Skip to content

Understanding Company Portal, Device Management, and Your Privacy

Applies toWindows 10Windows 11iOSAndroid
16 min read Updated 9 Aug 2026
Quick Answer

Company Portal (Microsoft Intune) lets your organization manage security policies on your device — like requiring a PIN or encrypting storage — but it does not give IT access to your personal photos, texts, or browsing history. IT can see your device name and OS version, not your personal data.

Checked against Microsoft Learn - Windows release health, Microsoft Learn - end of support and retirement and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Summary

This article explains what happens when your organization manages your device through Microsoft Intune and the Company Portal app. It answers the most common question employees have: "What can IT see on my phone or computer?" Understanding what IT can and cannot access builds trust, reduces anxiety, and helps you make informed decisions about enrolling personal devices.

In this guide

Before You Start

  • A Microsoft 365 account with your organization.
  • A device (computer, phone, or tablet) that is managed by your organization, or one you are considering enrolling.

Instructions

1. What Is Device Management (Intune)?

Microsoft Intune is a cloud-based service that helps organizations manage the devices employees use to access company data. When your device is "managed" or "enrolled," it means your organization has applied security policies to protect company data — not to monitor your personal activity.

Device management typically happens in two scenarios:

  • Company-owned devices — Your organization provided the laptop or phone. IT has full management rights.
  • BYOD (Bring Your Own Device) — You use your personal phone or laptop for work. IT can manage company data on it, but with significant privacy limitations.

2. What IT Can See on a Managed Device

The following information is visible to IT administrators regardless of whether the device is company-owned or personal. This section covers the device — for what your employer can see inside your Microsoft 365 account and on a company laptop, see Understanding What IT Can See on Your Work Computer.

Information IT Can SeeWhy They Need It
Device name and modelTo identify devices for support and inventory.
Operating system and versionTo verify you have required security updates.
Device compliance statusTo check if your device meets security policies (encryption, PIN, etc.).
Installed company appsTo verify required apps (like Teams or Outlook) are installed.
Serial number and device IDFor asset tracking and support troubleshooting.
Network (Wi-Fi) connection typeTo determine if the device is on a secured network.

3. What IT Cannot See on Your Personal (BYOD) Device

This is the most important section. When you enroll a personal device, IT cannot see or access any of the following:

Information IT Cannot SeeDetails
Personal emailsYour Gmail, Yahoo, or personal Outlook inbox is completely private.
Text messages (SMS/iMessage)IT has no access to your text conversations.
Personal photos and videosYour camera roll and personal media are never visible to IT.
Browsing historyWhat you search for or visit in your personal browser is not tracked.
Phone call historyIT cannot see who you call or who calls you.
Personal app dataData inside your personal apps (social media, banking, health, etc.) is private.
GPS location (in most cases)Your real-time location is not tracked. Some organizations may use location for lost device tracking only — but only if you explicitly enable it.
ContactsYour personal address book is not accessible to IT.

DANGER

This applies to BYOD (personal) devices enrolled with Intune. Company-owned devices may have broader management capabilities, including the ability to see installed apps, enforce stricter policies, and remotely wipe the entire device. If you are unsure which category your device falls into, ask IT to confirm how it is enrolled and to send you the device management or acceptable-use policy that applies to it — that document is what tells you exactly what is collected.

4. What IT Can Do (Actions on Your Device)

On a Personal (BYOD) Device

  • Enforce a screen lock or PIN — Require a passcode to unlock your device.
  • Require encryption — Ensure your device's storage is encrypted.
  • Remotely wipe company data only — If you leave the company or lose your device, IT can remove company apps, email, and files without touching your personal data, photos, or apps.
  • Block access to company resources — If your device does not meet security requirements (e.g., outdated OS), IT can block access to company email and apps until the device is updated.

On a Company-Owned Device

  • Everything listed above for BYOD, plus:
  • Remotely wipe the entire device — IT can factory reset a company-owned device.
  • Install or remove apps — IT can push required apps and remove unapproved ones.
  • Enforce stricter policies — Restrict app installations, disable features, and apply more granular security controls.

5. What Is the Company Portal App?

The Company Portal app is a self-service tool provided by your organization. It is available on Windows, iOS, and Android.

What you can do in Company Portal:

  • View your enrolled devices and their compliance status.
  • Install company-approved apps from an internal app catalog.
  • Check if your device meets your organization's security requirements.
  • Sync your device to refresh policies and app availability.
  • Contact IT support directly from within the app — your device name and compliance status travel with the request, so include the exact message you saw and what you were trying to open.
  • Remotely lock or reset your own device if it is lost or stolen.

What Company Portal does NOT do:

  • It does not track your location (unless you explicitly enable lost device tracking).
  • It does not monitor your personal apps, messages, or browsing.
  • It does not give IT access to your personal files.

