Category filter

Getting Started with Bring Your Own Device (BYOD) Management

Every organization eventually faces the same tradeoff: buy and manage a device for every employee, or let employees use their own — and lose visibility and control the moment you do. BYOD management is how Hexnode resolves that tradeoff without forcing a choice. It lets employees keep using the phone or laptop they already own and know, while giving IT the same security guarantees as a corporate-owned device — without ever touching the employee’s personal photos, messages, or apps.

Hexnode achieves this through containerization — a secure, encrypted container on the device that keeps corporate data walled off from personal data. Corporate data stays governed by policy; personal data stays untouched and invisible to IT.

Key Features of Hexnode BYOD Management

  • Data Segregation: Distinct separation of personal and work data.
  • Security & Compliance: Automated compliance checks and data protection.
  • App Management: Secure deployment of enterprise apps.
  • Corporate Wipe: Ability to remotely remove only work data, leaving personal data intact.

What this prevents?

Without containerization, a lost or stolen personal phone with corporate email on it becomes an all-or-nothing decision — wipe the whole device (destroying the employee’s personal photos and data) or leave corporate data exposed. Containerization means IT can wipe only the corporate container, leaving the employee’s personal data untouched, while still closing the security gap.

Core Strategic Benefits

  • Cost Reduction: Drastically lowers hardware procurement and maintenance expenses.
  • Employee Satisfaction: Allows users to work on familiar devices of their choice.
  • Productivity: Enables “anywhere, anytime” access to business-critical resources.
  • Privacy Assurance: Ensures corporate admins cannot view personal photos, messages, or apps.

Platform-Specific BYOD Capabilities

1. Android BYOD (Android Enterprise)

For personal Android devices, the recommended enrollment mode is Profile Owner (part of Android Enterprise). This creates a dedicated “Work Profile” on the device.

  • Visual Distinction: Work apps are marked with a briefcase icon badge. If a user has the same app (e.g., Chrome) for both personal and work use, two icons will appear—one unmanaged (personal) and one badged (managed).
  • Management Features:

Requirement: Your organization must be enrolled in the Android Enterprise program to use these features.

2. iOS BYOD (User Enrollment)

Hexnode protects iOS devices by designating specific apps and configurations as “Managed.”

  • Business Container: Controls the flow of data between managed (work) and unmanaged (personal) apps to prevent data leaks.
  • Key Policies:
    • Data Loss Prevention (DLP): Restrict copy/paste operations between work and personal apps.
    • Managed Domains: Mark specific email domains and web URLs as “managed” to ensure documents downloaded from them are secured. Managed Domains ensure a document downloaded from a corporate email account can’t be accidentally opened in a personal, unmanaged app (and vice versa) — the everyday scenario BYOD security actually has to prevent, not the rare edge case.
    • VPN: Configure secure connections for corporate traffic.
    • App Catalog: Create a customized store for approved enterprise apps.

3. Windows & macOS BYOD

For desktop operating systems, Hexnode balances security with user experience.

Feature Windows BYOD macOS BYOD
Email Remotely configure work email accounts. Configure Email and Exchange ActiveSync.
App Management Deploy and blocklist/allowlist apps. Customized App Catalog and deployment.
Network Secure Wi-Fi and VPN configurations. VPN and Firewall policy enforcement.
Security Windows Defender & BitLocker integration. FileVault management.

Troubleshooting Common BYOD Issues

If you encounter issues during BYOD management setup, check these common scenarios:

Android Work Profile Not Created

  • Cause: The organization is not enrolled in Android Enterprise, or the user is already enrolled as a “Device Owner” (fully managed).
  • Fix: Ensure you are using the Profile Owner enrollment method and that your Hexnode portal is linked to a valid Google Enterprise account.

Apps Not Installing (iOS/Android)

  • Cause: The device may be locked, missing internet access, or (for iOS) the Volume Purchase Program (VPP) licenses may be exhausted.
  • Fix: Ensure the device is unlocked and connected to Wi-Fi. Ensure you have available VPP app licenses.

“Account Action Required” Error

  • Cause: Often occurs on Android if the Google account used for enrollment was removed or changed.
  • Fix: The user must re-enter their work credentials. If the issue persists, re-enrollment may be required.

Frequently Asked Questions

Can the IT admin see my personal photos or messages?

No. In a BYOD setup (Profile Owner on Android or User Enrollment on iOS), the admin has zero access to your personal apps, photos, messages, or browsing history. They can only manage the “Work” container.

What is the difference between "Device Wipe" and "Corporate Wipe"?
  • Corporate Wipe: Removes only the work apps, work emails, and corporate configurations. Personal data remains untouched. This is the standard action for BYOD.
  • Device Wipe: Resets the device to factory settings, erasing everything. This is rarely used for BYOD unless the device is lost/stolen and the user requests it.
What happens if an employee leaves the company?

The admin initiates a Corporate Wipe. This instantly removes all business data (emails, VPN keys, work apps) from the user’s device, while leaving their personal phone exactly as it was.

Why do I see two Play Store icons on my Android phone?

This is normal for Android Enterprise. The icon with the briefcase badge is the Managed Google Play Store (for work apps), and the unbadged one is your personal Play Store.

Can the IT admin see my personal photos or messages?

No. In a BYOD setup (Profile Owner on Android or User Enrollment on iOS), the admin has zero access to your personal apps, photos, messages, or browsing history. They can only manage the “Work” container.

How to remotely wipe only corporate data on a BYOD device?

To remotely wipe only corporate data on a BYOD device in Hexnode, you need to disenroll the device. This removes all corporate data, managed apps, Wi-Fi, VPN configurations while keeping the employee’s personal data completely untouched.

To disenroll the device navigate to Manage > Devices > Choose your BYOD device > Actions > Disenroll

You could also dissociate all policies associated with the device.For that, navigate to Manage > Devices > Select the device > Policies Tab, and remove the associated policies from the device.

Get Started