Living guide · Microsoft 365 & Cloud

Intune and BYOD: How to Protect Company Data on Laptops and Phones Without Owning Every Device

Company laptops, personal phones with work email, contractors' Macs: Microsoft Intune can manage all of them, but not in the same way. This guide explains the two models, what each one can and cannot do, and how a small business should set them up.

Last reviewed 10 September 2026 Published 10 September 2026 11 min read
Book a Discovery Call
This guide is for you if
  • Staff read work email on their own phones and you are not sure what happens when one leaves.
  • You have Business Premium and have been told you 'have Intune' but nothing is enrolled.
  • A lost laptop, a leaver or a Cyber Essentials question has made device management urgent.
In this guide
  1. 1. Two models
  2. 2. Staff-owned phones
  3. 3. Company devices
  4. 4. Setup order
  5. 5. Objections
  6. 6. How we help
  7. 7. FAQs
01

Two models: manage the device, or protect the data

Intune, included in Microsoft 365 Business Premium as Intune Plan 1, does two different jobs and the difference matters most for staff-owned devices.

Device management (MDM)App protection (MAM)
What is managedThe whole device: settings, encryption, updates, apps, Wi-Fi, certificatesOnly the company data inside specific apps (Outlook, Teams, OneDrive, Office)
Typical deviceCompany-owned laptops, desktops and phonesStaff-owned phones and tablets; contractors' devices
What you can doEnforce encryption and screen lock, push updates and apps, block non-compliant devices, wipe the whole deviceRequire a PIN or biometric to open work apps, block copy-and-paste and save-as into personal apps, encrypt the work data, wipe the work data only
What staff give upControl of the device; IT can see installed apps and settingsNothing personal: Microsoft's documentation is explicit that policies apply only in a work context and personal data is untouched
Enrolment needed?YesNo (Android needs the Company Portal app installed, and devices register with Entra ID)

The rule of thumb: company owns it, manage it; person owns it, protect the data. A business can use both at once, and Intune lets you apply a stricter app protection policy to unenrolled devices than to managed ones.

02

Staff-owned phones: what app protection actually does

The scenario every business has: a member of staff with Outlook and Teams on their personal iPhone or Android. Without any policy, company email and files can be copied into personal apps, saved to personal cloud storage, and stay on the phone after the person leaves.

With an app protection policy, from Microsoft's documentation:

  • The work apps require a PIN or fingerprint/face to open in a work context, separate from the phone's own lock.
  • Copy, paste and save-as from work apps into personal apps can be blocked or restricted to approved apps.
  • Work data is encrypted inside the apps.
  • Apps can be blocked from running on jailbroken or rooted phones, and a minimum operating system version can be required.
  • When someone leaves, IT performs a selective wipe that removes the company data from the work apps and leaves photos, messages and personal apps untouched.

Microsoft organises these settings into three levels (basic, enhanced, high). Level 2, "enhanced data protection", is described as applicable to most users accessing work data, and it is where we start most businesses.

Two things to get right: pair the policies with a Conditional Access rule that requires an approved app with app protection, otherwise staff can simply use a different mail app and bypass everything; and tell people what the policy does and does not do, because "IT can see my phone" is the objection, and it is not true.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
03

Company laptops and phones: full management

For devices the business owns, enrol them in Intune and manage them properly. The settings that matter for a small business:

  1. Compliance policy. Encryption on (BitLocker on Windows, FileVault on Mac), screen lock, a supported operating system version, Defender running. A device that fails is marked non-compliant.
  2. Conditional Access. Company data only from compliant devices. This is the single control that turns "we have policies" into "the policy is enforced".
  3. Update rings. Windows and macOS updates applied on a schedule you control, with evidence for Cyber Essentials' 14-day requirement for high and critical fixes.
  4. Baseline configuration. Firewall on, admin rights removed from everyday accounts, unnecessary features off.
  5. Apps. Office, Teams, Defender and your line-of-business apps deployed automatically, so a new laptop is ready without an engineer touching it.
  6. Windows Autopilot. A new laptop shipped straight from the supplier, switched on by the user, and configured by Intune over the internet. Included with Business Premium.
  7. Remote wipe and retire. Tested, so that when a laptop is lost the button works.

Macs, iPhones and Android are all supported, so a mixed estate is not a reason to avoid it.

