BYOD

Work browsing on personal devices, without device takeover

People use personal laptops for work, but a device-wide VPN can be intrusive, hard to justify, and risky for calls, banking, personal browsing, and local tools.

Real-world situation

A regional sales manager needs CRM, order status and partner portals from a personal laptop during a two-week trip. IT wants accountable work access, but does not want to enroll the whole device into MDM or route personal calls, banking and local tools through a company network path.

What buyers worry about

  • A device-wide VPN is hard to justify on a personal laptop and can affect non-work traffic.
  • The company needs evidence of work access without controlling the employee’s whole device.
  • On unmanaged devices, the security boundary must be explicit: what BusinessProxy controls and what remains outside.

What you control

Control the managed browser path: routing mode, work domains, allowed egress region, domain/category policy, traffic limits, active sessions, and session history.

What stays outside

Personal apps, calls, banking, local tools, non-browser traffic, and unmanaged browser profiles stay outside BusinessProxy. On unmanaged devices, users can still use other browsers outside this product boundary.

Review

What administrators can verify

  • The managed path stays inside the work browser profile, not the whole personal device.
  • Personal apps, calls, banking and non-browser traffic stay outside BusinessProxy.
  • HTTPS page content is not decrypted on the managed browser path.
  • Admins can end work sessions without taking over the personal machine.
  • Forced rollout requires validation of customer-managed browser or device policy.

Success signals

  • Work sites open in the managed browser profile while calls, banking and local tools remain direct.
  • Administrators can review session history and end the work session without touching the personal device.
  • The BYOD rollout notes clearly state that unmanaged browsers and profiles are outside the product boundary.

Rollout

What the workflow looks like

  1. Define the work domains and internal apps that are allowed for the BYOD group.
  2. Choose the work-browser routing mode and document what stays outside BusinessProxy.
  3. Invite users, have them sign in from the supported browser profile, and verify the first work session.
  4. Review session history after rollout and tighten domain/category rules if needed.

FAQ

Will BusinessProxy see my personal browsing?

BusinessProxy manages the browser path configured for work. Personal apps, non-browser traffic, and unmanaged browser profiles are outside the product boundary. On the managed browser-proxy path, HTTPS page content is not decrypted.

Can users bypass the managed path?

On unmanaged devices, yes: users can use other browsers or unmanaged browser profiles outside BusinessProxy. Enforced BYOD deployments require customer-managed browser or device policy validation before rollout.

Does this replace endpoint management?

No. BusinessProxy is for managed browser access. It does not replace MDM, EDR, device compliance, or endpoint control.

Related use cases

Work browsing on personal devices, without device takeover