Many businesses today work with third parties, contractors, or associates who use their own devices (BYOD) when accessing company systems. While this approach offers flexibility, it comes with important security and compliance considerations. This article explores the device requirements for BYOD in the workplace.
Here’s what you need to know to ensure your business data remains safe while supporting BYOD users.
Device Requirements for BYOD Users
For associates using their own devices, we recommend the following:
-
Operating System: Windows 11 Home or Professional, running one of the two most recent releases (currently 25H2 or 24H2).
-
Security Software: Windows Defender, which comes free with Windows and updates automatically via Windows Updates.
-
Microsoft Account: If using Windows 11 Home, users must log in with a Microsoft Personal/ Family account. This activates BitLocker, which encrypts the hard drive and stores the encryption key in the user’s Microsoft account.
-
Updates: Users should regularly run Windows Updates and restart often.
-
Device Age: Devices should be less than 5 years old and still receiving updates from the manufacturer (e.g., Dell, HP). Warranty is not required, but updates are essential.
Note: We have not specified hardware specifications. While the make, model and specification affects end user performance, the most important factor is that the device is relatively modern and still supported by the manufacturer.
Microsoft Licensing Considerations
How you choose to license your users, impacts the control you have over your business data.
At the entry level, you have Microsoft 365 Business Basic, which provides web versions of Outlook, Word, Excel, Teams, and OneDrive. For BYOD users, we recommend using these applications only in a web browser (such as Microsoft Edge).
This ensures:
- Data remains in the cloud at all times.
-
If an associate leaves the business, their access can be disabled immediately.
-
No company data is downloaded or stored locally on personal devices.
-
Depending on your environment, you may be able to leverage Secure Enterprise Browser (with Edge), to control access even further.
Risks of BYOD
BYOD can create challenges for data control and compliance:
-
There’s no way to confirm that all personal devices meet the recommended security requirements.
-
Associates may download company data to their own devices without oversight.
-
If a BYOD user leaves, sensitive data could remain on their device.
Alternatives to BYOD for Greater Security
If you want full control over your business data, consider these options:
-
Company-Owned Devices: Providing associates with company devices ensures compliance and security, with full control over software, updates, and data.
-
Microsoft 365 Business Premium: Upgrading from Basic licenses provides access to Intune, Mobile Device Management (MDM), and Mobile Application Management (MAM). This allows remote deployment, management, and removal of apps and data from BYOD devices
-
Windows 365 Cloud PCs: Cloud PCs allow BYOD users to access a secure Windows environment from their own device. Applications and data remain in the cloud, ensuring maximum security and compliance.
Summary
BYOD can work well for flexibility, but businesses must carefully weigh security, compliance, and control. If full control and peace of mind are priorities, company-owned devices, Business Premium licenses, or Windows 365 Cloud PCs provide safer and more manageable solutions.
Conquered IT can help you navigate the options and ensure your business data stays secure, compliant, and accessible — whatever you choose.
