Monthly Archives: October 2026

lady holding phone while working on a laptop

Should Employees Use Personal Devices for Work?

Summary: Allow personal devices only for approved work, through approved apps, and when the device meets your security requirements. Use company-owned devices for administration, sensitive work, or jobs that require large amounts of data to be stored locally.

Employees often use personal devices for work before the business has made a decision about it. They add work email to a phone, download a file to a home laptop, or sign into a company app from a computer shared with family.

Once business data is stored on a personal device, you have less control over updates, installed apps, backups, and who else uses the device. You also need a way to remove company data when the employee leaves or the device is lost.

Personal devices can be allowed, but the business should decide which devices, applications, and types of work are permitted.

What BYOD includes

Bring your own device, usually shortened to BYOD, means an employee uses a personally owned phone, tablet, or computer for work.

That can include:

  • Adding work email to a personal phone
  • Signing into Microsoft 365 or Google Workspace
  • Joining online meetings
  • Opening customer or company files
  • Using a business messaging app
  • Accessing accounting, CRM, or project management software
  • Downloading documents to a personal computer

Depending on the application, business information may remain in the cloud or be downloaded to the device as messages, attachments, cached data, or files.

What you cannot fully control on a personal device

Your IT team can set and monitor security on company-owned devices. With personal devices, employees choose which apps to install, when to update the operating system, who else uses the device, and where files are backed up.

Management software can enforce some rules, but the available controls depend on the device, operating system, application, and enrollment method.

Other people may use the device

An employee may share a home computer or tablet with a partner, child, or another family member. Separate user accounts can reduce the risk, but many personal devices are used through one shared account.

The UK National Cyber Security Centre says BYOD access should not be permitted when an employee cannot follow the required security rules. Its example includes a device that cannot keep the employee’s work separate from other family users. NCSC BYOD guidance

Updates may be missing

Your IT provider may not be able to confirm whether a personal device runs a supported operating system or has current security updates.

An employee may delay an update because the device lacks storage, an older application might stop working, or the device is rarely restarted.

Business files may enter personal storage

A file downloaded from work email or cloud storage may remain in the Downloads folder, a personal document folder, or a device backup.

A personal cloud backup service could then copy the file to an account the business does not manage. Opening the document in a personal application may create another unmanaged copy.

Other applications may access business information

Personal devices contain applications chosen by the employee. Some may have permission to read files, contacts, browser activity, or information copied to the clipboard.

The business may not know which applications are installed or what those applications can access.

Repairs can expose business data

A broken personal phone or laptop may be taken to a repair shop chosen by the employee. Business email, saved sessions, or downloaded files could still be available on the device.

Your policy should tell employees who to contact before a device is repaired and what to do if the device cannot be opened.

Company data may remain after employment ends

Disabling an employee’s account stops future access to many cloud services. It does not remove copies that were downloaded to personal folders, opened in unmanaged applications, or copied to personal storage.

Managed work profiles and protected applications make it easier to remove company data. They can only remove the information they control.

Decide what work is allowed

Set access based on the work being performed and the information involved.

You might allow employees to read work email through an approved mobile app while requiring a company computer for customer database exports. Staff handling financial records, health information, legal documents, or large amounts of customer data may also need company-owned devices.

Administrative work should be performed from a managed device. Anyone responsible for user accounts, security settings, backups, or business systems should not do that work from an unmanaged personal computer.

Apply the same rules to contractors. Their access should be limited to the applications and information required for their work.

Security requirements for personal devices

A personal device should meet your requirements before it can access company information.

Use a supported operating system

The device should run an operating system that still receives security updates. Block access from devices that can no longer install current updates.

Install security updates

Operating system and application updates should install automatically where possible. Employees should restart their devices when an update requires it.

Require a screen lock

Require a PIN, password, fingerprint, or facial recognition to unlock the device. Configure the screen to lock automatically when the device is not being used.

Require device encryption

Encryption helps protect stored information if a device is lost or stolen. The Australian Cyber Security Centre recommends full-device encryption when personal devices may store business information. Cyber.gov.au BYOD guidance

Encryption must be enabled before the device is lost. It also needs to be supported by a strong device password or PIN.

