For most agencies between 70 and 150 people, BYOD is now a genuinely workable iPhone policy, not just a cheaper compromise. Apple’s account-driven User Enrolment creates a real technical separation between work and personal data on a personally owned iPhone, which changes what IT can see, control, and wipe. Company-issued devices still make sense for specific roles, but the case against BYOD on privacy or control grounds is largely out of date.
Most guidance on this topic still treats BYOD as a management headache to be tolerated rather than a properly supported option. That framing predates the tools Apple has since built specifically to solve it.
This matters more at 70-150 users than it does at either extreme. A ten-person studio can manage most of this informally. A 500-person enterprise usually has a dedicated mobility team to handle the complexity either way. Agencies in between need a policy that works without adding headcount, and that is exactly the gap User Enrolment was designed to close.
Company-issued and BYOD differ in how much of the device IT actually controls
A company-issued iPhone enrolled through standard device management gives IT full visibility and control. Every app, setting, and piece of data on that device sits within scope. This is the right approach for a device the business owns outright and expects to reissue or wipe completely when someone leaves.
BYOD under older management approaches offered a much rougher choice: either give IT that same full visibility over a personal device, which most staff understandably resist, or leave the device almost entirely unmanaged, which leaves company data exposed. Neither option satisfied anyone. This is the gap Apple’s User Enrolment was built to close.
Older enterprise mobility management guidance, much of which still circulates online, was written for this rougher choice. It treats BYOD as inherently riskier than company-issued because, historically, it was. That risk assessment has not caught up with what account-driven User Enrolment now actually does on an iPhone.
This piece sits alongside our wider look at our dedicated iPad and iPhone device management service, which covers how both enrolment types fit into a full Apple device management setup.
Apple’s User Enrolment changes what BYOD actually means for data control
Account-driven User Enrolment uses a Managed Apple Account, sometimes still called a Managed Apple ID, to create a genuinely separate, encrypted space on the device for work apps and data. Personal apps, photos, and messages sit in a completely separate space that the Managed Apple Account has no visibility into.
In practice, this means IT can manage, and if needed remove, only the work side. Personal data, including anything in the user’s own iCloud account, stays outside IT’s reach entirely. If someone leaves the business, removing the work profile clears company data and leaves everything personal untouched.
This is a meaningful shift from the assumption still common in generic BYOD guidance, that any device management on a personal phone means the employer can see everything on it. Under User Enrolment, that simply is not how the access is built.
The distinction is worth spelling out for staff directly, since it is usually the sticking point in getting BYOD accepted. IT is not being given a window into someone’s personal messages, photos, or browsing. The Managed Apple Account only ever has authority over the work partition it created. Nothing outside that boundary is reachable, regardless of what device management policies the business applies.
Ever get the feeling your IT is holding you back?
Whether you’re looking to make your existing systems more efficient or are toying with the idea of a complete overhaul, Dr Logic is here to help.
Which approach fits a 70-150 person creative agency
The right policy usually depends on the role rather than a single company-wide rule.
- Client-facing account and creative leads who need full Apple Business features, including certain collaboration and iCloud services, are often better served by a company-issued device.
- Internal operations, finance, and admin staff handling email, messaging, and shared documents are typically well served by BYOD under User Enrolment, since their day-to-day work fits comfortably within the managed partition.
- Staff who already carry a personal iPhone they would rather not duplicate are the clearest candidates for BYOD, provided the role does not need device-level features User Enrolment cannot reach.
Cost is a genuine factor too. Company-issued devices carry hardware and lifecycle costs the business absorbs directly. BYOD shifts that cost to the individual, though it usually calls for some form of stipend or reimbursement to be fair and to keep the policy something staff actually want to opt into.
None of this needs to be an all-or-nothing decision made once and left alone. Agencies growing through the 70-150 user range often start with a default position, BYOD for most roles, company-issued for a defined set of exceptions, and adjust as specific hires or client requirements make the case for a different split.
Company-issued vs BYOD: what changes under each approach
| Factor | Company-issued device | BYOD with user enrolment |
|---|---|---|
| Hardware cost | Business-owned | Employee-owned |
| IT visibility | Full device | Work partition only |
| Personal data access | N/A, device is company property | None, fully separated |
| Full Apple Business feature access | Yes | Partial |
| Best suited to | Client-facing, creative leads | Internal ops, admin, finance |
| Offboarding | Full wipe and reissue | Work profile removed only |
In Dr Logic’s experience, the biggest source of confusion is not the technology itself but out-of-date assumptions about what BYOD management can see. Once a business understands the actual boundary User Enrolment creates, the policy decision becomes much easier to have with staff.
What this means for a growing agency’s device policy
A blanket policy, all company-issued or all BYOD, rarely fits an agency at this size well. The more workable approach splits by role: company-issued where the full feature set genuinely matters, BYOD under User Enrolment everywhere else. Getting this right also depends on the device policy being written clearly enough that staff understand exactly what is and is not visible to the business, since that clarity is what makes BYOD acceptable to employees in the first place.
Reviewing this as part of a broader IT strategy, rather than device by device, tends to produce a policy that holds up as the team grows.
Looking for expert IT support? Get in touch.
Related articles
- Why Apple device management isn’t just an IT task – it’s a security strategy
- Mobile device security for business: key risks and how to fix them
- Endpoint protection alone no longer protects a 100-person creative agency
FAQs
Can IT see personal data on a BYOD iPhone under User Enrolment?
No. Account-driven User Enrolment creates a separate, encrypted work partition using a Managed Apple Account. IT can only see and manage that work partition. Personal apps, photos, messages, and the user’s own iCloud account remain completely outside IT’s visibility.
What happens to company data if someone leaves and uses their own iPhone?
IT removes the work profile created under User Enrolment, which clears all company apps, email, and data from the device. Personal data outside that profile is never touched, since it was never part of what IT could access.
Should client-facing staff use BYOD or a company-issued iPhone?
Client-facing and creative leads who need full Apple Business features, including certain collaboration and iCloud capabilities, are usually better served by a company-issued device. BYOD under User Enrolment suits internal roles where day-to-day work fits within the managed work partition.
Is BYOD cheaper than issuing company iPhones?
BYOD shifts hardware cost to the employee, which reduces direct spend, but a fair policy usually includes some stipend or reimbursement. The real saving is avoiding duplicate devices for staff who already carry a personal iPhone they would rather keep using.
Does a BYOD policy need to be written down formally?
Yes. A clear written policy setting out exactly what IT can and cannot see under User Enrolment is what makes BYOD acceptable to staff. Without that clarity, employees are more likely to resist enrolment even when the actual access is limited.



















