6. When IT Sets an Enrollment Deadline

If a message from IT has told you to enroll a device by a date, it is worth being plain about what that date is and what it is not.

What the deadline actually is

Your organization sets a compliance policy — a list of conditions a device has to meet before it is allowed to reach company data. Every such policy marks a device non-compliant the moment it fails, and your organization can extend that into a grace period so people have time to put things right. Your deadline is the end of that grace period.

What happens at the end of it is a rule running, not a person deciding you are in trouble. Once the device is marked non-compliant, a Conditional Access rule can block it from company resources such as email and files. Nobody reviews your case that morning.

Two details are worth knowing so the warnings do not alarm you:

  • Reminder emails about a non-compliant device come from [email protected], and Microsoft sends them within about six hours of the device being marked non-compliant. An email from that address is genuine, not a phishing attempt.
  • Company Portal can also send a push notification about non-compliance. Microsoft's own documentation says delivery of that notification is not guaranteed and it can arrive hours late, so treat the date IT gave you as the real one rather than waiting for a prompt.

What you lose if you do not enroll

Access to work email, files and company apps on that device. That is the whole consequence, and it is a policy consequence rather than a punishment.

What does not happen: nothing is deleted, your work account is not disabled, your personal data is not touched, and the phone or laptop carries on being an ordinary personal device. You keep working on a company computer.

The one thing worth checking before the deadline is whether browser access on a computer stays open to you. Some organizations require a managed device only for the apps on a phone and leave Outlook on the web reachable from a computer. Others require a managed device everywhere. Only your IT team knows which of those your organization has set, so ask them in the words below.

On a personal device, this is a choice

If your employer owns the device, enrollment comes with it. If you own it, you are being asked to accept your employer's rules on your own property, and there are real alternatives:

  • Use the web on a computer — read work mail at outlook.office.com and use Teams in a browser, with nothing installed on your phone.
  • Ask for a work-issued device — a phone your employer owns and manages, which takes the question off your personal one entirely.
  • Agree that mobile access is not part of your role — the honest answer in plenty of jobs.

What your employer is entitled to require of a device you own varies by where you work and what your contract says, so treat this as a conversation to have before the deadline rather than a rule to discover after it. Send IT something like this:

Before I enroll my personal phone by Friday, could you confirm two things?

First, if I do not enroll the phone, does browser access to Outlook and Teams on my work computer stay available?

Second, is a work-issued phone an option for my role?

Could you also send me the device management policy that would apply, so I can read what enrollment covers? If enrolling is the only route to what my job needs, I will go ahead — I would like to understand the options first.

If you have not decided which arrangement you want, Understanding BYOD Setup Choices for Your Personal Phone sets out the four your employer may be asking for and what each one costs you day to day.

7. Enrolling a Personal Device — What to Expect

If your organization requires you to enroll a personal phone or laptop, here is what typically happens:

  1. Download the Company Portal app from the App Store (iOS) or Google Play Store (Android), or install it on Windows.
  2. Sign in with your work Microsoft 365 credentials.
  3. Follow the enrollment prompts — the app will guide you through enabling required security settings (e.g., setting a device PIN, enabling encryption).
  4. Accept the terms — You will see a summary of what IT can and cannot see. Review this carefully.
  5. Once enrolled, you can access company email, apps, and files on your personal device.

Tip: If you are uncomfortable enrolling your personal phone, ask IT for the device management policy so you can read what enrollment actually covers, then ask whether web-only access is available instead — many organizations allow Outlook on the web and Teams in a browser with no enrollment at all. Full enrollment is one of four arrangements your employer may be asking for, and Understanding BYOD Setup Choices for Your Personal Phone compares them side by side — including keeping work off the phone entirely.

8. Your Enrollment-Day Checklist

Enrollment goes wrong through bad timing more often than anything else, so pick the right half hour and have the right things to hand.

Have these ready before you start

  • Your work email address and password, plus whatever second sign-in step your organization uses — the Microsoft Authenticator app, a text code, or a security key. Enrollment signs you in from scratch.
  • A stable Wi-Fi connection and an uninterrupted stretch of time. Microsoft's guidance for enrolling a personal iPhone is to stay on Wi-Fi until every step finishes, because pausing for more than a few minutes can close Company Portal and end setup — and then you start again.
  • Free storage space, since your organization installs its required apps onto the device as part of the process.
  • An up-to-date operating system. Compliance policies commonly set a minimum version, and an out-of-date device fails the check at the end of enrollment rather than the beginning. Update it the night before.
  • A willingness to change your screen lock. If the policy requires six digits and yours is four, you change yours during setup.

How long to set aside

The taps take a few minutes; the waiting is what makes it half an hour. After enrollment the device spends several more minutes receiving policies and apps from your organization, and Microsoft's own walkthroughs tell you to wait at several separate points. Set aside half an hour, and do not start it five minutes before a meeting.

