JJC SystemsBook a Consultation
Microsoft Intune · Legal

Confidentiality on devices you do not control

A control that depends on partners behaving differently from how they demonstrably behave is not a control — and in a negligence context it is worse than none.

PublishedFebruary 1, 2026
Length11 pages · 12 min read
SectorLegal
PlatformMicrosoft Intune
Service areaManaged IT & Security
Abstract

Confidentiality on devices you do not control

Summary

Every firm has a policy about personal devices. In most firms the policy is that they should not be used for client work, and the practice is that a partner in an airport reads a matter email on their own phone.

This paper argues that the gap between policy and practice is itself a professional risk, that the productive response is to protect the data rather than manage the device, and that the departure scenario is where the arrangement proves its worth.

Key findings

Four things this paper argues

If you read nothing else, read these. The analysis that follows sets out the evidence for each.

01

An unfollowed policy is a liability in a professional negligence context

It documents that the firm knew the risk and specifies a control that demonstrably did not operate.

02

Protecting the data avoids the fight about the device

Application protection controls corporate data inside the app without enrolment, which is the difference between a control partners accept and one they resist.

03

The departure scenario is the strongest argument

A partner leaving for a competitor with firm data on an unprotected personal phone is a problem with no good technical answer after the fact.

04

Protection status must be reported rather than assumed

Policy says required; the compliance report says applied. The gap between them is usually meaningful and it is what an insurer asks about.

Analysis

The argument in full

The gap and why it matters professionally

Partners read matter correspondence on personal phones. This is not going to stop, and a policy that pretends otherwise creates a specific professional risk: it establishes that the firm identified the exposure and relied on a control that was not operating.

Rewriting the policy to match observed behaviour, and then controlling that behaviour technically, converts a liability into a defensible position. It is also considerably easier to achieve than changing how senior people work.

The firms that handle this well include partners and senior staff in scope explicitly, because the exemption is usually where the most sensitive matters are.

Protecting the data rather than the device

Application protection policies apply controls to the corporate data inside an application — preventing copy to personal apps, requiring a PIN, encrypting the application's data, and allowing selective wipe of firm data without touching anything personal.

This is the difference between asking a partner to enrol their phone into firm management, which they will resist, and applying protection to firm data on it, which they will barely notice.

Five controls carry most of the benefit, and keeping the requirement proportionate matters: an aggressive PIN policy on a personal phone generates support tickets and workarounds rather than security.

  • Copy and paste from firm applications to personal ones blocked
  • PIN or biometric required to open firm applications, with a proportionate timeout
  • Saving firm documents to personal cloud storage blocked
  • Firm data encrypted within the application container
  • Selective wipe enabled and tested on a real device

The departure scenario

This is where the arrangement proves itself and it is the argument that persuades partners.

A partner leaves for a competitor. On an unprotected personal device, firm data remains on the phone and there is nothing to be done about it that does not involve lawyers and considerable awkwardness.

With application protection, firm data is removed and their photographs stay. The conversation is straightforward, there is a record that it happened, and the firm can evidence it to a client or an insurer who asks. Demonstrating that wipe on a real device before deployment is what makes partners comfortable with the arrangement in the first place.

Framework

Something you can apply without us

Every paper in this series ends with a framework you can run internally. We would rather you used it and reached your own conclusion than took ours on trust.

Framework

Protecting what you cannot manage

Five steps, in the order that produces adoption.

1

Count

Establish how many personal devices actually reach firm data. Not estimate — report.

2

Rewrite

Align the policy with observed practice, including partners and senior staff.

3

Protect

Application protection rather than enrolment. Five controls carry most of the benefit.

4

Demonstrate

Show a selective wipe on a real device. This is what makes it acceptable.

5

Evidence

Report protection status rather than assuming it, and check it matches your questionnaire answers.

Implications

What this means, depending on your seat

The same argument lands differently across an executive team. These are the three versions worth separating.

For the risk partner

For the managing partner

For the IT director

References

Where to check this for yourself

Microsoft's own documentation for the product behaviour described above. We would rather you verified the basis than accepted our summary of it.

01
App protection policies in Microsoft Intune
02
App protection policy settings for iOS and Android
03
Selective wipe in Microsoft Intune
04
Conditional Access app protection policy requirement
05
Microsoft Intune device compliance policies

On these references: each entry names a Microsoft Learn article or documentation area by title, because deep links change while titles are stable. Searching the title on learn.microsoft.com will reach the current version. Where we have cited a figure or a product behaviour, it is Microsoft's statement rather than ours; where we have given a number of our own it is labelled as such in the text.

Recognise the situation?

We will assess your current position against what your professional indemnity insurer asks, and demonstrate application protection working on a real personal phone before you commit to anything.

Discuss this paper Run the related checklist We reply to every message within one business day.
Keep reading

Related papers

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.