Skip to main content

Protecting Organization Data on Personal Devices

How managed web browsers and device checks, using tools like Google Cloud Identity Premium, help secure work on computers you don't own

Written by Giuseppe Morgana

Many organizations have staff doing at least some work on their own laptops and phones. This is often called Bring Your Own Device, or BYOD. Those devices belong to your people, not to you, so you have less say in how they're set up and used. That creates a gap: your data is only as safe as a laptop you've never seen and can't control.

You can't fully manage the device, but you can control the main door to your data. That means checking that the device meets a few basic requirements and that work happens in a browser you control before anyone gets in.

We recommend Google Cloud Identity Premium for this and reference it throughout this guide. We've found it to be a smooth experience for users, but the same approach can work with similar services.

What it is

Cloud Identity Premium is Google's upgraded set of tools for managing who can sign in to your organization's accounts and what devices they can sign in from. It checks the device, not just the password, and it adds protections inside the browser, where most of the work happens. Together, that gives you real protection for organization data on computers you don't own, without taking over someone's personal laptop.

Why it especially matters for BYOD

When your team works on personal laptops, you can't fully manage the hardware. Cloud Identity Premium lets us set conditions on the access instead. Organization data can only be reached from a device that passes the checks we set, through a Chrome profile we manage.

Those checks look at things we can actually verify:

  • The hard drive is encrypted

  • A screen lock is turned on

  • The operating system is up to date

  • The device has been approved

  • The Chrome profile is managed by your organization

Without Cloud Identity Premium, these are recommendations you hope people follow. With it, these are requirements you can enforce.

What we can protect inside the browser

Because work now has to happen in that managed Chrome profile, we can also protect what happens inside the browser:

  • Only approved extensions. We approve the extensions your team can use and block everything else. Extensions are an easy way in for attackers: people install them casually, malware can add them quietly, and many are allowed to read every page you visit.

  • Dangerous sites and downloads are blocked. Known phishing and malware sites are stopped while someone is working in the managed profile. We can also push out rules to block attacks targeting your organization.

  • A clearer picture when something goes wrong. In the event of an incident, we have better visibility into actions that were taken, which can help us investigate and stop an attack from spreading.

What it's like for your team

They keep using Chrome. No new browser if they are using Chrome, no different login routine. Work happens in a dedicated Chrome profile that gets set up automatically, and their existing personal profiles keep working exactly as they do today.

Some users may be prompted to install a lightweight component by Google that reads basic information like device encryption status, whether there is a password on the device, and basic device identifiers such as serial number and operating system version. After setup most people don't notice anything different as long as they keep their device in compliance.

More details about the on-device capabilities, including what device data is accessible by your organization, can be found at the Google Endpoint Verification overview and Device attributes collected by Endpoint Verification.

What it does not do

It does not monitor personal activity or manage the whole device. It governs the work context in the browser on a personal machine, not the machine itself. No access is enabled to personal email, files, or browsing outside the managed Chrome profile, and users' other Chrome profiles keep working as they do today.

It does not give you full visibility into a personal device. The checks are focused on the signals listed above. We can optionally add targeted checks for things we name in advance, such as whether a required security tool is installed, but these return metadata, not contents. It is not a scan of the device. Passing means the device met your stated conditions, not that it is clean. More details about the latest capabilities and data that can be accessed can be found at the links above.

It does not replace advanced device security. Endpoint detection and response (EDR) protects the device itself, meaning the operating system, local files, and anything happening outside the browser. Cloud Identity Premium protects the path to your data. The two are complements. The practical difference is that EDR is more intrusive and often used on a device your organization owns and controls, while browser and identity enforcement is more practical on personal hardware.

Common questions

Should we allow personal laptops at all? The most secure option is to provide and manage organization-owned laptops. Some organizations find that isn't practical, so when personal devices are part of how your team works, the goal is to close the real gaps they create as much as you can. The approach in this guide is one way that we do that.

Do we need Google Workspace? It works best with Google Workspace, but we can set up Cloud Identity even if you use Microsoft or other tools.

Do we still need multi-factor authentication and security keys or passkeys? Yes. Those prove the right person is signing in; Premium adds a check that they're on an approved device. MFA and security keys are part of standard Google account security and don't require Premium. You want both in place before anyone reaches organization data.

Will employees install anything? On laptops, a small Google component reports device status (see above). Phone work profiles and controls are set up separately.

How is it licensed? Per person, not per device. One license covers someone's laptops, phones, and tablets, and anyone signing in to a managed account needs one. Priced per user per month. If you use Google Workspace, this will be an add-on to your plan.

What if I also wanted to stop people from copying or uploading company data to places it shouldn't go? That's data loss prevention (DLP), and it comes from Chrome Enterprise Premium, a separate subscription that complements Cloud Identity Premium. It can block or warn when someone copies, pastes, prints, downloads, or uploads organization data to personal accounts, personal storage, or outside AI tools. Ask us if you’d like to explore this for your organization.

Did this answer your question?