Bring your own device (BYOD) means using private endpoints — smartphones, tablets, notebooks — for work purposes. The appeal is obvious: no second devices, familiar technology, fast onboarding of externals. The flip side: corporate data on devices the company neither owns nor fully controls.
BYOD becomes viable through architecture instead of trust: technical separation of business and private, access along Zero Trust principles instead of full device control — and an agreement governing rights, duties and the loss case.
The three technical models
Container approach: a managed area on the device — Android work profile, Apple user enrollment or app protection policies (MAM) — encapsulates corporate apps and data; IT controls only this area and can wipe it selectively. This is the established middle path for smartphones and tablets.
Clientless access goes further: applications are delivered via the browser — through a ZTNA portal or remote browser isolation —, data stays server-side, nothing lands on the device. Ideal for externals, temporary staff and unmanaged notebooks. The third model — fully managed private devices — mostly fails in practice on privacy and acceptance.
What a BYOD policy must clarify
- Data separation and wipe rights: what may IT see and delete — and what never?
- Minimum device requirements: OS version, passcode, encryption, no jailbreaks.
- Access model: which applications are reachable from BYOD — and which never?
- Support, costs and exit: who helps with problems, what happens on departure?