Require MFA

Require MFA for work email, cloud storage, and other important systems. The NCSC recommends MFA as a minimum for BYOD access.

Use MFA for account sign-ins. Protect downloaded information with encryption and managed applications.

Block rooted or jailbroken devices

Rooting or jailbreaking removes some of the operating system’s built-in restrictions. These devices should not be allowed to access company data.

Detection is not perfect, so it should be used with the other security controls in this article.

Approve the applications used for work

Tell employees which applications they may use for email, messaging, file access, and other work.

Where your management service supports it, prevent business information from being saved to personal storage or copied into unmanaged applications.

Use separate accounts on shared computers

A personal computer used for work should have a separate account for the employee. Other users should have their own accounts and should not know the employee’s password.

Do not allow BYOD access when work cannot be kept separate from other users of the device.

Tell employees how to report problems

Employees need to know who to contact if a device is lost, stolen, repaired, replaced, or infected with malware.

Early reporting gives the business more time to disable access, check account activity, and remove managed data.

Control business data with managed apps or work profiles

Device and application management services can help keep work information separate from personal information.

Mobile device management, or MDM, can apply settings to an enrolled device and report whether it meets company requirements. The amount of control depends on the platform and enrollment method.

Mobile application management, or MAM, applies controls to supported work applications and their data. Depending on the product, it may restrict copying, block saving to personal storage, require another PIN, or remove company information from managed apps.

For example, Microsoft Intune can remove company data from protected applications when a device is lost or an employee leaves. Personal information can remain on the device.

Selective removal only affects data managed by the service. It cannot delete a file copied into an unmanaged application, personal backup, or unsupported storage location.

A factory reset removes personal and business data. Microsoft warns administrators about the risk of applying full device management to computers and phones the business does not own. Configure selective removal where possible and tell employees exactly what your management service can see and do. Microsoft Intune planning guide

What your BYOD policy should cover

Your policy should answer these questions:

  • Which employees and contractors may use personal devices?
  • Which types of devices are permitted?
  • What work can be performed on them?
  • Which applications must be used?
  • Can company files be downloaded?
  • Can the device be shared with other people?
  • Which security settings are required?
  • What information can the business or IT provider see?
  • What settings can the business control?
  • Can company information be removed remotely?
  • What happens if the device is lost or stolen?
  • What must happen before the device is repaired or sold?
  • What happens when the employee leaves?
  • Who pays for mobile data, repairs, or replacement?

Privacy, employment, and data protection requirements vary between countries. Have the policy reviewed for each location where you employ people.

Employees should read and accept the policy before company access is added to their devices.

What to do when a personal device is lost or stolen

The employee should contact the business or IT provider as soon as possible.

Your response may include:

  1. Disabling access if the device cannot be accounted for
  2. Revoking active sign-in sessions
  3. Removing company data from managed applications
  4. Removing the device from approved-device lists
  5. Checking account activity for unexpected sign-ins
  6. Resetting credentials if they may have been exposed
  7. Recording which company files may have been stored on the device

Remote locking and removal commands only work after the device connects to the management service. A device that remains switched off or offline may never receive the command.

Encryption and account controls are still required because remote removal might not run.

What to do when an employee leaves

Disable the employee’s account and revoke active sessions at the agreed time. Remove company data from managed applications or work profiles.

Check whether business files were downloaded to the device and confirm how those copies will be returned or deleted.

Remove the device from your approved-device records. Where your management service supports it, remove business applications, certificates, email profiles, and VPN settings.

When personal devices should not be allowed

Provide a company-owned device when:

  • The employee handles sensitive information
  • The role requires administrator access
  • Large amounts of company data must be stored locally
  • The device is shared with other people
  • The operating system is no longer supported
  • Encryption cannot be enabled
  • The business cannot separate or remove its data
  • The employee does not accept the required security controls
  • The device has been rooted or jailbroken

Company-owned devices are easier for your IT provider to support because their settings and installed software are known.

Frequently asked questions

Can employees use a web browser without enrolling their personal device?

You can allow browser access, but information may still remain in the browser cache, Downloads folder, saved passwords, screenshots, or active sessions.

