Appearance
Understanding Company Portal, Device Management, and Your Privacy
Applies to: Windows 10, Windows 11, iOS, Android, Microsoft Intune
Article Type: Informational
Last Updated: 2026-05-19
Summary
This article explains what happens when your organization manages your device through Microsoft Intune and the Company Portal app. It answers the most common question employees have: "What can IT see on my phone or computer?" Understanding what IT can and cannot access builds trust, reduces anxiety, and helps you make informed decisions about enrolling personal devices.
Prerequisites
- A Microsoft 365 account with your organization.
- A device (computer, phone, or tablet) that is managed by your organization, or one you are considering enrolling.
Instructions
1. What Is Device Management (Intune)?
Microsoft Intune is a cloud-based service that helps organizations manage the devices employees use to access company data. When your device is "managed" or "enrolled," it means your organization has applied security policies to protect company data — not to monitor your personal activity.
Device management typically happens in two scenarios:
- Company-owned devices — Your organization provided the laptop or phone. IT has full management rights.
- BYOD (Bring Your Own Device) — You use your personal phone or laptop for work. IT can manage company data on it, but with significant privacy limitations.
2. What IT Can See on a Managed Device
The following information is visible to IT administrators regardless of whether the device is company-owned or personal. This section covers the device — for what your employer can see inside your Microsoft 365 account and on a company laptop, see Understanding What IT Can See on Your Work Computer.
| Information IT Can See | Why They Need It |
|---|---|
| Device name and model | To identify devices for support and inventory. |
| Operating system and version | To verify you have required security updates. |
| Device compliance status | To check if your device meets security policies (encryption, PIN, etc.). |
| Installed company apps | To verify required apps (like Teams or Outlook) are installed. |
| Serial number and device ID | For asset tracking and support troubleshooting. |
| Network (Wi-Fi) connection type | To determine if the device is on a secured network. |
3. What IT Cannot See on Your Personal (BYOD) Device
This is the most important section. When you enroll a personal device, IT cannot see or access any of the following:
| Information IT Cannot See | Details |
|---|---|
| Personal emails | Your Gmail, Yahoo, or personal Outlook inbox is completely private. |
| Text messages (SMS/iMessage) | IT has no access to your text conversations. |
| Personal photos and videos | Your camera roll and personal media are never visible to IT. |
| Browsing history | What you search for or visit in your personal browser is not tracked. |
| Phone call history | IT cannot see who you call or who calls you. |
| Personal app data | Data inside your personal apps (social media, banking, health, etc.) is private. |
| GPS location (in most cases) | Your real-time location is not tracked. Some organizations may use location for lost device tracking only — but only if you explicitly enable it. |
| Contacts | Your personal address book is not accessible to IT. |
DANGER
This applies to BYOD (personal) devices enrolled with Intune. Company-owned devices may have broader management capabilities, including the ability to see installed apps, enforce stricter policies, and remotely wipe the entire device. If you are unsure which category your device falls into, ask IT to confirm how it is enrolled and to send you the device management or acceptable-use policy that applies to it — that document is what tells you exactly what is collected.
4. What IT Can Do (Actions on Your Device)
On a Personal (BYOD) Device
- Enforce a screen lock or PIN — Require a passcode to unlock your device.
- Require encryption — Ensure your device's storage is encrypted.
- Remotely wipe company data only — If you leave the company or lose your device, IT can remove company apps, email, and files without touching your personal data, photos, or apps.
- Block access to company resources — If your device does not meet security requirements (e.g., outdated OS), IT can block access to company email and apps until the device is updated.
On a Company-Owned Device
- Everything listed above for BYOD, plus:
- Remotely wipe the entire device — IT can factory reset a company-owned device.
- Install or remove apps — IT can push required apps and remove unapproved ones.
- Enforce stricter policies — Restrict app installations, disable features, and apply more granular security controls.
