Forum Discussion

StuartK73's avatar
StuartK73
Steel Contributor
Apr 27, 2026

Protect org data on BYOD Windows / macOS devices

Hi All

I hope you are well.

Anyway, I have a need to protect org data on:

  • Window personal / BYOD devices
  • MacOS personal  / BYOD devices

What's the best way to achieve this?

My thinking is:

  • 1 X Conditional Access policy that blocks
  • 1 X Conditional Access policy that allows via Edge, no persistent session, no downloads etc
  • Device filter on both policies that target unmanaged devices

 

Any other suggestions?

 

SK

2 Replies

  • rahuljindal's avatar
    rahuljindal
    Bronze Contributor

    By protect do you want to restrict access on BYO, or allow access with DLP controls?

    • StuartK73's avatar
      StuartK73
      Steel Contributor

      Apologies, I should have been more specific.

      Anyway, we would like "allow access with DLP controls" for Windows and macOS devices only.

      We already have APP in place for Android and iOS unmanaged / BYOD devices.

      SK