BYOD and Microsoft 365: secure data, keep phones private
MAM or MDM for personal devices? What you can see and protect on a personal phone, and how to isolate work data without invading privacy.
Your employees check their Microsoft 365 email, open a Teams file or reply to a message from their personal phone. It has become a reflex, often outside office hours, and it is excellent for productivity. But every device that your organisation does not control is a potential door to your data: a lost phone, a child installing a dubious app, a sync to a personal cloud, and your business email leaks without a trace.
A good BYOD (Bring Your Own Device) strategy is not about taking over your team's phones. It is about protecting work data only, without ever touching the person's private life. This distinction is crucial, because it changes everything when it comes to employee buy-in and your own legal exposure under GDPR.
This balance is decisive. Too much control and teams refuse to enrol their device, or work around the rules by setting up a native, unprotected mail account. Too little control, and your email and files travel in the clear, copyable to any app. Microsoft Intune and Microsoft Entra provide exactly the tools to draw that line precisely. In this guide you will see how to choose between MAM and MDM, what you can really see on a personal device, and how to deploy effective protection without PowerShell.
MAM or MDM: two radically different approaches
Before configuring anything, you need to understand the fundamental distinction between managing a device and managing an application. It is the structuring choice of any BYOD project, and getting it wrong at this stage dooms the rest of the deployment.
MDM: full device management
Device management (MDM, Mobile Device Management, via Intune enrollment) takes control of the device as a whole: Wi-Fi and VPN configuration profiles, compliance policies, app deployment, and above all the ability to perform a full remote wipe. This fits company-owned devices perfectly, but it is rarely acceptable on a personal phone, since a full wipe would also destroy family photos and private contacts.
MAM: targeted application protection
App management (MAM, Mobile Application Management, via App Protection Policies) protects only the Microsoft 365 apps and the data they hold, without enrolling the device. No profile is installed on the phone and there is no access to the system: protection lives inside Outlook, Teams, Word or OneDrive.
- MDM: ideal for company-owned devices, full control, full wipe possible.
- MAM: ideal for BYOD, protects data inside apps without managing the device.
- With MAM you require an in-app PIN, encryption of work data and a selective wipe.
- MAM works even without Intune enrollment, which employees accept far more readily.
- You can combine both: MDM for company devices, MAM for personal devices.
What you can see, and what you cannot
This is the question that stalls most BYOD projects. "Will my employer read my texts? See my photos? Track my location?" In MAM mode, the answer is no, and communicating this clearly is essential to ease concerns and win buy-in. Transparency is your best deployment tool here.
- You do NOT see: text messages, calls, photos, browsing history, or personal apps installed.
- You CANNOT: read private messages or continuously track the personal device's location.
- You DO see: the model, OS version, work app name and its compliance state.
- You CAN: require a PIN, block copy/paste to personal apps, and wipe work data only.
This limitation is not a flaw, it is a feature. It protects your employees as much as your business, and it reduces your liability regarding personal data. A clear message such as "we see nothing of your private life, we only protect access to your work email" unblocks more projects than any technical documentation.
What an App Protection Policy can enforce
An App Protection Policy applies a set of rules at the level of each managed application. Here are the most useful protections to enable for realistic BYOD use.
Access controls
- Require a PIN or biometrics to open the work application.
- Block access on jailbroken or rooted devices, whose security is compromised.
- Enforce a minimum OS version to keep out obsolete devices.
- Automatically sign out after a defined period of inactivity.
Data leakage controls
- Restrict copy/paste from work apps to personal apps.
- Prevent saving work files to personal storage such as a private OneDrive.
- Block screenshots inside managed apps (on Android).
- Encrypt work data at rest inside the application.
Combine app protection with Conditional Access
An App Protection Policy reaches its full strength only when paired with a Conditional Access rule in Microsoft Entra. Without it, a user could simply configure their work email in the native Mail app of their iPhone, bypassing your protections entirely. Conditional Access closes that door by requiring the sign-in to come from an approved, protected app.
- 1First create your App Protection Policies for iOS and Android in the Intune admin center.
- 2Assign them to the target user group, excluding the emergency access account.
- 3In Entra, create a Conditional Access rule targeting Exchange Online and SharePoint.
- 4Under "Grant", require an approved client app AND an App Protection Policy.
- 5Enable the rule in report-only mode and watch the sign-in logs for one to two weeks.
- 6Once the impact is validated, switch the rule to "On" to actually enforce it.
- Require an approved client app (Outlook, Teams) rather than any mail app.
- Require an App Protection Policy to guarantee PIN and encryption.
- Always deploy Conditional Access in report-only mode first to measure the impact.
- Exclude a break-glass emergency account before any enforcement.
Common mistakes to avoid
BYOD projects rarely fail on pure technology; they fail on details of method. Here are the pitfalls we see most often.
- Turning a Conditional Access rule straight to production, with no report-only phase, and suddenly locking out a whole team.
- Forgetting to exclude a break-glass account and locking yourself out of the tenant.
- Deploying app protection without requiring the approved app: users keep using the unprotected native Mail app.
- Not telling teams what is seen and what is not, breeding distrust and workarounds.
- Overlooking the behavioural differences between iOS and Android, especially on screenshots and file transfer.
Successful BYOD is not the one that controls the most, but the one employees agree to use every day.
BYOD and regulatory compliance
A documented BYOD strategy maps directly to several ISO 27001, NIS2 and GDPR requirements, which demand control over data access from any endpoint, including personal ones. MAM containment and the traceability of your policies serve as concrete evidence during an audit or inspection, without imposing intrusive surveillance on your employees. You demonstrate that access is protected, that data can be wiped remotely when someone leaves or loses a device, and that privacy is respected by design.
FAQ
Do I need a special licence for app protection?
App Protection Policies are part of Microsoft Intune, included in Microsoft 365 E3/E5 and Business Premium plans. Conditional Access requires a Microsoft Entra ID P1 licence, also included in those same plans. Most SMBs therefore already hold the licences they need at no extra cost.
Can I wipe work data without touching personal data?
Yes, that is precisely the point of MAM. A selective wipe removes only the work data held inside managed apps: emails, files, authentication tokens. Personal photos, contacts and apps stay completely intact. It is ideal when an employee leaves the company.
Does the employee have to enrol their phone in Intune?
No. That is exactly the benefit of MAM without enrollment: protection applies inside the Microsoft 365 apps without the device being registered or managed. The employee simply installs Outlook or Teams, signs in, and the policy applies automatically.
Building a MAM policy by hand in Intune means dozens of correct settings, precise group assignment and a delicate orchestration with Conditional Access. AuPoint translates that complexity into plain language, previews the impact before deployment through report-only mode, automatically protects your break-glass account and makes every policy reversible in one click. You protect work data on personal devices in minutes, with no PowerShell and no consultant, while meeting your ISO 27001, NIS2 and GDPR requirements. Discover AuPoint and secure your BYOD today.