Access policies can limit the devices and browsers that are permitted. Sensitive work may still require a managed device.

Is MFA enough to secure a personal device?

MFA helps protect the employee’s account. Device encryption protects stored files, while managed applications control how company information is used and copied.

You still need updates, screen locks, approved applications, and a process for lost devices.

Can the business see an employee’s personal information?

It depends on the management method. App management focuses on business applications and their data. Device enrollment can show device details and allow broader control.

Give employees a written explanation of what your IT team can see, change, lock, or remove before they enroll.

Can the business erase a personal phone?

Some enrollment methods support a full factory reset, while app-only management does not. A factory reset deletes personal information as well as company data.

Use selective removal for employee-owned devices where it is available.

Is BYOD cheaper than providing company devices?

BYOD may reduce hardware purchases, but it can add costs for management, support, security, and administration. Whether it saves money depends on the devices, applications, and work you allow.

Sources and further reading

If employees already use personal devices for work, ask your IT provider to check what they can access and whether the required controls are in place.

And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it out.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

people working on computer

Why Your Employees Shouldn’t Have Administrator Access to Their Computers

Summary: Employees should use standard accounts for email, web browsing, and everyday work. Administrator access should be limited to approved IT tasks and protected with a separate account.

Administrator access often starts with one request. An employee needs to install a printer, update a specialist program, or change a setting on their computer.

Giving them administrator access gets the job done. The problem is that the access usually stays after the request has been completed.

From then on, the employee can approve other software installations and make changes that would normally require help from IT. If they install the wrong program or someone takes control of their account, those permissions can also be used to change the computer.

For everyday work, employees should use standard accounts. Administrator access should be kept for tasks that require it.

What administrator access allows someone to do

An administrator has more control over a computer than a standard user.

On Windows, members of the local Administrators group have full control over the resources on that computer. According to Microsoft’s guidance on local accounts, Microsoft recommends limiting the number of users in that group.

Depending on the computer and how it is managed, an administrator may be able to:

  • Install and remove software
  • Add drivers for printers and other equipment
  • Create, change, or remove user accounts
  • Change system settings
  • Change permissions on files and folders
  • Install services that continue running in the background
  • Make changes to some security settings

Mac computers also have standard and administrator accounts. Apple says administrators can install and remove software, manage other users, and change settings. Apple recommends limiting the number of administrative users and using a standard account when administrator rights aren’t required.

Local administrator access applies to the computer itself. It is different from Microsoft 365, Google Workspace, network, or server administrator access. Those accounts may control email, cloud files, user accounts, or several systems at once.

An employee may have local administrator access to a laptop without being a Microsoft 365 administrator. Both types of access should be reviewed separately.

Why permanent administrator access increases your risk

Software launched by an employee normally starts with the permissions available to that employee.

If the software asks for administrator approval and the employee approves it, the program may be able to install system components, change settings, or affect information belonging to other users.

That matters when someone downloads a fake installer, opens a harmful attachment, or installs software from an untrusted website. The employee may think they are approving a legitimate update while giving the program permission to change the computer.

Windows uses User Account Control to ask for approval before many administrative changes. An employee signed in with an administrator account can approve the request themselves. A standard user is normally asked for credentials belonging to an administrator.

Microsoft describes the standard account as the recommended and more secure way to use Windows.

Standard accounts also reduce the number of people who can change security settings without review. Employees cannot approve every installation themselves, so IT has a chance to check the program, where it came from, and what permissions it needs.

CISA advises businesses to control local administrator access and restrict who can install software. The Australian Cyber Security Centre includes restricting administrative privileges in its Essential Eight security measures and recommends creating separate accounts for administrative work. Cyber.gov.au

Standard accounts are suitable for everyday work

A standard account can still be used for normal business tasks, including:

  • Reading and sending email
  • Using a web browser
  • Working in Microsoft 365 or Google Workspace
  • Accessing approved business applications
  • Joining online meetings
  • Printing with an installed printer
  • Opening and saving files
  • Changing personal settings that do not affect other users

Some applications can be installed for one user without administrator access. Others need administrator approval because they add drivers, services, or files in protected parts of the computer.

