Application protection policies.
WHAT THEY DO
Control how organisational data behaves within applications.
WHAT THEY CAN ENFORCE
Preventing copying into unmanaged applications Preventing saving to personal locations Requiring a passcode to open the application Encrypting application data Wiping organisational data selectively
WHY SELECTIVE WIPE MATTERS
Personal devices can be protected without removing the owner's own content.
WHAT THAT MAKES POSSIBLE
Supporting personal devices with reasonable protection and no ownership dispute.
WHAT TO CONFIGURE
Policies per platform, since capabilities differ.
WHAT TO BE CAREFUL WITH
Restrictions preventing legitimate work, which drive people to workarounds.
WHAT WORKAROUNDS LOOK LIKE
Forwarding to personal mail Photographing screens Using unmanaged applications
WHY THAT MATTERS
Excessive restriction produces worse outcomes than moderate restriction.
WHAT TO ESTABLISH
What genuinely needs protecting.
WHAT TO COMMUNICATE
What the organisation can and cannot see on a personal device.
WHY
It is the commonest objection, and it is usually based on a misunderstanding.
WHAT TO TEST
That a selective wipe removes what it should and nothing else.