Every device that touches organizational data — including personal phones checking work email — is part of your security posture, whether it's managed or not.
- Encryption is turned on. BitLocker (Windows) or FileVault (Mac) should be enabled on every device, so a lost or stolen laptop doesn't mean a lost or stolen dataset.
- Screen locks are required, with a reasonably short timeout — a device left unlocked in a coffee shop is a real, common failure mode.
- Endpoint protection is current on every machine, not just the ones IT remembers to check.
- Personal devices have a minimum standard. If staff use their own phones for work email, a passcode and remote-wipe capability should be a condition of that access, not an afterthought.
- Software updates aren't optional. Unpatched operating systems and browsers are one of the most common ways devices get compromised.
- Offboarding includes device access. When someone leaves, their access to organizational data — not just their email account — should be removed the same day.
Most of this is achievable with Intune or similar device management, already included in many Microsoft 365 plans — see our Microsoft 365 governance guide for where to start.

