021 519 21 27
Blog · Security

Personal computers and external providers: how to protect company data

By Ricardo Da Silva, RSCOM · 10 October 2026

An employee reads work e-mail on their private phone, an assistant works on Fridays from the family computer, an accountant or an external developer needs access to certain files… It is convenient, but these devices are neither managed nor controlled by the company. How do you keep control of the data?

The risk

Private phones: protect the apps, not the whole phone

With Microsoft Intune, there is no need to “take over” the personal phone. Only the work apps are protected (Outlook, Teams, OneDrive): mandatory passcode, no copy-paste to private apps, and wiping of company data only when the employee leaves. Private photos and apps are never touched.

Private computers: browser-only access, under conditions

External providers: guest access, limited and time-bound

  1. A guest account (Microsoft Entra) rather than a shared employee account or a password sent by e-mail.
  2. Access to a single SharePoint site or Teams team, not to everything.
  3. An expiry date on access and sharing links.
  4. For remote maintenance: a tool that asks for the user’s consent and logs connections.
  5. A review of external access at the end of each assignment.

A simple rule, in writing

One page is enough: which devices may access what, what is forbidden (USB storage, shared accounts), and what happens in case of loss or departure. Signed by everyone, it protects the company and makes things clear for all. See also IT governance and documentation (page in French).

Need help? We support SMEs, practices and individuals in French-speaking Switzerland. Discover our Microsoft 365 service (page in French) or call us on +41 21 519 21 27.

☕ New business customers: the first meeting is on us — a coffee and a free IT review, with no obligation.

Contact us 021 519 21 27

Read also

← All articles