5. What Is the Company Portal App?
The Company Portal app is a self-service tool provided by your organization. It is available on Windows, iOS, and Android.
What you can do in Company Portal:
- View your enrolled devices and their compliance status.
- Install company-approved apps from an internal app catalog.
- Check if your device meets your organization's security requirements.
- Sync your device to refresh policies and app availability.
- Contact IT support directly from within the app — your device name and compliance status travel with the request, so include the exact message you saw and what you were trying to open.
- Remotely lock or reset your own device if it is lost or stolen.
What Company Portal does NOT do:
- It does not track your location (unless you explicitly enable lost device tracking).
- It does not monitor your personal apps, messages, or browsing.
- It does not give IT access to your personal files.
6. Enrolling a Personal Device — What to Expect
If your organization requires you to enroll a personal phone or laptop, here is what typically happens:
- Download the Company Portal app from the App Store (iOS) or Google Play Store (Android), or install it on Windows.
- Sign in with your work Microsoft 365 credentials.
- Follow the enrollment prompts — the app will guide you through enabling required security settings (e.g., setting a device PIN, enabling encryption).
- Accept the terms — You will see a summary of what IT can and cannot see. Review this carefully.
- Once enrolled, you can access company email, apps, and files on your personal device.
Tip: If you are uncomfortable enrolling your personal phone, ask IT for the device management policy so you can read what enrollment actually covers, then ask whether web-only access is available instead — many organizations allow Outlook on the web and Teams in a browser with no enrollment at all.
7. Unenrolling a Device
If you want to remove your personal device from management:
- Open the Company Portal app.
- Go to Devices and select the device you want to unenroll.
- Tap Remove (or Unenroll).
- Confirm the action.
What happens when you unenroll:
- Company apps and data are removed from your device.
- Your personal apps, photos, and data are not affected.
- You will lose access to company email and apps on that device.
- Your device is removed from IT's management inventory.
8. Frequently Asked Questions
Q: Can IT read my personal texts or emails? A: No. IT cannot access personal messages, emails, or any personal app data on a BYOD device.
Q: Can IT see what websites I visit? A: No. Your browsing history on your personal browser is not visible to IT. However, if you use a company VPN or a company-owned browser profile, web traffic through those tools may be logged.
Q: Can IT track my location? A: Generally, no. Location tracking is not enabled by default. If your organization uses lost device tracking, you would have been notified and asked for consent during enrollment.
Q: Will IT know if I uninstall the Company Portal? A: Yes — unenrolling removes the device from management. You will lose access to company resources on that device.
Q: Can IT wipe my entire phone? A: On a personal (BYOD) device, IT can only wipe company data — your personal photos, apps, and messages remain untouched. On a company-owned device, IT can perform a full factory reset.
Troubleshooting
TIP
If you are concerned about privacy, ask your IT department for a copy of your organization's Mobile Device Management (MDM) policy. This document details exactly what data is collected and what actions IT can take on enrolled devices.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| "Your device is not compliant" | Device does not meet security requirements | Open Company Portal > check what requirement is not met (usually OS update or PIN). Fix the issue and sync. |
| Cannot access company email on personal phone | Device not enrolled or compliance policy blocking access | Enroll your device via Company Portal (see Step 6). |
| Company Portal keeps asking to re-enroll | Enrollment profile was corrupted or removed | Unenroll (Step 7), restart the device, and re-enroll from scratch. |
| Worried about privacy after enrollment | Uncertainty about what IT can see | Review the tables in Sections 2 and 3 above, or ask IT for the MDM policy document. |
Related Articles
- Understanding Microsoft 365 Account Security — What Protects You and Why
- How to Set Up Self-Service Password Reset (SSPR)
- How to Use the Microsoft Authenticator App
- How to Understand MFA and Prevent Account Lockouts
- How to Manage App Permissions and Connected Apps in Microsoft 365
- How to Lock Your Computer Quickly on Windows
- Understanding What IT Can See on Your Work Computer