04

A setup order that does not break the office

Most Intune rollouts go wrong by switching on Conditional Access before devices are ready, locking everyone out on a Monday morning. The order we use:

  1. Inventory. Which devices exist, who owns them, and what operating systems they run. Anything unsupported is replaced first.
  2. App protection policies for everyone, in report-only or warning mode first, then enforced. This is low-risk and protects the phones immediately.
  3. Enrol company devices in groups, starting with IT and a friendly pilot team. Apply compliance policies but do not enforce Conditional Access yet; watch the compliance report.
  4. Fix what the report shows. Usually: a few machines without encryption, one on an old OS, a personal laptop someone has been using for work.
  5. Enforce Conditional Access once compliance is above 95 percent, with a documented exception route for the last few.
  6. Autopilot for new devices, so nothing is set up by hand from this point.
  7. Review quarterly. New starters, leavers, OS updates and Microsoft's own changes all move the picture.

Want a second opinion before you buy licences?

We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.

Book a Discovery Call
05

The objections, answered

  • "Staff will not accept IT on their personal phones." They do not need to. App protection touches only the work apps, and a selective wipe removes only work data. Show them the policy in writing.
  • "We are too small for this." Intune is included in a licence many small businesses already pay for. A ten-person business with laptops and phones has exactly the risks it addresses.
  • "It will slow people down." Done in the order above, the visible changes are a PIN on Outlook and occasional update prompts. The lockouts people fear come from rushed Conditional Access, which is a sequencing problem, not an Intune one.
  • "We have antivirus already." Antivirus does not encrypt a lost laptop, wipe a leaver's phone or prove your patching. Intune and Defender for Business are designed to work together and both come with Business Premium.
06

How Black Sheep Support helps

Device management is part of our standard onboarding: we enrol company devices, set the compliance and app protection policies, stage Conditional Access so nobody is locked out, set up Autopilot for new kit, and review the compliance reports as part of the managed service. It is also most of the evidence a Cyber Essentials assessor asks for, so we build it once and use it twice.

For the licence side, see the Microsoft 365 licensing and security guide; for what Cyber Essentials expects of devices, see the Cyber Essentials guide.

Want a second opinion before you buy licences?

We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.

Book a Discovery Call
07

Frequently asked questions

Can IT see personal photos and messages on a phone with app protection?

No. App protection policies apply only to the work apps in a work context. Microsoft's documentation states that policies do not apply to personal use and personal data is untouched. A selective wipe removes company data from the work apps only.

Do we need Business Premium for Intune?

Business Premium includes Intune Plan 1, which covers everything in this guide. Intune can also be bought separately for other plans, but Premium is the simplest route because it also includes Defender for Business and Conditional Access.

What is the difference between MDM and MAM?

MDM (mobile device management) manages the whole device and needs it to be enrolled. MAM (mobile application management, called app protection policies in Intune) protects company data inside specific apps and does not need enrolment. Use MDM for company-owned devices and MAM for staff-owned ones.

What happens when someone leaves?

Their account is disabled, which cuts access; a selective wipe removes company data from the work apps on their personal phone; a company laptop is wiped remotely or retired. All three are standard Intune actions when the setup is in place.

Can Intune manage Macs?

Yes. macOS enrolment, compliance, encryption (FileVault), updates and app deployment are supported, as are iPhones, iPads and Android devices.

Does Intune satisfy Cyber Essentials?

It provides the evidence for several of the five controls: secure configuration, update management (including the 14-day fix requirement) and, with Defender, malware protection. It is not required by the standard, but it is the easiest way to prove the controls are in place.

Will Conditional Access lock people out?

Only if it is enforced before devices are compliant. Enrol and fix first, enforce last, and keep an exception route for the few devices that need it.

Get the devices under control without the drama

We will look at what you have, what is enrolled, and what is exposed, and give you a staged plan that protects the phones this week and the laptops without locking anyone out.

  • An inventory of what is managed, what is not, and what is unsupported.
  • The app protection and compliance policies we would set, and why.
  • A rollout order that avoids the Monday-morning lockout.
  • How it connects to Cyber Essentials and your Microsoft 365 licence.
Book a device management review

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.Microsoft Learn: App protection policies overview (updated 1 Jul 2026) · accessed 10 September 2026
  2. 2.Microsoft Learn: Microsoft 365 for business security overview (Intune Plan 1 in Business Premium) · accessed 10 September 2026
  3. 3.Microsoft Learn: Data protection framework using app protection policies · accessed 10 September 2026

What has changed on this page

  • 10 September 2026Page published. App protection policy details checked against Microsoft Learn (Intune app protection overview, updated July 2026).

Related reading