An acceptable use policy (AUP) sets the rules for how employees may use company devices, apps and data. For any fleet that mixes corporate and personal phones, it is the document that turns your security posture into something staff can read, sign and follow.
What is an acceptable use policy for mobile devices?
An acceptable use policy for mobile devices is a written agreement that defines what employees can and cannot do with the smartphones, tablets and laptops they use for work. It covers permitted apps, data handling, security requirements such as passcodes and encryption, and what happens when a device is lost or an employee leaves. On a managed fleet, the AUP is what the MDM enforces in practice.
Why does a mobile fleet need one?
Three reasons. It protects company data by making expectations explicit before an incident, not after. It protects the employee, by stating clearly what the company can and cannot see on a device, which matters most on personal phones under BYOD. And it gives IT a basis to act: without a signed policy, remote-wiping a lost device or blocking an app is a decision no one agreed to.
What should an acceptable use policy include?
A workable AUP for a mobile fleet covers eight areas:
- Scope: which devices and which people the policy applies to, corporate-owned and BYOD.
- Permitted use: what work apps and services are allowed, and whether limited personal use is tolerated.
- Prohibited use: jailbreaking, installing apps from unknown sources, sharing credentials, storing company data in unapproved cloud accounts.
- Security requirements: passcode, screen lock, device encryption, OS updates kept current.
- Data ownership: what belongs to the company and what stays private to the employee, and what the MDM can and cannot access.
- Monitoring and privacy: exactly what IT can see, which on a well-configured MDM is device compliance, not personal content.
- Incident handling: how to report a lost or stolen device, and the response, including remote lock or selective wipe of work data.
- Offboarding: what happens to the device and the company data when someone leaves.
How do you enforce an acceptable use policy in practice?
A policy no one enforces is a document, not a control. An MDM turns each clause into a setting: it requires the passcode, enforces encryption, blocks unapproved app sources, keeps the OS updated, and on personal devices separates work data so that IT manages the work container without touching private photos or messages. When someone leaves, a selective wipe removes company data and nothing else. This is how mobile device management makes an AUP real, and how BYOD security keeps it fair to the employee.
How do you write and roll out an AUP?
Keep it short enough to be read. Draft the eight sections above in plain language, have legal and a works council or employee representative review the privacy clauses, then require a signature at onboarding and after any major change. On a managed fleet, map each clause to an MDM setting so the policy and the enforcement never drift apart. Review it once a year, and whenever you add a new operating system or a new class of device.
Frequently asked questions
Is an acceptable use policy legally required?
Not universally, but data protection regimes such as the GDPR expect you to secure personal data, and a signed AUP is strong evidence that you set and communicated the rules. For BYOD it also protects the employer by documenting consent to management.
Does the AUP differ for BYOD versus corporate devices?
Yes. On corporate-owned devices the company can manage the whole device. On BYOD the policy must be narrower and state plainly that management is limited to the work container, or employees will not enrol.