# Getting Started with Bring Your Own Device (BYOD) Management

Every organization eventually faces the same tradeoff: buy and manage a device for every employee, or let employees use their own — and lose visibility and control the moment you do. BYOD management is how Hexnode resolves that tradeoff without forcing a choice. It lets employees keep using the phone or laptop they already own and know, while giving IT the same security guarantees as a corporate-owned device — without ever touching the employee’s personal photos, messages, or apps.

Hexnode achieves this through containerization — a secure, encrypted container on the device that keeps corporate data walled off from personal data. Corporate data stays governed by policy; personal data stays untouched and invisible to IT.

Key Features of Hexnode BYOD Management 
----------------------------------------

- **Data Segregation**: Distinct separation of personal and work data.
- **Security & Compliance**: Automated compliance checks and data protection.
- **App Management**: Secure deployment of enterprise apps.
- **Corporate Wipe**: Ability to remotely remove only work data, leaving personal data intact.

**What this prevents?**

Without containerization, a lost or stolen personal phone with corporate email on it becomes an all-or-nothing decision — wipe the whole device (destroying the employee’s personal photos and data) or leave corporate data exposed. Containerization means IT can wipe only the corporate container, leaving the employee’s personal data untouched, while still closing the security gap.

### Core Strategic Benefits 

- **Cost Reduction**: Drastically lowers hardware procurement and maintenance expenses.
- **Employee Satisfaction**: Allows users to work on familiar devices of their choice.
- **Productivity**: Enables “anywhere, anytime” access to business-critical resources.
- **Privacy Assurance**: Ensures corporate admins cannot view personal photos, messages, or apps.

Platform-Specific BYOD Capabilities 
------------------------------------

### 1. Android BYOD (Android Enterprise) 

For personal Android devices, the recommended enrollment mode is [**Profile Owner** ](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-in-android-in-the-enterprise-as-profile-owner-using-hexnode-mdm/)(part of Android Enterprise). This creates a dedicated “Work Profile” on the device.

- **Visual Distinction**: Work apps are marked with a **briefcase icon** badge. If a user has the same app (e.g., Chrome) for both personal and work use, two icons will appear—one unmanaged (personal) and one badged (managed).
- **Management Features**: 
    - [**Managed Google Play**](https://www.hexnode.com/mobile-device-management/help/how-to-approve-and-add-afw-apps-using-hexnode-mdm/): Access to approved work apps only.
    - [**Work Container Security**](https://www.hexnode.com/mobile-device-management/help/how-to-deactivate-android-in-the-enterprise-work-container-on-non-compliance-using-hexnode-mdm/): Enforce a separate passcode for the work profile.
    - [**Password Rules**](https://www.hexnode.com/mobile-device-management/help/set-password-rules-android-enterprise-container-using-hexnode-mdm/): Mandate password set up on the device container.
    - [**Corporate Wipe**](https://www.hexnode.com/mobile-device-management/help/wipe-a-device-completely-using-hexnode-mdm/): Remove the work profile and all associated data without affecting personal photos or apps.

**Requirement**: Your organization must be enrolled in the [Android Enterprise program ](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-organization-in-android-in-the-enterprise-using-hexnode-mdm/)to use these features.

### 2. iOS BYOD (User Enrollment) 

Hexnode protects iOS devices by designating specific apps and configurations as “Managed.”

- [**Business Container**](https://www.hexnode.com/mobile-device-management/help/how-to-setup-business-container-for-ios-devices-using-hexnode-mdm/): Controls the flow of data between managed (work) and unmanaged (personal) apps to prevent data leaks.
- **Key Policies**: 
    - **Data Loss Prevention (DLP)**: Restrict copy/paste operations between work and personal apps.
    - [**Managed Domains**](https://www.hexnode.com/mobile-device-management/help/configure-domain-for-ios-devices-using-hexnode-mdm/): Mark specific email domains and web URLs as “managed” to ensure documents downloaded from them are secured. Managed Domains ensure a document downloaded from a corporate email account can’t be accidentally opened in a personal, unmanaged app (and vice versa) — the everyday scenario BYOD security actually has to prevent, not the rare edge case.
    - [**VPN**](https://www.hexnode.com/mobile-device-management/help/ios-vpn-settings/): Configure secure connections for corporate traffic.
    - [**App Catalog**](https://www.hexnode.com/mobile-device-management/help/how-to-configure-app-catalog-for-mac-devices-in-hexnode-mdm/): Create a customized store for approved enterprise apps.

### 3. Windows & macOS BYOD 

For desktop operating systems, Hexnode balances security with user experience.

FeatureWindows BYODmacOS BYOD**Email**Remotely configure work [email](https://www.hexnode.com/mobile-device-management/help/configuring-email-in-windows-devices-with-mdm/) accounts.Configure [Email](https://www.hexnode.com/mobile-device-management/help/add-email-accounts-to-macos-using-hexnode-mdm/) and [Exchange ActiveSync](https://www.hexnode.com/mobile-device-management/help/configure-exchange-activesync-on-macos-with-hexnode-mdm/).**App Management**[Deploy](https://www.hexnode.com/mobile-device-management/help/how-to-enforce-app-installation-on-windows-devices-using-hexnode-mdm/) and [blocklist/allowlist](https://www.hexnode.com/mobile-device-management/help/how-to-blacklist-whitelist-apps-on-windows-devices-using-hexnode-mdm/) apps.[Customized](https://www.hexnode.com/mobile-device-management/help/how-to-set-up-app-configurations-in-macos-using-hexnode/) [App Catalog](https://www.hexnode.com/mobile-device-management/help/how-to-configure-app-catalog-for-mac-devices-in-hexnode-mdm/) and [deployment](https://www.hexnode.com/mobile-device-management/help/how-to-enforce-app-installation-on-mac-devices-using-hexnode-mdm/).**Network**Secure [Wi-Fi](https://www.hexnode.com/mobile-device-management/help/wifi-configuration-on-windows-devices-with-mdm/) and [VPN](https://www.hexnode.com/mobile-device-management/help/how-to-configure-vpn-settings-on-your-windows-devices/) configurations.[VPN](https://www.hexnode.com/mobile-device-management/help/configure-vpn-on-macos-using-hexnode-mdm/) and [Firewall](https://www.hexnode.com/mobile-device-management/help/how-to-configure-firewall-for-mac-with-hexnode-mdm/) policy enforcement.**Security**Windows [Defender](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/) & [BitLocker](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/) integration.[FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/) management.Troubleshooting Common BYOD Issues 
-----------------------------------

If you encounter issues during **BYOD management** setup, check these common scenarios:

### Android Work Profile Not Created 

- **Cause**: The organization is not enrolled in Android Enterprise, or the user is already enrolled as a “Device Owner” (fully managed).
- **Fix**: Ensure you are using the **Profile Owner** enrollment method and that your Hexnode portal is linked to a valid Google Enterprise account.

### Apps Not Installing (iOS/Android) 

- **Cause**: The device may be locked, missing internet access, or (for iOS) the Volume Purchase Program (VPP) licenses may be exhausted.
- **Fix**: Ensure the device is unlocked and connected to Wi-Fi. Ensure you have available VPP app licenses.

### “Account Action Required” Error 

- **Cause**: Often occurs on Android if the Google account used for enrollment was removed or changed.
- **Fix**: The user must re-enter their work credentials. If the issue persists, re-enrollment may be required.