An employee should not receive permanent administrator access because one program needs an update. IT can approve the installation, deploy the update remotely, or use a separate administrator account for that task.

Older business applications sometimes expect the user to have administrator rights. Test those applications before changing account permissions. In many cases, IT can update the application, adjust its configuration, or grant access to the specific folders it needs.

How to manage software installations without permanent administrator access

Staff can still get software installed and updated without keeping administrator rights.

Let IT install approved software

Your IT team or provider can install the program remotely. This also gives them a chance to confirm that the installer came from the software company and that the requested version is supported.

Use managed software deployment

Businesses with managed computers can send approved applications and updates to employees without asking each person to run an installer. The available method will depend on the operating system and device management service.

Approve individual requests

An employee can contact IT when an installation requires administrator approval. IT can review the request and enter the required credentials without giving the password to the employee.

Provide time-limited administrator access

Some roles need to install or test software as part of their work. Give those employees a separate administrator account that is enabled only for the approved task, then disable it afterward.

Create a separate administrator account

Employees who regularly perform approved technical work can have a separate administrator account. They should continue using their standard account for email, browsing, and normal work.

The administrator account should only be used when a task requires the extra permissions.

Who should have administrator access?

Administrator access should be limited to people whose work requires it.

That may include:

  • Your internal IT staff
  • Your IT provider
  • An approved technical employee
  • A software specialist responsible for a particular system

Business owners should use standard accounts for their normal work too. Ownership of the company does not require permanent administrator access to every computer.

Your IT provider should keep a managed administrator account so they can support each device. The password should be protected and should not be shared with employees.

Using the same local administrator password on every computer creates another problem. If that password is stolen from one device, it may work on the others. Each computer should have a unique administrator password or use a management service that controls those passwords.

How to remove administrator access safely

Do not remove every administrator account at once. Someone still needs a working way to manage and repair each computer.

1. Check which employees have administrator access

Review the local Administrators group on every Windows computer and the administrator users on every Mac. Include old accounts, shared accounts, vendor accounts, and accounts created during the original setup.

2. Confirm why each person has it

Ask what tasks require administrator access. A clear business need should exist for every account that keeps the permission.

Needing to update one application occasionally does not require permanent access.

3. Make sure IT has a working administrator account

Confirm that your IT team or provider can sign in with a protected administrator account before removing permissions from employees.

Test the account on each device. This prevents the business from being locked out of its own computers.

4. Test important software

Check the programs each employee needs for their job. Confirm that they open, update, and work correctly when the employee uses a standard account.

Any application that fails should be reviewed before administrator access is removed permanently.

5. Change the employee’s account to a standard account

Once the computer has been checked, remove the employee from the local administrator group or change the account type.

The employee should then sign out and sign back in so the new permissions apply correctly.

6. Tell staff how to request an installation

Give employees one place to contact when they need software installed or a setting changed. Explain what information to include, such as the program name, the reason it is needed, and the official download page.

7. Review access when roles change

Check administrator access when an employee changes jobs, receives new responsibilities, or leaves the business. Include it in your regular access reviews as well.

Frequently asked questions

Can a standard user install software?

It depends on the software. Programs that only install inside the employee’s user profile may not need administrator approval. Software that changes protected system files, installs drivers, or adds background services usually requires administrator credentials.

Will removing administrator access stop employees from working?

Normal business applications should continue working. Test specialist and older applications before making the change across every computer.

Does removing administrator access stop malware?

It reduces what many harmful programs can change, but it does not prevent every attack. You still need supported software, security updates, endpoint protection, email security, MFA, and tested backups.

Should the business owner keep administrator access?

Use a standard account for everyday work. If you need administrator access for an approved task, use a separate account and keep its password protected.

Is local administrator access the same as Microsoft 365 administrator access?

No. Local administrator access controls one computer. Microsoft 365 administrator roles can control cloud users, email, files, security settings, and other parts of the company’s Microsoft environment.

Both should be limited and reviewed.

Sources and further reading

If you are not sure who has administrator access or whether your employees need it, ask your IT provider to review the accounts on your business computers.

And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it out.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.