedSelective → Full Wipe possibleWork apps/data removed
Admin rightsRetainedRetained❌ Standard UserRetained

Need Help?