---
title: "Bring Your Own Device (BYOD)"
slug: "byod"
status: "new"
updated: 2026-07-17T16:11:35Z
published: 2026-07-17T16:11:35Z
canonical: "trusted.jamf.com/byod"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://trusted.jamf.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Bring Your Own Device (BYOD)

:::(Error) (We’ve moved!)
Our content that usually lives here has been moved over to [concepts.jamf.com](https://concepts.jamf.com/en/guides/). 
:::
A device ownership model in which devices are not owned by the organization, but are enabled to access organizational data, is known as "Bring Your Own Device (BYOD)".

There are many advantages of BYOD programs, but their success largely depends on properly balancing usability, security, and privacy.  Most BYOD efforts fail to catch on or operate efficiently due falling short in one (or more) of these dimensions.

The Trusted Access solution only embraces BYOD deployment models that are able to balance these requirements.  Using these approved models, IT organizations are able to securely enable end users to easily access organziational data while retain control of that data as it is exists on the device.  An crucially, this enablement and control only applies to "work" apps and data, with **absolutely no** ability to access, modify, or survey personal data.

The supported models are:
* [User Enrollment](/v1/docs/user-enrollment) for iOS and iPadOS devices
* [Work Profile](/v1/docs/android-work-profile-for-employee-owned-devices) for Android Enterprise devices

:::(Internal) (Private notes)
* BYOD philosophy: separate work and personal data across two discreet managed partitions.  
    * Treat as separate logical devices as much as possible
* Personal side should be treated as completely untrusted, just like any other device out there.
    * Must not have access to anything priviledged
* Workside should be fortified with proper at-rest and in-flight encrpytions and controls
    * Basic hygenie is enforced (passcode, OS versions) with risk-based access controls enforced.
* Links to Resource Access Controls
:::
