Lost Phone or Angry Ex-Employee? Protecting Company Data on Personal Phones

When a phone with work email is lost or someone leaves on bad terms, can you remove the company data? Here's what to do today, and how app protection policies fix it without taking over anyone's phone.

An employee leaves their phone in a rideshare on Friday night. Or someone quits on bad terms and walks out with the phone they've used for work email for three years. Either way, the question is the same: what company data is on that phone, and can you get it off?

For most small businesses the honest answer is "a lot" and "no." The phone is personal, so nobody set it up, nobody put rules on it, and there's no way to remove just the company part. It's a company computer that follows none of your company's rules.

Quick answer

  1. If a phone is lost or someone has left today: reset their password and sign them out of every session (steps below). That cuts off email and files on that phone within about an hour.
  2. To be ready next time: turn on app protection policies for Outlook, Teams and OneDrive on personal phones. They let you wipe only the company data, and they're included in Microsoft 365 Business Premium.
  3. Set two rules: phones that open work email need a screen lock, and work data stays in the work apps.

If it's happening right now

Cut off access

A password change alone isn't enough. When someone signs in, the phone gets a session token, a "this device already signed in" pass, so it doesn't ask for the password every time. Anyone holding the unlocked phone doesn't need the password or the multi-factor code. You have to end those sessions explicitly.

In Microsoft 365, go to the Microsoft 365 admin center > Users > Active users, select the person, choose Reset password, then select their name again and on the Account tab choose Sign out of all sessions. Microsoft says it can take up to an hour for every app to notice. For someone who has left, also block their sign-in on the same page.

In Google Workspace, go to the Admin console > Directory > Users, open the person, reset the password, then under Security choose Sign-in cookies > Reset (Google's steps).

Remove the company data

If you already have app protection policies (below), go to the Microsoft Intune admin center > Apps > App selective wipe > Create wipe request, pick the user and the device, and choose Create. The next time the app runs, company email and files are removed from Outlook, Teams and OneDrive. Personal photos and apps aren't touched.

Without app protection, there's nothing to wipe selectively. Cutting off access stops new data arriving, but whatever is already cached on the phone stays there. That's the gap the rest of this post closes.

What's actually on that phone

"They read email on their phone" undersells it. A phone signed in to company email usually holds:

  • Cached mail and attachments. A local copy of months of messages, contracts and invoices, not just a window into the server.
  • A session token that lets it back in without a password.
  • Multi-factor codes. If your team uses text-message codes, the second factor arrives on the same device that holds the first. That's one factor and a formality.
  • Photos of documents. A signed form, a check, a driver's license for onboarding, sitting in the camera roll and syncing to a personal cloud account you've never heard of.
  • Saved passwords in the browser, a password app or a note.

Now add the everyday events that expose all of it: a phone left in a taxi, traded in or sold, or kept by someone who left angry. SecurityWeek notes that millions of phones and laptops go missing every year, but few are ever reported as data breaches, largely because nobody can prove what was on them. That doesn't mean the losses are harmless. It means they go uncounted.

Why attackers like phones too

It isn't only lost phones. Phones are also easier to fool. The sender's address is hidden behind a display name, long web addresses get cut off, and you can't hover over a link to preview it. People check them in line at the pharmacy, one-handed and half-distracted.

Attackers have built tactics around exactly this. The fastest-growing email attack Microsoft saw in early 2026 used QR codes, which push people from the protected work laptop onto their personal phone to scan. We cover that one in detail, including what to do if someone already scanned, in QR code phishing: the attack built to skip your email filter.

The fix: manage the work apps, not the phone

The usual recommendation is MDM (mobile device management): enroll the phone so the business controls it. On a personal phone, full MDM means the company could in principle wipe the whole device, family photos and all. Employees hate that, and they're right to. So the conversation stalls and everyone stays unmanaged.

The middle option is MAM (mobile app management), which Microsoft calls app protection policies. Instead of managing the phone, you put rules on the company data inside specific apps like Outlook, Teams, OneDrive and Word:

  • Require a PIN or fingerprint to open the work account in the app.
  • Keep company data encrypted inside the app.
  • Block copying work data into personal apps and saving attachments to the camera roll or a personal cloud.
  • Wipe only the company data when the phone is lost or the person leaves.

The phone isn't enrolled, and the company can't see or touch personal apps, photos or messages. That's the version employees will accept, because the pitch is true: we protect company data and leave yours alone.

What you need: Microsoft 365 Business Premium

App protection policies come from Microsoft Intune, and Microsoft 365 Business Premium includes Intune Plan 1, with app management for personal devices built in. Business Basic and Business Standard don't include Intune. They come with a lighter tool called Basic Mobility and Security, which can enroll and wipe devices but doesn't do app protection. If you're on Standard, upgrading the people who use personal phones for work (or buying Intune separately) is how you get it.

On Google Workspace, the equivalent controls (iOS app management, Android work profiles and advanced device management) are part of Business Plus and up.

Setting up app protection in Intune

This is the basic setup Microsoft recommends for Business Premium (menus as of October 2026):

  1. Sign in to the Microsoft Intune admin center (intune.microsoft.com) and go to Apps > Protection > Create policy, then choose iOS/iPadOS. You'll repeat this for Android.
  2. On Apps, set Target policy to Core Microsoft Apps. That covers Outlook, Teams, OneDrive, Word, Excel, Edge and the rest.
  3. On Data protection, set Backup org data to iTunes and iCloud backups to Block, Send org data to other apps to Policy managed apps, and Save copies of org data to Block, while allowing saves to OneDrive and SharePoint.
  4. On Access requirements, require a PIN (or fingerprint or face) for access.
  5. On Assignments, assign the policy to a group with the users who read work data on phones, then Create.
  6. Tell staff before it lands. The first time they open Outlook afterwards, they'll be asked to set a work PIN. Microsoft notes it can take a while for policies to reach existing devices.

Microsoft's step-by-step guide is How to create and assign app protection policies. Once the policies are working, add a Conditional Access rule that requires an app protection policy before a phone can reach company email, so people can't sidestep it with the phone's built-in mail app.

Your action plan

  1. List what "access" means. For each person, write down which company systems they reach from a personal device: email, files, the CRM, accounting.
  2. Turn on app protection policies for iOS and Android, as above.
  3. Get off text-message codes. Move to an authenticator app or, better, passkeys, which can't be typed into a fake login page. Our post on MFA fatigue and passkeys covers how.
  4. Set a minimum OS version. App protection policies can block work data on phones running an outdated iOS or Android. "Update your phone" is a request; a policy is a rule.
  5. Require a screen lock. A phone's built-in encryption only protects your data when a passcode is set; without one, anyone who picks it up can read it. App protection's work PIN adds a second lock on the company apps.
  6. Write an offboarding checklist and use it: block sign-in, reset the password, sign out of all sessions, then run the selective wipe.
  7. Use the free checklists. CISA's mobile device cybersecurity checklist and NIST's SP 800-124 Revision 2 are more rigorous than anything a vendor will hand you.

If steps 2, 3 and 6 are all you do, you've closed most of the gap.

When to call someone

  • A phone with company data is lost or a departure went badly, and you don't have app protection set up yet.
  • You're on Business Standard and need to decide whether Business Premium is worth it for your team.
  • Staff are pushing back on any management at all and you need a policy they'll sign.

If you'd like help setting it up, our IT services team does this for small offices.

Related reading