An enterprise application on a personal phone lacks the same authority as a fully managed device. Align protection with data separation, privacy and management boundaries.
Evaluation approach
MDM manages device or profile policies; RASP assesses application runtime conditions. Set collection, device requirements and restrictions according to the enterprise use case.
Application example
For an expense application, consider narrow transaction-relevant signals instead of inventorying every personal app. Provide a general block explanation and support reference.
Limits and considerations
Connecting a personal device to work does not justify unrestricted monitoring. Verify separation between managed and personal profiles.
Checks and decisions
- Separate MDM and RASP duties
- Match collection to employee notices
- Define alternative access
Use proportionate policies; corporate and personal devices may need different treatment.
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.