What the device prompts for

  • Signing in with your work or school account, followed by your second sign-in step.
  • Your organization's terms and conditions, if it has set any.
  • A screen listing what your organization can and cannot see. On Android, Company Portal asks you to review this and tap CONTINUE; on an iPhone it appears on the How to set up your device screen. Read it rather than tapping through — it is the shortest accurate statement of your own position, written against the policy your employer actually configured.
  • Permissions the platform requires. On Android, Company Portal asks for phone and contacts access. Microsoft's documentation is specific about why: the phone permission lets the device share its IMEI number with Intune, the contacts permission lets the app create and manage your work account, and Microsoft never makes calls or reads your contacts.
  • Device setting changes to meet policy — a longer passcode, encryption turned on, or an operating system update. Company Portal names each one and offers to take you to it.

What visibly changes afterwards

  • Your device appears in Company Portal under Devices, with a compliance status next to it.
  • Work apps stop refusing you. Signing in to Outlook or Teams with your work account goes through instead of prompting you to get the device managed.
  • On Android with a work profile, work apps carry a briefcase badge and gather under a Work tab in the app drawer.
  • On a personal iPhone, a management profile appears in Settings > General > VPN & Device Management.
  • Your personal apps, photos, messages and accounts are exactly where they were. Nothing on the personal side moves.

To confirm what kind of enrollment you ended up with, sign in to the Company Portal app or website and open Device Details — it shows the ownership type recorded for the device, which is what decides whether the personal-device limits in Section 3 apply to you.

Where the step-by-step lives

This article covers what enrollment means. The walkthroughs cover the taps:

9. Unenrolling a Device

If you want to remove your personal device from management:

  1. Open the Company Portal app.
  2. Go to Devices and select the device you want to unenroll.
  3. Tap Remove (or Unenroll).
  4. Confirm the action.

What happens when you unenroll:

  • Company apps and data are removed from your device.
  • Your personal apps, photos, and data are not affected.
  • You will lose access to company email and apps on that device.
  • Your device is removed from IT's management inventory.

10. Frequently Asked Questions

Q: Can IT read my personal texts or emails? A: No. IT cannot access personal messages, emails, or any personal app data on a BYOD device.

Q: Can IT see what websites I visit? A: No. Your browsing history on your personal browser is not visible to IT. However, if you use a company VPN or a company-owned browser profile, web traffic through those tools may be logged.

Q: Can IT track my location? A: Generally, no. Location tracking is not enabled by default. If your organization uses lost device tracking, you would have been notified and asked for consent during enrollment.

Q: Will IT know if I uninstall the Company Portal? A: Yes — unenrolling removes the device from management. You will lose access to company resources on that device.

Q: Can IT wipe my entire phone? A: On a personal (BYOD) device, IT can only wipe company data — your personal photos, apps, and messages remain untouched. On a company-owned device, IT can perform a full factory reset.

Troubleshooting

TIP

If you are concerned about privacy, ask your IT department for a copy of your organization's Mobile Device Management (MDM) policy. This document details exactly what data is collected and what actions IT can take on enrolled devices.

Symptom / ErrorPotential CauseSolution
"Your device is not compliant"Device does not meet security requirementsOpen Company Portal > check what requirement is not met (usually OS update or PIN). Fix the issue and sync.
Cannot access company email on personal phoneDevice not enrolled or compliance policy blocking accessEnroll your device via Company Portal (see Section 7), or ask IT whether browser access on a computer stays open to you (see Section 6).
Company Portal keeps asking to re-enrollEnrollment profile was corrupted or removedUnenroll (Section 9), restart the device, and re-enroll from scratch.
Work apps stop signing in after an enrollment deadline passesThe grace period ended, the device is marked non-compliant, and a Conditional Access rule is blocking itEnroll the device, or use a work computer while you settle the question with IT (see Section 6). Nothing on your device is deleted by the block.
Worried about privacy after enrollmentUncertainty about what IT can seeReview the tables in Sections 2 and 3 above, or ask IT for the MDM policy document.

Last updated:

Frequently asked questions

Can my employer see my text messages or personal photos?
No. Microsoft Intune and Company Portal cannot access your personal text messages, photos, web browsing history, or personal emails on your device.
Can my company wipe my personal phone?
If you are using a personal device (BYOD), IT can only perform a 'Selective Wipe', which removes company emails and apps (like Outlook and Teams) without touching your personal data.
What happens if I do not enroll my device by my organization's deadline?
Your organization's compliance policy stops treating that device as allowed, and access to work email, files and apps on it is blocked. Nothing is deleted, your personal data is untouched, and your work account keeps working elsewhere. Whether you can still reach work email in a browser on a computer depends on the rules your organization has set, so ask IT to confirm that before the deadline rather than after it.