Skip to content

The benefits of a bring your own device (BYOD) policy

BYOD is usually argued for on cost, productivity and morale. All three hold up — but only if you can still see what the devices are doing, which is the part the policy rarely covers.

The case for letting people use their own phones and laptops for work is usually made on three grounds: it costs less, people get more done, and they prefer it. Ten years of practice has not overturned any of the three. What has changed is the second half of the argument — what you give up in visibility, and whether you can get it back.

Take the benefits first, honestly.

Cost

The direct saving is straightforward. If employees use hardware they already own, the organisation is not buying that hardware, not replacing it on a refresh cycle, and not carrying the service contract. What the organisation pays for is business use, rather than the whole device.

Two caveats are worth stating plainly, because BYOD business cases routinely omit them.

The first is that the cost does not vanish; it moves. Some of it moves to the employee, which is a decision with a fairness dimension and should be made deliberately rather than by default. Some of it moves sideways into IT — support for a heterogeneous fleet, enrolment and management tooling, and the security controls a mixed environment needs.

The second is licensing. A personal device that runs company software is a licensable device under a good many agreements, and per-device licensing does not care who bought the hardware. Whether a BYOD machine consumes a licence, is covered by a user-based licence the person already holds, or qualifies as second use under an existing agreement, depends entirely on the terms you signed. Work it out before the policy ships, not during an audit.

Productivity

The productivity argument does not rest on device performance. It rests on removing constraints.

A personal device is one the person already knows. There is no learning curve, no waiting for provisioning, and no second phone in the other pocket. More importantly, it detaches work from a place and a nine-to-five window. Email gets read on the train. A presentation gets a final pass from a kitchen table. Something urgent gets handled from a hotel instead of waiting until Monday.

That flexibility is real and it is worth having. It also has a limit that is now much better understood than it was in 2016: always-available is not the same as always-on, and organisations that treat BYOD as an implicit extension of the working day tend to lose the morale benefit in the next section. The policy should say what is expected out of hours. Silence on that point is itself a policy, just not a good one.

Employee morale

The third benefit is the softest to measure and the easiest to observe. People are generally happier working on a device they chose, on the platform they prefer, configured the way they like it.

There is a secondary effect that matters more than it looks. A BYOD policy is IT saying yes. Where the alternative is a standard-issue device that people work around, an organisation that supports choice tends to have a better relationship with its own IT function — and a better relationship with IT is what makes people ask before they install something, rather than afterwards.

That is the connection between this section and the next one. Morale is not just a nice outcome. It is a control.

What BYOD costs you in visibility

Here is the part the 2016 version of this argument did not need to make.

A device you do not own is a device your inventory does not automatically see. In 2016 that mostly meant you could not tell which software was installed on it. Today it means something bigger, because the software people use on personal devices largely is not installed at all.

Personal devices are the shortest path to unmanaged SaaS. Somebody signs up for a tool on their own laptop, with their work email, on a free tier that later converts to a paid one. The average enterprise portfolio runs to 305 applications, and 46% of SaaS licences go unused. A meaningful share of both numbers arrives through routes that no device inventory was ever going to catch.

The same path now carries AI. An AI tool needs nothing more than a browser and an account, which makes a personal device the most likely place for company information to reach a model nobody approved. This is the version of the shadow IT problem that has a data consequence rather than only a cost one.

And there is the leaving problem. When someone hands back a corporate laptop, the hardware and most of what was on it comes back with it. When someone leaves and the device was theirs, nothing comes back — not the accounts, not the seats you are still paying for, and not the OAuth grants they consented to that still hold read access to company data.

None of this is an argument against BYOD. It is an argument that the benefits are only net positive if you can still see what is happening.

Getting the visibility back

The controls that make BYOD safe are not exotic, and they do not require owning the hardware.

Manage the device, not the person’s life. CerteroX ITAM includes mobile device management for iOS and Android with Apple DEP enrolment, so a personal phone can carry a managed work profile without the organisation taking over the device. The App-Centre self-service portal with manager approval chains gives people a sanctioned way to get software, which is the single most effective way to reduce the unsanctioned kind.

Discover the software that never installs. CerteroX SaaS Management uses three converging signals rather than relying on any one of them: identity provider sync from Entra ID and Okta, connector sync pulling authoritative user and licence lists from the vendor across 47 connectors shipping today, and a browser extension that detects SaaS domains with per-user attribution and time on app. The third of those is what covers the case a device inventory cannot reach.

Treat AI as its own asset class. Shadow AI detection classifies tools from application feature tags in a catalogue of more than 35,000 applications, rather than from a hardcoded list, so the detection set keeps up on its own. Adoption is ranked by the share of the organisation using each tool, because ten people using an AI assistant is a different problem from a thousand, and each tool can be set to managed, blocked or ignored.

Score the grants, not just the logins. OAuth grant discovery finds the third-party applications people have consented into your tenancy, and each grant is scored from 0 to 100 on data sensitivity, scope, consent and dormancy. Revocation is one click, or a workflow action if you would rather it happened automatically.

Close out leavers properly. An offboarding checklist shows every licence a departing person held, the connector status behind each revocation, and whether it is pending, in progress or complete — with the monthly cost of whatever is still open. Deprovisioning respects each vendor’s reality rather than assuming a common API: where a vendor has no suspend capability, roles are stripped instead; where files are involved, ownership transfers before the account is deactivated.

Get the licensing right. Per-device and per-user assignment are both modelled, second-use entitlement is applied by the engine, and the Exclude From Licensing workflow records devices that legitimately should not be counted as deliberate, auditable decisions rather than someone’s recollection.

The conclusion, updated

The original three benefits stand. BYOD reduces hardware spend, it removes constraints on where and when people work, and people prefer it.

What has changed is that the policy document is no longer the whole answer. In 2016 a BYOD policy was mostly a statement of what people were allowed to do. Now it has to be paired with the ability to see what they are actually doing — which applications are in use, which of them have data access, which seats are still being billed for someone who left, and which AI tools have quietly become part of how work gets done.

Write the policy. Then make sure you can see past it.

To see what SaaS and AI discovery finds across devices you do not own, book a demo.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.